
[Aug 26, 2023] 100% Latest Most updated CIPP-E Questions and Answers
Try with 100% Real Exam Questions and Answers
NEW QUESTION # 21
What is true of both the General Data Protection Regulation (GDPR) and the Council of Europe Convention
108?
- A. Both require notification of processing activities to a supervisory authority
- B. Both govern international transfers of personal data
- C. Both govern the manual processing of personal data
- D. Both only apply to European Union countries
Answer: A
NEW QUESTION # 22
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?
- A. When the personal data is processed by an individual only for their household activities
- B. When the personal data is collected and then pseudonymised by the controller
- C. When the personal data is held by the controller but not processed for further purposes
- D. When the personal data is processed only in non-electronic form
Answer: B
Explanation:
Explanation/Reference: https://gdpr-info.eu/art-6-gdpr/
NEW QUESTION # 23
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
- A. The requirement to demonstrate compliance to a supervisory authority.
- B. The obligation of companies to declare data breaches.
- C. The necessity of the bulk collection of personal data by the government.
Answer: A
NEW QUESTION # 24
Select the answer below that accurately completes the following:
"The right to compensation and liability under the GDPR...
- A. ...provides for an exemption from liability if the data controller (or data processor) proves that it is not in any way responsible for the event giving rise to the damage."
- B. ...precludes any subsequent recourse proceedings against other controllers or processors involved in the same processing."
- C. ...can only be exercised against the data controller, even if a data processor was involved in the same processing."
- D. ...is limited to a maximum amount of EUR 20 million per event of damage or loss."
Answer: B
NEW QUESTION # 25
SCENARIO
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage Why is the additional measure recommended by Jackie sufficient foe using UpFinance?
- A. UpFinance is based in a country without surveillance laws.
- B. UpFinance is in a highly regulated financial industry
- C. UpFinance is an established 7-year-old business.
- D. UpFinance implements sufficient data protection measures
Answer: A
NEW QUESTION # 26
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?
- A. Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.
- B. Name and contact details of each controller on behalf of which the processor is acting.
- C. Categories of processing carried out on behalf of each controller for which the processor is acting.
- D. Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.
Answer: A
Explanation:
Explanation/Reference: https://gdpr-info.eu/art-30-gdpr/
NEW QUESTION # 27
Which of the following is one of the supervisory authority's investigative powers?
- A. To determine whether a controller or processor has the right to a judicial remedy concerning a compensation decision made against them.
- B. To require that controllers or processors adopt approved data protection certification mechanisms.
- C. To notify the controller or the processor of an alleged infringement of the GDPR.
- D. To require data controllers to provide them with written notification of all new processing activities.
Answer: C
Explanation:
Reference https://gdpr-info.eu/art-58-gdpr/
NEW QUESTION # 28
A Spanish electricity customer calls her local supplier with questions about the company's upcoming merger.
Specifically, the customer wants to know the recipients to whom her personal data will be disclosed once the merger is final. According to Article 13 of the GDPR, what must the company do before providing the customer with the requested information?
- A. Verify that the purpose of the request from the customer is in line with the GDPR.
- B. Verify that the identity of the customer can be proven by other means.
- C. Verify that the request is applicable to the data collected before the GDPR entered into force.
- D. Verify that the personal data has not already been sent to the customer.
Answer: C
Explanation:
Explanation/Reference: https://fpf.org/wp-content/uploads/2018/11/GDPR_CCPA_Comparison-Guide.pdf
NEW QUESTION # 29
An entity's website stores text files on EU users' computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?
- A. Data Protection Directive 95/46/EC.
- B. E-Commerce Directive 2000/31/EC.
- C. E-Privacy Directive 2002/58/EC.
- D. General Data Protection Regulation 2016/679.
Answer: A
NEW QUESTION # 30
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
- A. Data inventory or data mapping exercises that have been conducted.
- B. Incidents of personal data breaches, whether disclosed or not.
- C. Retention periods for erasure and deletion of categories of personal data.
- D. Categories of recipients to whom the personal data have been disclosed.
Answer: C
Explanation:
Section: (none)
Explanation
NEW QUESTION # 31
You are the new Data Protection Officer for your company and have to determine whether the company has implemented appropriate technical and organizational measures as required by Article 32 of the GDPR. Which of the following would be the most important to consider when trying to determine this?
- A. Which security measures are endorsed by a majority of experts.
- B. How the public perceives what constitutes adequate security measures
- C. Which kinds of security measures your company has employed in the past
- D. How security measures might evolve in the future
Answer: B
NEW QUESTION # 32
Which type of personal data does the GDPR define as a "special category" of personal data?
- A. Financial information.
- B. Educational history.
- C. Closed Circuit Television (CCTV) footage.
- D. Trade-union membership.
Answer: D
Explanation:
Reference https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection- regulation-gdpr/lawful-basis-for-processing/special-category-data/#:~:text=The%20GDPR%20defines% 20special%20category%20data%20as%3A&text=personal%20data%20revealing%20trade%20union,used% 20for%20identification%20purposes)%3B
NEW QUESTION # 33
SCENARIO
Please use the following to answer the next question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
Which statement accurately summarizes Bedrock's obligation in regard to Louis's data portability request?
- A. Bedrock does not have a duty to transfer Louis's data to Zantrum if doing so is legitimately not technically feasible.
- B. Bedrock has failed to comply with the duty to transfer Louis's data to Zantrum because the duty applies wherever personal data are processed by automated means and necessary for the performance of a contract with the customer.
- C. Bedrock has failed to comply with the duty to transfer Louis's data to Zantrum because it has an obligation to develop commonly used, machine-readable and interoperable formats so that all customer data can be ported to other insurers on request.
- D. Bedrock does not have to transfer Louis's data to Zantrum because the right to data portability does not apply where personal data are processed in order to carry out tasks in the public interest.
Answer: D
NEW QUESTION # 34
Jerry the Chief Marketing Officer for a sports apparel and trophy company, sells products to schools and athletic clubs globally Recently the company has decided to invest in a new line of customized sports equipment Jerry plans to email his current customer base to offer them a discount on their first purchase of such equipment.
Jerry tells Kate, the Director of Privacy, about his plan. What is the best guidance Kate can provide to Jerry?
- A. Permit Jerry to carry out his plan on the basis of marketing similar products to existing customers.
- B. Require Jerry to include an option to opt out of marketing emails in the future
- C. Permit Jerry to carry out his marketing plan on the basis of legitimate interest
- D. Require Jerry to send all current customers a second notice to allow them to opt-in to marketing emails
Answer: D
NEW QUESTION # 35
Which GDPR requirement will present the most significant challenges for organizations with Bring Your Own Device (BYOD) programs?
- A. Data subjects must be sufficiently informed of the purposes for which their personal data is processed.
- B. Processing of special categories of personal data on a large scale requires appointing a DPO.
- C. Data controllers must be in control of the data they hold at all times.
- D. Personal data of data subjects must always be accurate and kept up to date.
Answer: C
NEW QUESTION # 36
A homeowner has installed a motion-detecting surveillance system that films his front doc and entryway. The camera does not film any public areas only areas that are the property of the homeowner. The system has seen declared to the authorities per the homeowner's country law, and a placard indicating the area is being video monitored is visible when entering the property Why can the homeowner NOT depend on the household exemption with regards to the processing of the video images recorded by the surveillance camera system?
- A. The homeowner has not specified which security measures ore in place as part of the surveillance camera system
- B. The GDPR specifically excludes surveillance camera images from the household exemption
- C. The surveillance camera system can potentially capture biometric information of the homeowner's family, which would be considered a processing of special categories of personal data.
- D. The surveillance camera system can potentially film individuals who enter its filming perimeter
Answer: C
NEW QUESTION # 37
If two controllers act as joint controllers pursuant to Article 26 of the GDPR, which of the following may NOT be validly determined by said controllers?
- A. The rules to provide information to data subjects in Articles 13 and 14.
- B. The rules regarding the exercising of data subjects" rights.
- C. The non-disclosure of the essence of their arrangement to data subjects
- D. The definition of a central contact point for data subjects.
Answer: A
NEW QUESTION # 38
SCENARIO
Please use the following to answer the next question:
You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company's revenue is due to international sales.
The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children's questions on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well. The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.
When a child asks the toy a question, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure's integrated speakers, making it appear as though that the toy is actually responding to the child's question. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.
In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures' abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character's abilities remain intact.
Why is this company obligated to comply with the GDPR?
- A. The company has offices in the EU.
- B. The company employs staff in the EU.
- C. The company's data center is located in a country outside the EU.
- D. The company's products are marketed directly to EU customers.
Answer: D
NEW QUESTION # 39
SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles. Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Based on the scenario, what is the main reason that Brady should be concerned with Hermes Designs' handling of customer personal data?
- A. The data is sensitive.
- B. The data is uncategorized.
- C. The data is being used for a new purpose.
- D. The data is being processed via a new means.
Answer: C
NEW QUESTION # 40
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canad a. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
The Customer for Life plan may conflict with which GDPR provision?
- A. Article 16, which provides data subjects with a rights to rectification.
- B. Article 20, which gives data subjects a right to data portability.
- C. Article 6, which requires processing to be lawful.
- D. Article 7, which requires consent to be as easy to withdraw as it is to give.
Answer: D
NEW QUESTION # 41
......
New IAPP CIPP-E Dumps & Questions: https://www.vcetorrent.com/CIPP-E-valid-vce-torrent.html
Dumps to Pass your CIPP-E Exam with 100% Real Questions and Answers: https://drive.google.com/open?id=1fIZF71AnJkQY7hEIOgCXWxKx9bk7N5cN