Free CIPP-E Exam Files Verified & Correct Answers Downloaded Instantly [Q24-Q45]

Share

Free CIPP-E Exam Files Verified & Correct Answers Downloaded Instantly

Instant Download CIPP-E Dumps Q&As Provide PDF&Test Engine


IAPP CIPP-E certification exam is a valuable credential for privacy professionals who work in Europe or with European data. CIPP-E exam is designed to test the candidate’s knowledge of GDPR and data protection principles, and is offered by the world’s largest association of privacy professionals. Certified Information Privacy Professional/Europe (CIPP/E) certification is valid for three years and can be renewed by earning continuing education credits.


The CIPP-E exam consists of 90 multiple-choice questions that must be completed within two and a half hours. CIPP-E exam is challenging, and it requires a thorough understanding of the laws and regulations governing data protection in Europe. To prepare for the exam, candidates are advised to review the IAPP's official study materials, which cover all of the topics that will be tested.


The CIPP-E exam is a rigorous and challenging certification program that requires extensive preparation and study. CIPP-E exam consists of 90 multiple-choice questions that must be completed within 2.5 hours. The passing score for the exam is 300 out of a possible 500 points. CIPP-E exam is available in multiple languages, including English, French, German, Italian, and Spanish.

 

NEW QUESTION # 24
According to the European Data Protection Board, which of the following concepts or practices does NOT follow from the principles relating to the processing of personal data under EU data protection law?

  • A. Error propagation avoidance along the processing chain.
  • B. Data ownership allocation.
  • C. Frequent pseudonymization key rotation.
  • D. Access control management.

Answer: C


NEW QUESTION # 25
SCENARIO
Please use the following to answer the next question:
You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company's revenue is due to international sales.
The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children's questions on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well.
The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.
When a child asks the toy a question, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure's integrated speakers, making it appear as though that the toy is actually responding to the child's question. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.
In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures' abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character's abilities remain intact.
In light of the requirements of Article 32 of the GDPR (related to the Security of Processing), which practice should the company institute?

  • A. Include three-factor authentication before each use by a child in order to ensure the best level of security possible.
  • B. Encrypt the data in transit over the wireless Bluetooth connection.
  • C. Include dual-factor authentication before each use by a child in order to ensure a minimum amount of security.
  • D. Insert contractual clauses into the contract between the toy manufacturer and the cloud service provider, since South Africa is outside the European Union.

Answer: B


NEW QUESTION # 26
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?

  • A. The European Commission
  • B. The European Parliament
  • C. The Council of the European Union
  • D. The European Council

Answer: A

Explanation:
Reference https://www.tandfonline.com/doi/full/10.1080/13600834.2019.1573501


NEW QUESTION # 27
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?

  • A. Special categories of data
  • B. Data access disputes
  • C. Cross-border processing
  • D. Data subject rights

Answer: C

Explanation:
Explanation/Reference: https://iapp.org/news/a/is-it-possible-to-choose-your-lead-supervisory-authority-under-the-gdpr/


NEW QUESTION # 28
According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject's personal data has been obtained from other sources?

  • A. Within a reasonable period after obtaining the personal data, but no later than one month.
  • B. As soon as possible after obtaining the personal data.
  • C. As soon as possible after the first communication with the data subject.
  • D. Within a reasonable period after obtaining the personal data, but no later than eight weeks.

Answer: A

Explanation:
Reference https://dataprivacymanager.net/gdpr-exemptions-from-the-obligation-to-provide-information-to-the- individual-data-subject/


NEW QUESTION # 29
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?

  • A. When the personal data is held by the controller but not processed for further purposes
  • B. When the personal data is processed by an individual only for their household activities
  • C. When the personal data is processed only in non-electronic form
  • D. When the personal data is collected and then pseudonymised by the controller

Answer: D

Explanation:
Explanation/Reference: https://gdpr-info.eu/art-6-gdpr/


NEW QUESTION # 30
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA.
Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
In preparing the company for its impending lawsuit, Alice's instruction to the company's IT Department violated Article 5 of the GDPR because the company failed to first do what?

  • A. Minimize the amount of data collected for the lawsuit.
  • B. Inform all of its employees about the lawsuit.
  • C. Send out consent forms to all of its employees.
  • D. Encrypt the data from all of its employees.

Answer: A


NEW QUESTION # 31
Which statement provides an accurate description of a directive?

  • A. A directive is a legal act that applies automatically and uniformly to all EU countries as soon as it enters into force.
  • B. A directive speo5es certain results that must be achieved, but each member state is free to decide how to turn it into a national law
  • C. A directive is a legal act relating to specific cases and directed towards member states, companies 0' private individuals.
  • D. A directive has binding legal force throughout every member state and enters into force on a set date in all the member states.

Answer: D


NEW QUESTION # 32
There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?

  • A. Preventative security.
  • B. Incident detection and response.
  • C. Consent management and withdrawal.
  • D. Remedial security.

Answer: C


NEW QUESTION # 33
An entity's website stores text files on EU users' computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?

  • A. Data Protection Directive 95/46/EC.
  • B. E-Commerce Directive 2000/31/EC.
  • C. General Data Protection Regulation 2016/679.
  • D. E-Privacy Directive 2002/58/EC.

Answer: D


NEW QUESTION # 34
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?

  • A. Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.
  • B. Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.
  • C. Only where the personal data is to be subjected to specific computerized processing, such as image scanning or optical character recognition.
  • D. Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.

Answer: D

Explanation:
Explanation/Reference: https://www.zimmerslaw.com/english-1/data-protection/


NEW QUESTION # 35
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their failure to provide sufficient security safeguards to Company A's data.
  • B. Their engagement of Company C to improve their payroll service.
  • C. Their decision to operate without a data protection officer.
  • D. Their omission of data protection provisions in their contract with Company C.

Answer: B


NEW QUESTION # 36
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?

  • A. Special categories of data
  • B. Data access disputes
  • C. Cross-border processing
  • D. Data subject rights

Answer: C

Explanation:
Reference https://iapp.org/news/a/is-it-possible-to-choose-your-lead-supervisory-authority-under-the-gdpr/


NEW QUESTION # 37
SCENARIO
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage Why was Jackie correct in not completing a transfer impact assessment for HRYourWay?

  • A. HRYourWay is not located in a third country.
  • B. HRYourWay was ultimately not selected
  • C. ProStorage can rely on its Binding Corporate Rules
  • D. ProStorage will obtain consent for all transfers.

Answer: D


NEW QUESTION # 38
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Why would the consent provided by Ms. Iman NOT be considered valid in regard to JaphSoft?

  • A. She did not read the privacy notice stating that her personal data would be shared.
  • B. She has never made any purchases from JaphSoft and has no relationship with the company.
  • C. She only viewed the visual representations of the privacy notice Liem provided.
  • D. She was not told which controller would be processing her personal data.

Answer: A


NEW QUESTION # 39
Company X has entrusted the processing of their payroll data to Provider Y.
Provider Y stores this encrypted data on its server.
The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server.
In this scenario, whom does Provider Y have the obligation to notify?

  • A. Law enforcement
  • B. The public
  • C. Company X
  • D. The supervisory authority

Answer: A


NEW QUESTION # 40
Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit organizations in a privacy group litigation or class action. These organizations are commonly known as?

  • A. Constitutional rights organizations.
  • B. Law firm organizations.
  • C. Human rights organizations.
  • D. Civil society organizations.

Answer: B


NEW QUESTION # 41
MagicClean is a web-based service located in the United States that matches home cleaning services to customers. It otters its services exclusively in the United States It uses a processor located in France to optimize its dat a. Is MagicClean subject to the GDPR?

  • A. No, because MagicClean is located m the United States only.
  • B. No. because MagicClean is not offering services to EU data subjects.
  • C. Yes. because MagicClean's data processing agreement with the French processor is an establishment in the EU
  • D. Yes, because MagicClean is processing data in the EU

Answer: C


NEW QUESTION # 42
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage What transfer mechanism did ProStorage most likely rely on to transfer Ruth's medical information to the hospital?

  • A. Protecting the vital interest of Ruth
  • B. Ruth's implied consent.
  • C. Performance of a contract with Ruth.
  • D. Protecting against legal liability from Ruth.

Answer: D


NEW QUESTION # 43
Please use the following to answer the next question:
WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:
"WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the dat a. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information. We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."
"We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."
"We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities." What direct marketing information can WonderKids send by email without prior consent of the person booking the childcare?

  • A. Marketing information related to other business operations of WonderKids.
  • B. Marketing information for products or services similar to those purchased from WonderKids.
  • C. No marketing information at all.
  • D. Any marketing information at all.

Answer: A


NEW QUESTION # 44
What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?

  • A. The establishment of a list of legitimate data processing criteria
  • B. The restriction of cross-border data flow
  • C. The creation of legally binding data protection principles
  • D. The synchronization of approaches to data protection

Answer: D

Explanation:
Reference https://ico.org.uk/media/about-the-ico/documents/1042349/review-of-eu-dp-directive.pdf (99)


NEW QUESTION # 45
......

Exam Valid Dumps with Instant Download Free Updates: https://examkiller.itexamreview.com/CIPP-E-valid-exam-braindumps.html