
CIPP-E Exam Dumps Free Test Engine Verified By Certified Information Privacy Professional Certified Experts
Use Real IAPP Achieve the CIPP-E Dumps - 100% Exam Passing Guarantee
IAPP CIPP-E (Certified Information Privacy Professional/Europe) Exam is designed for professionals who are interested in gaining expertise in European data protection laws and regulations. Certified Information Privacy Professional/Europe (CIPP/E) certification is internationally recognized and is a valuable asset for professionals working in the field of privacy and data protection.
NEW QUESTION # 32
WP29's "Guidelines on Personal data breach notification under Regulation 2016/679'' provides examples of ways to communicate data breaches transparently. Which of the following was listed as a method that would NOT be effective for communicating a breach to data subjects?
- A. A postal notification
- B. A notice on a corporate blog
- C. A prominent advertisement in print media
- D. A direct electronic message
Answer: B
Explanation:
Reference https://www.google.com/url? sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwih19CSx9LqAhVQe8AKHe- VDQEQFjAAegQIAhAB&url=https%3A%2F%2Fec.europa.eu%2Fnewsroom%2Farticle29%2Fdocument.cfm% 3Fdoc_id%3D49827&usg=AOvVaw2uhYsKyRzJ6lwhQyiMURJF (21)
NEW QUESTION # 33
Which statement provides an accurate description of a directive?
- A. A directive is a legal act that applies automatically and uniformly to all EU countries as soon as it enters into force.
- B. A directive has binding legal force throughout every member state and enters into force on a set date in all the member states.
- C. A directive speo5es certain results that must be achieved, but each member state is free to decide how to turn it into a national law
- D. A directive is a legal act relating to specific cases and directed towards member states, companies 0' private individuals.
Answer: C
Explanation:
According to the EU glossary1, a directive is a legal act that sets out a goal that EU countries must achieve, but leaves them the choice of form and methods to reach it. A directive is binding on the EU countries to which it is addressed, but it does not apply directly at the national level. Instead, it has to be transposed into national law by the national authorities, usually within a specified time limit. This allows for some flexibility and adaptation to the specific circumstances of each country. A directive is different from a regulation, which is a legal act that applies automatically and uniformly to all EU countries as soon as it enters into force, without needing to be transposed into national law. Reference:
Free CIPP/E Study Guide, page 14, section 2.3
Types of legislation, section 2
What are EU directives?
NEW QUESTION # 34
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?
- A. Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.
- B. Only where the personal data is to be subjected to specific computerized processing, such as image scanning or optical character recognition.
- C. Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.
- D. Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.
Answer: D
Explanation:
The GDPR applies to all personal data, regardless of whether it exists in physical form or not. The GDPR defines personal data as any information relating to an identified or identifiable natural person, such as names, identification numbers, location data, or online identifiers1. Therefore, any information that can be linked directly or indirectly to a natural person is considered personal data under the GDPR.
However, the GDPR also distinguishes between different types of processing activities and their legal bases. Processing activities are the operations performed on personal data, such as collection, storage, use, disclosure, or deletion. Processing activities can be either automated or manual. Automated processing means using technology to perform processing activities without human intervention. Manual processing means using human intervention to perform processing activities.
The GDPR requires that any processing activity that involves personal data must comply with certain principles and conditions, such as lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality. These principles and conditions apply to both automated and manual processing activities.
Therefore, the GDPR applies to personal data that exists in physical form only when it is processed by an automated means in some way that affects its rights and freedoms. For example, if a company scans paper documents and stores them electronically in a database without deleting them after a certain period of time or when they are no longer needed for the original purpose for which they were collected (Article 6), then this would be considered an automated processing activity that involves personal data in physical form.
However, the GDPR does not apply to personal data that exists in physical form when it is handled in a sufficiently structured manner so as to form part of a filing system. For example, if a company keeps paper documents in folders labeled with names and dates on their office shelves without scanning them or storing them electronically anywhere else (Article 5), then this would not be considered an automated processing activity that involves personal data in physical form.
Reference:
Physical Data - GDPR Summary
What GDPR Means for Your Physical Records - Access
Personal Data - Data Protection Act 2018
NEW QUESTION # 35
If a company chooses to ground an international data transfer on the contractual route, which of the following is NOT a valid set of standard contractual clauses?
- A. Decision 2010/87/EU (Non-EU or EEA processor from EU controller).
- B. Decision 2007/72/EC (EU processor to non-EU or EEA controller).
- C. Decision 2001/497/EC (EU controller to non-EU or EEA controller).
- D. Decision 2004/915/EC (EU controller to non-EU or EEA controller).
Answer: D
NEW QUESTION # 36
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
- A. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- B. A company wants to combine location data with other data in order to offer more personalized service for the customer.
- C. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
- D. A company wants to use location data to infer information on a person's clothes purchasing habits.
Answer: A
Explanation:
According to Article 35 of the GDPR, a Data Protection Impact Assessment (DPIA) is required when the processing of data is likely to result in a high risk to the rights and freedoms of natural persons, especially when using new technologies. A DPIA is supposed to show the characteristics of the processing, the risks and the measures adopted to mitigate them. The GDPR also provides some examples of processing operations that require a DPIA, such as:
a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, and on which decisions are based that produce legal or significant effects on the data subject; processing on a large scale of special categories of data or data relating to criminal convictions and offences; or a systematic monitoring of a publicly accessible area on a large scale.
Among the answer choices, only option C falls under the first example, as it involves a systematic and extensive evaluation of personal aspects based on location data and data from third-party sources, which could be used for profiling and matching purposes. This could have significant effects on the data subjects' privacy, personal relationships and reputation. Therefore, a DPIA would be required for this processing operation.
Option A does not necessarily involve a systematic and extensive evaluation of personal aspects, nor does it produce legal or significant effects on the data subject. It could be considered a legitimate interest of the company to offer more personalized service, as long as it respects the principles of data minimization, purpose limitation and transparency.
Option B does not involve a decision based on the processing, nor does it produce legal or significant effects on the data subject. It could be considered a form of direct marketing, which is subject to specific rules under the GDPR and the ePrivacy Directive.
Option D does not involve personal data relating to natural persons, but rather to delivery trucks. Therefore, it does not pose a high risk to the rights and freedoms of natural persons.
Reference:
GDPR Article 35
Guidelines on DPIA
Art. 35 GDPR - Data protection impact assessment - GDPR.eu
NEW QUESTION # 37
What is an important difference between the European Court of Human Rights (ECHR) and the Court of Justice of the European Union (CJEU) in relation to their roles and functions?
- A. CJEU can hear appeals on human rights decisions made by national courts, while the ECHR cannot.
- B. ECHR can enforce human rights laws against governments that fail to implement them, while the CJEU cannot.
- C. CJEU can force national governments to implement and honor EU law, while the ECHR cannot.
- D. ECHR can rule on issues concerning privacy as a fundamental right, while the CJEU cannot.
Answer: C
NEW QUESTION # 38
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
As a result of Sam's actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?
- A. Notify its Data Protection Authority about the data breach.
- B. Analyze and evaluate all of its breach notification obligations.
- C. Notify all of its customers that reside in the European Union.
- D. Analyze and evaluate the liability for customers in Ireland.
Answer: A
NEW QUESTION # 39
What was the aim of the European Data Protection Directive 95/46/EC?
- A. To harmonize the implementation of the European Convention of Human Rights across all member states.
- B. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.
- C. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.
- D. To completely prevent the transfer of personal data out of the European Union.
Answer: C
Explanation:
Reference https://www.oecd.org/sti/ieconomy/oecd_privacy_framework.pdf (3)
NEW QUESTION # 40
The Planet 49 CJEU Judgement applies to?
- A. Cookies used only by third parties.
- B. Cookies regardless of whether the data accessed is personal or not.
- C. Cookies that are deemed technically necessary.
- D. Cookies where the data accessed is considered as personal data only.
Answer: B
Explanation:
Reference https://www.twobirds.com/en/news/articles/2019/global/planet49-cjeu-rules-on-cookie-consent
NEW QUESTION # 41
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''
- A. No. the assessors do not quality as data processors as they do not copy the data to their facilities.
- B. Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.
- C. No, the assessors do not quality as data processors as they only have access to encrypted data.
- D. Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.
Answer: B
NEW QUESTION # 42
According to the E-Commerce Directive 2000/31/EC, where is the place of "establishment" for a company providing services via an Internet website confirmed by the GDPR?
- A. Where the decisions about processing are made
- B. Where the customer's Internet service provider is located
- C. Where the technology supporting the website is located
- D. Where the website is accessed
Answer: B
NEW QUESTION # 43
The GDPR specifies fines that may be levied against data controllers for certain infringements. Which of the following infringements would be subject to the less severe administrative fine of up to 10 million euros (or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year)?
- A. Failure to process personal information in a manner compatible with its original purpose.
- B. Failure to implement technical and organizational measures to ensure data protection is enshrined by design and default.
- C. Failure to demonstrate that consent was given by the data subject to the processing of their personal data where it is used as the basis for processing.
- D. Failure to provide the means for a data subject to rectify inaccuracies in personal data.
Answer: B
NEW QUESTION # 44
SCENARIO
Please use the following to answer the next question:
BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information - name, location, and prior purchase history - with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.
Prior to sharing its customer list, BHealthy conducted a review of Natural Insight's security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy's data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight's machine learning algorithms.
What is the nature of BHealthy and Natural Insight's relationship?
- A. Natural Insight is BHealthy's processor because BHealthy is sharing its customer information with Natural Insight.
- B. Natural Insight is a controller because it is separately determine the purpose of processing when it uses BHealthy's customer information to improve its machine learning algorithms.
- C. Natural Insight is the controller because it determines the security measures to implement to protect data it processes; BHealthy is a co-controller because it engaged Natural Insight to determine pricing for the new sunscreens.
- D. Natural Insight is BHealthy's processor because the companies entered into data processing terms.
Answer: B
Explanation:
According to the GDPR, a controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data1. A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller1. The controller and the processor must enter into a contract or other legal act that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller2.
In this scenario, BHealthy is the controller for the personal data of its customers, as it determines the purposes and means of the processing, such as conducting research to decide how to market its new line of sunscreens across Europe. Natural Insight is the processor for the personal data that BHealthy shares with it, as it processes the data on behalf of BHealthy for the purpose of determining the price point for the new sunscreens. However, Natural Insight is also a controller for the same personal data when it uses it for its own purpose of improving its machine learning algorithms, which is not part of the contract or legal act with BHealthy. Therefore, Natural Insight is a controller and a processor for the same personal data, depending on the purpose of the processing3.
Reference:
Art. 4 GDPR - Definitions
Art. 28 GDPR - Processor
Guidelines 07/2020 on the concepts of controller and processor in the GDPR I hope this helps you understand the GDPR and the controller-processor relationship better. If you have any other questions, please feel free to ask me.
NEW QUESTION # 45
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?
- A. Encrypting data in transit and at rest using strong encryption algorithms.
- B. Anonymizing special categories of data.
- C. Getting consent from the data subject for a cross border data transfer.
- D. Conducting regular audits of the data protection program.
Answer: D
Explanation:
The accountability principle found in Article 5, Section 2 of the GDPR requires data controllers to take responsibility for complying with the GDPR and to be able to demonstrate their compliance1. This means that data controllers must implement appropriate technical and organisational measures to ensure and show that they process personal data in accordance with the GDPR2. One of the measures that can demonstrate compliance with the accountability principle is conducting regular audits of the data protection program. Audits are systematic and independent assessments of the data processing activities and the data protection policies and procedures of an organisation3. They can help to identify and address any gaps or risks in the data protection program, as well as to verify the effectiveness and efficiency of the data protection measures3. Audits can also provide evidence of compliance to the supervisory authorities and the data subjects, as well as to enhance the trust and reputation of the organisation3. Therefore, conducting regular audits of the data protection program is a way to demonstrate compliance with the accountability principle. Reference: 1: CIPP/E study guide, page 15; Art. 5 GDPR; Accountability principle | ICO2: CIPP/E study guide, page 16; Art. 24 GDPR; [Guide to accountability and governance | ICO]3: CIPP/E study guide, page 91; [Auditing | ICO]; [GDPR Audits: What You Need to Know - IT Governance Blog].
NEW QUESTION # 46
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018 guidance, company Z should do which of the following?
- A. Notify the supervisory authority about the loss of availability
- B. Document the loss of availability to demonstrate accountability
- C. Conduct a thorough audit of all security systems
- D. Notify affected individuals that their data was unavailable for a period of time.
Answer: A
Explanation:
Explanation/Reference: https://www.google.com/url?
sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwihmsidxtTqAhXvQUEAHXRaAdYQFjABegQIARAB& url=https%3A%2F%2Fec.europa.eu%2Fnewsroom%2Farticle29%2Fdocument.cfm%3Fdoc_id%
3D49827&usg=AOvVaw2uhYsKyRzJ6lwhQyiMURJF (5)
NEW QUESTION # 47
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
- A. The predicted consequences of the breach.
- B. The measures being taken to address the breach.
- C. The contact details of the appropriate data protection officer.
- D. The type of security safeguards used to protect the data.
Answer: A
Explanation:
According to the CIPP/E study guide, Article 33 of the GDPR requires data controllers to notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons1. Article 34 of the GDPR requires data controllers to communicate the personal data breach to the data subject without undue delay when the breach is likely to result in a high risk to the rights and freedoms of natural persons2. Both articles specify the minimum information that the data controller must provide to the supervisory authority and the data subject, which includes: the nature of the breach, the categories and approximate number of data subjects and personal data records concerned, the name and contact details of the data protection officer or other contact point, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its possible adverse effects12. However, neither article requires the data controller to disclose the type of security safeguards used to protect the data, as this information is not relevant for the purposes of notification and may even compromise the security of the data further3. Reference: 1: CIPP/E study guide, page 84; Art. 33 GDPR; Guidelines 01/2021 on Examples regarding Data Breach Notification2: CIPP/E study guide, page 85; [Art. 34 GDPR]; Guidelines 01/2021 on Examples regarding Data Breach Notification3: Personal Data Breach | European Data Protection Supervisor; What is a data breach and what do we have to do ... - European Commission.
NEW QUESTION # 48
The transparency principle is most directly related to which of the following rights?
- A. Right to restriction of processing.
- B. Right to be informed.
- C. Right to object
- D. Right to be forgotten.
Answer: B
Explanation:
The transparency principle, as stated in Article 5(1)(a) of the GDPR, requires that personal data be processed lawfully, fairly and in a transparent manner in relation to the data subject. This principle is closely linked to the right to be informed, as specified in Articles 13 and 14 of the GDPR, which oblige the controller to provide the data subject with certain information about the processing of their personal data, such as the identity and contact details of the controller, the purposes and legal basis of the processing, the recipients or categories of recipients of the personal data, the existence of the data subject's rights, and the retention period or criteria for the personal data. The right to be informed aims to ensure that the data subject is aware of and can verify the lawfulness of the processing, and to enable them to exercise their rights effectively. Therefore, the transparency principle is most directly related to the right to be informed. Reference:
Article 5(1)(a) of the GDPR
Article 13 of the GDPR
Article 14 of the GDPR
IAPP CIPP/E Study Guide, page 31
NEW QUESTION # 49
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?
- A. The Council of the European Union
- B. The European Commission
- C. The European Council
- D. The European Parliament
Answer: B
Explanation:
According to the CIPP/E study guide1, the European Commission is the EU institution that has the power to propose new data protection legislation on its own initiative, as well as amend or repeal existing laws. The European Commission is also responsible for implementing and enforcing the EU data protection framework, in cooperation with other institutions and national authorities.
NEW QUESTION # 50
Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. Which GDPR principle is she following?
- A. Accuracy
- B. Integrity and confidentiality
- C. Lawfulness, fairness and transparency
- D. Storage Limitation
Answer: B
Explanation:
Explanation/Reference: https://www.icaew.com/technical/technology/data/data-protection/data-protection-articles/do-i-have- to-encrypt-personal-data-to-comply-with-dpa-2018
NEW QUESTION # 51
......
Check the Free demo of our CIPP-E Exam Dumps with 294 Questions: https://www.practicevce.com/IAPP/CIPP-E-practice-exam-dumps.html
Verified CIPP-E Q&As - Pass Guarantee CIPP-E Exam Dumps: https://drive.google.com/open?id=1DE9Fz6ad_ggSQrQu3OJfzcZqHC1KGpwn