
Free CIPP-E pdf Files With Updated and Accurate Dumps Training
Top-Class CIPP-E Question Answers Study Guide
You can read the IAPP CIPP/E Exam certified salary below
The Average Salary of an IAPP CIPP/E Exam in
- Europe - 104162 EURO
- United State - 122,750 USD
- England - 94029 POUND
- India - 9206648 INR
NEW QUESTION # 39
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?
- A. Approved data controllers.
- B. The European Data Protection Supervisor.
- C. The Council of the European Union.
- D. National data protection authorities.
Answer: A
Explanation:
Explanation/Reference: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/ standard-contractual-clauses-scc_en
NEW QUESTION # 40
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
- A. When the controller is required to have a Data Protection Officer.
- B. When the controller is collecting email addresses from individuals via an online registration form for marketing purposes.
- C. When personal data is being collected and combined with other personal data to profile the creditworthiness of individuals.
- D. When personal data is being transferred outside of the EEA.
Answer: A
Explanation:
Reference:
%20the%20General,and%20freedoms%20of%20natural%20persons%27.
NEW QUESTION # 41
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
- A. A company wants to combine location data with other data in order to offer more personalized service for the customer.
- B. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
- C. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- D. A company wants to use location data to infer information on a person's clothes purchasing habits.
Answer: C
Explanation:
Reference http://webcache.googleusercontent.com/search?q=cache:aQkU17eX9sQJ:https:// www.shlegal.com/insights/article-29-data-protection-working-party-gdpr-guidelines-on-data-protection-impact- assessments&client=firefox-b-e&hl=en&gl=pk&strip=1&vwsrc=0
NEW QUESTION # 42
What term BEST describes the European model for data protection?
- A. Sectoral
- B. Market-based
- C. Comprehensive
- D. Self-regulatory
Answer: C
Explanation:
Reference https://ec.europa.eu/info/sites/info/files/communication-european-strategy-data-19feb2020_en.pdf
NEW QUESTION # 43
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018 guidance, company Z should do which of the following?
- A. Notify affected individuals that their data was unavailable for a period of time.
- B. Document the loss of availability to demonstrate accountability
- C. Notify the supervisory authority about the loss of availability
- D. Conduct a thorough audit of all security systems
Answer: C
Explanation:
Reference https://www.google.com/url? sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwihmsidxtTqAhXvQUEAHXRaAdYQFjABegQIARAB& url=https%3A%2F%2Fec.europa.eu%2Fnewsroom%2Farticle29%2Fdocument.cfm%3Fdoc_id% 3D49827&usg=AOvVaw2uhYsKyRzJ6lwhQyiMURJF (5)
NEW QUESTION # 44
SCENARIO
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''
- A. Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.
- B. Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.
- C. No. the assessors do not quality as data processors as they do not copy the data to their facilities.
- D. No, the assessors do not quality as data processors as they only have access to encrypted data.
Answer: A
NEW QUESTION # 45
If two controllers act as joint controllers pursuant to Article 26 of the GDPR, which of the following may NOT be validly determined by said controllers?
- A. The rules regarding the exercising of data subjects" rights.
- B. The rules to provide information to data subjects in Articles 13 and 14.
- C. The definition of a central contact point for data subjects.
- D. The non-disclosure of the essence of their arrangement to data subjects
Answer: B
NEW QUESTION # 46
Many businesses print their employees' photographs on building passes, so that employees can be identified by security staff. This is notwithstanding the fact that facial images potentially qualify as biometric data under the GDPR. Why would such practice be permitted?
- A. Because photographs qualify as biometric data only when they undergo a "specific technical processing".
- B. Because photographic ID is a physical security measure which is "necessary for reasons of substantial public interest".
Reference https://ess.csa.canon.com/rs/206-CLL-191/images/IAPP-Top-10-Operational-Impacts-of- GDPR.pdf?TC=DM&CN=CSA_OMNIA_Partners&CS=CSA&CR=T1_Gov%20GenNonProfit (11) - C. Because employees are deemed to have given their explicit consent when they agree to be photographed by their employer.
- D. Because use of biometric data to confirm the unique identification of data subjects benefits from an exemption.
Answer: A
NEW QUESTION # 47
According to the European Data Protection Board, which of the following concepts or practices does NOT follow from the principles relating to the processing of personal data under EU data protection law?
- A. Access control management.
- B. Data ownership allocation.
- C. Frequent pseudonymization key rotation.
- D. Error propagation avoidance along the processing chain.
Answer: C
NEW QUESTION # 48
An entity's website stores text files on EU users' computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?
- A. E-Commerce Directive 2000/31/EC.
- B. E-Privacy Directive 2002/58/EC.
- C. Data Protection Directive 95/46/EC.
- D. General Data Protection Regulation 2016/679.
Answer: B
NEW QUESTION # 49
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Which of the following BEST describes the relationship between Liem, EcoMick and JaphSoft?
- A. JaphSoft is the sole processor because it processes personal data on behalf of its clients.
- B. Liem and EcoMick are joint controllers because they carry out joint marketing activities.
- C. Liem is a controller and EcoMick is a processor because Liem provides specific instructions regarding how the marketing campaigns should be rolled out.
- D. EcoMick and JaphSoft are is a controller and Liem is a processor because EcoMick is sharing its marketing data with Liem for contacts in Europe.
Answer: D
NEW QUESTION # 50
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?
- A. Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.
- B. Categories of processing carried out on behalf of each controller for which the processor is acting.
- C. Name and contact details of each controller on behalf of which the processor is acting.
- D. Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.
Answer: A
Explanation:
Reference https://gdpr-info.eu/art-30-gdpr/
NEW QUESTION # 51
What must a data controller do in order to make personal data pseudonymous?
- A. Use the data only in aggregated form for research purposes.
- B. Separately hold any information that would allow linking the data to the data subject.
- C. Remove all indirect data identifiers and dispose of them securely.
- D. Encrypt the data in order to prevent any unauthorized access or modification.
Answer: B
NEW QUESTION # 52
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA.
Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
As a result of Sam's actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?
- A. Notify all of its customers that reside in the European Union.
- B. Notify its Data Protection Authority about the data breach.
- C. Analyze and evaluate all of its breach notification obligations.
- D. Analyze and evaluate the liability for customers in Ireland.
Answer: B
NEW QUESTION # 53
Which of the following is an accurate statement regarding the "one-stop-shop" mechanism of the GDPR?
- A. It applies only to direct enforcement of data protection supervisory authorities (e.g.. finding a breach), but not to initiating or engaging m court proceedings
- B. It gives competence to the lead supervisory authority to address privacy issues derived from processes carried out by public authorities established in different countries.
- C. It allows supervisory authorities concerned (other than the lead supervisory authority) to act against organizations m exceptional cases even if they do not have any type of establishment in the Member State of the respective authority.
- D. It can result in several lead supervisory authorities in the EU assuming competence over the same data processing activities of an organization.
Answer: C
NEW QUESTION # 54
A key component of the OECD Guidelines is the "Individual Participation Principle". What parts of the General Data Protection Regulation (GDPR) provide the closest equivalent to that principle?
- A. The breach notification requirements specified in Articles 33 and 34
- B. The information requirements set out in Articles 13 and 14
- C. The lawful processing criteria stipulated by Articles 6 to 9
- D. The rights granted to data subjects under Articles 12 to 22
Answer: D
NEW QUESTION # 55
What is the main task of the European Data Protection Board?
- A. To proactively prevent disputes between national supervisory authorities.
- B. To publish guidelines tor data subjects on how to property enforce their rights
- C. To ensure consistent application of the GDPR.
- D. To assess adequacy of data protection in third countries
Answer: C
NEW QUESTION # 56
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?
- A. Only where the personal data is to be subjected to specific computerized processing, such as image scanning or optical character recognition.
- B. Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.
- C. Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.
- D. Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.
Answer: B
NEW QUESTION # 57
In 2016's Guidance, the United Kingdom's Information Commissioner's Office (ICO) reaffirmed the importance of using a "layered notice" to provide data subjects with what?
- A. A privacy notice containing brief information whilst offering access to further detail.
- B. An explanation of the security measures used when personal data is transferred to a third party.
- C. An efficient means of providing written consent in member states where they are required to do so.
- D. A privacy notice explaining the consequences for opting out of the use of cookies on a website.
Answer: A
NEW QUESTION # 58
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018 guidance, company Z should do which of the following?
- A. Notify affected individuals that their data was unavailable for a period of time.
- B. Document the loss of availability to demonstrate accountability
- C. Notify the supervisory authority about the loss of availability
- D. Conduct a thorough audit of all security systems
Answer: C
Explanation:
Explanation/Reference: https://www.google.com/url?
sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwihmsidxtTqAhXvQUEAHXRaAdYQFjABegQIARAB& url=https%3A%2F%2Fec.europa.eu%2Fnewsroom%2Farticle29%2Fdocument.cfm%3Fdoc_id%
3D49827&usg=AOvVaw2uhYsKyRzJ6lwhQyiMURJF (5)
NEW QUESTION # 59
SCENARIO
Please use the following to answer the next question:
WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:
"WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the dat a. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information. We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."
"We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."
"We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities." What additional information must Wonderkids provide in their Privacy Statement?
- A. Contact information of the hosting company.
- B. How often promotional emails will be sent.
- C. The categories of recipients with whom data will be shared.
- D. Technical and organizational measures to protect data.
Answer: A
NEW QUESTION # 60
......
Real Updated CIPP-E Questions & Answers Pass Your Exam Easily: https://www.examcost.com/CIPP-E-practice-exam.html
Easily To Pass New CIPP-E Verified & Correct Answers: https://drive.google.com/open?id=1Zxav2hff6EE-xw-12qeo7f2Ta7981_5q

