
[Jan 02, 2024] CIPP-E Exam Dumps, CIPP-E Practice Test Questions
Free CIPP-E Study Guides Exam Questions and Answer
NEW QUESTION # 108
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Why would the consent provided by Ms. Iman NOT be considered valid in regard to JaphSoft?
- A. She has never made any purchases from JaphSoft and has no relationship with the company.
- B. She only viewed the visual representations of the privacy notice Liem provided.
- C. She did not read the privacy notice stating that her personal data would be shared.
- D. She was not told which controller would be processing her personal data.
Answer: C
Explanation:
The reason why the consent provided by Ms. Iman would not be considered valid in regard to JaphSoft is not because she did not provide her consent for her personal data to be shared with EcoMick, but because she was not told which controller would be processing her personal data. JaphSoft is a controller, as it determines the purpose and means of the processing of personal data, which is to improve its marketing optimization models and to provide better services to its customers. JaphSoft does not act only on the instructions of Liem and EcoMick, who are the original controllers of the personal data, but rather uses the data for its own benefit and interest. Therefore, JaphSoft should have obtained a separate consent from Ms. Iman, or relied on another lawful basis, such as legitimate interest, to process her personal data. Ms. Iman only gave consent to Liem, not to JaphSoft, and she was not informed that her personal data would be shared with or processed by another controller.
NEW QUESTION # 109
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
- A. The necessity of the bulk collection of personal data by the government.
- B. The obligation of companies to declare data breaches.
- C. The requirement to demonstrate compliance to a supervisory authority.
Answer: A
Explanation:
The Convention 108+ is the modernized version of the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, which was opened for signature on 10 October 20181. The Convention 108+ aims to reinforce the individuals' protection, strengthen the implementation of the Convention, and promote it as a universal standard for data protection2. The Convention 108+ reflects the same principles as those enshrined in the EU's General Data Protection Regulation (GDPR), which applies from 25 May 20183. Therefore, the Convention 108+ and the GDPR are largely consistent and coherent in their provisions and objectives.
However, one of the principles of the Convention 108+ that is not consistent with a principle found in the GDPR is the necessity of the bulk collection of personal data by the government. The Convention 108+ allows for the possibility of bulk collection of personal data by the government for national security purposes, subject to certain safeguards and oversight mechanisms. The GDPR, on the other hand, does not regulate the processing of personal data by the government for national security purposes, as this falls outside the scope of EU law. The GDPR also does not explicitly endorse the bulk collection of personal data by the government, but rather requires that any processing of personal data must be based on a legal basis, respect the principles of data protection, and ensure the rights and freedoms of data subjects. Therefore, the correct answer is C.
Reference:
Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data Convention 108+ and the GDPR General Data Protection Regulation
[Convention 108+: the consultative committee of the convention for the protection of individuals with regard to the processing of personal data (T-PD) publishes its guidelines on artificial intelligence and data protection]
[Article 3 GDPR - Territorial scope]
[Article 5 GDPR - Principles relating to processing of personal data]
I hope this helps you understand the Convention 108+ and the GDPR better. If you have any other questions, please feel free to ask me.
NEW QUESTION # 110
SCENARIO
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta |EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Which of the following must be a component of the anti-money-laundering data-sharing practice of the platform?
- A. Customers snail receive a clear and conspicuous notice about such data sharing before submitting their data during the registration process.
- B. Customers shall have an opt-out feature to restrict data sharing with law enforcement agencies after the registration.
- C. The terms of service shall include the address of the anti-money laundering agency and contacts of the investigators who may access me data.
- D. The terms of service shall also enumerate all applicable anti-money laundering few.
Answer: A
Explanation:
According to Article 13 of the GDPR, when personal data are collected from the data subject, the controller shall provide the data subject with certain information, such as the purposes and legal basis of the processing, the recipients or categories of recipients of the personal data, and the existence of the data subject's rights. This information shall be provided at the time when personal data are obtained. The purpose of this requirement is to ensure that the data subject is informed and aware of how their personal data will be used and shared, and to enable them to exercise their rights accordingly. Therefore, customers shall receive a clear and conspicuous notice about such data sharing before submitting their data during the registration process. Reference:
Article 13 of the GDPR
IAPP CIPP/E Study Guide, page 32
NEW QUESTION # 111
In the Planet 49 case, what was the main judgement of the Court of Justice of the European Union (CJEU) regarding the issue of cookies?
- A. If the cookies do not track personal data, then pre-checked boxes are acceptable.
- B. If a data subject continues to scroll through a website after reading a cookie banner, this activity constitutes valid consent for the tracking described in the cookie banner.
- C. If the ePrivacy Directive requires consent for cookies, then the GDPR's consent requirements apply.
- D. If a website's cookie notice makes clear the information gathered and the lifespan of the cookie, then pre-checked boxes are acceptable.
Answer: C
Explanation:
The CJEU ruled that the consent required by the ePrivacy Directive for the use of cookies must comply with the conditions laid down in the GDPR, which means that it must be specific, informed, unambiguous, and freely given. Therefore, pre-checked boxes or implied consent by scrolling are not valid forms of consent for cookies. The CJEU also clarified that the ePrivacy Directive applies to any information stored or accessed on a user's device, regardless of whether it is personal data or not. Furthermore, the CJEU stated that the information provided to users about cookies must include the duration of the operation of cookies and the possibility of third parties accessing them.
NEW QUESTION # 112
According to Article 84 of the GDPR, the rules on penalties applicable to infringements shall be laid down by?
- A. The Member States.
- B. The European Data Protection Board.
- C. The EU Commission.
- D. The local Data Protection Supervisory Authorities.
Answer: A
Explanation:
Reference:
According to Article 84 of the GDPR, the rules on other penalties applicable to infringements of the GDPR, in particular for infringements which are not subject to administrative fines pursuant to Article 83, shall be laid down by the Member States1. Such penalties shall be effective, proportionate and dissuasive1. Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them1. Reference: 1: Art. 84 GDPR - Penalties - General Data Protection Regulation (GDPR)
NEW QUESTION # 113
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
The GDPR requires sufficient guarantees of a company's ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?
- A. Avoiding the use of another company's data to improve their own services.
- B. Hiring companies whose measures are consistent with recommendations of accrediting bodies.
- C. Vetting companies' measures with the appropriate supervisory authority.
- D. Requesting advice and technical support from Company A's IT team.
Answer: B
Explanation:
Article 82 of the GDPR1234 regulates the right to compensation and liability for any person who has suffered material or non-material damage as a result of an infringement of the GDPR.
Paragraph 4 of Article 821234 states that a controller or processor shall be exempt from liability under paragraph 2 (which holds them liable for the damage caused by processing which infringes the GDPR) if it proves that it is not in any way responsible for the event giving rise to the damage.
Therefore, the right to compensation and liability under the GDPR provides for an exemption from liability if the data controller (or data processor) proves that it is not in any way responsible for the event giving rise to the damage.
Reference:
1: Art. 82 GDPR - Right to compensation and liability - General Data Protection Regulation (GDPR)
2: Art. 82 GDPR - Right to compensation and liability - GDPR.eu
3: GDPR Article 82: Right to compensation and liability - Advisera
4: Article 82 GDPR | Right to compensation and liability
NEW QUESTION # 114
The transparency principle is most directly related to which of the following rights?
- A. Right to be informed.
- B. Right to restriction of processing.
- C. Right to object
- D. Right to be forgotten.
Answer: A
NEW QUESTION # 115
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?
- A. The group of undertakings must be comprised of organizations of similar sizes and functions.
- B. The data protection officer must be located in the country where the data controller has its main establishment.
- C. The group of undertakings must obtain approval from a supervisory authority.
- D. The data protection officer must be easily accessible from each establishment where the undertakings are located.
Answer: D
NEW QUESTION # 116
A company wishes to transfer personal data to a country outside of the European Union/EEA In order to do so, they are planning an assessment of the country's laws and practices, knowing that these may impinge upon the transfer safeguards they intend to use All of the following factors would be relevant for the company to consider EXCEPT'?
- A. The technical, financial, and staff resources available to an authority m the third country concerned that may access the personal data to be transferred
- B. Any onward transfers, such as transfers of personal data to a sub-processor in the same or another third country.
- C. The process of modernization in the third country concerned and their access to emerging technologies that rely on international transfers of personal data
- D. The contractual clauses between the data controller or processor established in the European Union/EEA and the recipient of the transfer established in the third country concerned
Answer: C
NEW QUESTION # 117
A mobile device application that uses cookies will be subject to the consent requirement of which of the following?
- A. The EU Cybersecurity Directive
- B. The Data Retention Directive
- C. The ePrivacy Directive
- D. The E-Commerce Directive
Answer: C
Explanation:
The ePrivacy Directive, also known as the Cookie Law, is the EU legislation that regulates the use of cookies and other tracking technologies on websites and mobile applications. The ePrivacy Directive states that the use of cookies on websites and mobile applications is conditioned upon the prior consent of users, unless the cookies are strictly necessary for the provision of the service. Users must also be given clear and comprehensive information about the purposes of the cookies and the means to refuse them. The ePrivacy Directive complements the GDPR, which also applies to the processing of personal data through cookies, but does not specifically address the consent requirement for cookies. The other answer choices are not relevant to the consent requirement for cookies, as they regulate different aspects of the digital economy and society. The E-Commerce Directive establishes the legal framework for online services in the EU, such as information society services, electronic contracts, and liability of intermediaries. The Data Retention Directive requires telecommunication providers to retain certain data for a period of time for the purpose of law enforcement and national security. The EU Cybersecurity Directive aims to enhance the security of network and information systems across the EU, by setting common standards and obligations for operators of essential services and digital service providers. Reference:
Cookies, the GDPR, and the ePrivacy Directive - GDPR.eu
What is the EU Cookie Law (ePrivacy Directive)? - Cookie Script
EU Cookie Law - Data Protection and Cookies - Cookiebot
ePrivacy Directive - Regulations - Learn how CookiePro Helps
NEW QUESTION # 118
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018 guidance, company Z should do which of the following?
- A. Conduct a thorough audit of all security systems
- B. Notify affected individuals that their data was unavailable for a period of time.
- C. Notify the supervisory authority about the loss of availability
- D. Document the loss of availability to demonstrate accountability
Answer: C
Explanation:
Reference https://www.google.com/url? sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwihmsidxtTqAhXvQUEAHXRaAdYQFjABegQIARAB& url=https%3A%2F%2Fec.europa.eu%2Fnewsroom%2Farticle29%2Fdocument.cfm%3Fdoc_id% 3D49827&usg=AOvVaw2uhYsKyRzJ6lwhQyiMURJF (5)
NEW QUESTION # 119
A Spanish electricity customer calls her local supplier with questions about the company's upcoming merger. Specifically, the customer wants to know the recipients to whom her personal data will be disclosed once the merger is final. According to Article 13 of the GDPR, what must the company do before providing the customer with the requested information?
- A. Verify that the purpose of the request from the customer is in line with the GDPR.
- B. Verify that the personal data has not already been sent to the customer.
- C. Verify that the identity of the customer can be proven by other means.
- D. Verify that the request is applicable to the data collected before the GDPR entered into force.
Answer: D
NEW QUESTION # 120
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
Ben's collection of additional data from customers created several potential issues for the company, which would most likely require what?
- A. A comprehensive data inventory.
- B. Hiring a data protection officer.
- C. A data protection impact assessment.
- D. New corporate governance and code of conduct.
Answer: C
Explanation:
Ben's collection of additional data from customers, especially sensitive data such as philosophical beliefs and political opinions, created several potential issues for the company, such as:
The risk of violating the data minimization principle, which requires that personal data collected must be adequate, relevant and limited to what is necessary for the purposes of the processing1.
The risk of infringing the rights and freedoms of the data subjects, who may not be aware of or consent to the secondary use of their data by Ben Knows Best, or the unauthorized access and copying of their data by Sam.
The risk of non-compliance with the GDPR's requirements for processing special categories of data, which include data revealing philosophical beliefs and political opinions. Such data can only be processed under certain conditions, such as explicit consent, substantial public interest, or legal claims2.
The risk of data breaches or losses, as the data is transferred to a separate database, copied by Sam, and stored on the company's servers in Vermont, which may not have adequate security measures or safeguards.
Therefore, the company would most likely require a data protection impact assessment (DPIA) to identify and mitigate these risks. A DPIA is a process that helps assess the impact of the envisaged processing operations on the protection of personal data, and consult with the supervisory authority if the DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk3. The other options are not necessarily required by the GDPR, although they may be good practices or contractual terms. Reference:
Free CIPP/E Study Guide, page 32, section 4.1.2
CIPP/E Certification, page 27, section 4.1.2
The Ultimate CIPP/E Study Guide for 2023, page 36, section 4.1.2
Principles - General Data Protection Regulation (GDPR), Article 5
Special categories of personal data - General Data Protection Regulation (GDPR), Article 9 Data protection impact assessment - General Data Protection Regulation (GDPR), Article 35
NEW QUESTION # 121
Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?
- A. The right to privacy is an absolute right
- B. The right to privacy has to be balanced against other rights under the ECHR
- C. The right to privacy protects the right to hold opinions and to receive and impart ideas without interference
- D. The right to freedom of expression under Article 10 of the ECHR will always override the right to privacy
Answer: B
Explanation:
Reference https://www.echr.coe.int/Documents/Guide_Art_8_ENG.pdf (15)
NEW QUESTION # 122
Which of the following is NOT recognized as a common characteristic of cloud computing services?
- A. The service's infrastructure is shared among the supplier's customers and can be located in a number of countries.
- B. The supplier determines the location, security measures, and service standards applicable to the processing.
- C. The supplier allows customer data to be transferred around the infrastructure according to capacity.
- D. The supplier assumes the vendor's business risk associated with data processed by the supplier.
Answer: D
Explanation:
cloud computing services are defined as the on-demand availability of computing resources (such as storage and infrastructure), as services over the internet. Cloud computing services share certain characteristics, such as on-demand self-service, broad network access, resource pooling, rapid elasticity, measured service, multi-tenancy, virtualization, resilient computing, flexible pricing models, security, automation, and sustainability234.
One of the characteristics that is not recognized as a common characteristic of cloud computing services is that the supplier assumes the vendor's business risk associated with data processed by the supplier. This is not a characteristic of cloud computing services, but rather a contractual or legal issue that depends on the agreement between the supplier and the vendor. The supplier and the vendor may have different roles and responsibilities regarding the data processed by the supplier, such as controller, processor, or sub-processor, and they may have different obligations and liabilities under the applicable data protection laws, such as the GDPR. Therefore, the supplier does not necessarily assume the vendor's business risk associated with data processed by the supplier, unless it is explicitly agreed by the parties or required by the law.
NEW QUESTION # 123
......
CIPP-E Exam Dumps, CIPP-E Practice Test Questions: https://actualtest.updatedumps.com/IAPP/CIPP-E-updated-exam-dumps.html