Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the IAPP Certified Information Privacy Professional CIPP-E Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CIPP-E Premium Access

View all detail and faqs for the CIPP-E exam


800 Students Passed

89% Average Score

93% Same Questions
Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions
Questions # 31:

SCENARIO

Please use the following to answer the next question:

ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage

In support of Ruth's strategic goals of hiring more sales representatives, the Human

Resources team is focused on improving its processes to ensure that new

employees are sourced, interviewed, hired, and onboarded efficiently. To help with

this, Mary identified two vendors, HRYourWay, a German based company, and

InstaHR, an Australian based company. She decided to have both vendors go

through ProStorage's vendor risk review process so she can work with Ruth to

make the final decision. As part of the review process, Jackie, who is responsible

for maintaining ProStorage's privacy program (including maintaining controller

BCRs and conducting vendor risk assessments), reviewed both vendors but

completed a transfer impact assessment only for InstaHR. After her review of both

vendors, she determined that InstaHR satisfied more of the requirements as it

boasted a more established privacy program and provided third-party attestations,

whereas HRYourWay was a small vendor with minimal data protection operations.

Thus, she recommended InstaHR.

ProStorage's marketing team also worked to meet the strategic goals of the

company by focusing on industries where it needed to grow its market share. To

help with this, the team selected as a partner UpFinance, a US based company

with deep connections to financial industry customers. During ProStorage's

diligence process, Jackie from the privacy team noted in the transfer impact

assessment that UpFinance implements several data protection measures

including end-to-end encryption, with encryption keys held by the customer.

Notably, UpFinance has not received any government requests in its 7 years of

business. Still, Jackie recommended that the contract require UpFinance to notify

ProStorage if it receives a government request for personal data UpFinance

processes on its behalf prior to disclosing such data.

What transfer mechanism did ProStorage most likely rely on to transfer Ruth's

medical information to the hospital?

Options:

A.

Ruth's implied consent.

B.

Protecting the vital interest of Ruth.

C.

Performance of a contract with Ruth.

D.

Protecting against legal liability from Ruth.

Questions # 32:

A German data subject was the victim of an embarrassing prank 20 years ago. A newspaper website published an article about the prank at the time, and the article is still available on the newspaper’s website. Unfortunately, the prank is the top search result when a user searches on the victim’s name. The data subject requests that SearchCo delist this result. SearchCo agrees, and instructs its technology team to avoid scanning or indexing the article. What else must SearchCo do?

Options:

A.

Notify the newspaper that its article it is delisting the article.

B.

Fully erase the URL to the content, as opposed to delist which is mainly based on data subject’s name.

C.

Identify other controllers who are processing the same information and inform them of the delisting request.

D.

Prevent the article from being listed in search results no matter what search terms are entered into the search engine.

Questions # 33:

In 2016’s Guidance, the United Kingdom’s Information Commissioner’s Office (ICO) reaffirmed the importance of using a “layered notice” to provide data subjects with what?

Options:

A.

A privacy notice containing brief information whilst offering access to further detail.

B.

A privacy notice explaining the consequences for opting out of the use of cookies on a website.

C.

An explanation of the security measures used when personal data is transferred to a third party.

D.

An efficient means of providing written consent in member states where they are required to do so.

Questions # 34:

An organisation receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal data. Under what condition can the organisation charge the data subject for processing the request?

Options:

A.

Only where the organisation can show that it is reasonable to do so because more than one request was made.

B.

Only to the extent this is allowed under the restrictions on data subjects’ rights introduced under Art 23 of GDPR.

C.

Only where the administrative costs of taking the action requested exceeds a certain threshold.

D.

Only if the organisation can demonstrate that the request is clearly excessive or misguided.

Questions # 35:

Higher fines are assessed for GDPR violations due to which of the following?

Options:

A.

Failure to notify a supervisory authority and data subjects of a personal data breach

B.

Violations of a data controller's obligations to obtain a child's consent

C.

Failure to appoint a data protection officer.

D.

Violations of a data subject"s rights

Questions # 36:

Which of the following is NOT considered a fair processing practice in relation to the transparency principle?

Options:

A.

Providing a multi-layered privacy notice, in a website environment.

B.

Providing a QR code linking to more detailed privacy notice, in a CCTV sign.

C.

Providing a hyperlink to the organization’s home page, in a hard copy application form.

D.

Providing a “just-in-time” contextual pop-up privacy notice, in an online application from field.

Questions # 37:

Which area of privacy is a lead supervisory authority’s (LSA) MAIN concern?

Options:

A.

Data subject rights

B.

Data access disputes

C.

Cross-border processing

D.

Special categories of data

Questions # 38:

SCENARIO

Please use the following to answer the next question:

ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.

Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain’s locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.

Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.

What are ABC Hotel Chain and XYZ Travel Agency’s roles in this relationship?

Options:

A.

ABC Hotel Chain is the controller and XYZ Travel Agency is the processor.

B.

XYZ Travel Agency is the controller and ABC Hotel Chain is the processor.

C.

ABC Hotel Chain and XYZ Travel Agency are independent controllers.

D.

ABC Hotel Chain and XYZ Travel Agency are joint controllers.

Questions # 39:

Which aspect of processing does the GDPR allow processors to determine for themselves?

Options:

A.

The question of whether the controller needs to be informed about the substitution of another processor carrying out specific processing activities on behalf of the controller.

B.

Their own purposes for the processing, if such purposes are compatible with those for which the personal data were initially collected.

C.

The parameters of their marketing campaigns using personal data relating to the controller's customers.

D.

Their own type of hardware or software and the specific security measures for the processing.

Questions # 40:

SCENARIO

Please use the following to answer the next question:

Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Governance. Through her first initiative in conducting a data inventory, Sandy learned that Market4U maintains a list of 19 million global contacts that were collected throughout the course of Market4U’s existence. Knowing the risk of having such a large amount of data, Sandy wanted to purge all contacts that were entered into Market4U’s systems prior to May 2018, unless such contacts had a more recent interaction with Market4U content. However, Dan, the VP of Sales, informed Sandy that all of the contacts provide useful information regarding successful marketing campaigns and trends in industry verticals for Market4U’s clients.

Dan also informed Sandy that he had wanted to focus on gaining more customers within the sports and entertainment industry. To assist with this behavior, Market4U’s marketing team decided to add several new fields to Market4U’s website forms, including forms for downloading white papers, creating accounts to participate in Market4U’s forum, and attending events. Such fields include birth date and salary.

What should Sandy give as feedback to Dan and the marketing team regarding the new fields Dan wants to add to Market4U’s forms?

Options:

A.

Make all the fields optional.

B.

Only request the information in brackets (i.e., age group and salary range).

C.

Eliminate the fields, as they are not proportional to the services being offered.

D.

Eliminate the fields as they are not necessary for the purposes of providing white papers or registration for events.

Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.