Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the IAPP Certified Information Privacy Professional CIPP-E Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CIPP-E Premium Access

View all detail and faqs for the CIPP-E exam


800 Students Passed

89% Average Score

93% Same Questions
Viewing page 5 out of 9 pages
Viewing questions 41-50 out of questions
Questions # 41:

Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. Which of the following is NOT one of these exceptions?

Options:

A.

The processing is done by a non-profit organization and the results are disclosed outside the organization.

B.

The processing is necessary to protect the vital interests of the data subject when he or she is incapable of giving consent.

C.

The processing is necessary for the establishment, exercise or defense of legal claims when courts are acting in a judicial capacity.

D.

The processing is explicitly consented to by the data subject and he or she is allowed by Union or Member State law to lift the prohibition.

Questions # 42:

After leaving the EU under the terms of Brexit, the United Kingdom will seek an adequacy determination. What is the reason for this?

Options:

A.

The Insurance Commissioner determined that an adequacy determination is required by the Data Protection Act.

B.

Adequacy determinations automatically lapse when a Member State leaves the EU.

C.

The UK is now a third country because it’s no longer subject to the GDPR.

D.

The UK is less trustworthy now that its not part of the Union.

Questions # 43:

Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?

Options:

A.

Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.

B.

Only where the personal data is to be subjected to specific computerized processing, such as image

scanning or optical character recognition.

C.

Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.

D.

Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.

Questions # 44:

SCENARIO

Please use the following to answer the next question:

Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in

Greece (5), Italy (15) and Spain (1), have registered their most profitable results

ever. To celebrate this achievement, ARRA Hotels' Human Resources office, based

in ARRA's main Italian establishment, has organized a team event for its 420

employees and their families at its hotel in Spain.

Upon arrival at the hotel, each employee and family member is given an electronic

wristband at the reception desk. The wristband serves a number of functions:

. Allows access to the "party zone" of the hotel, and emits a buzz if the user

approaches any unauthorized areas

. Allows up to three free drinks for each person of legal age, and emits a

buzz once this limit has been reached

. Grants a unique ID number for participating in the games and contests that

have been planned.

Along with the wristband, each guest receives a QR code that leads to the online

privacy notice describing the use of the wristband. The page also contains an

unchecked consent checkbox. In the case of employee family members under the

age of 16, consent must be given by a parent.

Among the various activities planned for the event, ARRA Hotels' HR office has

autonomously set up a photocall area, separate from the main event venue, where

employees can come and have their pictures taken in traditional carnival costume.

The photos will be posted on ARRA Hotels' main website for general marketing

purposes.

On the night of the event, an employee from one of ARRA's Greek hotels is

displeased with the results of the photos in which he appears. He intends to file a

complaint with the relevant supervisory authority in regard to the following:

. The lack of any privacy notice in the separate photocall area

The unlawful cross-border processing of his personal data

. The unacceptable aesthetic outcome of his photos

Why would consent NOT be considered an adequate legal basis for accessing the

party zone?

Options:

A.

The consent is not completely unambiguous.

B.

The consent is not sufficiently informed.

C.

The consent is not freely given.

D.

The consent is not in writing.

Questions # 45:

SCENARIO

Please use the following to answer the next question:

Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees’ computers to see if they have software that is no

longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees’ computers.

Since these measures would potentially impact employees, Building Block’s Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.

After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees’ computers activity and their location. During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.

Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company’s computers, and from working remotely without authorization.

To comply with the GDPR, what should Building Block have done as a first step before implementing the SecurityScan measure?

Options:

A.

Assessed potential privacy risks by conducting a data protection impact assessment.

B.

Consulted with the relevant data protection authority about potential privacy violations.

C.

Distributed a more comprehensive notice to employees and received their express consent.

D.

Consulted with the Information Security team to weigh security measures against possible server impacts.

Questions # 46:

Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?

Options:

A.

Incidents of personal data breaches, whether disclosed or not.

B.

Data inventory or data mapping exercises that have been conducted.

C.

Categories of recipients to whom the personal data have been disclosed.

D.

Retention periods for erasure and deletion of categories of personal data.

Questions # 47:

Through a combination of hardware failure and human error, the decryption key for a bank's customer account transaction database has been lost. An investigation has determined that this was not the result of hacking or malfeasance, simply an unfortunate combination of circumstances. Which of the following accurately indicates the nature of this incident?

Options:

A.

A data breach has not occurred because the loss was not the result of hacking.

B.

A data breach has not occurred because no data was exposed to any unauthorized individual.

C.

A data breach has occurred because the loss of the key has resulted in the data no longer being accessible.

D.

A data breach has occurred because the loss of the key has resulted in the loss of confidentiality or integrity of the data.

Questions # 48:

MagicClean is a web-based service located in the United States that matches home cleaning services to customers. It otters its services exclusively in the United States It uses a processor located in France to optimize its data. Is MagicClean subject to the GDPR?

Options:

A.

Yes, because MagicClean is processing data in the EU

B.

Yes. because MagicClean's data processing agreement with the French processor is an establishment in the EU

C.

No, because MagicClean is located m the United States only.

D.

No. because MagicClean is not offering services to EU data subjects.

Questions # 49:

If two controllers act as joint controllers pursuant to Article 26 of the GDPR, which of the following may NOT be validly determined by said controllers?

Options:

A.

The definition of a central contact point for data subjects.

B.

The rules regarding the exercising of data subjects" rights.

C.

The rules to provide information to data subjects in Articles 13 and 14.

D.

The non-disclosure of the essence of their arrangement to data subjects

Questions # 50:

Under the GDPR, which essential pieces of information must be provided to data subjects before collecting their personal data?

Options:

A.

The authority by which the controller is collecting the data and the third parties to whom the data will be sent.

B.

The name/s of relevant government agencies involved and the steps needed for revising the data.

C.

The identity and contact details of the controller and the reasons the data is being collected.

D.

The contact information of the controller and a description of the retention policy.

Viewing page 5 out of 9 pages
Viewing questions 41-50 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.