Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the IAPP Certified Information Privacy Professional CIPP-E Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CIPP-E Premium Access

View all detail and faqs for the CIPP-E exam


800 Students Passed

89% Average Score

93% Same Questions
Viewing page 9 out of 9 pages
Viewing questions 81-90 out of questions
Questions # 81:

SCENARIO

Please use the following to answer the next question:

Dynaroux Fashion (‘Dynaroux’) is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company’s compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.

The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.

In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company’s customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that

Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.

Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux’s business plan and associated processing activities.

Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?

Options:

A.

The company will be undertaking processing activities involving sensitive data categories such as financial and children’s data.

B.

The company employs approximately 650 people and will therefore be carrying out extensive processing activities.

C.

The company plans to undertake profiling of its customers through analysis of their purchasing patterns.

D.

The company intends to shift their business model to rely more heavily on online shopping.

Questions # 82:

The GDPR specifies fines that may be levied against data controllers for certain infringements. Which of the following infringements would be subject to the less severe administrative fine of up to 10 million euros (or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year)?

Options:

A.

Failure to demonstrate that consent was given by the data subject to the processing of their personal data where it is used as the basis for processing.

B.

Failure to implement technical and organizational measures to ensure data protection is enshrined by design and default.

C.

Failure to process personal information in a manner compatible with its original purpose.

D.

Failure to provide the means for a data subject to rectify inaccuracies in personal data.

Questions # 83:

As a result of the European Court of Justice’s ruling in the case of Google v. Spain, search engines outside the EEA are also likely to be subject to the Regulation’s right to be forgotten. This holds true if the activities of an EU subsidiary and its U.S. parent are what?

Options:

A.

Supervised by the same Data Protection Officer.

B.

Consistent with Privacy Shield requirements

C.

Bound by a standard contractual clause.

D.

Inextricably linked in their businesses.

Questions # 84:

The GDPR requires controllers to supply data subjects with detailed information about the processing of their data. Where a controller obtains data directly from data subjects, which of the following items of information does NOT legally have to be supplied?

Options:

A.

The recipients or categories of recipients.

B.

The categories of personal data concerned.

C.

The rights of access, erasure, restriction, and portability.

D.

The right to lodge a complaint with a supervisory authority.

Viewing page 9 out of 9 pages
Viewing questions 81-90 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.