
CIPP-E Actual Questions 100% Same Braindumps with Actual Exam!
CIPP-E Study Material, Preparation Guide and PDF Download
The CIPP-E certification exam is challenging and requires a significant amount of preparation. To help individuals prepare for the exam, the IAPP offers a range of training courses and study materials. These resources cover all of the exam topics in detail and provide individuals with the knowledge and skills they need to pass the exam.
The CIPP/E Exam covers a range of topics related to data protection laws and regulations in Europe, including the General Data Protection Regulation (GDPR), and provides a comprehensive understanding of the legal principles that govern the collection, use, and disclosure of personal information. CIPP-E exam is designed to test the knowledge, skills, and abilities of professionals who are responsible for managing and protecting personal data in their organizations, and it is recognized as the gold standard in privacy certification for European privacy professionals.
The International Association of Privacy Professionals (IAPP) Certified Information Privacy Professional/Europe (CIPP/E) Certification Exam is a globally recognized certification that demonstrates an individual's knowledge and understanding of European data protection laws and regulations. The CIPP/E certification is designed for privacy professionals who work in or with organizations that operate within the European Union (EU) or handle EU citizens' personal data.
NEW QUESTION # 28
Which institution has the power to adopt findings that confirm the adequacy of the data protection level in a non-EU country?
- A. The European Council
- B. The European Commission
- C. The Article 29 Working Party
- D. The European Parliament
Answer: B
NEW QUESTION # 29
Company X has entrusted the processing of their payroll data to Provider Y. Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server. In this scenario, whom does Provider Y have the obligation to notify?
- A. Company X
- B. The public
- C. Law enforcement
- D. The supervisory authority
Answer: C
NEW QUESTION # 30
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location. During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
In addition to notifying employees about the purpose of the monitoring, the potential uses of their data and their privacy rights, what information should Building Block have provided them before implementing the security measures?
- A. Information about how the measures are in the best interests of the company.
- B. Information about what is specified in the employment contract.
- C. Information about how providing consent could affect them as employees.
- D. Information about who employees should contact with any queries.
Answer: B
NEW QUESTION # 31
Which of the following is one of the supervisory authority's investigative powers?
- A. To require that controllers or processors adopt approved data protection certification mechanisms.
- B. To require data controllers to provide them with written notification of all new processing activities.
- C. To notify the controller or the processor of an alleged infringement of the GDPR.
- D. To determine whether a controller or processor has the right to a judicial remedy concerning a compensation decision made against them.
Answer: C
Explanation:
Reference https://gdpr-info.eu/art-58-gdpr/
NEW QUESTION # 32
According to the GDPR. Article 4(14). biometric data is defined as:
"Personal data resulting from specific technical processing relating to the______charactenstics of a natural person" Which term could NOT be placed in the above definition?
- A. Physical.
- B. Psychological.
- C. Behavioral
- D. Intellectual.
Answer: A
NEW QUESTION # 33
When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in compliance with the European Union (EU) level?
- A. On an ongoing basis.
- B. Every year.
- C. Every three (3) years.
- D. After a personal data breach.
Answer: A
Explanation:
Reference https://edpb.europa.eu/sites/default/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_en.pdf
NEW QUESTION # 34
As per the GDPR, which legal basis would be the most appropriate for an online shop that wishes to process personal data for the purpose of fraud prevention?
- A. Legitimate interest
- B. Performance of a contact
- C. Consent
- D. Protection of the interests of the data subjects.
Answer: C
NEW QUESTION # 35
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
- A. The measures being taken to address the breach.
- B. The predicted consequences of the breach.
- C. The type of security safeguards used to protect the data.
- D. The contact details of the appropriate data protection officer.
Answer: D
NEW QUESTION # 36
Which of the following would most likely NOT be covered by the definition of "personal data" under the GDPR?
- A. The unlinked aggregated data used for statistical purposes by an Italian company
- B. The U.S. social security number of an American citizen living in France
- C. The identification number of a German candidate for a professional examination in Germany
- D. The payment card number of a Dutch citizen
Answer: C
NEW QUESTION # 37
The GDPR requires controllers to supply data subjects with detailed information about the processing of their dat a. Where a controller obtains data directly from data subjects, which of the following items of information does NOT legally have to be supplied?
- A. The categories of personal data concerned.
- B. The right to lodge a complaint with a supervisory authority.
- C. The recipients or categories of recipients.
- D. The rights of access, erasure, restriction, and portability.
Answer: A
Explanation:
Reference https://gdpr-info.eu/art-13-gdpr/
NEW QUESTION # 38
What was the aim of the European Data Protection Directive 95/46/EC?
- A. To completely prevent the transfer of personal data out of the European Union.
- B. To harmonize the implementation of the European Convention of Human Rights across all member states.
- C. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.
- D. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.
Answer: D
NEW QUESTION # 39
A homeowner has installed a motion-detecting surveillance system that films his front doc and entryway. The camera does not film any public areas only areas that are the property of the homeowner. The system has seen declared to the authorities per the homeowner's country law, and a placard indicating the area is being video monitored is visible when entering the property Why can the homeowner NOT depend on the household exemption with regards to the processing of the video images recorded by the surveillance camera system?
- A. The surveillance camera system can potentially capture biometric information of the homeowner's family, which would be considered a processing of special categories of personal data.
- B. The surveillance camera system can potentially film individuals who enter its filming perimeter
- C. The GDPR specifically excludes surveillance camera images from the household exemption
- D. The homeowner has not specified which security measures ore in place as part of the surveillance camera system
Answer: B
NEW QUESTION # 40
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?
- A. A mandatory notification for personal data breaches applicable to all data controllers.
- B. A voluntary notification for personal data breaches applicable to electronic communication providers.
- C. A voluntary notification for personal data breaches applicable to all data controllers.
- D. A mandatory notification for personal data breaches applicable to electronic communication providers.
Answer: D
Explanation:
Reference https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32009L0136
NEW QUESTION # 41
What term BEST describes the European model for data protection?
- A. Self-regulatory
- B. Market-based
- C. Sectoral
- D. Comprehensive
Answer: C
Explanation:
Explanation/Reference: https://ec.europa.eu/info/sites/info/files/communication-european-strategy-data-19feb2020_en.pdf
NEW QUESTION # 42
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What must Zandelay provide to the supervisory authority during the prior consultation?
- A. An evaluation of the complexity of the intended processing.
- B. An of the purposes and means of the intended processing.
- C. Records showing that customers have explicitly consented to the intended profiling activities.
- D. Certificates that prove Martin's professional qualities and expert knowledge of data protection law.
Answer: B
NEW QUESTION # 43
Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?
- A. All employees are subject to the rules in their entirety, regardless of where the work is taking place.
- B. Employees must sign an ad hoc contractual agreement each time personal data is exported.
- C. All employees must follow the privacy regulations of the jurisdictions where the current scope of their work is established.
- D. Employees who control personal data must complete a rigorous certification procedure, as they are exempt from legal enforcement.
Answer: A
NEW QUESTION # 44
What term BEST describes the European model for data protection?
- A. Self-regulatory
- B. Market-based
- C. Comprehensive
- D. Sectoral
Answer: C
Explanation:
Reference https://ec.europa.eu/info/sites/info/files/communication-european-strategy-data-19feb2020_en.pdf
NEW QUESTION # 45
SCENARIO
Please use the following to answer the next question:
Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Governance. Through her first initiative in conducting a data inventory, Sandy learned that Market4U maintains a list of 19 million global contacts that were collected throughout the course of Market4U's existence. Knowing the risk of having such a large amount of data, Sandy wanted to purge all contacts that were entered into Market4U's systems prior to May 2018, unless such contacts had a more recent interaction with Market4U content. However, Dan, the VP of Sales, informed Sandy that all of the contacts provide useful information regarding successful marketing campaigns and trends in industry verticals for Market4U's clients.
Dan also informed Sandy that he had wanted to focus on gaining more customers within the sports and entertainment industry. To assist with this behavior, Market4U's marketing team decided to add several new fields to Market4U's website forms, including forms for downloading white papers, creating accounts to participate in Market4U's forum, and attending events. Such fields include birth date and salary.
What is the best way that Sandy can gain the insights that Dan seeks while still minimizing risks for Market4U?
- A. Conduct analysis only on anonymized personal data.
- B. Conduct analysis only on pseudonymized personal data.
- C. Procure a third party to conduct the analysis and delete the data from Market4U's systems.
- D. Delete all data collected prior to May 2018 after conducting the trend analysis.
Answer: A
NEW QUESTION # 46
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?
- A. The European Council
- B. The Council of the European Union
- C. The European Commission
- D. The European Parliament
Answer: B
NEW QUESTION # 47
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent.
All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
The data transfer mechanism that Alice drafted violates the GDPR because the company did not first get approval from?
- A. The Court of Justice of the European Union.
- B. The European Commission.
- C. The European Data Protection Board.
- D. The Data Protection Authority.
Answer: D
NEW QUESTION # 48
With the issue of consent, the GDPR allows member states some choice regarding what?
- A. The age at which children must be required to obtain parental consent
- B. The timeframe in which data subjects are allowed to withdraw their consent
- C. The mechanisms through which consent may be communicated
- D. The circumstances in which silence or inactivity may constitute consent
Answer: A
Explanation:
Reference https://gdpr-info.eu/issues/consent/
NEW QUESTION # 49
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
JaphSoft's use of pseudonymization is NOT in compliance with the CDPR because?
- A. JaphSoft pseudonymized all the data instead of deleting what it no longer needed.
- B. JaphSoft was in possession of information that could be used to identify data subjects.
- C. JaphSoft failed to keep personally identifiable information in a separate database.
- D. JaphSoft failed to first anonymize the personal data.
Answer: A
NEW QUESTION # 50
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?
- A. Within 40 days of receipt
- B. Within one month of receipt, which may be extended by up to an additional month
- C. Within 40 days of receipt, which may be extended by up to 40 additional days
- D. Within one month of receipt, which may be extended by an additional two months
Answer: B
NEW QUESTION # 51
......
CIPP-E Certification Study Guide Pass CIPP-E Fast: https://www.dumpexam.com/CIPP-E-valid-torrent.html
Free CIPP-E Certification Sample Questions with Online Practice Test: https://drive.google.com/open?id=1QZzVSmWVLKB3wJF4TsN0QS2BsyfRNi1j
