Exam Details

  • Exam Code
    :CIPP-E
  • Exam Name
    :Certified Information Privacy Professional/Europe (CIPP/E)
  • Certification
    :Certified Information Privacy Professional
  • Vendor
    :IAPP
  • Total Questions
    :298 Q&As
  • Last Updated
    :Apr 22, 2024

IAPP Certified Information Privacy Professional CIPP-E Questions & Answers

  • Question 1:

    According to Article 84 of the GDPR, the rules on penalties applicable to infringements shall be laid down by?

    A. The local Data Protection Supervisory Authorities.

    B. The European Data Protection Board.

    C. The EU Commission.

    D. The Member States.

  • Question 2:

    SCENARIO

    Please use the following to answer the next question:

    Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.

    Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.

    If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.

    Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.

    Joe also hires his best friend's daughter, Alice, who just graduated from law school in the US., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S. Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm. In preparing the company for its impending lawsuit, Alice's instruction to the company's IT Department violated Article 5 of the GDPR because the company failed to first do what?

    A. Send out consent forms to all of its employees.

    B. Minimize the amount of data collected for the lawsuit.

    C. Inform all of its employees about the lawsuit.

    D. Encrypt the data from all of its employees.

  • Question 3:

    SCENARIO

    Please use the following to answer the next question:

    WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:

    "WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the data. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information. We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."

    "We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."

    "We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to

    you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities."

    What additional information must Wonderkids provide in their Privacy Statement?

    A. How often promotional emails will be sent.

    B. Contact information of the hosting company.

    C. Technical and organizational measures to protect data.

    D. The categories of recipients with whom data will be shared.

  • Question 4:

    Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?

    A. Incidents of personal data breaches, whether disclosed or not.

    B. Data inventory or data mapping exercises that have been conducted.

    C. Categories of recipients to whom the personal data have been disclosed.

    D. Retention periods for erasure and deletion of categories of personal data.

  • Question 5:

    Which of the following entities would most likely be exempt from complying with the GDPR?

    A. A South American company that regularly collects European customers' personal data.

    B. A company that stores all customer data in Australia and is headquartered in a European Union (EU) member state.

    C. A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.

    D. A North American company servicing customers in South Africa that uses a cloud storage system made by a European company.

  • Question 6:

    SCENARIO

    Please use the following to answer the next question:

    Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.

    Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.

    If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.

    Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.

    Joe also hires his best friend's daughter, Alice, who just graduated from law school in the US., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S. Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm. The data transfer mechanism that Alice drafted violates the GDPR because the company did not first get approval from?

    A. The Court of Justice of the European Union.

    B. The European Data Protection Board.

    C. The Data Protection Authority.

    D. The European Commission.

  • Question 7:

    Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?

    A. Legislative powers.

    B. Corrective powers.

    C. Investigatory powers.

    D. Authorization and advisory powers.

  • Question 8:

    What was the aim of the European Data Protection Directive 95/46/EC?

    A. To harmonize the implementation of the European Convention of Human Rights across all member states.

    B. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.

    C. To completely prevent the transfer of personal data out of the European Union.

    D. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.

  • Question 9:

    To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?

    A. The Court of Justice of the European Union.

    B. The European Data Protection Supervisor.

    C. The European Court of Human Rights.

    D. The European Data Protection Board.

  • Question 10:

    As a result of the European Court of Justice's ruling in the case of Google v. Spain, search engines outside the EEA are also likely to be subject to the Regulation's right to be forgotten. This holds true if the activities of an EU subsidiary and its U.S. parent are what?

    A. Supervised by the same Data Protection Officer.

    B. Consistent with Privacy Shield requirements

    C. Bound by a standard contractual clause.

    D. Inextricably linked in their businesses.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only IAPP exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CIPP-E exam preparations and IAPP certification application, do not hesitate to visit our Vcedump.com to find your solutions here.