Exam Details

  • Exam Code
    :CIPP-E
  • Exam Name
    :Certified Information Privacy Professional/Europe (CIPP/E)
  • Certification
    :IAPP Certifications
  • Vendor
    :IAPP
  • Total Questions
    :298 Q&As
  • Last Updated
    :May 08, 2025

IAPP IAPP Certifications CIPP-E Questions & Answers

  • Question 101:

    SCENARIO

    Please use the following to answer the next question:

    Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical company on a clinical trial related to COVID-19. As part of his onboarding process Jack received privacy training He was explicitly informed that while he would need to process confidential patient data in the course of his work, he may under no circumstances use this data for anything other than the performance of work-related (asks This was also specified in the privacy policy, which Jack signed upon conclusion of the training.

    After several months of employment, Jack got into an argument with a patient over the phone. Out of anger he later posted the patient's name and hearth information, along with disparaging comments, on a social media website. When this was discovered by his Pharmacovigilance supervisors. Jack was immediately dismissed

    Jack's lawyer sent a letter to the company stating that dismissal was a disproportionate sanction, and that if Jack was not reinstated within 14 days his firm would have no alternative but to commence legal proceedings against the company. This letter was accompanied by a data access request from Jack requesting a copy of "all personal data, including internal emails that were sent/received by Jack or where Jack is directly or indirectly identifiable from the contents * In relation to the emails Jack listed six members of the management team whose inboxes he required access.

    The company conducted an initial search of its IT systems, which returned a large amount of information They then contacted Jack, requesting that he be more specific regarding what information he required, so that they could carry out a targeted search Jack responded by stating that he would not narrow the scope of the information requester.

    What would be the most appropriate response to Jacks data subject access request?

    A. The company should not provide any information, as the company is headquartered outside of the EU.

    B. The company should decline to provide any information, as the amount of information requested is too excessive to provide in one month.

    C. The company should cite the need for an extension, and agree to provide the information requested in Jack's original DSAR within a period of 3 months.

    D. The company should provide all requested information except for the emails, as they are excluded from data access request requirements under the GDPR.

  • Question 102:

    What is the key difference between the European Council and the Council of the European Union?

    A. The Council of the European Union is helmed by a president.

    B. The Council of the European Union has a degree of legislative power.

    C. The European Council focuses primarily on issues involving human rights.

    D. The European Council is comprised of the heads of each EU member state.

  • Question 103:

    A company plans to transfer employee health information between two of its entities in France. To maintain the security of the processing, what would be the most important security measure to apply to the health data transmission?

    A. Inform the data subject of the security measures in place.

    B. Ensure that the receiving entity has signed a data processing agreement.

    C. Encrypt the transferred data in transit and at rest.

    D. Conduct a data protection impact assessment.

  • Question 104:

    In which of the following cases, cited as an example by a WP29 guidance, would conducting a single data protection impact assessment to address multiple processing operations be allowed?

    A. A medical organization that wants to begin genetic testing to support earlier research for which they have performed a DPIA.

    B. A data controller who plans to use a new technology product that has already undergone a DPIA by the product's provider.

    C. A marketing team that wants to collect mailing addresses of customers for whom they already have email addresses.

    D. A railway operator who plans to evaluate the same video surveillance in all the train stations of his company.

  • Question 105:

    Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?

    A. Data subject rights

    B. Data access disputes

    C. Cross-border processing

    D. Special categories of data

  • Question 106:

    SCENARIO

    Please use the following to answer the next question:

    The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its website as a free download. Vigotron's marketing manager asks his assistant Emily to create a webpage that describes the app and specifies the terms of use. Emily, who is new at Vigotron, is excited about this task. At her previous job she took a data protection class, and though the details are a little hazy, she recognizes that Vigotron is going to need to obtain user consent for use of the app in some cases. Emily sketches out the following draft, trying to cover as much as possible before sending it to Vigotron's legal department.

    Registration Form

    Vigotron's new M-Health app makes it easy for you to monitor a variety of health-related activities, including diet, exercise, and sleep patterns. M-Health relies on your smartphone settings (along with other third-party apps you may already

    have) to collect data about all of these important lifestyle elements, and provide the information necessary for you to enrich your quality of life. (Please click here to read a full description of the services that M-Health provides.)

    Vigotron values your privacy. The M-Heaith app allows you to decide which information is stored in it, and which apps can access your data. When your device is locked with a passcode, all of your health and fitness data is encrypted with

    your passcode. You can back up data stored in the Health app to Vigotron's cloud provider, Stratculous. (Read more about Stratculous here.)

    Vigotron will never trade, rent or sell personal information gathered from the M-Health app. Furthermore, we will not provide a customer's name, email address or any other information gathered from the app to any third-party without a

    customer's consent, unless ordered by a court, directed by a subpoena, or to enforce the manufacturer's legal rights or protect its business or property.

    We are happy to offer the M-Health app free of charge. If you want to download and use it, we ask that you

    first complete this registration form. (Please note that use of the M-Health app is restricted to adults aged 16 or older, unless parental consent has been given to minors intending to use it.)

    First name:

    Surname:

    Year of birth:

    Email:

    Physical Address (optional*):

    Health status:

    *If you are interested in receiving newsletters about our products and services that we think may be of interest to you, please include your physical address. If you decide later that you do not wish to receive these newsletters, you can

    unsubscribe by sending an email to [email protected] or send a letter with your request to the address listed at the bottom of this page.

    Terms and Conditions

    1.Jurisdiction. [...]

    2.Applicable law. [...]

    3.Limitation of liability. [...]

    Consent

    By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of

    any advertising or marketing, you agree that Vigotron may contact you or provide you with any required notices, agreements, or other information concerning the services by email or other electronic means. You also agree that the Company

    may send automated emails with alerts regarding any problems with the M-Health app that may affect your well being.

    If a user of the M-Health app were to decide to withdraw his consent, Vigotron would first be required to do what?

    A. Provide the user with logs of data collected through use of the app.

    B. Erase any data collected from the time the app was first used.

    C. Inform any third parties of the user's withdrawal of consent.

    D. Cease processing any data collected through use of the app.

  • Question 107:

    SCENARIO

    Please use the following to answer the next question:

    TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.

    During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories ?age, income, ethnicity ?that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.

    Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'swebsite, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.

    If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?

    A. The resulting obligation to notify data subjects would involve disproportionate effort.

    B. The incident resulted from the actions of a third-party that were beyond their control.

    C. The destruction of the stolen data makes any risk to the affected data subjects unlikely.

    D. The sensitivity of the categories of data involved in the incident was not substantial enough.

  • Question 108:

    SCENARIO

    Please use the following to answer the next question:

    TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a salesrepresentative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business. During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories ?age, income, ethnicity ?that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan

    to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.

    Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.

    With regard to TripBliss Inc.'s use of website cookies, which of the following statements is correct?

    A. Because not all of the cookies are strictly necessary to enable the use of a service requested from TripBliss Inc., consent requirements apply to their use of cookies.

    B. Because of the categories of data involved, explicit consent for the use of cookies must be obtained separately from customers.

    C. Because Techiva will receive only aggregate statistics of data collected from the cookies, no additional consent is necessary.

    D. Because the use of cookies involves the potential for location tracking, explicit consent must be obtained from customers.

  • Question 109:

    SCENARIO Please use the following to answer the next question:

    Gentle Hedgehog Inc. is a privately owned website design agency incorporated in Italy. The company has numerous remote workers in different EU countries. Recently, the management of Gentle Hedgehog noticed a decrease in productivity

    of their sales team, especially among remote workers. As a result, the company plans to implement a robust but privacy-friendly remote surveillance system to prevent absenteeism, reward top performers, and ensure the best quality of

    customer service when sales people are interacting with customers.

    Gentle Hedgehog eventually hires Sauron Eye Inc., a Chinese vendor of employee surveillance software whose European headquarters is in Germany. Sauron Eye s software provides powerful remote-monitoring capabilities, including 24/7

    access to computer cameras and microphones, screen captures, emails, website history, and keystrokes. Any device can be remotely monitored from a central server that is securely installed at Gentle Hedgehog headquarters. The

    monitoring is invisible by default; however, a so-called Transparent Mode, which regularly and conspicuously notifies all users about the monitoring and its precise scope, also exists. Additionally, the monitored employees are required to use

    a built-in verification technology involving facial recognition each time they log in.

    All monitoring data, including the facial recognition data, is securely stored in Microsoft Azure cloud servers operated by Sauron Eye, which are physically located in France.

    What monitoring may be lawfully performed within the scope of Gentle Hedgehog's business?

    A. Everything offered by Sauron Eye's software with the exception of camera and microphone monitoring.

    B. Everything offered by Sauron Eye's software, assuming employees provide daily consent to the monitoring.

    C. Only video calls conducted during business hours and emails that do not contain a “private” or “personal” tag.

    D. Only emails, website browsing history and camera for internal video calls that are expressly marked as monitored.

  • Question 110:

    SCENARIO Please use the following to answer the next question:

    Gentle Hedgehog Inc. is a privately owned website design agency incorporated in Italy. The company has numerous remote workers in different EU countries. Recently, the management of Gentle Hedgehog noticed a decrease in productivity

    of their sales team, especially among remote workers. As a result, the company plans to implement a robust but privacy-friendly remote surveillance system to prevent absenteeism, reward top performers, and ensure the best quality of

    customer service when sales people are interacting with customers.

    Gentle Hedgehog eventually hires Sauron Eye Inc., a Chinese vendor of employee surveillance software whose European headquarters is in Germany. Sauron Eye s software provides powerful remote-monitoring capabilities, including 24/7

    access to computer cameras and microphones, screen captures, emails, website history, and keystrokes. Any device can be remotely monitored from a central server that is securely installed at Gentle Hedgehog headquarters. The

    monitoring is invisible by default; however, a so-called Transparent Mode, which regularly and conspicuously notifies all users about the monitoring and its precise scope, also exists. Additionally, the monitored employees are required to use

    a built-in verification technology involving facial recognition each time they log in.

    All monitoring data, including the facial recognition data, is securely stored in Microsoft Azure cloud servers operated by Sauron Eye, which are physically located in France.

    What is the main problem with the 24/7 camera monitoring?

    A. It must not be operated during non-business hours and employee holidays.

    B. It may accidentally film third parties whose consent is required for monitoring.

    C. It has no valid legal basis to be implemented in the context of Gentle Hedgehog's business.

    D. It must first be approved by the trade union and then granted a license from the national DPA.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only IAPP exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CIPP-E exam preparations and IAPP certification application, do not hesitate to visit our Vcedump.com to find your solutions here.