CIPP-E Exam Details

  • Exam Code
    :CIPP-E
  • Exam Name
    :Certified Information Privacy Professional/Europe (CIPP/E)
  • Certification
    :IAPP Certifications
  • Vendor
    :IAPP
  • Total Questions
    :307 Q&As
  • Last Updated
    :

IAPP CIPP-E Online Questions & Answers

  • Question 111:

    According to guidance from the European Data Protection Board, in which of the following cases would a controller established outside of the EU not be subject to the GDPR?

    A. If the controller monitors the behavior of persons on the territory of the Republic of Switzerland.
    B. If the controller has a fully-owned branch office in the EU overseeing all its European operations, including marketing and advertising.
    C. If the controller has its some of its offices and servers based in the EU without having a legal branch or subsidiary in any EU Member State.
    D. If the controller uses the services of an EU-based processor without offering goods or services to persons on EU territory or monitoring their behavior.

  • Question 112:

    The GDPR forbids the practice of "forum shopping", which occurs when companies do what?

    A. Choose the data protection officer that is most sympathetic to their business concerns.
    B. Designate their main establishment in member state with the most flexible practices.
    C. File appeals of infringement judgments with more than one EU institution simultaneously.
    D. Select third-party processors on the basis of cost rather than quality of privacy protection.

  • Question 113:

    Please use the following to answer the next question:

    WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:

    "WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the data. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information. We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."

    "We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."

    "We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities."

    What direct marketing information can WonderKids send by email without prior consent of the person booking the childcare?

    A. No marketing information at all.
    B. Any marketing information at all.
    C. Marketing information related to other business operations of WonderKids.
    D. Marketing information for products or services similar to those purchased from WonderKids.

  • Question 114:

    What must a data controller do in order to make personal data pseudonymous?

    A. Separately hold any information that would allow linking the data to the data subject.
    B. Encrypt the data in order to prevent any unauthorized access or modification.
    C. Remove all indirect data identifiers and dispose of them securely.
    D. Use the data only in aggregated form for research purposes.

  • Question 115:

    SCENARIO

    Please use the following to answer the next question:

    TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.

    During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories ?age, income, ethnicity ?that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.

    Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'swebsite, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.

    If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?

    A. The resulting obligation to notify data subjects would involve disproportionate effort.
    B. The incident resulted from the actions of a third-party that were beyond their control.
    C. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
    D. The sensitivity of the categories of data involved in the incident was not substantial enough.

  • Question 116:

    Under Article 9 of the GDPR, which of the following categories of data is NOT expressly prohibited from data processing?

    A. Personal data revealing ethnic origin.
    B. Personal data revealing genetic data.
    C. Personal data revealing financial data.
    D. Personal data revealing trade union membership.

  • Question 117:

    In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?

    A. The predicted consequences of the breach.
    B. The measures being taken to address the breach.
    C. The type of security safeguards used to protect the data.
    D. The contact details of the appropriate data protection officer.

  • Question 118:

    Which institution has the power to adopt findings that confirm the adequacy of the data protection level in a non-EU country?

    A. The European Parliament
    B. The European Commission
    C. The Article 29 Working Party
    D. The European Council

  • Question 119:

    Which mechanism, introduced by the GDPR as a means of ensuring both compliance and transparency, allows for the possibility of personal data transfers to third countries under Article 42?

    A. Approved certifications.
    B. Binding corporate rules.
    C. Law enforcement requests.
    D. Standard contractual clauses.

  • Question 120:

    WP29's "Guidelines on Personal data breach notification under Regulation 2016/679'' provides examples of ways to communicate data breaches transparently. Which of the following was listed as a method that would NOT be effective for communicating a breach to data subjects?

    A. A postal notification
    B. A direct electronic message
    C. A notice on a corporate blog
    D. A prominent advertisement in print media

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only IAPP exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CIPP-E exam preparations and IAPP certification application, do not hesitate to visit our Vcedump.com to find your solutions here.