CIPP-E Exam Details

  • Exam Code
    :CIPP-E
  • Exam Name
    :Certified Information Privacy Professional/Europe (CIPP/E)
  • Certification
    :IAPP Certifications
  • Vendor
    :IAPP
  • Total Questions
    :307 Q&As
  • Last Updated
    :May 31, 2026

IAPP CIPP-E Online Questions & Answers

  • Question 161:

    As per the GDPR, which legal basis would be the most appropriate for an online shop that wishes to process personal data for the purpose of fraud prevention?

    A. Protection of the interests of the data subjects.
    B. Performance of a contact
    C. Legitimate interest
    D. Consent

  • Question 162:

    A news website based m (he United Slates reports primarily on North American events The website is accessible to any user regardless of location, as the website operator does not block connections from outside of the U.S. The website offers a pad subscription that requires the creation of a user account; this subscription can only be paid in U.S. dollars.

    Which of the following explains why the website operator, who is the responsible for all processing related to account creation and subscriptions, is NOT required to comply with the GDPR?

    A. Payments cannot be made in a European Union currency.
    B. The controller does not have an establishment in the European Union.
    C. The website is not available in several official languages of European Un on Member States
    D. The website cannot block connections from outside the U.S. that use a Virtual Private Network (VPN) to simulate a US location.

  • Question 163:

    Data retention in the EU was underpinned by a legal framework established by the Data Retention Directive (2006/24/EC). Why is the Directive no longer part of EU law?

    A. The Directive was superseded by the EU Directive on Privacy and Electronic Communications.
    B. The Directive was superseded by the General Data Protection Regulation.
    C. The Directive was annulled by the Court of Justice of the European Union.
    D. The Directive was annulled by the European Court of Human Rights.

  • Question 164:

    SCENARIO

    Please use the following to answer the next question:

    Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.

    Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.

    If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.

    Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.

    Joe also hires his best friend's daughter, Alice, who just graduated from law school in the US., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S. Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm. When Ben had the company collect additional data from its customers, the most serious violation of the GDPR occurred because the processing of the data created what?

    A. An information security risk by copying the data into a new database.
    B. A potential legal liability and financial exposure from its customers.
    C. A significant risk to the customers' fundamental rights and freedoms.
    D. A significant risk due to the lack of an informed consent mechanism.

  • Question 165:

    A homeowner has installed a motion-detecting surveillance system that films his front doc and entryway. The camera does not film any public areas only areas that are the property of the homeowner. The system has seen declared to the authorities per the homeowner's country law, and a placard indicating the area is being video monitored is visible when entering the property

    Why can the homeowner NOT depend on the household exemption with regards to the processing of the video images recorded by the surveillance camera system?

    A. The surveillance camera system can potentially capture biometric information of the homeowner's family, which would be considered a processing of special categories of personal data.
    B. The homeowner has not specified which security measures ore in place as part of the surveillance camera system
    C. The GDPR specifically excludes surveillance camera images from the household exemption
    D. The surveillance camera system can potentially film individuals who enter its filming perimeter

  • Question 166:

    Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?

    A. Approved certifications.
    B. Binding corporate rules.
    C. Law enforcement requests.
    D. Standard contractual clauses.

  • Question 167:

    What is true if an employee makes an access request to his employer for any personal data held about him?

    A. The employer can automatically decline the request if it contains personal data about a third person.
    B. The employer can decline the request if the information is only held electronically.
    C. The employer must supply all the information held about the employee.
    D. The employer must supply any information held about an employee unless an exemption applies.

  • Question 168:

    What monitoring may lawfully be performed within the scope of Gentle Hedgehog's business?

    A. Everything offered by Sauron Eye's software in relation to activity by sales team contractors.
    B. Everything offered by Sauron Eye's software, assuming employees provide daily consent to the monitoring.
    C. Only emails, website browsing history, and camera for internal video calls conducted in a non-secure environment.
    D. Only emails, website browsing history, and camera for internal video calls that are expressly marked as monitored.

  • Question 169:

    SCENARIO

    Please use the following to answer the next question:

    Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in Greece (5), Italy (15) and Spain (1), have registered their most profitable results ever. To celebrate this achievement, ARRA Hotels' Human Resources

    office, based in ARRA's main Italian establishment, has organized a team event for its 420 employees and their families at its hotel in Spain.

    Upon arrival at the hotel, each employee and family member is given an electronic wristband at the reception desk. The wristband serves a number of functions:

    1.

    Allows access to the "party zone" of the hotel, and emits a buzz if the user approaches any unauthorized areas

    2.

    Allows up to three free drinks for each person of legal age, and emits a buzz once this limit has been reached

    3.

    Grants a unique ID number for participating in the games and contests that have been planned.

    Along with the wristband, each guest receives a QR code that leads to the online privacy notice describing the use of the wristband. The page also contains an unchecked consent checkbox. In the case of employee family members under the age of 16, consent must be given by a parent. Among the various activities planned for the event, ARRA Hotels' HR office has autonomously set up a photocall area, separate from the main event venue, where employees can come and have their pictures taken in traditional carnival

    costume. The photos will be posted on ARRA Hotels' main website for general marketing purposes.

    On the night of the event, an employee from one of ARRA's Greek hotels is displeased with the results of the photos in which he appears. He intends to file a complaint with the relevant supervisory authority in regard to the following:

    1.

    The lack of any privacy notice in the separate photocall area

    2.

    The unlawful cross-border processing of his personal data

    3.

    The unacceptable aesthetic outcome of his photos

    Which of the following principles has likely been violated in the processing of the photocall photos containing personal data?

    A. Adequacy.
    B. Lawfulness.
    C. Transparency.
    D. Data minimization.

  • Question 170:

    Which of the following entities would most likely be exempt from complying with the GDPR?

    A. A South American company that regularly collects European customers' personal data.
    B. A company that stores all customer data in Australia and is headquartered in a European Union (EU) member state.
    C. A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.
    D. A North American company servicing customers in South Africa that uses a cloud storage system made by a European company.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only IAPP exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CIPP-E exam preparations and IAPP certification application, do not hesitate to visit our Vcedump.com to find your solutions here.