CIPP-E Exam Details

  • Exam Code
    :CIPP-E
  • Exam Name
    :Certified Information Privacy Professional/Europe (CIPP/E)
  • Certification
    :IAPP Certifications
  • Vendor
    :IAPP
  • Total Questions
    :307 Q&As
  • Last Updated
    :May 31, 2026

IAPP CIPP-E Online Questions & Answers

  • Question 201:

    If a company is planning to use closed-circuit television (CCTV) on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?

    A. Notify the appropriate data protection authority.
    B. Perform a data protection impact assessment (DPIA).
    C. Create an information retention policy for those who operate the system.
    D. Ensure that safeguards are in place to prevent unauthorized access to the footage.

  • Question 202:

    SCENARIO

    Please use the following to answer the next question: Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no

    longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.

    Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.

    After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location. During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.

    Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.

    To comply with the GDPR, what should Building Block have done as a first step before implementing the SecurityScan measure?

    A. Assessed potential privacy risks by conducting a data protection impact assessment.
    B. Consulted with the relevant data protection authority about potential privacy violations.
    C. Distributed a more comprehensive notice to employees and received their express consent.
    D. Consulted with the Information Security team to weigh security measures against possible server impacts.

  • Question 203:

    Which judicial body makes decisions on actions taken by individuals wishing to enforce their rights under EU law?

    A. Court of Auditors
    B. Court of Justice of European Union
    C. European Court of Human Rights
    D. European Data Protection Board

  • Question 204:

    It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements?

    A. Notify the police and Tile a criminal complaint about the incident
    B. Start an investigation to understand the incident's possible scope, duration and nature
    C. Send a notification to the competent supervisory authority describing the incident.
    D. Send an email about the incident to all clients and ask them to change their passwords

  • Question 205:

    Which of the following is NOT recognized as being a common characteristic of cloud-computing services?

    A. The service's infrastructure is shared among the supplier's customers and can be located in a number of countries.
    B. The supplier determines the location, security measures, and service standards applicable to the processing.
    C. The supplier allows customer data to be transferred around the infrastructure according to capacity.
    D. The supplier assumes the vendor's business risk associated with data processed by the supplier.

  • Question 206:

    According to the Personal Data Protection Commission’s (PDPC) “Guide to basic data anonymization techniques,” recently adopted by the Spanish Data Protection Agency, which of the following is NOT a valid basic anonymization technique?

    A. Swapping.
    B. Generalization.
    C. Data Adjustment.
    D. Attribute Suppression.

  • Question 207:

    SCENARIO

    Please use the following to answer the next question:

    ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO, Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage's global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments. The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized in New Delhi. Unable to reach Ruth's family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR, provided information to the doctors based on accommodation requests Ruth made when she started at ProStorage.

    In support of Ruth's strategic goals of hiring more sales representatives, the Human Resources team is focused on improving its processes to ensure that new employees are sourced, interviewed, hired, and on boarded efficiently. To help with this, Mary identified two vendors, HRYourWay, a German based company, and InstaHR, an Australian based company. She decided to have both vendors go through ProStorage's vendor risk review process so she can work with Ruth to make the final decision. As part of the review process, Jackie, who is responsible for maintaining ProStorage's privacy program (including maintaining controller BCRs and conducting vendor risk assessments), reviewed both vendors but completed a transfer impact assessment only for InstaHR. After her review of both vendors, she determined that InstaHR satisfied more of the requirements as it boasted a more established privacy program and provided third-party attestations, whereas HRYourWay was a small vendor with minimal data protection operations. Thus, she recommended InstaHR.

    ProStorage's marketing team also worked to meet the strategic goals of the company by focusing on industries where it needed to grow its market share. To help with this, the team selected as a partner UpFinance. a US based company with deep connections to financial industry customers. During ProStorage's diligence process, Jackie from the privacy team noted in the transfer impact assessment that UpFinance implements several data protection measures including end-loend encryption, with encryption keys held by the customer. Notably, UpFinance has not received any government requests in its 7 years of business. Still, Jackie recommended that the contract require UpFinance to notify ProStorage if it receives a government request for personal data UpFinance processes on its behalf prior to disclosing such data.

    What transfer mechanism should Jackie recommend for using InstaHR?

    A. Adequacy
    B. Binding corporate rules.
    C. Explicit consent of employees.
    D. Standard contractual clauses

  • Question 208:

    A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if it imports personal data from another organization in the European Economic Area (EEA) under standard contractual clauses?

    A. Submit the contract to its own government authority.
    B. Ensure that notice is given to and consent is obtained from data subjects.
    C. Supply any information requested by a data protection authority (DPA) within 30 days.
    D. Ensure that local laws do not impede the company from meeting its contractual obligations.

  • Question 209:

    Which type of personal data does the GDPR define as a "special category" of personal data?

    A. Educational history.
    B. Trade-union membership.
    C. Closed Circuit Television (CCTV) footage.
    D. Financial information.

  • Question 210:

    Which of the following elements does NOT need to be presented to a data subject in order to collect valid consent for the use of cookies?

    A. A "Cookies Settings" button.
    B. A "Reject All" cookies button.
    C. A list of cookies that may be placed.
    D. Information on the purpose of the cookies.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only IAPP exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CIPP-E exam preparations and IAPP certification application, do not hesitate to visit our Vcedump.com to find your solutions here.