Exam Details

  • Exam Code
    :CIPP-E
  • Exam Name
    :Certified Information Privacy Professional/Europe (CIPP/E)
  • Certification
    :IAPP Certifications
  • Vendor
    :IAPP
  • Total Questions
    :298 Q&As
  • Last Updated
    :May 08, 2025

IAPP IAPP Certifications CIPP-E Questions & Answers

  • Question 251:

    SCENARIO Please use the following to answer the next question: BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of

    sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information ?name, location, and prior purchase history ?with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens. Prior to sharing its customer list, BHealthy conducted a review of Natural Insight's security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy's data processing

    contractualterms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight's machine learning algorithms.

    Under the GDPR, what are Natural Insight's security obligations with respect to the customer information it received from BHealthy?

    A. Appropriate security that takes into account the industry practices for protecting customer contact information and purchase history.

    B. Only the security measures assessed by BHealthy prior to entering into the data processing contract.

    C. Absolute security since BHealthy is sharing personal data, including purchase history, with Natural Insight.

    D. The level of security that a reasonable data subject whose data is processed would expect in relation to the data subject's purchase history.

  • Question 252:

    What was the aim of the European Data Protection Directive 95/46/EC?

    A. To harmonize the implementation of the European Convention of Human Rights across all member states.

    B. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.

    C. To completely prevent the transfer of personal data out of the European Union.

    D. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.

  • Question 253:

    Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?

    A. Legislative powers.

    B. Corrective powers.

    C. Investigatory powers.

    D. Authorization and advisory powers.

  • Question 254:

    To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?

    A. The Court of Justice of the European Union.

    B. The European Data Protection Supervisor.

    C. The European Court of Human Rights.

    D. The European Data Protection Board.

  • Question 255:

    As a result of the European Court of Justice's ruling in the case of Google v. Spain, search engines outside the EEA are also likely to be subject to the Regulation's right to be forgotten. This holds true if the activities of an EU subsidiary and its U.S. parent are what?

    A. Supervised by the same Data Protection Officer.

    B. Consistent with Privacy Shield requirements

    C. Bound by a standard contractual clause.

    D. Inextricably linked in their businesses.

  • Question 256:

    Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?

    A. Anonymizing special categories of data.

    B. Conducting regular audits of the data protection program.

    C. Getting consent from the data subject for a cross border data transfer.

    D. Encrypting data in transit and at rest using strong encryption algorithms.

  • Question 257:

    The transparency principle is most directly related to which of the following rights?

    A. Right to object

    B. Right to be informed.

    C. Right to be forgotten.

    D. Right to restriction of processing.

  • Question 258:

    SCENARIO

    Please use the following to answer the next question:

    ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO, Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage's global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments. The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized in New Delhi. Unable to reach Ruth's family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR, provided information to the doctors based on accommodation requests Ruth made when she started at ProStorage.

    In support of Ruth's strategic goals of hiring more sales representatives, the Human Resources team is focused on improving its processes to ensure that new employees are sourced, interviewed, hired, and on boarded efficiently. To help with this, Mary identified two vendors, HRYourWay, a German based company, and InstaHR, an Australian based company. She decided to have both vendors go through ProStorage's vendor risk review process so she can work with Ruth to make the final decision. As part of the review process, Jackie, who is responsible for maintaining ProStorage's privacy program (including maintaining controller BCRs and conducting vendor risk assessments), reviewed both vendors but completed a transfer impact assessment only for InstaHR. After her review of both vendors, she determined that InstaHR satisfied more of the requirements as it boasted a more established privacy program and provided third-party attestations, whereas HRYourWay was a small vendor with minimal data protection operations. Thus, she recommended InstaHR.

    ProStorage's marketing team also worked to meet the strategic goals of the company by focusing on industries where it needed to grow its market share. To help with this, the team selected as a partner UpFinance. a US based company with deep connections to financial industry customers. During ProStorage's diligence process, Jackie from the privacy team noted in the transfer impact assessment that UpFinance implements several data protection measures including end-loend encryption, with encryption keys held by the customer. Notably, UpFinance has not received any government requests in its 7 years of business. Still, Jackie recommended that the contract require UpFinance to notify ProStorage if it receives a government request for personal data UpFinance processes on its behalf prior to disclosing such data.

    Why was Jackie correct in not completing a transfer impact assessment for HRYourWay?

    A. HRYourWay was ultimately not selected

    B. HRYourWay is not located in a third country.

    C. ProStorage will obtain consent for all transfers.

    D. ProStorage can rely on its Binding Corporate Rules

  • Question 259:

    SCENARIO

    Please use the following to answer the next question:

    Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.

    Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.

    If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.

    Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.

    Joe also hires his best friend's daughter, Alice, who just graduated from law school in the US., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S. Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm. The data transfer mechanism that Alice drafted violates the GDPR because the company did not first get approval from?

    A. The Court of Justice of the European Union.

    B. The European Data Protection Board.

    C. The Data Protection Authority.

    D. The European Commission.

  • Question 260:

    Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?

    A. Incidents of personal data breaches, whether disclosed or not.

    B. Data inventory or data mapping exercises that have been conducted.

    C. Categories of recipients to whom the personal data have been disclosed.

    D. Retention periods for erasure and deletion of categories of personal data.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only IAPP exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CIPP-E exam preparations and IAPP certification application, do not hesitate to visit our Vcedump.com to find your solutions here.