Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified Information Privacy Professional/Europe (CIPP/E) Practice Questions

Exams4sure Dumps

Exam style questions across every CIPP-E domain

Last Update 4 hours ago
Total Questions : 295

Start with our free CIPP-E practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Certified Information Privacy Professional exam. Each CIPP-E exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your IAPP weak domains, see where you're losing marks, and build a focused study plan in minutes.

CIPP-E PDF

CIPP-E PDF (Printable)
$46.5
$154.99

CIPP-E Testing Engine

CIPP-E PDF (Printable)
$51
$169.99

CIPP-E PDF + Testing Engine

CIPP-E PDF (Printable)
$63.9
$212.99
Question # 11

An online company’s privacy practices vary due to the fact that it offers a wide variety of services. How could it best address the concern that explaining them all would make the policies incomprehensible?

Options:

A.  

Use a layered privacy notice on its website and in its email communications.

B.  

Identify uses of data in a privacy notice mailed to the data subject.

C.  

Provide only general information about its processing activities and offer a toll-free number for more information.

D.  

Place a banner on its website stipulating that visitors agree to its privacy policy and terms of use by visiting the site.

Discussion 0
Question # 12

SCENARIO

Please use the following to answer the next question:

Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Governance. Through her first initiative in conducting a data inventory, Sandy learned that Market4U maintains a list of 19 million global contacts that were collected throughout the course of Market4U’s existence. Knowing the risk of having such a large amount of data, Sandy wanted to purge all contacts that were entered into Market4U’s systems prior to May 2018, unless such contacts had a more recent interaction with Market4U content. However, Dan, the VP of Sales, informed Sandy that all of the contacts provide useful information regarding successful marketing campaigns and trends in industry verticals for Market4U’s clients.

Dan also informed Sandy that he had wanted to focus on gaining more customers within the sports and entertainment industry. To assist with this behavior, Market4U’s marketing team decided to add several new fields to Market4U’s website forms, including forms for downloading white papers, creating accounts to participate in Market4U’s forum, and attending events. Such fields include birth date and salary.

What is the best way that Sandy can gain the insights that Dan seeks while still minimizing risks for Market4U?

Options:

A.  

Conduct analysis only on anonymized personal data.

B.  

Conduct analysis only on pseudonymized personal data.

C.  

Delete all data collected prior to May 2018 after conducting the trend analysis.

D.  

Procure a third party to conduct the analysis and delete the data from Market4U’s systems.

Discussion 0
Question # 13

Under the GDPR, which of the following is true in regard to adequacy decisions involving cross-border transfers?

Options:

A.  

The European Commission can adopt an adequacy decision for individual companies.

B.  

The European Commission can adopt, repeal or amend an existing adequacy decision.

C.  

EU member states are vested with the power to accept or reject a European Commission adequacy decision.

D.  

To be considered as adequate, third countries must implement the EU General Data Protection Regulation into their national legislation.

Discussion 0
Question # 14

What was the aim of the European Data Protection Directive 95/46/EC?

Options:

A.  

To harmonize the implementation of the European Convention of Human Rights across all member states.

B.  

To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.

C.  

To completely prevent the transfer of personal data out of the European Union.

D.  

To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.

Discussion 0
Question # 15

SCENARIO

Please use the following to answer the next question:

Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Javier lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Javier was photographed while working out at a branch of EVERFIT in Frankfurt, Germany. At the time, Javier gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club’s U.K. brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Javier no longer feels comfortable with his photograph being publicly associated with the fitness club.

After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Javier sends a letter to EVETFIT requesting that his image be removed from the website and all promotional materials. Months pass and Javier, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact EVETFIT through alternate channels, he decides to take action against the company.

Javier contacts the U.K. Information Commissioner’s Office (‘ICO’ – the U.K.’s supervisory authority) to lodge a complaint about this matter. The ICO, pursuant to Article 56 (3) of the GDPR, informs the CNIL (i.e. the supervisory authority of EVERFIT’s main establishment) about this matter. Despite the fact that EVERFIT has an establishment in the U.K., the CNIL decides to handle the case in accordance with Article 60 of the GDPR. The CNIL liaises with the ICO, as relevant under the cooperation procedure. In light of issues amongst the supervisory authorities to reach a decision, the European Data Protection Board becomes involved and, pursuant to the consistency mechanism, issues a binding decision.

Additionally, Javier sues EVERFIT for the damages caused as a result of its failure to honor his request to have his photograph removed from the brochure and website.

Under the cooperation mechanism, what should the lead authority (the CNIL) do after it has formed its view on the matter?

Options:

A.  

Submit a draft decision to other supervisory authorities for their opinion.

B.  

Request that the other supervisory authorities provide the lead authority with a draft decision for its consideration.

C.  

Submit a draft decision directly to the Commission to ensure the effectiveness of the consistency mechanism.

D.  

Request that members of the seconding supervisory authority and the host supervisory authority co-draft a decision.

Discussion 0
Question # 16

Under Article 58 of the GDPR, which of the following describes a power of supervisory authorities in European Union (EU) member states?

Options:

A.  

The ability to enact new laws by executive order.

B.  

The right to access data for investigative purposes.

C.  

The discretion to carry out goals of elected officials within the member state.

D.  

The authority to select penalties when a controller is found guilty in a court of law.

Discussion 0
Question # 17

What permissions are required for a marketer to send an email marketing message to a consumer in the EU?

Options:

A.  

A prior opt-in consent for consumers unless they are already customers.

B.  

A pre-checked box stating that the consumer agrees to receive email marketing.

C.  

A notice that the consumer’s email address will be used for marketing purposes.

D.  

No prior permission required, but an opt-out requirement on all emails sent to consumers.

Discussion 0
Question # 18

SCENARIO

Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers’ data to third parties, and he’s convinced that Accidentable must have gotten his information from Bedrock Insurance.

Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.

Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.

In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.

Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis’s contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.

In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.

Accidentable’s response letter confirms Louis’s suspicions. Accidentable is Bedrock Insurance’s wholly owned subsidiary, and they received information about Louis’s accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis’s contract included, a provision in which he agreed to share his information with Bedrock’s affiliates for business purposes.

Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.

Based on the GDPR’s position on the use of personal data for direct marketing purposes, which of the following is true about Louis’s rights as a data subject?

Options:

A.  

Louis does not have the right to object to the use of his data because he previously consented to it.

B.  

Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.

C.  

Louis has the right to object to the use of his data, unless his data is required by Bedrock for the purpose

of exercising a legal claim.

D.  

Louis does not have the right to object to the use of his data if Bedrock can demonstrate compelling legitimate grounds for the processing.

Discussion 0
Question # 19

SCENARIO

Please use the following to answer the next question:

Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.

Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick’s instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.

Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its

clients’ data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying

information from the contact information. JaphSoft’s engineers, however, maintain all contact information in the same database as the identifying information.

Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies’ websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem’s as well as EcoMick’s latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem’s products, she has never shopped EcoMick, nor provided her personal data to that company.

JaphSoft’s use of pseudonymization is NOT in compliance with the CDPR because?

Options:

A.  

JaphSoft failed to first anonymize the personal data.

B.  

JaphSoft pseudonymized all the data instead of deleting what it no longer needed.

C.  

JaphSoft was in possession of information that could be used to identify data subjects.

D.  

JaphSoft failed to keep personally identifiable information in a separate database.

Discussion 0
Question # 20

Which type of personal data does the GDPR define as a “special category” of personal data?

Options:

A.  

Educational history.

B.  

Trade-union membership.

C.  

Closed Circuit Television (CCTV) footage.

D.  

Financial information.

Discussion 0

Free Exams Sample Questions