Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified Information Privacy Professional/Europe (CIPP/E) Practice Questions

Exams4sure Dumps

Exam style questions across every CIPP-E domain

Last Update 5 hours ago
Total Questions : 295

Start with our free CIPP-E practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Certified Information Privacy Professional exam. Each CIPP-E exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your IAPP weak domains, see where you're losing marks, and build a focused study plan in minutes.

CIPP-E PDF

CIPP-E PDF (Printable)
$46.5
$154.99

CIPP-E Testing Engine

CIPP-E PDF (Printable)
$51
$169.99

CIPP-E PDF + Testing Engine

CIPP-E PDF (Printable)
$63.9
$212.99
Question # 21

According to the GDPR, what is the main task of a Data Protection Officer (DPO)?

Options:

A.  

To create and maintain records of processing activities.

B.  

To conduct Privacy Impact Assessments on behalf of the controller or processor.

C.  

To monitor compliance with other local or European data protection provisions.

D.  

To create procedures for notification of personal data breaches to competent supervisory authorities.

Discussion 0
Question # 22

With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?

Options:

A.  

If the data controller has received preapproval from a Data Protection Authority (DPA), after submitting the appropriate documents.

B.  

When it has been determined that adequate protection can be performed.

C.  

Only if the Data Protection Impact Assessment (DPIA) shows low risk.

D.  

Only as a last resort and when interpreted restrictively.

Discussion 0
Question # 23

Through a combination of hardware failure and human error, the decryption key for a bank's customer account transaction database has been lost. An investigation has determined that this was not the result of hacking or malfeasance, simply an unfortunate combination of circumstances. Which of the following accurately indicates the nature of this incident?

Options:

A.  

A data breach has not occurred because the loss was not the result of hacking.

B.  

A data breach has not occurred because no data was exposed to any unauthorized individual.

C.  

A data breach has occurred because the loss of the key has resulted in the data no longer being accessible.

D.  

A data breach has occurred because the loss of the key has resulted in the loss of confidentiality or integrity of the data.

Discussion 0
Question # 24

What are the obligations of a processor that engages a sub-processor?

Options:

A.  

The processor must give the controller prior written notice and perform a preliminary audit of the sub- processor.

B.  

The processor must obtain the controller’s specific written authorization and provide annual reports on the sub-processor’s performance.

C.  

The processor must receive a written agreement that the sub-processor will be fully liable to the controller for the performance of its obligations in relation to the personal data concerned.

D.  

The processor must obtain the consent of the controller and ensure the sub-processor complies with data processing obligations that are equivalent to those that apply to the processor.

Discussion 0
Question # 25

When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?

Options:

A.  

Inform the subjects about the collection

B.  

Provide a public notice regarding the data

C.  

Upgrade security to match that of the source

D.  

Update the data within a reasonable timeframe

Discussion 0
Question # 26

Which of the following elements does NOT need to be presented to a data subject in order to collect valid consent for the use of cookies?

Options:

A.  

A "Cookies Settings" button.

B.  

A "Reject All" cookies button.

C.  

A list of cookies that may be placed.

D.  

Information on the purpose of the cookies.

Discussion 0
Question # 27

Why is advisable to avoid consent as a legal basis for an employer to process employee data?

Options:

A.  

Employee data can only be processed if there is an approval from the data protection officer.

B.  

Consent may not be valid if the employee feels compelled to provide it.

C.  

An employer might have difficulty obtaining consent from every employee.

D.  

Data protection laws do not apply to processing of employee data.

Discussion 0
Question # 28

What term BEST describes the European model for data protection?

Options:

A.  

Sectoral

B.  

Self-regulatory

C.  

Market-based

D.  

Comprehensive

Discussion 0
Question # 29

MagicClean is a web-based service located in the United States that matches home cleaning services to customers. It otters its services exclusively in the United States It uses a processor located in France to optimize its data. Is MagicClean subject to the GDPR?

Options:

A.  

Yes, because MagicClean is processing data in the EU

B.  

Yes. because MagicClean's data processing agreement with the French processor is an establishment in the EU

C.  

No, because MagicClean is located m the United States only.

D.  

No. because MagicClean is not offering services to EU data subjects.

Discussion 0
Question # 30

SCENARIO

Please use the following to answer the next question:

T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.

T-Craze also opened various office locations throughout Europe to help expand its business. While Germany

Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.

The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.

What is the best option for the lead regulator when responding to the Spanish supervisory authority’s notice that it plans to take action regarding Sofia’s complaint?

Options:

A.  

Accept, because it did not receive any complaints.

B.  

Accept, because GDPR permits non-lead authorities to take action for such complaints.

C.  

Reject, because Right Target’s processing was conducted throughout Europe.

D.  

Reject, because GDPR does not allow other supervisory authorities to take action if there is a lead authority.

Discussion 0

Free Exams Sample Questions