Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified Information Privacy Professional/Europe (CIPP/E) Practice Questions

Exams4sure Dumps

Exam style questions across every CIPP-E domain

Last Update 4 hours ago
Total Questions : 295

Start with our free CIPP-E practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Certified Information Privacy Professional exam. Each CIPP-E exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your IAPP weak domains, see where you're losing marks, and build a focused study plan in minutes.

CIPP-E PDF

CIPP-E PDF (Printable)
$46.5
$154.99

CIPP-E Testing Engine

CIPP-E PDF (Printable)
$51
$169.99

CIPP-E PDF + Testing Engine

CIPP-E PDF (Printable)
$63.9
$212.99
Question # 31

Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?

Options:

A.  

Incidents of personal data breaches, whether disclosed or not.

B.  

Data inventory or data mapping exercises that have been conducted.

C.  

Categories of recipients to whom the personal data have been disclosed.

D.  

Retention periods for erasure and deletion of categories of personal data.

Discussion 0
Question # 32

Pursuant to Article 4(5) of the GDPR, data is considered “pseudonymized” if?

Options:

A.  

It cannot be attributed to a data subject without the use of additional information.

B.  

It cannot be attributed to a person under any circumstances.

C.  

It can only be attributed to a person by the controller.

D.  

It can only be attributed to a person by a third party.

Discussion 0
Question # 33

How can the relationship between the GDPR and the Digital Services Act, the Data Governance Act and the Digital Markets Act most accurately be described?

Options:

A.  

The aforementioned legal acts do not refer to (i.e., do not mention) the GDPR.

B.  

The aforementioned legal acts apply without prejudice (i.e., in parallel) to the GDPR.

C.  

The aforementioned legal acts change specific provisions (i.e., certain articles) of the GDPR.

D.  

The aforementioned legal acts contain some sector-specific exemptions (i.e., only for certain businesses) from the GDPR.

Discussion 0
Question # 34

A homeowner has installed a motion-detecting surveillance system that films his front doc and entryway. The camera does not film any public areas only areas that are the property of the homeowner. The system has seen declared to the authorities per the homeowner's country law, and a placard indicating the area is being video monitored is visible when entering the property

Why can the homeowner NOT depend on the household exemption with regards to the processing of the video images recorded by the surveillance camera system?

Options:

A.  

The surveillance camera system can potentially capture biometric information of the homeowner's family, which would be considered a processing of special categories of personal data.

B.  

The homeowner has not specified which security measures ore in place as part of the surveillance camera system

C.  

The GDPR specifically excludes surveillance camera images from the household exemption

D.  

The surveillance camera system can potentially film individuals who enter its filming perimeter

Discussion 0
Question # 35

Jerry the Chief Marketing Officer for a sports apparel and trophy company, sells products to schools and athletic clubs globally Recently the company has decided to invest in a new line of customized sports equipment Jerry plans to email his current customer base to offer them a discount on their first purchase of such equipment.

Jerry tells Kate, the Director of Privacy, about his plan. What is the best guidance Kate can provide to Jerry?

Options:

A.  

Permit Jerry to carry out his plan on the basis of marketing similar products to existing customers.

B.  

Require Jerry to send all current customers a second notice to allow them to opt-in to marketing emails

C.  

Permit Jerry to carry out his marketing plan on the basis of legitimate interest

D.  

Require Jerry to include an option to opt out of marketing emails in the future

Discussion 0
Question # 36

As a result of the European Court of Justice’s ruling in the case of Google v. Spain, search engines outside the EEA are also likely to be subject to the Regulation’s right to be forgotten. This holds true if the activities of an EU subsidiary and its U.S. parent are what?

Options:

A.  

Supervised by the same Data Protection Officer.

B.  

Consistent with Privacy Shield requirements

C.  

Bound by a standard contractual clause.

D.  

Inextricably linked in their businesses.

Discussion 0
Question # 37

The Planet 49 CJEU Judgement applies to?

Options:

A.  

Cookies used only by third parties.

B.  

Cookies that are deemed technically necessary.

C.  

Cookies regardless of whether the data accessed is personal or not.

D.  

Cookies where the data accessed is considered as personal data only.

Discussion 0
Question # 38

WP29’s “Guidelines on Personal data breach notification under Regulation 2016/679’’ provides examples of ways to communicate data breaches transparently. Which of the following was listed as a method that would NOT be effective for communicating a breach to data subjects?

Options:

A.  

A postal notification

B.  

A direct electronic message

C.  

A notice on a corporate blog

D.  

A prominent advertisement in print media

Discussion 0
Question # 39

What must a data controller do in order to make personal data pseudonymous?

Options:

A.  

Separately hold any information that would allow linking the data to the data subject.

B.  

Encrypt the data in order to prevent any unauthorized access or modification.

C.  

Remove all indirect data identifiers and dispose of them securely.

D.  

Use the data only in aggregated form for research purposes.

Discussion 0
Question # 40

SCENARIO

Please use the following to answer the next question:

Joe started the Gummy Bear Company in 2000 from his home in Vermont, US

A.  

Today, it is a multi-billion-dollar candy company operating in every continent. All of the company’s IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father’s company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.

Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company’s online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers’ philosophical beliefs, political opinions and marital status.

If a customer identifies as single, Ben then copies all of that customer’s personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.

Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.

Joe also hires his best friend’s daughter, Alice, who just graduated from law school in the U.S., to be the company’s new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company’s operations in the European Union to the U.S.

Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company’s IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone’s information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.

As a result of Sam’s actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?

Options:

A.  

Notify its Data Protection Authority about the data breach.

B.  

Analyze and evaluate the liability for customers in Ireland.

C.  

Analyze and evaluate all of its breach notification obligations.

D.  

Notify all of its customers that reside in the European Union.

Discussion 0

Free Exams Sample Questions