Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified Information Privacy Professional/Europe (CIPP/E) Practice Questions

Exams4sure Dumps

Exam style questions across every CIPP-E domain

Last Update 4 hours ago
Total Questions : 295

Start with our free CIPP-E practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Certified Information Privacy Professional exam. Each CIPP-E exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your IAPP weak domains, see where you're losing marks, and build a focused study plan in minutes.

CIPP-E PDF

CIPP-E PDF (Printable)
$46.5
$154.99

CIPP-E Testing Engine

CIPP-E PDF (Printable)
$51
$169.99

CIPP-E PDF + Testing Engine

CIPP-E PDF (Printable)
$63.9
$212.99
Question # 41

Please use the following to answer the next question:

WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids’ website states the following:

“WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child’s personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the data. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child’s personal information. We will only share you and your child’s personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers.”

“We may retain you and your child’s personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years.”

“We are processing you and your child’s personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child’s personal information; rectify or erase you or your child’s personal information; the right to correction or erasure of you and/or your child’s personal information; object to any processing of you and your child’s personal information. You also have the right to complain to the supervisory authority about our data processing activities.”

What direct marketing information can WonderKids send by email without prior consent of the person booking the childcare?

Options:

A.  

No marketing information at all.

B.  

Any marketing information at all.

C.  

Marketing information related to other business operations of WonderKids.

D.  

Marketing information for products or services similar to those purchased from WonderKids.

Discussion 0
Question # 42

Which kind of privacy notice, originally advocated by the Article 29 Working Party, is commonly recommended tor Al-based technologies because of the way it provides processing information at specific points of data collection?

Options:

A.  

Privacy dashboard notice

B.  

Visualization notice.

C.  

Just-in-lime notice.

D.  

Layered notice.

Discussion 0
Question # 43

Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?

Options:

A.  

Name and contact details of each controller on behalf of which the processor is acting.

B.  

Categories of processing carried out on behalf of each controller for which the processor is acting.

C.  

Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.

D.  

Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.

Discussion 0
Question # 44

A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?

Options:

A.  

Obtain specific consent for the new processing

B.  

Only inform the data subjects of the new purpose.

C.  

Proceed no further, as such repurposing is unlawful

D.  

Update the privacy notice upon which consent was given

Discussion 0
Question # 45

Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?

Options:

A.  

Anonymizing special categories of data.

B.  

Conducting regular audits of the data protection program.

C.  

Getting consent from the data subject for a cross border data transfer.

D.  

Encrypting data in transit and at rest using strong encryption algorithms.

Discussion 0
Question # 46

What is true of both the General Data Protection Regulation (GDPR) and the Council of Europe Convention 108?

Options:

A.  

Both govern international transfers of personal data

B.  

Both govern the manual processing of personal data

C.  

Both only apply to European Union countries

D.  

Both require notification of processing activities to a supervisory authority

Discussion 0
Question # 47

A private company has establishments in France, Poland, the United Kingdom, and most prominently, Germany, where its headquarters is established. The company offers its services worldwide. Most of the services are designed in Germany and supported in the other establishments. However, one of the services, a Software as a Service (SaaS) application, was defined and implemented by the Polish establishment. It is also supported by the other establishments.

What is the lead supervisory authority for the SaaS service?

Options:

A.  

The supervisory authority of Germany at the federal level.

B.  

The supervisory authority of Germany at the regional level.

C.  

The supervisory authority of the Republic of Poland.

D.  

The supervisory authority of the European Union.

Discussion 0
Question # 48

After detecting an intrusion involving the theft of unencrypted personal data, who shall the breached company notify first under GDPR requirements?

Options:

A.  

Any parents of children whose personal data was compromised.

B.  

Any affected customers whose data was compromised.

C.  

A competent supervisory authority.

D.  

A local law enforcement agency

Discussion 0
Question # 49

Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?

Options:

A.  

The European Council

B.  

The European Parliament

C.  

The European Commission

D.  

The Council of the European Union

Discussion 0
Question # 50

There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?

Options:

A.  

Consent management and withdrawal.

B.  

Incident detection and response.

C.  

Preventative security.

D.  

Remedial security.

Discussion 0

Free Exams Sample Questions