Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified Information Privacy Professional/Europe (CIPP/E) Practice Questions

Exams4sure Dumps

Exam style questions across every CIPP-E domain

Last Update 4 hours ago
Total Questions : 295

Start with our free CIPP-E practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Certified Information Privacy Professional exam. Each CIPP-E exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your IAPP weak domains, see where you're losing marks, and build a focused study plan in minutes.

CIPP-E PDF

CIPP-E PDF (Printable)
$46.5
$154.99

CIPP-E Testing Engine

CIPP-E PDF (Printable)
$51
$169.99

CIPP-E PDF + Testing Engine

CIPP-E PDF (Printable)
$63.9
$212.99
Question # 51

Which mechanism, introduced by the GDPR as a means of ensuring both compliance and transparency, allows for the possibility of personal data transfers to third countries under Article 42?

Options:

A.  

Approved certifications.

B.  

Binding corporate rules.

C.  

Law enforcement requests.

D.  

Standard contractual clauses.

Discussion 0
Question # 52

According to the European Data Protection Board, data subjects should be aware of any video surveillance in operation. How should a retail shop operator ensure that data subjects receive at information required for such a purpose under EU data protection law?

Options:

A.  

The shop operator should post a copy of the manual of the video surveillance system in the shop and on its social media channels.

B.  

The shop operator should provide full notice of the intended video surveillance outside the shop, for example with a sign or a stand-up display.

C.  

The shop operator should instruct the data protection officer to hand out a comprehensive notice to data subjects every time they enter the shop.

D.  

The shop operator should provide the most important information on a clearly readable warning sign to data subjects before they enter the monitored area, and additional mandatory details by other means.

Discussion 0
Question # 53

SCENARIO

Please use the following to answer the next question:

Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.

Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick’s instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.

Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its

clients’ data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying

information from the contact information. JaphSoft’s engineers, however, maintain all contact information in the same database as the identifying information.

Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies’ websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem’s as well as EcoMick’s latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem’s products, she has never shopped EcoMick, nor provided her personal data to that company.

Which of the following BEST describes the relationship between Liem, EcoMick and JaphSoft?

Options:

A.  

Liem is a controller and EcoMick is a processor because Liem provides specific instructions regarding how the marketing campaigns should be rolled out.

B.  

EcoMick and JaphSoft are is a controller and Liem is a processor because EcoMick is sharing its marketing data with Liem for contacts in Europe.

C.  

JaphSoft is the sole processor because it processes personal data on behalf of its clients.

D.  

Liem and EcoMick are joint controllers because they carry out joint marketing activities.

Discussion 0
Question # 54

A private company has establishments in France, Poland, the United Kingdom and, most prominently, Germany, where its headquarters is established. The company offers its services worldwide. Most of the services are designed in Germany and supported in the other establishments. However, one of the services, a Software as a Service (SaaS) application, was defined and implemented by the Polish establishment. It is also supported by the other establishments.

What is the lead supervisory authority for the SaaS service?

Options:

A.  

The supervisory authority of Germany at federal level.

B.  

The supervisory authority of Germany at regional level.

C.  

The supervisory authority of the Republic of Poland.

D.  

The supervisory authority of the European Union.

Discussion 0
Question # 55

Which of the following is NOT recognized as a common characteristic of cloud computing services?

Options:

A.  

The service's infrastructure is shared among the supplier's customers and can be located in a number of countries.

B.  

The supplier determines the location, security measures, and service standards applicable to the processing.

C.  

The supplier allows customer data to be transferred around the infrastructure according to capacity.

D.  

The supplier assumes the vendor's business risk associated with data processed by the supplier.

Discussion 0
Question # 56

SCENARIO

Please use the following to answer the next question:

Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Governance. Through her first initiative in conducting a data inventory, Sandy learned that Market4U maintains a list of 19 million global contacts that were collected throughout the course of Market4U’s existence. Knowing the risk of having such a large amount of data, Sandy wanted to purge all contacts that were entered into Market4U’s systems prior to May 2018, unless such contacts had a more recent interaction with Market4U content. However, Dan, the VP of Sales, informed Sandy that all of the contacts provide useful information regarding successful marketing campaigns and trends in industry verticals for Market4U’s clients.

Dan also informed Sandy that he had wanted to focus on gaining more customers within the sports and entertainment industry. To assist with this behavior, Market4U’s marketing team decided to add several new fields to Market4U’s website forms, including forms for downloading white papers, creating accounts to participate in Market4U’s forum, and attending events. Such fields include birth date and salary.

What should Sandy give as feedback to Dan and the marketing team regarding the new fields Dan wants to add to Market4U’s forms?

Options:

A.  

Make all the fields optional.

B.  

Only request the information in brackets (i.e., age group and salary range).

C.  

Eliminate the fields, as they are not proportional to the services being offered.

D.  

Eliminate the fields as they are not necessary for the purposes of providing white papers or registration for events.

Discussion 0
Question # 57

In the Planet 49 case, what was the man judgement of the Coon of Justice of the European Union (CJEU) regarding the issue of cookies?

Options:

A.  

If the cookies do not track personal data, then pre-checked boxes are acceptable.

B.  

If the ePrivacy Directive requires consent for cookies, then the GDPR's consent requirements apply.

C.  

If a website's cookie notice makes clear the information gathered and the lifespan of the cookie, then pre-checked boxes are acceptable.

D.  

If a data subject continues to scroll through a website after reading a cookie banner, this activity constitutes valid consent for the tracking described in the cookie banner.

Discussion 0
Question # 58

If a multi-national company wanted to conduct background checks on all current and potential employees, including those based in Europe, what key provision would the company have to follow?

Options:

A.  

Background checks on employees could be performed only under prior notice to all employees.

B.  

Background checks are only authorized with prior notice and express consent from all employees including those based in Europe.

C.  

Background checks on European employees will stem from data protection and employment law, which can vary between member states.

D.  

Background checks may not be allowed on European employees, but the company can create lists based on its legitimate interests, identifying individuals who are ineligible for employment.

Discussion 0
Question # 59

Which of the following is an example of direct marketing that would be subject to European data protection laws?

Options:

A.  

An updated privacy notice sent to an individual’s personal email address.

B.  

A charity fundraising event notice sent to an individual at her business address.

C.  

A service outage notification provided to an individual by recorded telephone message.

D.  

A revision of contract terms conveyed to an individual by SMS from a marketing organization.

Discussion 0
Question # 60

A multinational company is appointing a mandatory data protection officer. In addition to considering the rules set out in Article 37 (1) of the GDPR, which of the following actions must the company also undertake to ensure compliance in all EU jurisdictions in which it operates?

Options:

A.  

Consult national derogations to evaluate if there are additional cases to be considered in relation to the matter.

B.  

Conduct a Data Protection Privacy Assessment on the processing operations of the company in all the countries it operates.

C.  

Assess whether the company has more than 250 employees in each of the EU member-states in which it is established.

D.  

Revise the data processing activities of the company that affect more than one jurisdiction to evaluate whether they comply with the principles of privacy by design and by default.

Discussion 0

Free Exams Sample Questions