Summer Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dealsixty

CIPP-E Exam Dumps - IAPP Certified Information Privacy Professional Questions and Answers

Question # 54

The GDPR requires controllers to supply data subjects with detailed information about the processing of their data. Where a controller obtains data directly from data subjects, which of the following items of information does NOT legally have to be supplied?

Options:

A.

The recipients or categories of recipients.

B.

The categories of personal data concerned.

C.

The rights of access, erasure, restriction, and portability.

D.

The right to lodge a complaint with a supervisory authority.

Buy Now
Question # 55

Which of the following is NOT an explicit right granted to data subjects under the GDPR?

Options:

A.

The right to request access to the personal data a controller holds about them.

B.

The right to request the deletion of data a controller holds about them.

C.

The right to opt-out of the sale of their personal data to third parties.

D.

The right to request restriction of processing of personal data, under certain scenarios.

Buy Now
Question # 56

SCENARIO

Please use the following to answer the next question:

ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage

In support of Ruth's strategic goals of hiring more sales representatives, the Human

Resources team is focused on improving its processes to ensure that new

employees are sourced, interviewed, hired, and onboarded efficiently. To help with

this, Mary identified two vendors, HRYourWay, a German based company, and

InstaHR, an Australian based company. She decided to have both vendors go

through ProStorage's vendor risk review process so she can work with Ruth to

make the final decision. As part of the review process, Jackie, who is responsible

for maintaining ProStorage's privacy program (including maintaining controller

BCRs and conducting vendor risk assessments), reviewed both vendors but

completed a transfer impact assessment only for InstaHR. After her review of both

vendors, she determined that InstaHR satisfied more of the requirements as it

boasted a more established privacy program and provided third-party attestations,

whereas HRYourWay was a small vendor with minimal data protection operations.

Thus, she recommended InstaHR.

ProStorage's marketing team also worked to meet the strategic goals of the

company by focusing on industries where it needed to grow its market share. To

help with this, the team selected as a partner UpFinance, a US based company

with deep connections to financial industry customers. During ProStorage's

diligence process, Jackie from the privacy team noted in the transfer impact

assessment that UpFinance implements several data protection measures

including end-to-end encryption, with encryption keys held by the customer.

Notably, UpFinance has not received any government requests in its 7 years of

business. Still, Jackie recommended that the contract require UpFinance to notify

ProStorage if it receives a government request for personal data UpFinance

processes on its behalf prior to disclosing such data.

What transfer mechanism should Jackie recommend for using InstaHR?

Options:

A.

Adequacy

B.

Binding corporate rules.

C.

Explicit consent of employees.

D.

Standard contractual clauses

Buy Now
Question # 57

An organization conducts body temperature checks as a part of COVID-19 monitoring. Body temperature is measured manually and is not followed by registration, documentation or other processing of an individual’s personal data.

Which of the following best explain why this practice would NOT be subject to the GDPR?

Options:

A.

Body temperature is not considered personal data.

B.

The practice does not involve completion by automated means.

C.

Body temperature is considered pseudonymous data.

D.

The practice is for the purpose of alleviating extreme risks to public health.

Buy Now
Question # 58

In 2016’s Guidance, the United Kingdom’s Information Commissioner’s Office (ICO) reaffirmed the importance of using a “layered notice” to provide data subjects with what?

Options:

A.

A privacy notice containing brief information whilst offering access to further detail.

B.

A privacy notice explaining the consequences for opting out of the use of cookies on a website.

C.

An explanation of the security measures used when personal data is transferred to a third party.

D.

An efficient means of providing written consent in member states where they are required to do so.

Buy Now
Question # 59

In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?

Options:

A.

When the controller is collecting email addresses from individuals via an online registration form for marketing purposes.

B.

When personal data is being collected and combined with other personal data to profile the creditworthiness of individuals.

C.

When the controller is required to have a Data Protection Officer.

D.

When personal data is being transferred outside of the EEA.

Buy Now
Question # 60

A German data subject was the victim of an embarrassing prank 20 years ago. A newspaper website published an article about the prank at the time, and the article is still available on the newspaper’s website. Unfortunately, the prank is the top search result when a user searches on the victim’s name. The data subject requests that SearchCo delist this result. SearchCo agrees, and instructs its technology team to avoid scanning or indexing the article. What else must SearchCo do?

Options:

A.

Notify the newspaper that its article it is delisting the article.

B.

Fully erase the URL to the content, as opposed to delist which is mainly based on data subject’s name.

C.

Identify other controllers who are processing the same information and inform them of the delisting request.

D.

Prevent the article from being listed in search results no matter what search terms are entered into the search engine.

Buy Now
Question # 61

SCENARIO

Please use the following to answer the next question:

You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company’s revenue is due to international sales.

The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children’s Questions: on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well. The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.

When a child asks the toy a question, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure’s integrated

speakers, making it appear as though that the toy is actually responding to the child’s question. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.

In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures’ abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character’s abilities remain intact.

What presents the BIGGEST potential privacy issue with the company’s practices?

Options:

A.

The NFC portal can read any data stored in the action figures

B.

The information about the data processing involved has not been specified

C.

The cloud service provider is in a country that has not been deemed adequate

D.

The RFID tag in the action figures has the potential for misuse because of the toy’s evolving capabilities

Buy Now
Question # 62

Why is advisable to avoid consent as a legal basis for an employer to process employee data?

Options:

A.

Employee data can only be processed if there is an approval from the data protection officer.

B.

Consent may not be valid if the employee feels compelled to provide it.

C.

An employer might have difficulty obtaining consent from every employee.

D.

Data protection laws do not apply to processing of employee data.

Buy Now
Question # 63

To which of the following parties does the territorial scope of the GDPR NOT apply?

Options:

A.

All member countries of the European Economic Area.

B.

All member countries party to the Treaty of Lisbon.

C.

All member countries party to the Paris Agreement.

D.

All member countries of the European Union.

Buy Now
Exam Code: CIPP-E
Exam Name: Certified Information Privacy Professional/Europe (CIPP/E)
Last Update: Jun 3, 2025
Questions: 295
CIPP-E pdf

CIPP-E PDF

$34  $84.99
CIPP-E Engine

CIPP-E Testing Engine

$38  $94.99
CIPP-E PDF + Engine

CIPP-E PDF + Testing Engine

$54  $134.99