Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

CIPP-E VCE Exam Download

Page: 4 / 19
Question 16

There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?

Options:

A.

Consent management and withdrawal.

B.

Incident detection and response.

C.

Preventative security.

D.

Remedial security.

Question 17

Which statement provides an accurate description of a directive?

Options:

A.

A directive speo5es certain results that must be achieved, but each member state is free to decide how to turn it into a national law

B.

A directive has binding legal force throughout every member state and enters into force on a set date in all the member states.

C.

A directive is a legal act relating to specific cases and directed towards member states, companies 0' private individuals.

D.

A directive is a legal act that applies automatically and uniformly to all EU countries as soon as it enters into force.

Question 18

To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client.

Regarding the domain of the controller-processor relationships, how is this situation considered?

Options:

A.

Compliant with the security principle, because the data base is password-protected.

B.

Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the controller.

C.

Not applicable, because the data base is password protected, and therefore is not at risk of identifying any data subject.

D.

Compliant with the storage limitation principle, so long as the internal auditor permanently deletes the data base.

Question 19

Pursuant to Article 17 and EDPB Guidelines S'2019 on RTBF criteria in search engines cases, all of the following would be valid grounds for data subject delisting requests EXCEPT?

Options:

A.

The personal dale has been collected in relation to the offer of Information society services (ISS) to a child.

B.

The data subject withdraws consent and there is no other legal basis for the processing.

C.

The personal data is no longer necessary in relation to the search engine provider's processing

D.

The processing s necessary for exercising the right of freedom of expression and information

Page: 4 / 19
Exam Code: CIPP-E
Exam Name: Certified Information Privacy Professional/Europe (CIPP/E)
Last Update: May 18, 2024
Questions: 268
CIPP-E pdf

CIPP-E PDF

$28  $80
CIPP-E Engine

CIPP-E Testing Engine

$33.25  $95
CIPP-E PDF + Engine

CIPP-E PDF + Testing Engine

$45.5  $130