Free CIPP-E Exam Braindumps certification guide Q&A [Q109-Q124]

Share

Free CIPP-E Exam Braindumps certification guide Q&A

CIPP-E Certification Overview Latest CIPP-E PDF Dumps


The IAPP CIPP-E exam covers various topics such as the General Data Protection Regulation (GDPR), the Data Protection Directive, and other relevant European laws and regulations. It also assesses the candidate's knowledge and understanding of privacy frameworks, principles, and best practices. Certified Information Privacy Professional/Europe (CIPP/E) certification provides a comprehensive understanding of data protection laws and regulations in Europe and helps professionals to develop a strong foundation in privacy practices.

 

NEW QUESTION # 109
SCENARIO
Please use the following to answer the next question:
Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical company on a clinical trial related to COVID-19. As part of his onboarding process Jack received privacy training He was explicitly informed that while he would need to process confidential patient data in the course of his work, he may under no circumstances use this data for anything other than the performance of work-related (asks This was also specified in the privacy policy, which Jack signed upon conclusion of the training.
After several months of employment, Jack got into an argument with a patient over the phone. Out of anger he later posted the patient's name and hearth information, along with disparaging comments, on a social media website. When this was discovered by his Pharmacovigilance supervisors. Jack was immediately dismissed Jack's lawyer sent a letter to the company stating that dismissal was a disproportionate sanction, and that if Jack was not reinstated within 14 days his firm would have no alternative but to commence legal proceedings against the company. This letter was accompanied by a data access request from Jack requesting a copy of "all personal data, including internal emails that were sent/received by Jack or where Jack is directly or indirectly identifiable from the contents. In relation to the emails Jack listed six members of the management team whose inboxes the required access.
How should the company respond to Jack's request to be forgotten?

  • A. The company should erase all data relating to Jack without undue delay as the right to be forgotten is an absolute right.
  • B. The company should ensure that the information is stored outside of the European Union so that the right to be forgotten under the GDPR does not apply.
  • C. The company should not erase the data at this time as it may be required to defend a legal claim of unfair dismissal.
  • D. The company should claim that the right to be forgotten is not applicable to them, as only a fraction of their global workforce resides in the European Union.

Answer: C

Explanation:
According to the GDPR, the right to be forgotten, also known as the right to erasure, is not an absolute right and only applies in certain circumstances1. One of the exceptions to this right is when the processing of personal data is necessary for the establishment, exercise or defence of legal claims2. In this scenario, the company may need to retain the personal data of Jack, such as his employment records, performance reviews, and internal emails, in order to defend itself against a possible legal action of unfair dismissal. Therefore, the company should not erase the data at this time, unless it is confident that it has no legal basis to keep it. The company should also inform Jack of the reasons for not complying with his request and of his right to lodge a complaint with a supervisory authority or a judicial remedy3. Reference: 1: Everything you need to know about the "Right to be forgotten"2: Article 17(3)(e) of the GDPR3: Article 12(4) of the GDPR.


NEW QUESTION # 110
What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?

  • A. The synchronization of approaches to data protection
  • B. The establishment of a list of legitimate data processing criteria
  • C. The restriction of cross-border data flow
  • D. The creation of legally binding data protection principles

Answer: A

Explanation:
Reference https://ico.org.uk/media/about-the-ico/documents/1042349/review-of-eu-dp-directive.pdf (99)


NEW QUESTION # 111
SCENARIO
Please use the following to answer the next question:
Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical company on a clinical trial related to COVID-19. As part of his onboarding process Jack received privacy training He was explicitly informed that while he would need to process confidential patient data in the course of his work, he may under no circumstances use this data for anything other than the performance of work-related (asks This was also specified in the privacy policy, which Jack signed upon conclusion of the training.
After several months of employment, Jack got into an argument with a patient over the phone. Out of anger he later posted the patient's name and hearth information, along with disparaging comments, on a social media website. When this was discovered by his Pharmacovigilance supervisors. Jack was immediately dismissed Jack's lawyer sent a letter to the company stating that dismissal was a disproportionate sanction, and that if Jack was not reinstated within 14 days his firm would have no alternative but to commence legal proceedings against the company. This letter was accompanied by a data access request from Jack requesting a copy of "all personal data, including internal emails that were sent/received by Jack or where Jack is directly or indirectly identifiable from the contents In relation to the emails Jack listed six members of the management team whose inboxes he required access.
The company conducted an initial search of its IT systems, which returned a large amount of information They then contacted Jack, requesting that he be more specific regarding what information he required, so that they could carry out a targeted search Jack responded by stating that he would not narrow the scope of the information requester.
Under Article 82 of the GDPR ("Right to compensation and liability-), which party is liable for the damage caused by the data breach?

  • A. Jack and the pharmaceutical company are jointly liable.
  • B. The pharmaceutical company is liable.
  • C. Jack is liable
  • D. Both parties are exempt, as the company is involved in human health research

Answer: C

Explanation:
Article 82 of the GDPR introduces a right to compensation for damage caused as a result of an infringement of the GDPR1. Article 82 (1) states that any person who has suffered material or non-material damage as a result of an infringement of the GDPR shall have the right to receive compensation from the controller or processor for the damage suffered1. Article 82 (2) states that any controller involved in processing shall be liable for the damage caused by processing which infringes the GDPR1. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller1. Article 82 (3) states that a controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage1. In this case, Jack is liable for the damage caused by the data breach, as he violated the GDPR by posting the patient's name and health information, along with disparaging comments, on a social media website. This constitutes an infringement of the GDPR, as it violates the principles of lawfulness, fairness, and transparency (Article 5 (1) (a)), purpose limitation (Article 5 (1) (b)), data minimisation (Article 5 (1) ), accuracy (Article 5 (1) (d)), integrity and confidentiality (Article 5 (1) (f)), and the rights of the data subject (Articles 12-23)1. The pharmaceutical company is not liable for the damage caused by the data breach, as it can prove that it is not in any way responsible for the event giving rise to the damage. The company provided privacy training to Jack, informed him of the privacy policy, obtained his consent, and dismissed him as soon as the breach was discovered. Therefore, the company complied with the obligations of the GDPR, such as the accountability principle (Article 5 (2)), the data protection by design and by default principle (Article 25), the security of processing principle (Article 32), and the notification of a personal data breach to the supervisory authority principle (Article 33)1. Therefore, option D is the correct answer. Reference: Art. 82 GDPR - Right to compensation and liability, Article 82 GDPR - GDPRhub


NEW QUESTION # 112
SCENARIO
Please use the following to answer the next question:
You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company's revenue is due to international sales.
The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children's questions on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well.
The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.
When a child asks the toy a question, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure's integrated speakers, making it appear as though that the toy is actually responding to the child's question. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.
In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures' abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character's abilities remain intact.
In light of the requirements of Article 32 of the GDPR (related to the Security of Processing), which practice should the company institute?

  • A. Encrypt the data in transit over the wireless Bluetooth connection.
  • B. Include three-factor authentication before each use by a child in order to ensure the best level of security possible.
  • C. Include dual-factor authentication before each use by a child in order to ensure a minimum amount of security.
  • D. Insert contractual clauses into the contract between the toy manufacturer and the cloud service provider, since South Africa is outside the European Union.

Answer: A


NEW QUESTION # 113
Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?

  • A. Corrective powers.
  • B. Investigatory powers.
  • C. Authorization and advisory powers.
  • D. Legislative powers.

Answer: D

Explanation:
Reference:
Article 58 of the GDPR lists the powers of supervisory authorities, which include investigative, corrective, and authorization and advisory powers. However, legislative powers are not among those granted to supervisory authorities, as they belong to the EU and the member states. Therefore, option A is the correct answer. Reference: Art. 58 GDPR - Powers, Article 58 Powers - GDPR, Article 58 GDPR - GDPRhub


NEW QUESTION # 114
To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?

  • A. The European Court of Human Rights.
  • B. The European Data Protection Board.
  • C. The Court of Justice of the European Union.
  • D. The European Data Protection Supervisor.

Answer: C


NEW QUESTION # 115
The transparency principle is most directly related to which of the following rights?

  • A. Right to object
  • B. Right to be informed.
  • C. Right to be forgotten.
  • D. Right to restriction of processing.

Answer: B

Explanation:
The transparency principle, as stated in Article 5(1)(a) of the GDPR, requires that personal data be processed lawfully, fairly and in a transparent manner in relation to the data subject. This principle is closely linked to the right to be informed, as specified in Articles 13 and 14 of the GDPR, which oblige the controller to provide the data subject with certain information about the processing of their personal data, such as the identity and contact details of the controller, the purposes and legal basis of the processing, the recipients or categories of recipients of the personal data, the existence of the data subject's rights, and the retention period or criteria for the personal data. The right to be informed aims to ensure that the data subject is aware of and can verify the lawfulness of the processing, and to enable them to exercise their rights effectively. Therefore, the transparency principle is most directly related to the right to be informed. Reference:
Article 5(1)(a) of the GDPR
Article 13 of the GDPR
Article 14 of the GDPR
IAPP CIPP/E Study Guide, page 31


NEW QUESTION # 116
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze's headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
Which of the following is T-Craze's lead supervisory authority?

  • A. France, because that is where T-Craze conducts processing of personal information.
  • B. T-Craze may choose its lead supervisory authority where any of its affiliates are based, because it has presence in several European countries.
  • C. Germany, because that is where T-Craze is headquartered.
  • D. Spain, because that is T-Craze's primary market based on its marketing campaigns.

Answer: B


NEW QUESTION # 117
Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. Which GDPR principle is she following?

  • A. Integrity and confidentiality
  • B. Storage Limitation
  • C. Accuracy
  • D. Lawfulness, fairness and transparency

Answer: A

Explanation:
Reference https://www.icaew.com/technical/technology/data/data-protection/data-protection-articles/do-i- have-to-encrypt-personal-data-to-comply-with-dpa-2018


NEW QUESTION # 118
A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if it imports personal data from another organization in the European Economic Area (EEA) under standard contractual clauses?

  • A. Submit the contract to its own government authority.
  • B. Supply any information requested by a data protection authority (DPA) within 30 days.
  • C. Ensure that local laws do not impede the company from meeting its contractual obligations.
  • D. Ensure that notice is given to and consent is obtained from data subjects.

Answer: A


NEW QUESTION # 119
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B.
Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
* Name
* Address
* Date of Birth
* Payroll number
* National Insurance number
* Sick pay entitlement
* Maternity/paternity pay entitlement
* Holiday entitlement
* Pension and benefits contributions
* Trade union contributions
Jenny is the compliance officer at Company A.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their failure to provide sufficient security safeguards to Company A's data.
  • B. Their omission of data protection provisions in their contract with Company C.
  • C. Their engagement of Company C to improve their payroll service.
  • D. Their decision to operate without a data protection officer.

Answer: C


NEW QUESTION # 120
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location.
During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
To comply with the GDPR, what should Building Block have done as a first step before implementing the SecurityScan measure?

  • A. Assessed potential privacy risks by conducting a data protection impact assessment.
  • B. Consulted with the Information Security team to weigh security measures against possible server impacts.
  • C. Distributed a more comprehensive notice to employees and received their express consent.
  • D. Consulted with the relevant data protection authority about potential privacy violations.

Answer: C


NEW QUESTION # 121
An organization receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal dat a. Under what condition can the organization charge the data subject a fee for processing the request?

  • A. Only if the organization can demonstrate that the request is clearly excessive or misguided.
  • B. Only where the organization can show that it is reasonable to do so because more than one request was made.
  • C. Only where the administrative costs of taking the action requested exceeds a certain threshold.
  • D. Only to the extent this is allowed under the restrictions on data subjects' rights introduced under Art 23 of GDPR.

Answer: A

Explanation:
Reference https://gdpr-info.eu/art-23-gdpr/


NEW QUESTION # 122
Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?

  • A. Binding corporate rules.
  • B. Approved certifications.
  • C. Standard contractual clauses.
  • D. Law enforcement requests.

Answer: B

Explanation:
Reference https://www.anonos.com/gdpr-chapter-5-transfers-of-personal-data-to-third-countries-or- international-organisations


NEW QUESTION # 123
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?

  • A. Name and contact details of each controller on behalf of which the processor is acting.
  • B. Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.
  • C. Categories of processing carried out on behalf of each controller for which the processor is acting.
  • D. Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.

Answer: D

Explanation:
Explanation/Reference: https://gdpr-info.eu/art-30-gdpr/


NEW QUESTION # 124
......


IAPP CIPP-E (Certified Information Privacy Professional/Europe) Exam is a certification offered by the International Association of Privacy Professionals (IAPP) for professionals who work in the field of data privacy. CIPP-E exam is specifically designed for individuals who work in Europe and covers the European Union’s General Data Protection Regulation (GDPR). The CIPP-E certification is highly regarded in the industry and is recognized as a standard for privacy professionals in Europe.

 

The Best IAPP CIPP-E Study Guides and Dumps of 2024: https://examcollection.prep4king.com/CIPP-E-latest-questions.html