CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1Legislative Framework
What type of data lies beyond the scope of the General Data Protection Regulation?
anonymized dataGDPR scopepersonal data definitionArticle 2 GDPR - Question #2Legislative Framework
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?
filing systemsmanual processingGDPR material scopestructured data - Question #3Legislative Framework
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
territorial scopetargeting criterionArticle 3 GDPRextraterritorial effect - Question #4Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
transparencyinformation obligationsconnected toyschildren's data - Question #5Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
children's consentparental consentArticle 8 GDPRconsent conditions - Question #6Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
encryption in transittechnical measuresArticle 32 GDPRdata security - Question #7Legislative Framework
Which of the following would most likely NOT be covered by the definition of "personal data" under the GDPR?
personal data definitionaggregated dataanonymizationGDPR scope - Question #8Legislative Framework
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?
extraterritorial scopeArticle 3 GDPRnon-EU controllerstargeting criterion - Question #9Legislative Framework
How does the GDPR now define "processing"?
processing definitionArticle 4 GDPRGDPR definitionspersonal data - Question #10Legislative Framework
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?
controller vs processorprocessor liabilityArticle 28 GDPRcontroller definition - Question #11Legislative Framework
According to the GDPR, how is pseudonymous personal data defined?
pseudonymizationArticle 4 GDPRGDPR definitionsre-identification - Question #12Legislative Framework
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?
household exemptionGDPR material scopeArticle 2 GDPRpersonal activity - Question #13Legislative Framework
According to the E-Commerce Directive 2000/31/EC, where is the place of "establishment" for a company providing services via an Internet website confirmed by the GDPR?
establishmentE-Commerce Directiveplace of establishmentterritorial applicability - Question #14Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no...
data portabilityArticle 20 GDPRdata subject rightsinsurance sector - Question #15Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no...
restriction of processingArticle 18 GDPRdata subject rightsthird party disclosure - Question #16Compliance with European Data Protection Law
Under the GDPR, who would be LEAST likely to be allowed to engage in the collection, use, and disclosure of a data subject's sensitive medical information without the data subject'...
special categoriesArticle 9 GDPRsensitive medical datajournalistic exemption - Question #17Legislative Framework
With the issue of consent, the GDPR allows member states some choice regarding what?
member state derogationschildren's consent ageArticle 8 GDPRconsent - Question #18Legislative Framework
Which sentence BEST summarizes the concepts of "fairness," "lawfulness" and "transparency", as expressly required by Article 5 of the GDPR?
Article 5 GDPRdata protection principlesfairnesstransparency - Question #19Legislative Framework
Article 5(1)(b) of the GDPR states that personal data must be "collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those...
purpose limitationArticle 5(1)(b) GDPRcompatible processingmember state discretion - Question #20Compliance with European Data Protection Law
Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. Which GDPR principle is she...
integrity and confidentialityArticle 5 GDPRencryption at restdata security principle - Question #21Compliance with European Data Protection Law
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citi...
legitimate interestconsent exemptiondocumentary productionArticle 6 - Question #22Compliance with European Data Protection Law
A Spanish electricity customer calls her local supplier with Questions: about the company's upcoming merger. Specifically, the customer wants to know the recipients to whom her per...
Article 13transparency obligationidentity verificationdata subject rights - Question #23Compliance with European Data Protection Law
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject...
Article 14indirect data collectiontransparency exemptiondata subject information - Question #24Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B i...
sub-processorArticle 28processor obligationsunauthorized engagement - Question #25Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B i...
sub-processor due diligenceaccreditationsecurity measuresArticle 28 - Question #26Compliance with European Data Protection Law
In 2016's Guidance, the United Kingdom's Information Commissioner's Office (ICO) reaffirmed the importance of using a "layered notice" to provide data subjects with what?
layered noticeprivacy noticeICO guidancetransparency - Question #27Compliance with European Data Protection Law
When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?
Article 14indirect collectiondata subject notificationtransparency - Question #28Compliance with European Data Protection Law
Under the GDPR, which essential pieces of information must be provided to data subjects before collecting their personal data?
Article 13privacy noticecontroller identityprocessing purpose - Question #29Compliance with European Data Protection Law
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?
DSARArticle 12response timelinedata access request - Question #30Compliance with European Data Protection Law
A U.S.-based online shop uses sophisticated software to track the browsing behavior of its European customers and predict future purchases. It also shares this information with thi...
profilinginformed consentterritorial scopeArticle 22 - Question #31Compliance with European Data Protection Law
Which of the following would NOT be relevant when determining if a processing activity would be considered profiling?
profiling definitionArticle 4automated processingGDPR scope - Question #32Compliance with European Data Protection Law
Under Article 21 of the GDPR, a controller must stop profiling when requested by a data subject, unless it can demonstrate compelling legitimate grounds that override the interests...
Article 21 objectionlegitimate groundsprofilingWP29 guidelines - Question #33Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new mana...
data breachArticle 34notification exemptionrisk assessment - Question #34Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new mana...
cookiesePrivacyconsentstrictly necessary cookies - Question #35Compliance with European Data Protection Law
Company X has entrusted the processing of their payroll data to Provider Y. Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that some...
data breachArticle 33processor notificationcontroller obligation - Question #36Compliance with European Data Protection Law
When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?
processor liabilityArticle 28controller due diligencesecurity breach - Question #37Compliance with European Data Protection Law
WP29's "Guidelines on Personal data breach notification under Regulation 2016/679'' provides examples of ways to communicate data breaches transparently. Which of the following was...
breach communicationArticle 34WP29 guidelinesnotification methods - Question #38Compliance with European Data Protection Law
Which of the following would require designating a data protection officer?
DPO designationArticle 37mandatory DPOlarge-scale processing - Question #39Compliance with European Data Protection Law
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?
DPOgroup of undertakingsArticle 37accessibility requirement - Question #40Compliance with European Data Protection Law
What obligation does a data controller or processor have after appointing a data protection officer?
DPO resourcesArticle 38organizational obligationDPO independence - Question #41Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
controller/processor distinctiondata processorprocessing purposesMarketIQ - Question #42Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
consent validityprivacy noticedata subject awarenesslawful basis - Question #43Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
pseudonymizationdata retentionstorage limitationArticle 5 - Question #44Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
joint controllersArticle 26controller definitiondata sharing - Question #45Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
processor obligationsArticle 28DPIA assistancedata processing agreement - Question #46Compliance with European Data Protection Law
When is data sharing agreement MOST likely to be needed?
data sharing agreementjoint controllersArticle 26commercial organizations - Question #47Compliance with European Data Protection Law
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data o...
data breach notificationArticle 33supervisory authorityunencrypted data - Question #48Compliance with European Data Protection Law
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?
records of processing activitiesArticle 30processor obligationsDPIA exclusion - Question #49Compliance with European Data Protection Law
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 2...
availability breachArticle 32accountabilityWP29 guidance - Question #50International Data Transfers
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?
standard contractual clausesSCCsnational DPAsArticle 46