CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1
What type of data lies beyond the scope of the General Data Protection Regulation?
- Question #2
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?
- Question #3
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
- Question #4
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
- Question #5
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
- Question #6
SCENARIO Please use the following to answer the next question: You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action f...
- Question #7
Which of the following would most likely NOT be covered by the definition of "personal data" under the GDPR?
- Question #8
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?
- Question #9
How does the GDPR now define "processing"?
- Question #10
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?
- Question #11
According to the GDPR, how is pseudonymous personal data defined?
- Question #12
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?
- Question #13
According to the E-Commerce Directive 2000/31/EC, where is the place of "establishment" for a company providing services via an Internet website confirmed by the GDPR?
- Question #14
SCENARIO Please use the following to answer the next question: Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no...
- Question #15
SCENARIO Please use the following to answer the next question: Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no...
- Question #16
Under the GDPR, who would be LEAST likely to be allowed to engage in the collection, use, and disclosure of a data subject's sensitive medical information without the data subject'...
- Question #17
With the issue of consent, the GDPR allows member states some choice regarding what?
- Question #18
Which sentence BEST summarizes the concepts of "fairness," "lawfulness" and "transparency", as expressly required by Article 5 of the GDPR?
- Question #19
Article 5(1)(b) of the GDPR states that personal data must be "collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those...
- Question #20
Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. Which GDPR principle is she...
- Question #21
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citi...
- Question #22
A Spanish electricity customer calls her local supplier with Questions: about the company's upcoming merger. Specifically, the customer wants to know the recipients to whom her per...
- Question #23
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject...
- Question #24
SCENARIO Please use the following to answer the next question: Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B i...
- Question #25
SCENARIO Please use the following to answer the next question: Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B i...
- Question #26
In 2016's Guidance, the United Kingdom's Information Commissioner's Office (ICO) reaffirmed the importance of using a "layered notice" to provide data subjects with what?
- Question #27
When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?
- Question #28
Under the GDPR, which essential pieces of information must be provided to data subjects before collecting their personal data?
- Question #29
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?
- Question #30
A U.S.-based online shop uses sophisticated software to track the browsing behavior of its European customers and predict future purchases. It also shares this information with thi...
- Question #31
Which of the following would NOT be relevant when determining if a processing activity would be considered profiling?
- Question #32
Under Article 21 of the GDPR, a controller must stop profiling when requested by a data subject, unless it can demonstrate compelling legitimate grounds that override the interests...
- Question #33
SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new mana...
- Question #34
SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new mana...
- Question #35
Company X has entrusted the processing of their payroll data to Provider Y. Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that some...
- Question #36
When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?
- Question #37
WP29's "Guidelines on Personal data breach notification under Regulation 2016/679'' provides examples of ways to communicate data breaches transparently. Which of the following was...
- Question #38
Which of the following would require designating a data protection officer?
- Question #39
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?
- Question #40
What obligation does a data controller or processor have after appointing a data protection officer?
- Question #41
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
- Question #42
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
- Question #43
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
- Question #44
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
- Question #45
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe....
- Question #46
When is data sharing agreement MOST likely to be needed?
- Question #47
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data o...
- Question #48
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?
- Question #49
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 2...
- Question #50
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?