CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 2 of 6.
- Question #51Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Zandelay Fashion (`Zandelay') is a successful international online clothing retailer that employs approximately 650 p...
DPIAArticle 35supervisory authority guidanceDPO responsibilities - Question #52Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Zandelay Fashion (`Zandelay') is a successful international online clothing retailer that employs approximately 650 p...
DPIA requirementsArticle 35processing purposesprofiling - Question #53International Data Transfers
A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if...
standard contractual clausesdata importer obligationslocal law impedimentadequacy mechanism - Question #54International Data Transfers
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?
adequacy decisionsthird countriesSwitzerlandArticle 45 - Question #55International Data Transfers
A company is hesitating between Binding Corporate Rules and Standard Contractual Clauses as a global data transfer solution. Which of the following statements would help the compan...
binding corporate rulesBCRsstandard contractual clausestransfer mechanism comparison - Question #56International Data Transfers
Under the GDPR, which of the following is true in regard to adequacy decisions involving cross- border transfers?
adequacy decisionsEuropean Commission powersArticle 45cross-border transfers - Question #57European Regulatory Institutions
Under Article 58 of the GDPR, which of the following describes a power of supervisory authorities in European Union (EU) member states?
supervisory authority powersArticle 58investigative powersdata access - Question #58European Regulatory Institutions
SCENARIO Please use the following to answer the next question: Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purpo...
lead supervisory authorityconsistency mechanismone-stop-shopArticle 60 - Question #59Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purpo...
judicial remediesArticle 79controller liabilitydata subject rights enforcement - Question #60Compliance with European Data Protection Law
The GDPR specifies fines that may be levied against data controllers for certain infringements. Which of the following infringements would be subject to the less severe administrat...
administrative finesArticle 83technical measuresArticle 24 - Question #61Legislative Framework
What is the MAIN reason GDPR Article 4(22) establishes the concept of the "concerned supervisory authority"?
concerned supervisory authorityGDPR Article 4one-stop-shopcross-border processing - Question #62Compliance with European Data Protection Law
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?
lead supervisory authoritycross-border processingone-stop-shop - Question #63Compliance with European Data Protection Law
If a multi-national company wanted to conduct background checks on all current and potential employees, including those based in Europe, what key provision would the company have t...
employee background checksemployment lawlegal basisHR data processing - Question #64Compliance with European Data Protection Law
Why is advisable to avoid consent as a legal basis for an employer to process employee data?
consentemployee datapower imbalancelegal basis - Question #65Compliance with European Data Protection Law
What is true if an employee makes an access request to his employer for any personal data held about him?
subject access requestemployee datadata subject rightsexemptions - Question #66Compliance with European Data Protection Law
Read the following steps: Discover which employees are accessing cloud services and from which devices and apps Lock down the data in those apps and devices Monitor and analyze the...
BYODcloud servicesemployee monitoringdevice management - Question #67Compliance with European Data Protection Law
If a company is planning to use closed-circuit television (CCTV) on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?
CCTVDPIAvideo surveillancedata protection compliance - Question #68Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, A...
DPIAemployee monitoringsecurity measuresdata breach - Question #69Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, A...
employee monitoringtransparencypurpose limitationnotice - Question #70Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, A...
employee noticetransparencydata subject informationcontact details - Question #71Compliance with European Data Protection Law
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
DPIAArticle 35high-risk processinglocation data - Question #72Legislative Framework
In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?
ePrivacy Directivedata protectionelectronic communicationstargeted advertising - Question #73Legislative Framework
What permissions are required for a marketer to send an email marketing message to a consumer in the EU?
email marketingopt-in consentePrivacy Directivedirect marketing - Question #74Legislative Framework
Under what circumstances might the "soft opt-in" rule apply in relation to direct marketing?
soft opt-indirect marketingePrivacyexisting customers - Question #75Compliance with European Data Protection Law
What should a controller do after a data subject opts out of a direct marketing activity?
opt-outdirect marketingobjection to processingdata subject rights - Question #76Compliance with European Data Protection Law
How is the GDPR's position on consent MOST likely to affect future app design and implementation?
consentapp designgranular consentGDPR compliance - Question #77Legislative Framework
A mobile device application that uses cookies will be subject to the consent requirement of which of the following?
cookiesePrivacy Directivemobile appsconsent - Question #78Introduction to European Data Protection
What term BEST describes the European model for data protection?
data protection modelcomprehensive modelEU privacy framework - Question #79Introduction to European Data Protection
What was the aim of the European Data Protection Directive 95/46/EC?
Directive 95/46/ECfundamental rightsfree flow of dataGDPR history - Question #80European Regulatory Institutions
What is the key difference between the European Council and the Council of the European Union?
European CouncilCouncil of EUEU institutionslegislative power - Question #81Legislative Framework
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?
e-Privacy Directivedata breach notificationelectronic communications2009 amendments - Question #82European Regulatory Institutions
What is a reason the European Court of Justice declared the Data Retention Directive invalid in 2014?
Data Retention DirectiveECJ rulingproportionalityfundamental rights - Question #83Legislative Framework
Which type of personal data does the GDPR define as a "special category" of personal data?
special categoriesGDPR Article 9trade union membershipsensitive data - Question #84International Data Transfers
After leaving the EU under the terms of Brexit, the United Kingdom will seek an adequacy determination. What is the reason for this?
Brexitadequacy determinationthird country statusGDPR territorial scope - Question #85Legislative Framework
To which of the following parties does the territorial scope of the GDPR NOT apply?
GDPR territorial scopeEEAParis AgreementTreaty of Lisbon - Question #86Compliance with European Data Protection Law
What must a data controller do in order to make personal data pseudonymous?
pseudonymizationdata identifiersGDPR definitionsdata minimization - Question #87Legislative Framework
Which of the following entities would most likely be exempt from complying with the GDPR?
GDPR territorial scopeextraterritorial applicationestablishmenttargeting criterion - Question #88European Regulatory Institutions
Article 29 Working Party has emphasized that the GDPR forbids "forum shopping", which occurs when companies do what?
forum shoppingmain establishmentlead supervisory authorityone-stop-shop - Question #89Legislative Framework
Under Article 9 of the GDPR, which of the following categories of data is NOT expressly prohibited from data processing?
special categoriesArticle 9financial dataprohibited processing - Question #90Compliance with European Data Protection Law
When does the GDPR provide more latitude for a company to process data beyond its original collection purpose?
purpose limitationlegitimate interestcompatible processingGDPR principles - Question #91Compliance with European Data Protection Law
In which situation would a data controller most likely be able to justify the processing of the data of a child without parental consent?
children's dataparental consentArticle 8counselling services - Question #92Compliance with European Data Protection Law
An organisation receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal data. Under what condition can the organisatio...
data subject rightsexcessive requestsArticle 12administrative fees - Question #93Compliance with European Data Protection Law
Which GDPR principle would a Spanish employer most likely depend upon to annually send the personal data of its employees to the national tax authority?
legal basislegal obligationArticle 6employer processing - Question #94Compliance with European Data Protection Law
An online company's privacy practices vary due to the fact that it offers a wide variety of services. How could it best address the concern that explaining them all would make the...
privacy noticelayered noticetransparencycomplex services - Question #95Compliance with European Data Protection Law
The GDPR requires controllers to supply data subjects with detailed information about the processing of their data. Where a controller obtains data directly from data subjects, whi...
Article 13transparency obligationsdirect collectioninformation requirements - Question #96Compliance with European Data Protection Law
According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject's personal data has been obtained...
Article 14indirect data collectionprivacy notice timelineone month - Question #97Compliance with European Data Protection Law
When would a data subject NOT be able to exercise the right to portability?
right to portabilityArticle 20public authority exemptiondata subject rights - Question #98Compliance with European Data Protection Law
In which of the following situations would an individual most likely to be able to withdraw her consent for processing?
consent withdrawalmarketingArticle 7data subject rights - Question #99European Regulatory Institutions
As a result of the European Court of Justice's ruling in the case of Google v. Spain, search engines outside the EEA are also likely to be subject to the Regulation's right to be f...
Google v Spainright to be forgottenterritorial scopeinextricably linked - Question #100Compliance with European Data Protection Law
A German data subject was the victim of an embarrassing prank 20 years ago. A newspaper website published an article about the prank at the time, and the article is still available...
right to erasuresearch engine delistingcontroller obligationsthird-party notification