CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 3 of 6.
- Question #101Compliance with European Data Protection Law
What are the obligations of a processor that engages a sub-processor?
sub-processorprocessor obligationscontroller authorizationArticle 28 - Question #102Compliance with European Data Protection Law
What must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?
controller-processor agreementArticle 28processor obligationsdata breach notification - Question #103Compliance with European Data Protection Law
To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the...
controller-processor relationshippurpose limitationunauthorized processingGDPR compliance - Question #104Compliance with European Data Protection Law
There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?
Article 32security measuresincident responsetechnical safeguards - Question #105Compliance with European Data Protection Law
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
data breach notificationArticle 33supervisory authoritydata subjects - Question #106Compliance with European Data Protection Law
In which case would a controller who has undertaken a DPIA most likely need to consult with a supervisory authority?
DPIAprior consultationsupervisory authorityhigh risk processing - Question #107Compliance with European Data Protection Law
According to the GDPR, what is the main task of a Data Protection Officer (DPO)?
DPOdata protection officerArticle 39compliance monitoring - Question #108Compliance with European Data Protection Law
In which of the following cases, cited as an example by a WP29 guidance, would conducting a single data protection impact assessment to address multiple processing operations be al...
DPIAWP29 guidancemultiple processing operationsArticle 35 - Question #109Compliance with European Data Protection Law
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
Article 30records of processingROPAretention periods - Question #110Compliance with European Data Protection Law
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
DPIAArticle 35profilinghigh risk processing - Question #111Compliance with European Data Protection Law
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?
accountability principleArticle 5compliance auditGDPR principles - Question #112Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Dynaroux Fashion (`Dynaroux') is a successful international online clothing retailer that employs approximately 650 p...
DPIAprofilingchildren's datasystematic processing - Question #113International Data Transfers
Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?
Article 42certificationsinternational transfersthird countries - Question #114International Data Transfers
Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?
binding corporate rulesBCRsintra-group transfersArticle 47 - Question #115International Data Transfers
With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?
derogationsArticle 49EDPBinternational transfers - Question #116European Regulatory Institutions
SCENARIO Please use the following to answer the next question: T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan citi...
lead supervisory authorityone-stop-shopmain establishmentArticle 56 - Question #117European Regulatory Institutions
SCENARIO Please use the following to answer the next question: T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan citi...
lead supervisory authoritycross-border processingsupervisory jurisdictionone-stop-shop - Question #118European Regulatory Institutions
SCENARIO Please use the following to answer the next question: T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan citi...
supervisory authoritycomplaint handlingnon-lead authoritycross-border enforcement - Question #119European Regulatory Institutions
Which of the following is one of the supervisory authority's investigative powers?
supervisory authorityinvestigative powersArticle 58GDPR enforcement - Question #120Legislative Framework
Many businesses print their employees' photographs on building passes, so that employees can be identified by security staff. This is notwithstanding the fact that facial images po...
biometric dataArticle 9special categoriesfacial images - Question #121Compliance with European Data Protection Law
A worker in a European Union (EU) member state has ceased his employment with a company. What should the employer most likely do in regard to the worker's personal data?
data retentionemployment datastorage limitationlocal law compliance - Question #122Legislative Framework
Which of the following is NOT a role of works councils?
works councilsemployee representationemployer obligationsdata breach fines - Question #123Legislative Framework
Under the Data Protection Law Enforcement Directive of the EU, a government can carry out covert investigations involving personal data, as long it is set forth by law and constitu...
Law Enforcement Directivecovert investigationsproportionalitynecessity principle - Question #124Compliance with European Data Protection Law
Which GDPR requirement will present the most significant challenges for organizations with Bring Your Own Device (BYOD) programs?
BYODdata controller obligationsGDPR Article 5data control - Question #125Compliance with European Data Protection Law
A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, th...
CCTV surveillancedata minimizationArticle 5 principlesworkplace monitoring - Question #126Compliance with European Data Protection Law
Which of the following is an example of direct marketing that would be subject to European data protection laws?
direct marketingePrivacy DirectiveSMS marketingelectronic communications - Question #127Legislative Framework
Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. Which of the following is NOT one of these exceptions?
Article 9 GDPRbiometric dataspecial categoriesprocessing exceptions - Question #128Legislative Framework
Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002/58/EC)?
ePrivacy DirectivePECR scopeelectronic marketingpassive advertising - Question #129Compliance with European Data Protection Law
Which of the following is NOT recognized as being a common characteristic of cloud-computing services?
cloud computingdata processorshared infrastructurevendor risk - Question #130Compliance with European Data Protection Law
When may browser settings be relied upon for the lawful application of cookies?
cookiesbrowser consentePrivacyopt-out mechanisms - Question #131Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its websit...
direct marketing consentexplicit consenthealth app registrationconsent conditions - Question #132Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its websit...
consent withdrawalGDPR Article 7processing cessationdata subject rights - Question #133Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its websit...
children's dataage of consenthealth data age restrictionsGDPR Article 8 - Question #134Compliance with European Data Protection Law
SCENARIO Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and call...
right to objectdirect marketingGDPR Article 21data subject rights - Question #135Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's busi...
purpose limitationcompatible purposesGDPR Article 5new purpose processing - Question #136Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's busi...
opt-in consentadvertising networkscookiesbehavioral advertising - Question #137Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's busi...
purpose limitationSNS data usetestimonial endorsementpersonal data misuse - Question #138Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new mana...
data breach notificationprocessor obligationsArticle 33controller-processor relationship - Question #139Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
location dataconsentmobile appssensitive data processing - Question #140Legislative Framework
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
GDPR Article 7consent withdrawalconsent conditionsdata subject rights - Question #141Legislative Framework
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
GDPR territorial scopebehavioral monitoringextraterritorialityArticle 3 - Question #142Legislative Framework
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
GDPR territorial scopeestablishmentdata breachcontroller definition - Question #143Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website th...
privacy noticetransparencyArticle 13data sharing - Question #144Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website th...
controller-processor agreementArticle 28data processing contracttechnical measures - Question #145Compliance with European Data Protection Law
Please use the following to answer the next question: WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a c...
legitimate interestdirect marketingconsentpurpose limitation - Question #146Legislative Framework
An organization conducts body temperature checks as a part of COVID-19 monitoring. Body temperature is measured manually and is not followed by registration, documentation or other...
GDPR scopeautomated processingpersonal data definitionArticle 2 - Question #147Compliance with European Data Protection Law
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?
data breach assessmentrisk factorsArticle 33notification criteria - Question #148Legislative Framework
Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit organizations in a privacy group litigation or class action. These organizations are comm...
Article 80data subject representationcivil society organizationscollective redress - Question #149Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The...
controller vs processorpurpose determinationjoint controllersArticle 4 - Question #150Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The...
data securityArticle 32appropriate measuresprocessor obligations