CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 3 of 6.
- Question #101
What are the obligations of a processor that engages a sub-processor?
- Question #102
What must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?
- Question #103
To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the...
- Question #104
There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?
- Question #105
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
- Question #106
In which case would a controller who has undertaken a DPIA most likely need to consult with a supervisory authority?
- Question #107
According to the GDPR, what is the main task of a Data Protection Officer (DPO)?
- Question #108
In which of the following cases, cited as an example by a WP29 guidance, would conducting a single data protection impact assessment to address multiple processing operations be al...
- Question #109
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
- Question #110
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
- Question #111
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?
- Question #112
SCENARIO Please use the following to answer the next question: Dynaroux Fashion (`Dynaroux') is a successful international online clothing retailer that employs approximately 650 p...
- Question #113
Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?
- Question #114
Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?
- Question #115
With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?
- Question #116
SCENARIO Please use the following to answer the next question: T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan citi...
- Question #117
SCENARIO Please use the following to answer the next question: T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan citi...
- Question #118
SCENARIO Please use the following to answer the next question: T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan citi...
- Question #119
Which of the following is one of the supervisory authority's investigative powers?
- Question #120
Many businesses print their employees' photographs on building passes, so that employees can be identified by security staff. This is notwithstanding the fact that facial images po...
- Question #121
A worker in a European Union (EU) member state has ceased his employment with a company. What should the employer most likely do in regard to the worker's personal data?
- Question #122
Which of the following is NOT a role of works councils?
- Question #123
Under the Data Protection Law Enforcement Directive of the EU, a government can carry out covert investigations involving personal data, as long it is set forth by law and constitu...
- Question #124
Which GDPR requirement will present the most significant challenges for organizations with Bring Your Own Device (BYOD) programs?
- Question #125
A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, th...
- Question #126
Which of the following is an example of direct marketing that would be subject to European data protection laws?
- Question #127
Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. Which of the following is NOT one of these exceptions?
- Question #128
Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002/58/EC)?
- Question #129
Which of the following is NOT recognized as being a common characteristic of cloud-computing services?
- Question #130
When may browser settings be relied upon for the lawful application of cookies?
- Question #131
SCENARIO Please use the following to answer the next question: The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its websit...
- Question #132
SCENARIO Please use the following to answer the next question: The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its websit...
- Question #133
SCENARIO Please use the following to answer the next question: The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its websit...
- Question #134
SCENARIO Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and call...
- Question #135
SCENARIO Please use the following to answer the next question: Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's busi...
- Question #136
SCENARIO Please use the following to answer the next question: Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's busi...
- Question #137
SCENARIO Please use the following to answer the next question: Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's busi...
- Question #138
SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new mana...
- Question #139
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
- Question #140
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
- Question #141
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
- Question #142
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquarte...
- Question #143
SCENARIO Please use the following to answer the next question: WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website th...
- Question #144
SCENARIO Please use the following to answer the next question: WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website th...
- Question #145
Please use the following to answer the next question: WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a c...
- Question #146
An organization conducts body temperature checks as a part of COVID-19 monitoring. Body temperature is measured manually and is not followed by registration, documentation or other...
- Question #147
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?
- Question #148
Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit organizations in a privacy group litigation or class action. These organizations are comm...
- Question #149
SCENARIO Please use the following to answer the next question: BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The...
- Question #150
SCENARIO Please use the following to answer the next question: BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The...