CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 4 of 6.
- Question #151Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The...
processor definitioncontroller instructionsArticle 28purpose limitation - Question #152Legislative Framework
Which of the following is NOT an explicit right granted to data subjects under the GDPR?
data subject rightsGDPR rightsopt-outArticle 17 - Question #153Compliance with European Data Protection Law
As per the GDPR, which legal basis would be the most appropriate for an online shop that wishes to process personal data for the purpose of fraud prevention?
legal basislegitimate interestfraud preventionArticle 6 - Question #154Legislative Framework
The Planet 49 CJEU Judgement applies to?
Planet 49cookie consentePrivacyCJEU case law - Question #155Legislative Framework
Bioface is a company based in the United States. It has no servers, personnel or assets in the European Union. By collecting photographs from social media and other web-based servi...
GDPR territorial scopeArticle 3behavioral monitoringfacial recognition - Question #156Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
DPIAfundamental rightsdata breach riskArticle 35 - Question #157Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
data minimizationlitigation holdArticle 5proportionality - Question #158Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
breach notificationArticle 33multi-jurisdictionobligation assessment - Question #159European Regulatory Institutions
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
supervisory authorityDPAArticle 77enforcement - Question #160Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
DPIAArticle 35high-risk processingdata protection by design - Question #161Introduction to European Data Protection
Which of the following was the first legally binding international instrument in the area of data protection?
Convention 108data protection historyinternational instrumentslegally binding - Question #162Compliance with European Data Protection Law
A multinational company is appointing a mandatory data protection officer. In addition to considering the rules set out in Article 37 (1) of the GDPR, which of the following action...
DPO appointmentGDPR Article 37national derogationsmandatory DPO - Question #163European Regulatory Institutions
The European Parliament jointly exercises legislative and budgetary functions with which of the following?
European ParliamentCouncil of European Unionlegislative functionEU institutions - Question #164Compliance with European Data Protection Law
A U.S. company's website sells widgets. Which of the following factors would NOT in itself subject the company to the GDPR?
GDPR territorial scopeArticle 3targeting criterionestablishment - Question #165International Data Transfers
When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in complianc...
EDPBtransfer toolsongoing monitoringadequacy assessment - Question #166European Regulatory Institutions
Which judicial body makes decisions on actions taken by individuals wishing to enforce their rights under EU law?
CJEUjudicial bodyEU law enforcementindividual rights - Question #167Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Go...
data minimizationpurpose limitationproportionalityform design - Question #168Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Go...
pseudonymizationdata minimizationanalyticslawful processing - Question #169Compliance with European Data Protection Law
A data controller appoints a data protection officer. Which of the following conditions would NOT result in an infringement of Articles 37 to 39 of the GDPR?
DPO qualificationsGDPR Articles 37-39DPO requirementsconflicts of interest - Question #170Legislative Framework
Data retention in the EU was underpinned by a legal framework established by the Data Retention Directive (2006/24/EC). Why is the Directive no longer part of EU law?
Data Retention DirectiveCJEU annulmentlegislative historyEU law - Question #171Compliance with European Data Protection Law
Which of the following is the weakest lawful basis for processing employee personal data?
lawful basisconsent in employmentpower imbalanceemployee data - Question #172Compliance with European Data Protection Law
An organization receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal data. Under what condition can the organizatio...
data subject rightsexcessive requestsfeesright of access - Question #173European Regulatory Institutions
To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?
CJEUpreliminary rulingGDPR interpretationnational courts - Question #174Compliance with European Data Protection Law
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?
biometric dataspecial category dataexplicit consentfacial recognition - Question #175Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platf...
data subject rightsaccess request timelineresponse deadlinejoint controllers - Question #176Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platf...
joint controllerscontroller definitionprocessor definitiondata sharing - Question #177Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platf...
right to erasuredata subject rightserasure limitationsconflicting interests - Question #178Legislative Framework
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
Convention 108+GDPR comparisonbulk data collectiongovernment surveillance - Question #179Compliance with European Data Protection Law
If a data subject puts a complaint before a DPA and receives no information about its progress or outcome, how long does the data subject have to wait before taking action in the c...
DPA complaintjudicial remedyprocedural timelinescourt action - Question #180Compliance with European Data Protection Law
For which of the following operations would an employer most likely be justified in requesting the data subject's consent?
employee consentlawful basissocial mediaemployment context - Question #181Legislative Framework
An entity's website stores text files on EU users' computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing informati...
ePrivacy Directivecookie consentbrowser storagenotice requirements - Question #182Compliance with European Data Protection Law
Which of the following is NOT considered a fair processing practice in relation to the transparency principle?
transparency principleprivacy noticefair processinglayered notices - Question #183Introduction to European Data Protection
Which of the following was the first to implement national law for data protection in 1973?
data protection historySwedennational legislation1970s - Question #184Compliance with European Data Protection Law
The GDPR forbids the practice of "forum shopping", which occurs when companies do what?
forum shoppingone-stop-shopmain establishmentlead supervisory authority - Question #185International Data Transfers
What is the most frequently used mechanism for legitimizing cross-border data transfer?
standard contractual clausescross-border transfertransfer mechanismsSCCs - Question #186Legislative Framework
If a French controller has a car-sharing app available only in Morocco, Algeria and Tunisia, but the data processing activities are carried out by the appointed processor in Spain,...
territorial scopetargeting criterionthird countriesGDPR Article 3 - Question #187Compliance with European Data Protection Law
Select the answer below that accurately completes the following: "The right to compensation and liability under the GDPR...
right to compensationliabilityGDPR Article 82recourse proceedings - Question #188Legislative Framework
Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?
pseudonymizationGDPR Article 4personal data definitionre-identification risk - Question #189Legislative Framework
According to Article 84 of the GDPR, the rules on penalties applicable to infringements shall be laid down by?
GDPR Article 84penaltiesmember state discretionnational law - Question #190Compliance with European Data Protection Law
A company plans to transfer employee health information between two of its entities in France. To maintain the security of the processing, what would be the most important security...
health data securityencryptiondata transferspecial category data - Question #191International Data Transfers
If a company chooses to ground an international data transfer on the contractual route, which of the following is NOT a valid set of standard contractual clauses?
standard contractual clausesSCC Commission decisionscontroller-to-processor SCCsinternational transfers - Question #192European Regulatory Institutions
Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?
supervisory authority powersGDPR Article 58investigatory powerscorrective powers - Question #193Compliance with European Data Protection Law
According to the European Data Protection Board, which of the following concepts or practices does NOT follow from the principles relating to the processing of personal data under...
EDPB guidelinesdata protection principlesdata ownershipaccountability - Question #194Legislative Framework
According to the GDPR, when should the processing of photographs be considered processing of special categories of personal data?
photographsbiometric dataspecial category dataGDPR Article 9 - Question #195European Privacy Human Rights Law
The origin of privacy as a fundamental human right can be found in which document?
privacy as human rightUDHR 1948historical originsfundamental rights - Question #196Legislative Framework
Which statement provides an accurate description of a directive?
EU directivelegal instrumentsmember state implementationEU law types - Question #197Legislative Framework
Which of the following regulates the use of electronic communications services within the European Union?
ePrivacy Directiveelectronic communicationsEU legislative actstelecommunications regulation - Question #198Introduction to European Data Protection
What was the main failing of Convention 108 that led to the creation of the Data Protection Directive (Directive 95/46/EC)?
Convention 108Data Protection Directiveharmonization failurehistorical development - Question #199Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and se...
data processorKYCcontroller-processor relationshipprocessing agreement - Question #200Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and se...
transparencynotice requirementlaw enforcement data sharingdata subject rights