CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 4 of 6.
- Question #151
SCENARIO Please use the following to answer the next question: BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The...
- Question #152
Which of the following is NOT an explicit right granted to data subjects under the GDPR?
- Question #153
As per the GDPR, which legal basis would be the most appropriate for an online shop that wishes to process personal data for the purpose of fraud prevention?
- Question #154
The Planet 49 CJEU Judgement applies to?
- Question #155
Bioface is a company based in the United States. It has no servers, personnel or assets in the European Union. By collecting photographs from social media and other web-based servi...
- Question #156
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
- Question #157
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
- Question #158
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
- Question #159
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
- Question #160
SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy c...
- Question #161
Which of the following was the first legally binding international instrument in the area of data protection?
- Question #162
A multinational company is appointing a mandatory data protection officer. In addition to considering the rules set out in Article 37 (1) of the GDPR, which of the following action...
- Question #163
The European Parliament jointly exercises legislative and budgetary functions with which of the following?
- Question #164
A U.S. company's website sells widgets. Which of the following factors would NOT in itself subject the company to the GDPR?
- Question #165
When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in complianc...
- Question #166
Which judicial body makes decisions on actions taken by individuals wishing to enforce their rights under EU law?
- Question #167
SCENARIO Please use the following to answer the next question: Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Go...
- Question #168
SCENARIO Please use the following to answer the next question: Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Go...
- Question #169
A data controller appoints a data protection officer. Which of the following conditions would NOT result in an infringement of Articles 37 to 39 of the GDPR?
- Question #170
Data retention in the EU was underpinned by a legal framework established by the Data Retention Directive (2006/24/EC). Why is the Directive no longer part of EU law?
- Question #171
Which of the following is the weakest lawful basis for processing employee personal data?
- Question #172
An organization receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal data. Under what condition can the organizatio...
- Question #173
To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?
- Question #174
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?
- Question #175
SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platf...
- Question #176
SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platf...
- Question #177
SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platf...
- Question #178
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
- Question #179
If a data subject puts a complaint before a DPA and receives no information about its progress or outcome, how long does the data subject have to wait before taking action in the c...
- Question #180
For which of the following operations would an employer most likely be justified in requesting the data subject's consent?
- Question #181
An entity's website stores text files on EU users' computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing informati...
- Question #182
Which of the following is NOT considered a fair processing practice in relation to the transparency principle?
- Question #183
Which of the following was the first to implement national law for data protection in 1973?
- Question #184
The GDPR forbids the practice of "forum shopping", which occurs when companies do what?
- Question #185
What is the most frequently used mechanism for legitimizing cross-border data transfer?
- Question #186
If a French controller has a car-sharing app available only in Morocco, Algeria and Tunisia, but the data processing activities are carried out by the appointed processor in Spain,...
- Question #187
Select the answer below that accurately completes the following: "The right to compensation and liability under the GDPR...
- Question #188
Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?
- Question #189
According to Article 84 of the GDPR, the rules on penalties applicable to infringements shall be laid down by?
- Question #190
A company plans to transfer employee health information between two of its entities in France. To maintain the security of the processing, what would be the most important security...
- Question #191
If a company chooses to ground an international data transfer on the contractual route, which of the following is NOT a valid set of standard contractual clauses?
- Question #192
Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?
- Question #193
According to the European Data Protection Board, which of the following concepts or practices does NOT follow from the principles relating to the processing of personal data under...
- Question #194
According to the GDPR, when should the processing of photographs be considered processing of special categories of personal data?
- Question #195
The origin of privacy as a fundamental human right can be found in which document?
- Question #196
Which statement provides an accurate description of a directive?
- Question #197
Which of the following regulates the use of electronic communications services within the European Union?
- Question #198
What was the main failing of Convention 108 that led to the creation of the Data Protection Directive (Directive 95/46/EC)?
- Question #199
SCENARIO Please use the following to answer the next question: Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and se...
- Question #200
SCENARIO Please use the following to answer the next question: Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and se...