CIPP-E Exam Questions
268 real CIPP-E exam questions with expert-verified answers and explanations. Page 5 of 6.
- Question #201Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and se...
data processing agreementcontroller-processorcloud storageprocessor obligations - Question #202Legislative Framework
A dynamic Internet Protocol (IP) address is considered persona! data when it is combined with what?
personal data definitionIP addressidentifiabilitycontroller held data - Question #203Legislative Framework
Two companies, Gellcoat and Freifish, make plans to launch a co-branded product the prototype of which is called Gellifish 9090. The companies want to organize an event to introduc...
joint controllerscontroller definitiondata sharingco-processing - Question #204Legislative Framework
Which of the following is NOT exempt from the material scope of the GDPR. insofar as the processing of personal data is concerned?
material scopehousehold exemptionGDPR applicabilitylarge-scale personal activity - Question #205Legislative Framework
MagicClean is a web-based service located in the United States that matches home cleaning services to customers. It otters its services exclusively in the United States It uses a p...
territorial scopeestablishmenttargeting EU subjectsArticle 3 - Question #206Legislative Framework
A news website based m (he United Slates reports primarily on North American events The website is accessible to any user regardless of location, as the website operator does not b...
territorial scopetargeting criterioncurrency indicatorArticle 3 - Question #207Compliance with European Data Protection Law
A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is...
purpose limitationconsentrepurposing datanew processing purpose - Question #208Compliance with European Data Protection Law
Which kind of privacy notice, originally advocated by the Article 29 Working Party, is commonly recommended tor Al-based technologies because of the way it provides processing info...
privacy noticetransparencyAI technologiesArticle 29 Working Party - Question #209Compliance with European Data Protection Law
Articles 13 and 14 of the GDPR provide details on the obligation of data controllers to inform data subjects when collecting personal data. However, both articles specify an exempt...
right to be informedArticle 14transparency obligationdisproportionate effort - Question #210Compliance with European Data Protection Law
The transparency principle is most directly related to which of the following rights?
transparency principleright to be informeddata subject rightsGDPR principles - Question #211Legislative Framework
In the Planet 49 case, what was the man judgement of the Coon of Justice of the European Union (CJEU) regarding the issue of cookies?
Planet 49cookie consentePrivacy Directivepre-checked boxes - Question #212Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical compa...
employee liabilityunauthorized processingcontroller liabilitypharmacovigilance - Question #213Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical compa...
data subject access requestexcessive requestsright of accessresponse obligations - Question #214Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical compa...
right to erasurelegal claim defenseArticle 17employment data retention - Question #215Compliance with European Data Protection Law
Pursuant to Article 17 and EDPB Guidelines S'2019 on RTBF criteria in search engines cases, all of the following would be valid grounds for data subject delisting requests EXCEPT?
right to be forgottensearch engine delistingArticle 17freedom of expression - Question #216Compliance with European Data Protection Law
According to Art 23 GDPR, which of the following data subject rights can NOT be restricted?
Article 23 restrictionssupervisory authority complaintnon-restrictable rightsdata subject rights - Question #217International Data Transfers
The European Data Protection Board (EDPB) recommends measures to supplement transfer tools, in order to ensure compliance with the European Union (EU) level of personal data protec...
adequacy decisionEDPB recommendationsthird country monitoringsupplementary measures - Question #218European Regulatory Institutions
Which of the following is an accurate statement regarding the "one-stop-shop" mechanism of the GDPR?
one-stop-shoplead supervisory authorityconcerned supervisory authoritiescross-border processing - Question #219Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has devel...
special category datavital interestshealth datalegal basis - Question #220International Data Transfers
SCENARIO Please use the following to answer the next question: ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has devel...
standard contractual clausesinternational data transfersemployee datatransfer mechanisms - Question #221International Data Transfers
SCENARIO Please use the following to answer the next question: ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has devel...
transfer impact assessmentthird country adequacydata protection measurescloud storage - Question #222International Data Transfers
SCENARIO Please use the following to answer the next question: Why was Jackie correct in not completing a transfer impact assessment for HRYourWay?
transfer impact assessmentthird country definitionEEA transfersdata transfers - Question #223Legislative Framework
Higher fines are assessed for GDPR violations due to which of the following?
GDPR finesArticle 83data subject rightssupervisory authority powers - Question #224Compliance with European Data Protection Law
A company would like to implement CCTV monitoring in its offices for safety and security purposes. Which of the following would be the best legal basis for the company to rely upon...
CCTV monitoringlegal basispublic interestlegitimate interest - Question #225Legislative Framework
According to the GDPR. Article 4(14). biometric data is defined as: "Personal data resulting from specific technical processing relating to the______charactenstics of a natural per...
biometric dataArticle 4 definitionsGDPR terminologyspecial categories - Question #226Compliance with European Data Protection Law
According to the European Data Protection Board, data subjects should be aware of any video surveillance in operation. How should a retail shop operator ensure that data subjects r...
video surveillancetransparency requirementsEDPB guidelineslayered notice - Question #227Compliance with European Data Protection Law
Jerry the Chief Marketing Officer for a sports apparel and trophy company, sells products to schools and athletic clubs globally Recently the company has decided to invest in a new...
direct marketingconsentemail marketingsoft opt-in - Question #228Introduction to European Data Protection
A homeowner has installed a motion-detecting surveillance system that films his front doc and entryway. The camera does not film any public areas only areas that are the property o...
household exemptionCCTVGDPR material scopebiometric data - Question #229Introduction to European Data Protection
Which of the following is NOT one of the 4 principles developed by the European Al Alliance regarding the ethical use of Artificial Intelligence?
AI ethicsEuropean AI Alliancetrustworthy AIAI principles - Question #230Introduction to European Data Protection
Since blockchain transactions are classified as pseudonymous, are they considered to be within the material scope of the GDPR or outside of it?
blockchainpseudonymous dataGDPR material scopeemerging technologies - Question #231Compliance with European Data Protection Law
After detecting an intrusion involving the theft of unencrypted personal data, who shall the breached company notify first under GDPR requirements?
data breach notificationArticle 33Article 34supervisory authority - Question #232Legislative Framework
What ruling did the Planet 49 CJEU judgment make regarding the issue of pre-ticked boxes?
Planet 49CJEU case lawconsentpre-ticked boxes - Question #233Compliance with European Data Protection Law
You are the new Data Protection Officer for your company and have to determine whether the company has implemented appropriate technical and organizational measures as required by...
Article 32security measurestechnical measuresorganizational measures - Question #234Compliance with European Data Protection Law
It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3
data breach notificationransomwareArticle 33incident response - Question #235Compliance with European Data Protection Law
If two controllers act as joint controllers pursuant to Article 26 of the GDPR, which of the following may NOT be validly determined by said controllers?
joint controllersArticle 26controller obligationsdata subject information - Question #236European Regulatory Institutions
What is the main task of the European Data Protection Board?
EDPBconsistency mechanismGDPR enforcementsupervisory authority - Question #237International Data Transfers
In relation to third countries and international organizations, which of the following shall, along with the supervisory authorities, take appropriate steps to develop internationa...
international cooperationArticle 50enforcement mechanismsEuropean Commission - Question #238International Data Transfers
A company wishes to transfer personal data to a country outside of the European Union/EEA In order to do so, they are planning an assessment of the country's laws and practices, kn...
transfer impact assessmentTIA factorsthird country lawsadequacy assessment - Question #239European Privacy Human Rights Law
What is the primary purpose of Convention 108+, which amends the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data?
Convention 108+Council of Europeinternational data protectionfundamental rights - Question #240Legislative Framework
SCENARIO Please use the following to answer the next question: Jane starts her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and se...
GDPR territorial scopeArticle 3cryptocurrency platformdata subject rights waiver - Question #241Legislative Framework
Sanctions for non-compliance with the EU Artificial Intelligence Act (Al Act) could result in a maximum fine of?
AI Actsanctionsmaximum finesregulatory penalties - Question #242Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in Greece (5), Italy (15) and Spai...
data breachrisk assessmentdata subjects affectedDPIA factors - Question #243Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in Greece (5), Italy (15) and Spai...
GDPR principlestransparencywristband trackingdata processing - Question #244Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in Greece (5), Italy (15) and Spai...
consentfreely givenemployer-employee relationshipArticle 7 - Question #245Compliance with European Data Protection Law
SCENARIO Please use the following to answer the next question: Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in Greece (5), Italy (15) and Spai...
processor establishmentjurisdictionmain establishmentone-stop-shop - Question #246Compliance with European Data Protection Law
As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his name,...
DSARidentity verificationdata subject rightsArticle 12 - Question #247Legislative Framework
In the Planet 49 case, what was the main judgement of the Court of Justice of the European Union (CJEU) regarding the issue of cookies?
Planet 49cookiesePrivacy DirectiveCJEU case law - Question #248Compliance with European Data Protection Law
According to the EDPB Guidelines 01/2021 on Examples regarding Personal Data Breach Notification, if exfiltration of job application data (submitted through online application form...
confidentiality breachdata breach typesEDPB guidelinesbreach notification - Question #249Introduction to European Data Protection
ISO 31700 has set forth requirements relating to consumer products and services. In particular, this international standard focuses on the implementation of which of the following?
ISO 31700privacy by designinternational standardsconsumer products - Question #250International Data Transfers
In the wake of the Schrems II ruling, which of the following actions has been recommended by the EDPB for companies transferring personal data to third countries?
Schrems IIsupplementary measuresthird country transfersEDPB recommendations