Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Certified Information Privacy Professional/Europe (CIPP/E)

Last Update 4 hours ago Total Questions : 307

The Certified Information Privacy Professional/Europe (CIPP/E) content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include CIPP-E practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CIPP-E exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CIPP-E sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Certified Information Privacy Professional/Europe (CIPP/E) practice test comfortably within the allotted time.

Question # 81

According to Art 23 GDPR, which of the following data subject rights can NOT be restricted?

A.

Right to restriction of processing.

B.

Right to erasure ("Right to be forgotten").

C.

Right to lodge a complaint with a supervisory authority.

D.

Right not to be subject to automated individual decision-making

Question # 82

A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?

A.

If obtaining consent is deemed to involve disproportionate effort.

B.

If obtaining consent is deemed voluntary by local legislation.

C.

If the company limits the footage to data subjects solely of legal age.

D.

If the company’s status as a documentary provider allows it to claim legitimate interest.

Question # 83

SCENARIO

Please use the following to answer the next question:

Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Javier lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Javier was photographed while working out at a branch of EVERFIT in Frankfurt, Germany. At the time, Javier gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club’s U.K. brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Javier no longer feels comfortable with his photograph being publicly associated with the fitness club.

After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Javier sends a letter to EVETFIT requesting that his image be removed from the website and all promotional materials. Months pass and Javier, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact EVETFIT through alternate channels, he decides to take action against the company.

Javier contacts the U.K. Information Commissioner’s Office (‘ICO’ – the U.K.’s supervisory authority) to lodge a complaint about this matter. The ICO, pursuant to Article 56 (3) of the GDPR, informs the CNIL (i.e. the supervisory authority of EVERFIT’s main establishment) about this matter. Despite the fact that EVERFIT has an establishment in the U.K., the CNIL decides to handle the case in accordance with Article 60 of the GDPR. The CNIL liaises with the ICO, as relevant under the cooperation procedure. In light of issues amongst the supervisory authorities to reach a decision, the European Data Protection Board becomes involved and, pursuant to the consistency mechanism, issues a binding decision.

Additionally, Javier sues EVERFIT for the damages caused as a result of its failure to honor his request to have his photograph removed from the brochure and website.

Assuming that multiple EVETFIT branches across several EU countries are acting as separate data controllers, and that each of those branches were responsible for mishandling Javier’s request, how may Javier proceed in order to seek compensation?

A.

He will have to sue the EVETFIT’s head office in France, where EVETFIT has its main establishment.

B.

He will be able to sue any one of the relevant EVETFIT branches, as each one may be held liable for the entire damage.

C.

He will have to sue each EVETFIT branch so that each branch provides proportionate compensation commensurate with its contribution to the damage or distress suffered by Javier.

D.

He will be able to apply to the European Data Protection Board in order to determine which particular EVETFIT branch is liable for damages, based on the decision that was made by the board.

Question # 84

How is the GDPR’s position on consent MOST likely to affect future app design and implementation?

A.

App developers will expand the amount of data necessary to collect for an app’s functionality.

B.

Users will be given granular types of consent for particular types of processing.

C.

App developers’ responsibilities as data controllers will increase.

D.

Users will see fewer advertisements when using apps.

Question # 85

ISO 31700 has set forth requirements relating to consumer products and services. In particular, this international standard focuses on the implementation of which of the following?

A.

Privacy by design.

B.

Comprehensive ethical Al software.

C.

Privacy notices for companies providing services to consumers.

D.

Automated systems for identifying EU data subjects' personal data.

Question # 86

A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?

A.

The school places a notice near each camera.

B.

The school gets explicit consent from the students.

C.

Processing is necessary for the legitimate interests pursed by the school.

D.

A state law requires facial recognition to verify attendance.

Question # 87

What are the obligations of a processor that engages a sub-processor?

A.

The processor must give the controller prior written notice and perform a preliminary audit of the sub- processor.

B.

The processor must obtain the controller’s specific written authorization and provide annual reports on the sub-processor’s performance.

C.

The processor must receive a written agreement that the sub-processor will be fully liable to the controller for the performance of its obligations in relation to the personal data concerned.

D.

The processor must obtain the consent of the controller and ensure the sub-processor complies with data processing obligations that are equivalent to those that apply to the processor.

Question # 88

A private company has establishments in France, Poland, the United Kingdom, and most prominently, Germany, where its headquarters is established. The company offers its services worldwide. Most of the services are designed in Germany and supported in the other establishments. However, one of the services, a Software as a Service (SaaS) application, was defined and implemented by the Polish establishment. It is also supported by the other establishments.

What is the lead supervisory authority for the SaaS service?

A.

The supervisory authority of Germany at the federal level.

B.

The supervisory authority of Germany at the regional level.

C.

The supervisory authority of the Republic of Poland.

D.

The supervisory authority of the European Union.

Question # 89

As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his

name, and has used the email address registered in your system.

What would be the most appropriate way to confirm the identity of the customer?

A.

Request that the customer provide his bank account number.

B.

Request that the customer answer additional security questions.

C.

Request a copy of the customer's last bank account statement.

D.

Request a copy of the customer's government-issued ID document.

Question # 90

Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?

A.

A voluntary notification for personal data breaches applicable to all data controllers.

B.

A voluntary notification for personal data breaches applicable to electronic communication providers.

C.

A mandatory notification for personal data breaches applicable to all data controllers.

D.

A mandatory notification for personal data breaches applicable to electronic communication providers.

Go to page: