[Oct-2023] CIPP-E Certification with Actual Questions from Exam-Killer [Q127-Q146]

Share

[Oct-2023] CIPP-E Certification with Actual Questions from Exam-Killer

Updated CIPP-E Dumps PDF - CIPP-E Real Valid Brain Dumps With 252 Questions!

NEW QUESTION # 127
How is the retention of communications traffic data for law enforcement purposes addressed by European data protection law?

  • A. The ePrivacy Directive harmonizes EU member states' rules concerning such data retention.
  • B. The Data Retention Directive's annulment makes such data retention now permissible.
  • C. The GDPR allows the retention of such data for the prevention, investigation, detection or prosecution of criminal offences only.
  • D. The ePrivacy Directive allows individual EU member states to engage in such data retention.

Answer: C

Explanation:
Reference https://www.law.kuleuven.be/citip/en/archive/copy_of_publications/440retention-of-traffic-data- dumortier-goemans2f90.pdf (9)


NEW QUESTION # 128
What is the MAIN reason GDPR Article 4(22) establishes the concept of the "concerned supervisory authority"?

  • A. To ensure that the interests of individuals residing outside the lead authority's jurisdiction are represented.
  • B. To give corporations a choice about who their supervisory authority will be.
  • C. To ensure the GDPR covers controllers that do not have an establishment in the EU but have a representative in a member state.
  • D. To encourage the consistency of local data processing activity.

Answer: A


NEW QUESTION # 129
According to the GDPR, what is the main task of a Data Protection Officer (DPO)?

  • A. To create and maintain records of processing activities.
  • B. To conduct Privacy Impact Assessments on behalf of the controller or processor.
  • C. To create procedures for notification of personal data breaches to competent supervisory authorities.
  • D. To monitor compliance with other local or European data protection provisions.

Answer: B


NEW QUESTION # 130
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location.
During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization.
The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
To comply with the GDPR, what should Building Block have done as a first step before implementing the SecurityScan measure?

  • A. Distributed a more comprehensive notice to employees and received their express consent.
  • B. Assessed potential privacy risks by conducting a data protection impact assessment.
  • C. Consulted with the relevant data protection authority about potential privacy violations.
  • D. Consulted with the Information Security team to weigh security measures against possible server impacts.

Answer: A


NEW QUESTION # 131
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
When Ben had the company collect additional data from its customers, the most serious violation of the GDPR occurred because the processing of the data created what?

  • A. An information security risk by copying the data into a new database.
  • B. A significant risk to the customers' fundamental rights and freedoms.
  • C. A potential legal liability and financial exposure from its customers.
  • D. A significant risk due to the lack of an informed consent mechanism.

Answer: B


NEW QUESTION # 132
Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. Which GDPR principle is she following?

  • A. Accuracy
  • B. Integrity and confidentiality
  • C. Lawfulness, fairness and transparency
  • D. Storage Limitation

Answer: B


NEW QUESTION # 133
Under the GDPR, who would be LEAST likely to be allowed to engage in the collection, use, and disclosure of a data subject's sensitive medical information without the data subject's knowledge or consent?

  • A. A health professional involved in the medical care for the data subject, where the data subject's life hinges on the timely dissemination of such information.
  • B. A member of the judiciary involved in adjudicating a legal dispute involving the data subject and concerning the health of the data subject.
  • C. A journalist writing an article relating to the medical condition in question, who believes that the publication of such information is in the public interest.
  • D. A public authority responsible for public health, where the sharing of such information is considered necessary for the protection of the general populace.

Answer: D

Explanation:
Explanation/Reference: https://www.eui.eu/Documents/ServicesAdmin/DeanOfStudies/ResearchEthics/Guide-Data- Protection-Research.pdf


NEW QUESTION # 134
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?

  • A. The data protection officer must be located in the country where the data controller has its main establishment.
  • B. The data protection officer must be easily accessible from each establishment where the undertakings are located.
  • C. The group of undertakings must obtain approval from a supervisory authority.
  • D. The group of undertakings must be comprised of organizations of similar sizes and functions.

Answer: B


NEW QUESTION # 135
SCENARIO
Please use the following to answer the next question:
Ben is a member of the fitness club STAYFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Ben lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Ben was photographed while working out at a branch of STAYFIT in Frankfurt, Germany. At the time, Ben gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club's U.K. brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Ben no longer feels comfortable with his photograph being publicly associated with the fitness club.
After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Ben sends a letter to STAYFIT requesting that his image be removed from the website and all promotional materials. Months pass and Ben, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact STAYFIT through alternate channels, he decides to take action against the company.
Ben contacts the U.K. Information Commissioner's Office ('ICO' - the U.K.'s supervisory authority) to lodge a complaint about this matter.
Assuming that multiple STAYFIT branches across several EU countries are acting as separate data controllers, and that each of those branches were responsible for mishandling Ben's request, how may Ben proceed in order to seek compensation?

  • A. He will be able to sue any one of the relevant STAYFIT branches, as each one may be held liable for the entire damage.
  • B. He will have to sue the STAYFIT's head office in France, where STAYFIT has its main establishment.
  • C. He will be able to apply to the European Data Protection Board in order to determine which particular STAYFIT branch is liable for damages, based on the decision that was made by the board.
  • D. He will have to sue each STAYFIT branch so that each branch provides proportionate compensation commensurate with its contribution to the damage or distress suffered by Ben.

Answer: B

Explanation:
Explanation/Reference:


NEW QUESTION # 136
Under the GDPR, which of the following is true in regard to adequacy decisions involving cross-border transfers?

  • A. The European Commission can adopt, repeal or amend an existing adequacy decision.
  • B. EU member states are vested with the power to accept or reject a European Commission adequacy decision.
  • C. To be considered as adequate, third countries must implement the EU General Data Protection Regulation into their national legislation.
  • D. The European Commission can adopt an adequacy decision for individual companies.

Answer: D

Explanation:
Reference https://www.futurelearn.com/courses/general-data-protection-regulation/0/steps/32449


NEW QUESTION # 137
Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit organizations in a privacy group litigation or class action. These organizations are commonly known as?

  • A. Human rights organizations.
  • B. Law firm organizations.
  • C. Constitutional rights organizations.
  • D. Civil society organizations.

Answer: D

Explanation:
Reference https://gdpr-info.eu/art-80-gdpr/


NEW QUESTION # 138
Which of the following entities would most likely be exempt from complying with the GDPR?

  • A. A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.
  • B. A South American company that regularly collects European customers' personal data.
  • C. A North American company servicing customers in South Africa that uses a cloud storage system made by a European company.
  • D. A company that stores all customer data in Australia and is headquartered in a European Union (EU) member state.

Answer: C


NEW QUESTION # 139
Company X has entrusted the processing of their payroll data to Provider
Y. Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server. In this scenario, whom does Provider Y have the obligation to notify?

  • A. Law enforcement
  • B. The supervisory authority
  • C. The public
  • D. Company X

Answer: A


NEW QUESTION # 140
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?

  • A. When the personal data is processed by an individual only for their household activities
  • B. When the personal data is collected and then pseudonymised by the controller
  • C. When the personal data is held by the controller but not processed for further purposes
  • D. When the personal data is processed only in non-electronic form

Answer: B


NEW QUESTION # 141
What should a controller do after a data subject opts out of a direct marketing activity?

  • A. Refrain from processing personal data relating to the data subject for the relevant type of communication.
  • B. Take reasonable steps to inform third-party recipients that the data subject's personal data should be deleted and no longer processed.
  • C. Without exception, securely delete all personal data relating to the data subject.
  • D. Without undue delay, provide information to the data subject on the action that will be taken.

Answer: A


NEW QUESTION # 142
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their failure to provide sufficient security safeguards to Company A's data.
  • B. Their omission of data protection provisions in their contract with Company C.
  • C. Their engagement of Company C to improve their payroll service.
  • D. Their decision to operate without a data protection officer.

Answer: C


NEW QUESTION # 143
An entity's website stores text files on EU users' computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?

  • A. Data Protection Directive 95/46/EC.
  • B. E-Commerce Directive 2000/31/EC.
  • C. E-Privacy Directive 2002/58/EC.
  • D. General Data Protection Regulation 2016/679.

Answer: C


NEW QUESTION # 144
An organisation receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal dat a. Under what condition can the organisation charge the data subject for processing the request?

  • A. Only if the organisation can demonstrate that the request is clearly excessive or misguided.
  • B. Only to the extent this is allowed under the restrictions on data subjects' rights introduced under Art 23 of GDPR.
  • C. Only where the administrative costs of taking the action requested exceeds a certain threshold.
  • D. Only where the organisation can show that it is reasonable to do so because more than one request was made.

Answer: A


NEW QUESTION # 145
A Spanish electricity customer calls her local supplier with Questions: about the company's upcoming merger. Specifically, the customer wants to know the recipients to whom her personal data will be disclosed once the merger is final. According to Article 13 of the GDPR, what must the company do before providing the customer with the requested information?

  • A. Verify that the personal data has not already been sent to the customer.
  • B. Verify that the request is applicable to the data collected before the GDPR entered into force.
  • C. Verify that the purpose of the request from the customer is in line with the GDPR.
  • D. Verify that the identity of the customer can be proven by other means.

Answer: B

Explanation:
Reference https://fpf.org/wp-content/uploads/2018/11/GDPR_CCPA_Comparison-Guide.pdf


NEW QUESTION # 146
......

Pass Your CIPP-E Exam Easily With 100% Exam Passing Guarantee: https://pass4sure.exam-killer.com/CIPP-E-valid-questions.html