Ultimate Guide to Prepare Free IAPP CIPP-E Exam Questions & Answer [Q111-Q129] | DumpsMaterials

Ultimate Guide to Prepare Free IAPP CIPP-E Exam Questions & Answer [Q111-Q129]

Share

Ultimate Guide to Prepare Free IAPP CIPP-E Exam Questions and Answer

Pass IAPP CIPP-E Tests Engine pdf - All Free Dumps

NEW QUESTION # 111
Which GDPR principle would a Spanish employer most likely depend upon to annually send the personal data of its employees to the national tax authority?

  • A. The consent of the employees.
  • B. The legal obligation of the employer.
  • C. The legitimate interest of the public administration.
  • D. The protection of the vital interest of the employees.

Answer: B

Explanation:
Reference https://www.huntonprivacyblog.com/2020/03/25/spanish-dpa-publishes-report-on-data-processing- activities-in-relation-to-covid-19/


NEW QUESTION # 112
Under the GDPR, who would be LEAST likely to be allowed to engage in the collection, use, and disclosure of a data subject's sensitive medical information without the data subject's knowledge or consent?

  • A. A health professional involved in the medical care for the data subject, where the data subject's life hinges on the timely dissemination of such information.
  • B. A journalist writing an article relating to the medical condition in question, who believes that the publication of such information is in the public interest.
  • C. A public authority responsible for public health, where the sharing of such information is considered necessary for the protection of the general populace.
  • D. A member of the judiciary involved in adjudicating a legal dispute involving the data subject and concerning the health of the data subject.

Answer: C

Explanation:
Explanation/Reference: https://www.eui.eu/Documents/ServicesAdmin/DeanOfStudies/ResearchEthics/Guide-Data- Protection-Research.pdf


NEW QUESTION # 113
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?

  • A. Personal data of EU residents being processed by a non-EU business that targets EU customers.
  • B. Personal data of EU citizens being processed by a controller or processor based outside the EU.
  • C. The behavior of suspected terrorists being monitored by EU law enforcement bodies.
  • D. The behavior of EU citizens outside the EU being monitored by non-EU law enforcement bodies.

Answer: B


NEW QUESTION # 114
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?

  • A. If the company limits the footage to data subjects solely of legal age.
  • B. If obtaining consent is deemed to involve disproportionate effort.
  • C. If obtaining consent is deemed voluntary by local legislation.
  • D. If the company's status as a documentary provider allows it to claim legitimate interest.

Answer: C

Explanation:
Explanation


NEW QUESTION # 115
Which of the following elements does NOT need to be presented to a data subject in order to collect valid consent for the use of cookies?

  • A. A "Reject All" cookies button.
  • B. A list of cookies that may be placed.
  • C. A "Cookies Settings" button.
  • D. Information on the purpose of the cookies.

Answer: C

Explanation:
According to the EDPB Guidelines 05/2020 on consent under Regulation 2016/6791, valid consent for the use of cookies must meet the following conditions:
* It must be freely given, which means that the data subject must have a genuine choice and the ability to refuse or withdraw consent without detriment.
* It must be specific, which means that the data subject must give consent for each distinct purpose of the processing and for each type of cookie.
* It must be informed, which means that the data subject must receive clear and comprehensive information about the identity of the controller, the purposes of the processing, the types of cookies used, the duration of the cookies, and the possibility of withdrawing consent.
* It must be unambiguous, which means that the data subject must express their consent by a clear affirmative action, such as clicking on an "I agree" button or selecting specific settings in a cookie banner.
* It must be granular, which means that the data subject must be able to consent to different types of cookies separately, such as essential, functional, performance, or marketing cookies.
Therefore, a "Cookies Settings" button is not a necessary element to collect valid consent for the use of cookies, as long as the data subject can exercise their choice and preference through other means, such as a cookie banner with different options. However, a "Cookies Settings" button may be a good practice to enhance transparency and user control, as it allows the data subject to access and modify their consent settings at any time.
On the other hand, a "Reject All" cookies button is a necessary element to collect valid consent for the use of cookies, as it ensures that the data subject can freely refuse consent without detriment. A list of cookies that may be placed and information on the purpose of the cookies are also necessary elements to collect valid consent for the use of cookies, as they ensure that the data subject is informed and can give specific consent for each type of cookie.


NEW QUESTION # 116
In which of the following cases, cited as an example by a WP29 guidance, would conducting a single data protection impact assessment to address multiple processing operations be allowed?

  • A. A railway operator who plans to evaluate the same video surveillance in all the train stations of his company.
  • B. A marketing team that wants to collect mailing addresses of customers for whom they already have email addresses.
  • C. A medical organization that wants to begin genetic testing to support earlier research for which they have performed a DPIA.
  • D. A data controller who plans to use a new technology product that has already undergone a DPIA by the product's provider.

Answer: A


NEW QUESTION # 117
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?

  • A. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
  • B. The sensitivity of the categories of data involved in the incident was not substantial enough.
  • C. The incident resulted from the actions of a third-party that were beyond their control.
  • D. The resulting obligation to notify data subjects would involve disproportionate effort.

Answer: C


NEW QUESTION # 118
The Planet 49 CJEU Judgement applies to?

  • A. Cookies where the data accessed is considered as personal data only.
  • B. Cookies used only by third parties.
  • C. Cookies that are deemed technically necessary.
  • D. Cookies regardless of whether the data accessed is personal or not.

Answer: D

Explanation:
Reference https://www.twobirds.com/en/news/articles/2019/global/planet49-cjeu-rules-on-cookie-consent


NEW QUESTION # 119
Under the GDPR, who would be LEAST likely to be allowed to engage in the collection, use, and disclosure of a data subject's sensitive medical information without the data subject's knowledge or consent?

  • A. A public authority responsible for public health, where the sharing of such information is considered necessary for the protection of the general populace.
  • B. A journalist writing an article relating to the medical condition in QUESTION, who believes that the publication of such information is in the public interest.
  • C. A health professional involved in the medical care for the data subject, where the data subject's life hinges on the timely dissemination of such information.
  • D. A member of the judiciary involved in adjudicating a legal dispute involving the data subject and concerning the health of the data subject.

Answer: B

Explanation:
The GDPR defines data concerning health as a special category of personal data that is subject to specific processing conditions and safeguards. The GDPR prohibits the processing of such data unless one of the exceptions in Article 9 applies. One of these exceptions is the explicit consent of the data subject, which means that the data subject has given a clear and affirmative indication of their agreement to the processing of their health data. Another exception is when the processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care. A third exception is when the processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services. These exceptions are based on the principle of necessity, which means that the processing must be strictly necessary for a specific purpose and cannot be achieved by other means.
In the given scenario, the journalist does not fall under any of these exceptions. The journalist is not a health professional, a public authority, or a person who has obtained the explicit consent of the data subject. The journalist is not processing the data for any legitimate purpose related to public health, medical care, or social protection. The journalist is merely pursuing their own interest in publishing a story that may or may not be in the public interest. The journalist is not respecting the data subject's rights and freedoms, especially their right to privacy and confidentiality. Therefore, the journalist would be least likely to be allowed to engage in the collection, use, and disclosure of the data subject's sensitive medical information without their knowledge or consent. Reference:
Article 4 (15) and Article 9 of the GDPR
Health data | ICO
What does the GDPR mean for personal data in medical reports?
Sensitive data and medical confidentiality - FutureLearn
Health data and data privacy: storing sensitive data under GDPR


NEW QUESTION # 120
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?

  • A. The necessity of the bulk collection of personal data by the government.
  • B. The requirement to demonstrate compliance to a supervisory authority.
  • C. The obligation of companies to declare data breaches.

Answer: B

Explanation:
Reference https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52018PC0449&from=HU


NEW QUESTION # 121
Which of the following is NOT exempt from the material scope of the GDPR. insofar as the processing of personal data is concerned?

  • A. A natural person in the course of processing purely personal or household data on behalf of a spouse who is beyond the age of majority.
  • B. A natural person in the course of activity conducted purely tor a personally-owned sole proprietorship.
  • C. A natural person in the course of a large-scale but purely personal or household activity.
  • D. A natural person processing data foe a small-scale, purely personal or household activity.

Answer: D


NEW QUESTION # 122
A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if it imports personal data from another organization in the European Economic Area (EEA) under standard contractual clauses?

  • A. Ensure that notice is given to and consent is obtained from data subjects.
  • B. Supply any information requested by a data protection authority (DPA) within 30 days.
  • C. Submit the contract to its own government authority.
  • D. Ensure that local laws do not impede the company from meeting its contractual obligations.

Answer: C


NEW QUESTION # 123
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their decision to operate without a data protection officer.
  • B. Their omission of data protection provisions in their contract with Company C.
  • C. Their engagement of Company C to improve their payroll service.
  • D. Their failure to provide sufficient security safeguards to Company A's data.

Answer: C


NEW QUESTION # 124
Which of the following would NOT be relevant when determining if a processing activity would be considered profiling?

  • A. If the processing is to be performed by a third-party vendor
  • B. If the processing involves data that is considered personal data
  • C. If the processing of the data is done through automated means
  • D. If the processing is used to predict the behavior of data subjects

Answer: D


NEW QUESTION # 125
SCENARIO
Please use the following to answer the next question:
Jane starts her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform.
The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a Know Your Customer (KYC) due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and ticking a checkbox on a separate page in order to get their account approved on the platform.
All customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a customer fails the KYC process, its KYC data will be automatically shared with the national anti-money laundering agency.
The KYC procedure requires customers to answer many questions, including whether they have any criminal convictions, whether they use recreational drugs or have problems with alcohol, and whether they have a terminal illness. While providing this data, customers see a conspicuous message saying that this data is meant only to prevent fraud and account takeover, and will be never shared with private third parties.
The company regularly conducts external security testing of its online systems by independent cybersecurity companies from the EU. At the final stage of testing, the company provides cybersecurity assessors with access to its central database to review security permissions, roles and policies. Personal data in the database is encrypted; however, cybersecurity assessors usually have access to the decryption keys obtained while running initial security testing. The assessors must strictly follow the guidelines imposed by the company during the entire testing and auditing process.
All customer data, including trading activities and all internal communications with technical support, are permanently stored in a secured AWS S3 Glacier cloud data storage, located in Ireland, for backup and compliance purposes. The data is securely transferred to the cloud and then is properly encrypted while at rest by using AWS-native encryption mechanisms. These mechanisms give AWS the necessary technical means to encrypt and decrypt the data when such is required by the company. There is no data processing agreement between AWS and the company.
Should Jane modify the required GDPR rights waiver for non-European residents?

  • A. No, but all non-EU residents must manually sign a separate waiver to ensure its lawfulness and enforceability under GDPR.
  • B. No, the non-EU residents are not protected by GDPR unless they are physically located in the EU.
  • C. Yes, the waiver must not apply to any residents of countries with an adequacy decision from the EC.
  • D. Yes, this clause must be entirely removed as all customers,
    regardless of residence or nationality, shall enjoy the same individual rights granted under GDPR.

Answer: D

Explanation:
The GDPR applies to the processing of personal data of data subjects who are in the EU, regardless of their nationality or residence. This means that non-EU residents who are physically located in the EU are protected by the GDPR, and EU residents who are outside the EU are not. However, this does not mean that non-EU residents who are outside the EU can be asked to waive their GDPR rights by a company that is subject to the GDPR. The GDPR does not allow such waivers, as they would undermine the essence of the fundamental rights and freedoms of data subjects. The GDPR also requires that data subjects are provided with clear and transparent information about the processing of their personal data, and that they give their consent freely, specifically, informedly and unambiguously. A blanket waiver of GDPR rights does not meet these criteria, and would therefore be invalid and unenforceable.
Reference:
* GDPR Article 3 - Territorial scope1
* GDPR Article 7 - Conditions for consent2
* GDPR Article 25 - Data protection by design and by default3
* GDPR Recital 171 - Relationship with previously concluded agreements4


NEW QUESTION # 126
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data on the stick is unencrypted and in clear text. It is uncertain what has happened to the stick at this stage, but it likely was lost during the travel of an employee. What should the company do?

  • A. Notify as soon as possible the data protection supervisory authority that a data breach may have taken place.
  • B. Immediately notify all the customers of the company that their information has been accessed by an unauthorized person.
  • C. Launch an investigation and if nothing is found within one month, notify the data protection supervisory authority.
  • D. Invoke the "disproportionate effort" exception under Article 33 to postpone notifying data subjects until more information can be gathered.

Answer: A


NEW QUESTION # 127
When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in compliance with the European Union (EU) level?

  • A. After a personal data breach.
  • B. Every three (3) years.
  • C. On an ongoing basis.
  • D. Every year.

Answer: C


NEW QUESTION # 128
SCENARIO
Please use the following to answer the next question:
Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Javier lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Javier was photographed while working out at a branch of EVERFIT in Frankfurt, Germany. At the time, Javier gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club's U.K. brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Javier no longer feels comfortable with his photograph being publicly associated with the fitness club.
After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Javier sends a letter to EVETFIT requesting that his image be removed from the website and all promotional materials. Months pass and Javier, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact EVETFIT through alternate channels, he decides to take action against the company.
Javier contacts the U.K. Information Commissioner's Office ('ICO' - the U.K.'s supervisory authority) to lodge a complaint about this matter. The ICO, pursuant to Article 56 (3) of the GDPR, informs the CNIL (i.e. the supervisory authority of EVERFIT's main establishment) about this matter. Despite the fact that EVERFIT has an establishment in the U.K., the CNIL decides to handle the case in accordance with Article 60 of the GDPR. The CNIL liaises with the ICO, as relevant under the cooperation procedure. In light of issues amongst the supervisory authorities to reach a decision, the European Data Protection Board becomes involved and, pursuant to the consistency mechanism, issues a binding decision.
Additionally, Javier sues EVERFIT for the damages caused as a result of its failure to honor his request to have his photograph removed from the brochure and website.
Under the cooperation mechanism, what should the lead authority (the CNIL) do after it has formed its view on the matter?

  • A. Submit a draft decision to other supervisory authorities for their opinion.
  • B. Request that members of the seconding supervisory authority and the host supervisory authority co-draft a decision.
  • C. Request that the other supervisory authorities provide the lead authority with a draft decision for its consideration.
  • D. Submit a draft decision directly to the Commission to ensure the effectiveness of the consistency mechanism.

Answer: A

Explanation:
According to Article 60 of the GDPR, the lead authority (the CNIL in this case) shall cooperate with the other concerned supervisory authorities (the ICO and any other authority where EVERFIT has an establishment or where data subjects are affected) to reach a consensus on the case. The lead authority shall submit a draft decision to the other authorities for their opinion and take due account of their views. If the other authorities agree with the draft decision, the lead authority shall adopt and notify it to the controller (EVERFIT) and the complainant (Javier). If the other authorities object to the draft decision, they shall express their objections within a specified period and try to reach a consensus with the lead authority. If no consensus is reached, the matter shall be referred to the EDPB for a binding decision under the consistency mechanism (Article 65 of the GDPR). Reference: GDPR Cooperation and Enforcement, First overview on the implementation of the GDPR and the roles and means of the national supervisory authorities, Data protection: Commission adopts new rules to ensure stronger cooperation and enforcement, Article 65 FAQ


NEW QUESTION # 129
......

Online Exam Practice Tests with detailed explanations!: https://braindumps2go.dumpsmaterials.com/CIPP-E-real-torrent.html