
Mar-2023 Get Totally Free Updates on CIPP-E Dumps PDF Questions
Prepare With Top Rated High-quality CIPP-E Dumps For Success in CIPP-E Exam
Conclusion
The IAPP CIPP-E exam will help a candidate stamp their knowledge of EU-US data protection laws and how well they can apply them in their practice. Data protection officials with this certification have an upper hand in the industry, and can even fit in international work environments. The study course as well as guides are very useful in helping the candidate pass their exams on the first try.
What are the Topics for IAPP CIPP/E Exam
Candidates must know the exam topics before they start of preparation. Because it will really help them in hitting the core. Our IAPP CIPP/E exam dumps will include the following topics:
- Compliance with European Data Protection Law and Regulation
- Legislative Framework
- International Data Transfers
- European Regulatory Institutions
- Introduction to European Data Protection
The IAPP CIPP-E exam is formulated to ensure that the candidate has extensive knowledge of pan-European as well as national data security laws. The candidate also demonstrates their knowledge of main privacy terminologies and applicable concepts on how to protect personal data as well as protecting international data processes. The French and German versions of this test are ISO certified, and the evaluation has the ANSI/ISO certificate. Moreover, the exam is updated regularly to ensure that it tests the candidate on the most updated content in the industry. It encompasses important topics such as the EU-US Privacy Shield as well as the GDPR.
NEW QUESTION 49
What should a controller do after a data subject opts out of a direct marketing activity?
- A. Refrain from processing personal data relating to the data subject for the relevant type of communication.
- B. Take reasonable steps to inform third-party recipients that the data subject's personal data should be deleted and no longer processed.
- C. Without undue delay, provide information to the data subject on the action that will be taken.
- D. Without exception, securely delete all personal data relating to the data subject.
Answer: A
NEW QUESTION 50
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Why would the consent provided by Ms. Iman NOT be considered valid in regard to JaphSoft?
- A. She did not read the privacy notice stating that her personal data would be shared.
- B. She was not told which controller would be processing her personal data.
- C. She has never made any purchases from JaphSoft and has no relationship with the company.
- D. She only viewed the visual representations of the privacy notice Liem provided.
Answer: A
NEW QUESTION 51
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately
650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What must Zandelay provide to the supervisory authority during the prior consultation?
- A. Records showing that customers have explicitly consented to the intended profiling activities.
- B. An explanation of the purposes and means of the intended processing.
- C. Certificates that prove Martin's professional qualities and expert knowledge of data protection law.
- D. An evaluation of the complexity of the intended processing.
Answer: B
NEW QUESTION 52
According to Article 84 of the GDPR, the rules on penalties applicable to infringements shall be laid down by?
- A. The European Data Protection Board.
- B. The local Data Protection Supervisory Authorities.
- C. The Member States.
- D. The EU Commission.
Answer: C
NEW QUESTION 53
If a company chooses to ground an international data transfer on the contractual route, which of the following is NOT a valid set of standard contractual clauses?
- A. Decision 2004/915/EC (EU controller to non-EU or EEA controller).
- B. Decision 2007/72/EC (EU processor to non-EU or EEA controller).
- C. Decision 2001/497/EC (EU controller to non-EU or EEA controller).
- D. Decision 2010/87/EU (Non-EU or EEA processor from EU controller).
Answer: A
NEW QUESTION 54
SCENARIO
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage Why was Jackie correct in not completing a transfer impact assessment for HRYourWay?
- A. HRYourWay was ultimately not selected
- B. ProStorage can rely on its Binding Corporate Rules
- C. ProStorage will obtain consent for all transfers.
- D. HRYourWay is not located in a third country.
Answer: C
NEW QUESTION 55
A dynamic Internet Protocol (IP) address is considered persona! data when it is combined with what?
- A. Other data held by the processor.
- B. Other data held by Internet Service Providers (ISPs).
- C. Other data held by the controller
- D. Other data held by recipients of the data.
Answer: B
NEW QUESTION 56
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canad a. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
If Who-R-U adopts the We-Track-U pilot plan, why is it likely to be subject to the territorial scope of the GDPR?
- A. It would be offering goods or services to data subjects in the Union.
- B. Its plan would be in the context of the establishment of a controller in the Union.
- C. It is engaging in commercial activities conducted in the Union.
- D. It is monitoring the behavior of data subjects in the Union.
Answer: D
NEW QUESTION 57
Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?
- A. The right to privacy has to be balanced against other rights under the ECHR
- B. The right to freedom of expression under Article 10 of the ECHR will always override the right to privacy
- C. The right to privacy protects the right to hold opinions and to receive and impart ideas without interference
- D. The right to privacy is an absolute right
Answer: A
NEW QUESTION 58
What type of data lies beyond the scope of the General Data Protection Regulation?
- A. Masked
- B. Encrypted
- C. Pseudonymized
- D. Anonymized
Answer: D
Explanation:
Reference https://www.datainspektionen.se/other-lang/in-english/the-general-data-protection-regulation-gdpr/ the-purposes-and-scope-of-the-general-data-protection-regulation/
NEW QUESTION 59
The GDPR requires controllers to supply data subjects with detailed information about the processing of their dat a. Where a controller obtains data directly from data subjects, which of the following items of information does NOT legally have to be supplied?
- A. The recipients or categories of recipients.
- B. The categories of personal data concerned.
- C. The rights of access, erasure, restriction, and portability.
- D. The right to lodge a complaint with a supervisory authority.
Answer: B
NEW QUESTION 60
A U.S. company's website sells widgets. Which of the following factors would NOT in itself subject the company to the GDPR?
- A. The widgets are offered in EU and priced in euro.
- B. An affiliate office is located in France but the processing is in the U.S.
- C. The website is in English and French, and is accessible in France.
- D. The website places cookies to monitor the EU website user behavior.
Answer: C
NEW QUESTION 61
SCENARIO
Please use the following to answer the next question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
After Louis has exercised his right to restrict the use of his data, under what conditions would Accidentable have grounds for refusing to comply?
- A. If Accidentable is entitled to use of the data as an affiliate of Bedrock.
- B. If Accidentable also uses the data to conduct public health research.
- C. If the accuracy of the data is not an aspect that Louis is disputing.
- D. If the data becomes necessary to defend Accidentable's legal rights.
Answer: A
NEW QUESTION 62
Please use the following to answer the next question:
Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Javier lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Javier was photographed while working out at a branch of EVERFIT in Frankfurt, Germany. At the time, Javier gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club's U.K. brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Javier no longer feels comfortable with his photograph being publicly associated with the fitness club.
After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Javier sends a letter to EVETFIT requesting that his image be removed from the website and all promotional materials. Months pass and Javier, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact EVETFIT through alternate channels, he decides to take action against the company.
Javier contacts the U.K. Information Commissioner's Office ('ICO' - the U.K.'s supervisory authority) to lodge a complaint about this matter. The ICO, pursuant to Article 56 (3) of the GDPR, informs the CNIL (i.e. the supervisory authority of EVERFIT's main establishment) about this matter. Despite the fact that EVERFIT has an establishment in the U.K., the CNIL decides to handle the case in accordance with Article 60 of the GDPR. The CNIL liaises with the ICO, as relevant under the cooperation procedure. In light of issues amongst the supervisory authorities to reach a decision, the European Data Protection Board becomes involved and, pursuant to the consistency mechanism, issues a binding decision.
Additionally, Javier sues EVERFIT for the damages caused as a result of its failure to honor his request to have his photograph removed from the brochure and website.
Under the cooperation mechanism, what should the lead authority (the CNIL) do after it has formed its view on the matter?
- A. Submit a draft decision directly to the Commission to ensure the effectiveness of the consistency mechanism.
- B. Submit a draft decision to other supervisory authorities for their opinion.
- C. Request that the other supervisory authorities provide the lead authority with a draft decision for its consideration.
- D. Request that members of the seconding supervisory authority and the host supervisory authority co-draft a decision.
Answer: C
NEW QUESTION 63
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
- A. When personal data is being collected and combined with other personal data to profile the creditworthiness of individuals.
- B. When the controller is required to have a Data Protection Officer.
- C. When the controller is collecting email addresses from individuals via an online registration form for marketing purposes.
- D. When personal data is being transferred outside of the EEA.
Answer: A
Explanation:
Reference https://www.tandfonline.com/doi/full/10.1080/13600834.2020.1790092#:~:text=Article%2035%20of
%20the%20General,and%20freedoms%20of%20natural%20persons%27.
NEW QUESTION 64
Which judicial body makes decisions on actions taken by individuals wishing to enforce their rights under EU law?
- A. Court of Justice of European Union
- B. Court of Auditors
- C. European Court of Human Rights
- D. European Data Protection Board
Answer: A
Explanation:
Reference https://europa.eu/european-union/about-eu/institutions-bodies/court-justice_en
NEW QUESTION 65
In the Planet 49 case, what was the man judgement of the Coon of Justice of the European Union (CJEU) regarding the issue of cookies?
- A. If the ePrivacy Directive requires consent for cookies, then the GDPR's consent requirements apply.
- B. If a website's cookie notice makes clear the information gathered and the lifespan of the cookie, then pre-checked boxes are acceptable.
- C. If a data subject continues to scroll through a website after reading a cookie banner, this activity constitutes valid consent for the tracking described in the cookie banner.
- D. If the cookies do not track personal data, then pre-checked boxes are acceptable.
Answer: A
NEW QUESTION 66
Which of the following was the first to implement national law for data protection in 1973?
- A. Germany
- B. Sweden
- C. United Kingdom
- D. France
Answer: B
Explanation:
Reference https://scandinavianlaw.se/pdf/47-18.pdf
NEW QUESTION 67
Which of the following is NOT an explicit right granted to data subjects under the GDPR?
- A. The right to request the deletion of data a controller holds about them.
- B. The right to request restriction of processing of personal data, under certain scenarios.
- C. The right to request access to the personal data a controller holds about them.
- D. The right to opt-out of the sale of their personal data to third parties.
Answer: C
Explanation:
Reference https://www.i-scoop.eu/gdpr/data-subject-rights-gdpr/
NEW QUESTION 68
How is the retention of communications traffic data for law enforcement purposes addressed by European data protection law?
- A. The Data Retention Directive's annulment makes such data retention now permissible.
- B. The GDPR allows the retention of such data for the prevention, investigation, detection or prosecution of criminal offences only.
- C. The ePrivacy Directive harmonizes EU member states' rules concerning such data retention.
- D. The ePrivacy Directive allows individual EU member states to engage in such data retention.
Answer: B
Explanation:
Reference https://www.law.kuleuven.be/citip/en/archive/copy_of_publications/440retention-of-traffic-data- dumortier-goemans2f90.pdf (9)
NEW QUESTION 69
......
Get 100% Success with Latest Certified Information Privacy Professional CIPP-E Exam Dumps: https://www.dumpstillvalid.com/CIPP-E-prep4sure-review.html
CIPP-E Free Certification Exam Easy to Download PDF Format 2023: https://drive.google.com/open?id=1Q2rVvqYM4-FhLKncta6p6zyHGzUWMMQH
