New Year Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CIPP-E Exam Dumps - Certified Information Privacy Professional/Europe (CIPP/E)

Go to page:
Question # 81

Start-up company MagicAI is developing an AI system that will be part of a medical device that detects skin cancer. To take measures against potential bias in its AI system, the IT Team decides to collect data about users' ethnic origin, nationality, and gender.

Which would be the most appropriate legal basis for this processing under the GDPR, Article 9 (Processing of special categories of personal data)?

A.

Processing necessary for scientific or statistical purposes.

B.

Processing necessary for reasons of substantial public interest.

C.

Processing necessary for purposes of preventive or occupational medicine.

D.

Processing necessary for the defense of legal claims in potential negligence cases.

Full Access
Question # 82

According to the European Data Protection Board, controllers responding to a data subject access request can refuse to provide a copy of personal data under certain conditions. Which of the following is NOT one of these conditions?

A.

If the data subject access request was sent to an employee that is not involved in the processing of such requests.

B.

If there is such a large amount of data that the controller cannot identify the data subject of the request.

C.

If the controller is unable to use end-to-end encrypted emails for responding to such requests.

D.

If the personal data was processed in the past but is no longer at the controller's disposal at the time of the request.

Full Access
Question # 83

What ruling did the Planet 49 CJEU judgment make regarding the issue of pre-ticked boxes?

A.

They are allowed if determined to be technically necessary.

B.

They do not amount to valid consent under any circumstances.

C.

They are allowed if recorded In the register of processing activities.

D.

They constitute valid consent if the processing is necessary for purposes of legitimate interest

Full Access
Question # 84

SCENARIO

Please use the following to answer the next question:

Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).

People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.

The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.

The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a

Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''

A.

No, the assessors do not quality as data processors as they only have access to encrypted data.

B.

No. the assessors do not quality as data processors as they do not copy the data to their facilities.

C.

Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.

D.

Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.

Full Access
Question # 85

Which of the following regulates the use of electronic communications services within the European Union?

A.

Regulator (EU) 2015/2120 of the European Parliament and of the Council of 25 November 2015.

B.

Regulation (EU) 2017/1953 of the European Parliament and of the Council of 25 October 2017.

C.

Directive 2002/58'EC of the European Parliament and of the Council of 12 July 2002.

D.

Directive (EU) 2019.789 of the European Parliament and of the Council of 17 April 2019.

Full Access
Question # 86

Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?

A.

Legislative powers.

B.

Corrective powers.

C.

Investigatory powers.

D.

Authorization and advisory powers.

Full Access
Go to page: