New Year Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CIPP-E Exam Dumps - Certified Information Privacy Professional/Europe (CIPP/E)

Go to page:
Question # 9

What is a reason the European Court of Justice declared the Data Retention Directive invalid in 2014?

A.

The requirements affected individuals without exception.

B.

The requirements were financially burdensome to EU businesses.

C.

The requirements specified that data must be held within the EU.

D.

The requirements had limitations on how national authorities could use data.

Full Access
Question # 10

Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit organizations in a privacy group litigation or class action. These organizations are commonly known as?

A.

Law firm organizations.

B.

Civil society organizations.

C.

Human rights organizations.

D.

Constitutional rights organizations.

Full Access
Question # 11

Which of the following is NOT exempt from the material scope of the GDPR. insofar as the processing of personal data is concerned?

A.

A natural person in the course of a large-scale but purely personal or household activity.

B.

A natural person processing data foe a small-scale, purely personal or household activity.

C.

A natural person in the course of processing purely personal or household data on behalf of a spouse who is beyond the age of majority.

D.

A natural person in the course of activity conducted purely tor a personally-owned sole proprietorship.

Full Access
Question # 12

Which of the following is NOT recognized as a common characteristic of cloud computing services?

A.

The service's infrastructure is shared among the supplier's customers and can be located in a number of countries.

B.

The supplier determines the location, security measures, and service standards applicable to the processing.

C.

The supplier allows customer data to be transferred around the infrastructure according to capacity.

D.

The supplier assumes the vendor's business risk associated with data processed by the supplier.

Full Access
Question # 13

Under the Data Protection Law Enforcement Directive of the EU, a government can carry out covert investigations involving personal data, as long it is set forth by law and constitutes a measure that is both necessary and what?

A.

Prudent.

B.

Important.

C.

Proportionate.

D.

DPA-approved.

Full Access
Question # 14

Which of the following elements does NOT need to be presented to a data subject in order to collect valid consent for the use of cookies?

A.

A "Cookies Settings" button.

B.

A "Reject All" cookies button.

C.

A list of cookies that may be placed.

D.

Information on the purpose of the cookies.

Full Access
Question # 15

SCENARIO

Please use the following to answer the next question:

Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located m Malta |EU).

People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.

The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.

The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a

What is potentially wrong with the backup system operated in the AWS cloud?

A.

The AWS servers are located in the EU but in a country different than the location of the corporate headquarters.

B.

It is unlawful to process any personal data in a cloud unless the cloud is certified as GOPR-compliant by a competent supervisory authority.

C.

The data storage period has to be revised, and a data processing agreement w*h AWS must be signed

D.

AWS is a U S company, and no personal data of European residents may be transferred to it without explicit written consent from data subjects.

Full Access
Question # 16

SCENARIO

Please use the following to answer the next question:

Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees’ computers to see if they have software that is no

longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees’ computers.

Since these measures would potentially impact employees, Building Block’s Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.

After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees’ computers activity and their location. During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.

Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company’s computers, and from working remotely without authorization.

To comply with the GDPR, what should Building Block have done as a first step before implementing the SecurityScan measure?

A.

Assessed potential privacy risks by conducting a data protection impact assessment.

B.

Consulted with the relevant data protection authority about potential privacy violations.

C.

Distributed a more comprehensive notice to employees and received their express consent.

D.

Consulted with the Information Security team to weigh security measures against possible server impacts.

Full Access
Go to page: