New Year Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CIPP-E Exam Dumps - Certified Information Privacy Professional/Europe (CIPP/E)

Go to page:
Question # 17

According to the European Data Protection Board, if a controller that is not established in the EU but still subject to the GDPR becomes aware of a personal data breach, which supervisory authority or authorities must be notified?

A.

Only the supervisory authority of the EU member state in which the controller's EU representative (pursuant to Article 27) is established.

B.

Only one lead supervisory authority, as a controller benefits from the one-stop shop mechanism under the GDPR's enforcement regime.

C.

Every supervisory authority of the EU member states where the controller is offering goods or services.

D.

Every supervisory authority for which affected data subjects reside in their EU member state.

Full Access
Question # 18

The GDPR forbids the practice of “forum shopping”, which occurs when companies do what?

A.

Choose the data protection officer that is most sympathetic to their business concerns.

B.

Designate their main establishment in member state with the most flexible practices.

C.

File appeals of infringement judgments with more than one EU institution simultaneously.

D.

Select third-party processors on the basis of cost rather than quality of privacy protection.

Full Access
Question # 19

According to the European Data Protection Board, data subjects should be aware of any video surveillance in operation. How should a retail shop operator ensure that data subjects receive at information required for such a purpose under EU data protection law?

A.

The shop operator should post a copy of the manual of the video surveillance system in the shop and on its social media channels.

B.

The shop operator should provide full notice of the intended video surveillance outside the shop, for example with a sign or a stand-up display.

C.

The shop operator should instruct the data protection officer to hand out a comprehensive notice to data subjects every time they enter the shop.

D.

The shop operator should provide the most important information on a clearly readable warning sign to data subjects before they enter the monitored area, and additional mandatory details by other means.

Full Access
Question # 20

Which aspect of processing does the GDPR allow processors to determine for themselves?

A.

The question of whether the controller needs to be informed about the substitution of another processor carrying out specific processing activities on behalf of the controller.

B.

Their own purposes for the processing, if such purposes are compatible with those for which the personal data were initially collected.

C.

The parameters of their marketing campaigns using personal data relating to the controller's customers.

D.

Their own type of hardware or software and the specific security measures for the processing.

Full Access
Question # 21

A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?

A.

The school places a notice near each camera.

B.

The school gets explicit consent from the students.

C.

Processing is necessary for the legitimate interests pursed by the school.

D.

A state law requires facial recognition to verify attendance.

Full Access
Question # 22

Which of the following is NOT an explicit right granted to data subjects under the GDPR?

A.

The right to request access to the personal data a controller holds about them.

B.

The right to request the deletion of data a controller holds about them.

C.

The right to opt-out of the sale of their personal data to third parties.

D.

The right to request restriction of processing of personal data, under certain scenarios.

Full Access
Question # 23

To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?

A.

The Court of Justice of the European Union.

B.

The European Data Protection Supervisor.

C.

The European Court of Human Rights.

D.

The European Data Protection Board.

Full Access
Question # 24

A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?

A.

Obtain specific consent for the new processing

B.

Only inform the data subjects of the new purpose.

C.

Proceed no further, as such repurposing is unlawful

D.

Update the privacy notice upon which consent was given

Full Access
Go to page: