[Q49-Q64] IAPP CIPP-E Dumps Updated [Nov-2023] Get 100% Real Exam Questions!

Share

[Nov-2023] Pass IAPP CIPP-E Exam in First Attempt Guaranteed!

Full CIPP-E Practice Test and 252 unique questions with explanations waiting just for you, get it now!

NEW QUESTION # 49
If a company chooses to ground an international data transfer on the contractual route, which of the following is NOT a valid set of standard contractual clauses?

  • A. Decision 2001/497/EC (EU controller to non-EU or EEA controller).
  • B. Decision 2010/87/EU (Non-EU or EEA processor from EU controller).
  • C. Decision 2007/72/EC (EU processor to non-EU or EEA controller).
  • D. Decision 2004/915/EC (EU controller to non-EU or EEA controller).

Answer: D


NEW QUESTION # 50
Which aspect of the GDPR will likely have the most impact on the consistent implementation of data protection laws throughout the European Union?

  • A. That it makes appointment of a data protection officer mandatory
  • B. That it makes notification of large-scale data breaches mandatory
  • C. That it essentially functions as a one-stop shop mechanism
  • D. That it takes the form of a Regulation as opposed to a Directive

Answer: A


NEW QUESTION # 51
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage What transfer mechanism should Jackie recommend for using InstaHR?

  • A. Explicit consent of employees.
  • B. Standard contractual clauses
  • C. Binding corporate rules.
  • D. Adequacy

Answer: A


NEW QUESTION # 52
In relation to third countries and international organizations, which of the following shall, along with the supervisory authorities, take appropriate steps to develop international cooperation mechanisms for the enforcement of data protection legislation?

  • A. The Council of the European Union.
  • B. The European Commission
  • C. The designated Data Protection Officers
  • D. The European Parliament

Answer: C


NEW QUESTION # 53
SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles. Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Based on current trends in European privacy practices, which aspect of Brady Box' Online Behavioral Advertising (OBA) is most likely to be insufficient if the company becomes established in Europe?

  • A. The lack of the option to opt in.
  • B. The need to have the contents of the advertising approved.
    Section: (none)
    Explanation
  • C. The level of security within the website.
  • D. The contract with the third-party advertising network.

Answer: A


NEW QUESTION # 54
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?

  • A. Within 40 days of receipt
  • B. Within one month of receipt, which may be extended by an additional two months
  • C. Within one month of receipt, which may be extended by up to an additional month
  • D. Within 40 days of receipt, which may be extended by up to 40 additional days

Answer: C

Explanation:
Explanation/Reference: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection- regulation-gdpr/individual-rights/right-of-access/


NEW QUESTION # 55
SCENARIO
Please use the following to answer the next question:
You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company's revenue is due to international sales.
The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children's questions on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well.
The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.
When a child asks the toy a question, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure's integrated speakers, making it appear as though that the toy is actually responding to the child's question. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.
In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures' abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character's abilities remain intact.
In light of the requirements of Article 32 of the GDPR (related to the Security of Processing), which practice should the company institute?

  • A. Include three-factor authentication before each use by a child in order to ensure the best level of security possible.
  • B. Include dual-factor authentication before each use by a child in order to ensure a minimum amount of security.
  • C. Insert contractual clauses into the contract between the toy manufacturer and the cloud service provider, since South Africa is outside the European Union.
  • D. Encrypt the data in transit over the wireless Bluetooth connection.

Answer: D


NEW QUESTION # 56
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?

  • A. Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.
  • B. Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.
  • C. Only where the personal data is to be subjected to specific computerized processing, such as image scanning or optical character recognition.
  • D. Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.

Answer: D


NEW QUESTION # 57
SCENARIO
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''

  • A. No, the assessors do not quality as data processors as they only have access to encrypted data.
  • B. Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.
  • C. Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.
  • D. No. the assessors do not quality as data processors as they do not copy the data to their facilities.

Answer: B


NEW QUESTION # 58
A U.S. company's website sells widgets. Which of the following factors would NOT in itself subject the company to the GDPR?

  • A. An affiliate office is located in France but the processing is in the U.S.
  • B. The widgets are offered in EU and priced in euro.
  • C. The website places cookies to monitor the EU website user behavior.
  • D. The website is in English and French, and is accessible in France.

Answer: D


NEW QUESTION # 59
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?

  • A. The Council of the European Union.
  • B. National data protection authorities.
  • C. The European Data Protection Supervisor.
  • D. Approved data controllers.

Answer: D

Explanation:
Explanation/Reference: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/ standard-contractual-clauses-scc_en


NEW QUESTION # 60
Why is advisable to avoid consent as a legal basis for an employer to process employee data?

  • A. An employer might have difficulty obtaining consent from every employee.
  • B. Data protection laws do not apply to processing of employee data.
  • C. Employee data can only be processed if there is an approval from the data protection officer.
  • D. Consent may not be valid if the employee feels compelled to provide it.

Answer: D


NEW QUESTION # 61
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
The GDPR requires sufficient guarantees of a company's ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?

  • A. Requesting advice and technical support from Company A's IT team.
  • B. Vetting companies' measures with the appropriate supervisory authority.
  • C. Avoiding the use of another company's data to improve their own services.
  • D. Hiring companies whose measures are consistent with recommendations of accrediting bodies.

Answer: D


NEW QUESTION # 62
Under the GDPR, which essential pieces of information must be provided to data subjects before collecting their personal data?

  • A. The contact information of the controller and a description of the retention policy.
  • B. The name/s of relevant government agencies involved and the steps needed for revising the data.
  • C. The identity and contact details of the controller and the reasons the data is being collected.
  • D. The authority by which the controller is collecting the data and the third parties to whom the data will be sent.

Answer: C


NEW QUESTION # 63
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage What transfer mechanism did ProStorage most likely rely on to transfer Ruth's medical information to the hospital?

  • A. Protecting against legal liability from Ruth.
  • B. Ruth's implied consent.
  • C. Performance of a contract with Ruth.
  • D. Protecting the vital interest of Ruth

Answer: A


NEW QUESTION # 64
......

Get Latest CIPP-E Dumps Exam Questions in here: https://gocertify.actual4labs.com/IAPP/CIPP-E-actual-exam-dumps.html

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now