
Pass IAPP CIPP-E Exam with Guarantee Updated 252 Questions
Latest CIPP-E Pass Guaranteed Exam Dumps Certification Sample Questions
What are the Problems of IAPP CIPP/E Exam
Candidates face many problems when they start preparing for the IAPP CIPP/E Exam. If a candidate wants to prepare his for the IAPP CIPP/E Exam without any problem and get good grades in the exam. Then they have to choose the best IAPP CIPP/E Exam exam dumps for real exam questions practice. There are many websites that are offering the latest IAPP CIPP/E Exam questions and answers but these questions are not verified by IAPP certified experts and that's why many are failed in their just first attempt. PracticeVCE is the best platform which provides the candidate with the necessary IAPP 63 questions that will help him to pass the IAPP CIPP/E Exam on the first time. The candidate will not have to take the IAPP CIPP/E Exam twice because with the help of IAPP CIPP/E Exam exam dumps the Candidate will have every valuable material required to pass the IAPP CIPP/E Exam. We are providing the latest and actual questions and that is the reason why this is the one that he needs to use and there are no chances to fail when a candidate will have valid braindumps from PracticeVCE. We have the guarantee that the questions that we have will be the ones that will pass candidate in the IAPP CIPP/E Exam in the very first attempt.
NEW QUESTION 85
Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric dat a. Which of the following is NOT one of these exceptions?
- A. The processing is done by a non-profit organization and the results are disclosed outside the organization.
- B. The processing is necessary to protect the vital interests of the data subject when he or she is incapable of giving consent.
- C. The processing is explicitly consented to by the data subject and he or she is allowed by Union or Member State law to lift the prohibition.
- D. The processing is necessary for the establishment, exercise or defense of legal claims when courts are acting in a judicial capacity.
Answer: A
Explanation:
Reference https://dataprivacymanager.net/sensitive-personal-data-special-category-under-the-gdpr/
NEW QUESTION 86
A Spanish electricity customer calls her local supplier with questions about the company's upcoming merger.
Specifically, the customer wants to know the recipients to whom her personal data will be disclosed once the merger is final. According to Article 13 of the GDPR, what must the company do before providing the customer with the requested information?
- A. Verify that the identity of the customer can be proven by other means.
- B. Verify that the request is applicable to the data collected before the GDPR entered into force.
- C. Verify that the purpose of the request from the customer is in line with the GDPR.
- D. Verify that the personal data has not already been sent to the customer.
Answer: B
Explanation:
Explanation/Reference: https://fpf.org/wp-content/uploads/2018/11/GDPR_CCPA_Comparison-Guide.pdf
NEW QUESTION 87
What is the key difference between the European Council and the Council of the European Union?
- A. The European Council is comprised of the heads of each EU member state.
Section: (none)
Explanation - B. The Council of the European Union is helmed by a president.
- C. The Council of the European Union has a degree of legislative power.
- D. The European Council focuses primarily on issues involving human rights.
Answer: A
NEW QUESTION 88
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
The GDPR requires sufficient guarantees of a company's ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?
- A. Requesting advice and technical support from Company A's IT team.
- B. Avoiding the use of another company's data to improve their own services.
- C. Hiring companies whose measures are consistent with recommendations of accrediting bodies.
- D. Vetting companies' measures with the appropriate supervisory authority.
Answer: C
Explanation:
Reference https://www.knowyourcompliance.com/gdpr-technical-organisational-measures/
NEW QUESTION 89
Under the Data Protection Law Enforcement Directive of the EU, a government can carry out covert investigations involving personal data, as long it is set forth by law and constitutes a measure that is both necessary and what?
- A. Prudent.
- B. Proportionate.
- C. Important.
- D. DPA-approved.
Answer: B
NEW QUESTION 90
Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?
- A. The right to privacy has to be balanced against other rights under the ECHR
- B. The right to privacy is an absolute right
- C. The right to freedom of expression under Article 10 of the ECHR will always override the right to privacy
- D. The right to privacy protects the right to hold opinions and to receive and impart ideas without interference
Answer: A
NEW QUESTION 91
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
- A. A company wants to use location data to infer information on a person's clothes purchasing habits.
- B. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
- C. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- D. A company wants to combine location data with other data in order to offer more personalized service for the customer.
Answer: C
NEW QUESTION 92
Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?
- A. Standard contractual clauses.
- B. Law enforcement requests.
- C. Approved certifications.
- D. Binding corporate rules.
Answer: C
NEW QUESTION 93
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?
- A. Norway
- B. Australia
- C. Switzerland
- D. Greece
Answer: C
Explanation:
Explanation/Reference: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/ adequacy-decisions_en
NEW QUESTION 94
Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?
- A. Standard contractual clauses.
- B. Law enforcement requests.
- C. Approved certifications.
- D. Binding corporate rules.
Answer: C
Explanation:
Reference https://www.anonos.com/gdpr-chapter-5-transfers-of-personal-data-to-third-countries-or- international-organisations
NEW QUESTION 95
According to Art 23 GDPR, which of the following data subject rights can NOT be restricted?
- A. Right to lodge a complaint with a supervisory authority.
- B. Right to erasure ("Right to be forgotten").
- C. Right to restriction of processing.
- D. Right not to be subject to automated individual decision-making
Answer: C
NEW QUESTION 96
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?
- A. The data protection officer must be located in the country where the data controller has its main establishment.
- B. The group of undertakings must be comprised of organizations of similar sizes and functions.
- C. The group of undertakings must obtain approval from a supervisory authority.
- D. The data protection officer must be easily accessible from each establishment where the undertakings are located.
Answer: D
Explanation:
Reference https://www.privacy-regulation.eu/en/article-37-designation-of-the-data-protection-officer- GDPR.htm
NEW QUESTION 97
Which of the following is NOT recognized as being a common characteristic of cloud-computing services?
- A. The supplier allows customer data to be transferred around the infrastructure according to capacity.
- B. The supplier determines the location, security measures, and service standards applicable to the processing.
- C. The service's infrastructure is shared among the supplier's customers and can be located in a number of countries.
- D. The supplier assumes the vendor's business risk associated with data processed by the supplier.
Answer: D
Explanation:
Reference https://www.softwaremajor.com/news-articles/64-gdpr-how-does-it-apply-to-the-cloud
NEW QUESTION 98
SCENARIO
Please use the following to answer the next question:
ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
What is the time period in which Mike should receive a response to his request?
- A. Not more than one month of receipt of Mike's request.
- B. Not more than two months after verifying Mike's identity.
- C. Not more than thirty days after submission of Mike's request.
- D. When all the information about Mike has been collected.
Answer: A
NEW QUESTION 99
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent.
All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
The data transfer mechanism that Alice drafted violates the GDPR because the company did not first get approval from?
- A. The Data Protection Authority.
- B. The European Commission.
- C. The European Data Protection Board.
- D. The Court of Justice of the European Union.
Answer: A
NEW QUESTION 100
SCENARIO
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage What transfer mechanism did ProStorage most likely rely on to transfer Ruth's medical information to the hospital?
- A. Protecting the vital interest of Ruth
- B. Protecting against legal liability from Ruth.
- C. Ruth's implied consent.
- D. Performance of a contract with Ruth.
Answer: B
NEW QUESTION 101
A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if it imports personal data from another organization in the European Economic Area (EEA) under standard contractual clauses?
- A. Supply any information requested by a data protection authority (DPA) within 30 days.
- B. Submit the contract to its own government authority.
- C. Ensure that notice is given to and consent is obtained from data subjects.
- D. Ensure that local laws do not impede the company from meeting its contractual obligations.
Answer: B
NEW QUESTION 102
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located m Malta |EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a What is potentially wrong with the backup system operated in the AWS cloud?
- A. AWS is a U S company, and no personal data of European residents may be transferred to it without explicit written consent from data subjects.
- B. The data storage period has to be revised, and a data processing agreement w*h AWS must be signed
- C. It is unlawful to process any personal data in a cloud unless the cloud is certified as GOPR-compliant by a competent supervisory authority.
- D. The AWS servers are located in the EU but in a country different than the location of the corporate headquarters.
Answer: B
NEW QUESTION 103
The transparency principle is most directly related to which of the following rights?
- A. Right to restriction of processing.
- B. Right to object
- C. Right to be forgotten.
- D. Right to be informed.
Answer: D
NEW QUESTION 104
A company would like to implement CCTV monitoring in its offices for safety and security purposes. Which of the following would be the best legal basis for the company to rely upon?
- A. Public interest.
- B. Individual consent
- C. Exercise of pubic authority.
- D. Legitimate interest.
Answer: A
NEW QUESTION 105
......
Conclusion
The IAPP CIPP-E exam will help a candidate stamp their knowledge of EU-US data protection laws and how well they can apply them in their practice. Data protection officials with this certification have an upper hand in the industry, and can even fit in international work environments. The study course as well as guides are very useful in helping the candidate pass their exams on the first try.
Guides for Final Evaluation
Study guides help candidates study and revise for the actual exam, as they familiarize themselves with the test requirements. Commonly, such materials include a deep consideration of the areas to be tested such as European-based data protection basics, regulatory institutions, and legislative framework. Others are how to comply with European laws in addition to regulation for data protection and international transfer of data. So, here are a few study guides for this exam:
- CIPP-US & CIPP-E Information Privacy Professional Certification Exams ExamFOCUS Study Notes & Review Questions 2018/2019 Edition
This book by ExamREVIEW is constantly updated with relevant questions and exam tips for the CIPP-E evaluation. It was recently updated in 2020 ensuring that the users get the most updated content. The guide is a great way for candidates to test their knowledge of concepts on data protection laws in Europe. The exam questions in this book cover jurisdictional law, regulations and different models of enforcement, and the relevant legal requirements of data transfer and handling in different countries in the EU.
- Complete CIPP-E Practice Exam: 90 Questions, Not by IAPP
This material by Privacy Law Practice Exams encourages the candidates not to plunge into the real exam before testing their readiness for it. The book has 90 questions which help a student gauge how much of their lessons they have understood, and their problem areas if any. It also helps the candidates get familiar with the test setting and understand the tips and tricks to understand the questions and answer them appropriately.
- Official Study Guides
The IAPP Store includes various guides that one can use to learn more about different topics regarding data privacy. Also, a free guide for the CIPP-E exam is available on the vendor's site. It is written in English, German, and French and covers key areas regarding the test, sample questions, exam info, and preparation steps.
- Real CIPP-E Prep: American’s Guide to European Data Protection Law and the General Data Protection Regulation (GDPR)
Gordon Yu authored this book to help CIPP-E candidates understand the data protection concepts tested in the exam better, so they would help them even in their professional spaces. The author indicates that he wrote such a book to support the specialists who wanted to go for the certification after they have completed their GDPR implementations.
New CIPP-E Test Materials & Valid CIPP-E Test Engine: https://killexams.practicevce.com/IAPP/CIPP-E-practice-exam-dumps.html