[Sep-2023] CIPP-E Braindumps - CIPP-E Questions to Get Better Grades [Q66-Q83]

Share

[Sep-2023] CIPP-E Braindumps – CIPP-E Questions to Get Better Grades

CIPP-E Exam Dumps - Try Best CIPP-E Exam Questions - PracticeVCE

NEW QUESTION # 66
Many businesses print their employees' photographs on building passes, so that employees can be identified by security staff. This is notwithstanding the fact that facial images potentially qualify as biometric data under the GDPR. Why would such practice be permitted?

  • A. Because photographic ID is a physical security measure which is "necessary for reasons of substantial public interest".
    Reference https://ess.csa.canon.com/rs/206-CLL-191/images/IAPP-Top-10-Operational-Impacts-of- GDPR.pdf?TC=DM&CN=CSA_OMNIA_Partners&CS=CSA&CR=T1_Gov%20GenNonProfit (11)
  • B. Because use of biometric data to confirm the unique identification of data subjects benefits from an exemption.
  • C. Because photographs qualify as biometric data only when they undergo a "specific technical processing".
  • D. Because employees are deemed to have given their explicit consent when they agree to be photographed by their employer.

Answer: C


NEW QUESTION # 67
The European Data Protection Board (EDPB) recommends measures to supplement transfer tools, in order to ensure compliance with the European Union (EU) level of personal data protection. According to these recommendations, what additional actions should be taken when a transfer to a third country is based upon an adequacy decision?

  • A. Adopt a supplementary data transfer mechanism.
  • B. Monitor the ongoing validity of the data transfer mechanism.
  • C. Monitor changes in the law or practice of the third country that would tower the level of protection of personal data
  • D. Adopt technical, contractual or organizational supplementary measures.

Answer: C


NEW QUESTION # 68
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze's headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
Which of the following is T-Craze's lead supervisory authority?

  • A. Germany, because that is where T-Craze is headquartered.
  • B. Spain, because that is T-Craze's primary market based on its marketing campaigns.
  • C. France, because that is where T-Craze conducts processing of personal information.
  • D. T-Craze may choose its lead supervisory authority where any of its affiliates are based, because it has presence in several European countries.

Answer: D


NEW QUESTION # 69
According to Art 23 GDPR, which of the following data subject rights can NOT be restricted?

  • A. Right to erasure ("Right to be forgotten").
  • B. Right not to be subject to automated individual decision-making
  • C. Right to lodge a complaint with a supervisory authority.
  • D. Right to restriction of processing.

Answer: D


NEW QUESTION # 70
SCENARIO
Please use the following to answer the next question:
Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Governance. Through her first initiative in conducting a data inventory, Sandy learned that Market4U maintains a list of 19 million global contacts that were collected throughout the course of Market4U's existence. Knowing the risk of having such a large amount of data, Sandy wanted to purge all contacts that were entered into Market4U's systems prior to May 2018, unless such contacts had a more recent interaction with Market4U content. However, Dan, the VP of Sales, informed Sandy that all of the contacts provide useful information regarding successful marketing campaigns and trends in industry verticals for Market4U's clients.
Dan also informed Sandy that he had wanted to focus on gaining more customers within the sports and entertainment industry. To assist with this behavior, Market4U's marketing team decided to add several new fields to Market4U's website forms, including forms for downloading white papers, creating accounts to participate in Market4U's forum, and attending events. Such fields include birth date and salary.
What is the best way that Sandy can gain the insights that Dan seeks while still minimizing risks for Market4U?

  • A. Procure a third party to conduct the analysis and delete the data from Market4U's systems.
  • B. Delete all data collected prior to May 2018 after conducting the trend analysis.
  • C. Conduct analysis only on anonymized personal data.
  • D. Conduct analysis only on pseudonymized personal data.

Answer: C


NEW QUESTION # 71
Under Article 21 of the GDPR, a controller must stop profiling when requested by a data subject, unless it can demonstrate compelling legitimate grounds that override the interests of the individual. In the Guidelines on Automated individual decision-making and Profiling, the WP 29 says the controller needs to do all of the following to demonstrate that it has such legitimate grounds EXCEPT?

  • A. Demonstrate that the profiling is for the purposes of direct marketing.
  • B. Consider the impact of the profiling on the data subject's interest, rights and freedoms.
  • C. Consider the importance of the profiling to their particular objective.
  • D. Carry out an exercise that weighs the interests of the controller and the basis for the data subject's objection.

Answer: A

Explanation:
Reference https://gdpr-info.eu/art-21-gdpr/


NEW QUESTION # 72
There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?

  • A. Remedial security.
  • B. Incident detection and response.
  • C. Consent management and withdrawal.
  • D. Preventative security.

Answer: C


NEW QUESTION # 73
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location. During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
To comply with the GDPR, what should Building Block have done as a first step before implementing the SecurityScan measure?

  • A. Distributed a more comprehensive notice to employees and received their express consent.
  • B. Assessed potential privacy risks by conducting a data protection impact assessment.
  • C. Consulted with the Information Security team to weigh security measures against possible server impacts.
  • D. Consulted with the relevant data protection authority about potential privacy violations.

Answer: A


NEW QUESTION # 74
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?

  • A. Data inventory or data mapping exercises that have been conducted.
  • B. Retention periods for erasure and deletion of categories of personal data.
    Section: (none)
    Explanation
  • C. Incidents of personal data breaches, whether disclosed or not.
  • D. Categories of recipients to whom the personal data have been disclosed.

Answer: B


NEW QUESTION # 75
A multinational company is appointing a mandatory data protection officer. In addition to considering the rules set out in Article 37 (1) of the GDPR, which of the following actions must the company also undertake to ensure compliance in all EU jurisdictions in which it operates?

  • A. Conduct a Data Protection Privacy Assessment on the processing operations of the company in all the countries it operates.
  • B. Consult national derogations to evaluate if there are additional cases to be considered in relation to the matter.
  • C. Assess whether the company has more than 250 employees in each of the EU member-states in which it is established.
  • D. Revise the data processing activities of the company that affect more than one jurisdiction to evaluate whether they comply with the principles of privacy by design and by default.

Answer: A


NEW QUESTION # 76
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?

  • A. The data subject already has information regarding how his data will be used
  • B. The processing of the data subject's data is protected by appropriate technical measures
  • C. The provision of such information to the data subject would be too problematic
  • D. Third-party data would be disclosed by providing such information to the data subject

Answer: A

Explanation:
Reference https://dataprivacymanager.net/gdpr-exemptions-from-the-obligation-to-provide-information-to-the- individual-data-subject/


NEW QUESTION # 77
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What must Zandelay provide to the supervisory authority during the prior consultation?

  • A. Certificates that prove Martin's professional qualities and expert knowledge of data protection law.
  • B. An evaluation of the complexity of the intended processing.
  • C. An explanation of the purposes and means of the intended processing.
  • D. Records showing that customers have explicitly consented to the intended profiling activities.

Answer: C


NEW QUESTION # 78
SCENARIO
Please use the following to answer the next Question: 01
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
Based on the GDPR's position on the use of personal data for direct marketing purposes, which of the following is true about Louis's rights as a data subject?

  • A. Louis does not have the right to object to the use of his data if Bedrock can demonstrate compelling legitimate grounds for the processing.
  • B. Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.
  • C. Louis does not have the right to object to the use of his data because he previously consented to it.
  • D. Louis has the right to object to the use of his data, unless his data is required by Bedrock for the purpose of exercising a legal claim.

Answer: B


NEW QUESTION # 79
In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?

  • A. When calling a potential customer to notify her of an upcoming product sale.
  • B. When creating an untargeted pop-up ad on a website.
  • C. When emailing a customer to announce that his recent order should arrive earlier than expected.
  • D. When paying a search engine company to give prominence to certain products and services within specific search results.

Answer: C

Explanation:
Reference https://www.privacytrust.com/guidance/gdpr-vs-eprivacy-regulation.html


NEW QUESTION # 80
What term BEST describes the European model for data protection?

  • A. Market-based
  • B. Self-regulatory
  • C. Comprehensive
  • D. Sectoral

Answer: C

Explanation:
Reference https://ec.europa.eu/info/sites/info/files/communication-european-strategy-data-19feb2020_en.pdf


NEW QUESTION # 81
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?

  • A. Switzerland
  • B. Greece
  • C. Norway
  • D. Australia

Answer: A

Explanation:
Reference https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/ adequacy-decisions_en


NEW QUESTION # 82
If a company is planning to use closed-circuit television (CCTV) on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?

  • A. Ensure that safeguards are in place to prevent unauthorized access to the footage.
  • B. Create an information retention policy for those who operate the system.
  • C. Notify the appropriate data protection authority.
  • D. Perform a data protection impact assessment (DPIA).

Answer: B


NEW QUESTION # 83
......

Verified CIPP-E exam dumps Q&As with Correct 252 Questions and Answers: https://killexams.practicevce.com/IAPP/CIPP-E-practice-exam-dumps.html