
CIPP-E Exam PDF [2025] Tests Free Updated Today with Correct 310 Questions
IAPP CIPP-E Exam Preparation Guide and PDF Download
IAPP CIPP-E Certification Exam is an excellent opportunity for professionals who are interested in the privacy laws of Europe. Certified Information Privacy Professional/Europe (CIPP/E) certification program equips professionals with the necessary skills and knowledge to navigate the complex privacy landscape of Europe and is recognized globally as a leading certification program for privacy professionals. Whether you are a seasoned professional or new to the field, the CIPP-E certification exam is an excellent way to advance your career and demonstrate your expertise in the privacy field.
NEW QUESTION # 172
With the issue of consent, the GDPR allows member states some choice regarding what?
- A. The timeframe in which data subjects are allowed to withdraw their consent
- B. The circumstances in which silence or inactivity may constitute consent
- C. The age at which children must be required to obtain parental consent
- D. The mechanisms through which consent may be communicated
Answer: C
NEW QUESTION # 173
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?
- A. Getting consent from the data subject for a cross border data transfer.
- B. Encrypting data in transit and at rest using strong encryption algorithms.
- C. Conducting regular audits of the data protection program.
- D. Anonymizing special categories of data.
Answer: C
Explanation:
The accountability principle found in Article 5, Section 2 of the GDPR requires data controllers to take responsibility for complying with the GDPR and to be able to demonstrate their compliance1. This means that data controllers must implement appropriate technical and organisational measures to ensure and show that they process personal data in accordance with the GDPR2. One of the measures that can demonstrate compliance with the accountability principle is conducting regular audits of the data protection program. Audits are systematic and independent assessments of the data processing activities and the data protection policies and procedures of an organisation3. They can help to identify and address any gaps or risks in the data protection program, as well as to verify the effectiveness and efficiency of the data protection measures3. Audits can also provide evidence of compliance to the supervisory authorities and the data subjects, as well as to enhance the trust and reputation of the organisation3. Therefore, conducting regular audits of the data protection program is a way to demonstrate compliance with the accountability principle. Reference: 1: CIPP/E study guide, page 15; Art. 5 GDPR; Accountability principle | ICO2: CIPP/E study guide, page 16; Art. 24 GDPR; [Guide to accountability and governance | ICO]3: CIPP/E study guide, page 91; [Auditing | ICO]; [GDPR Audits: What You Need to Know - IT Governance Blog].
NEW QUESTION # 174
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed questionnaires, which could be used to tailor their preferences to specific travel destinations.
TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the questionnaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick.
Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
With regard to TripBliss Inc.'s use of website cookies, which of the following statements is correct?
- A. Because the use of cookies involves the potential for location tracking, explicit consent must be obtained from customers.
- B. Because not all of the cookies are strictly necessary to enable the use of a service requested from TripBliss Inc., consent requirements apply to their use of cookies.
- C. Because Techiva will receive only aggregate statistics of data collected from the cookies, no additional consent is necessary.
- D. Because of the categories of data involved, explicit consent for the use of cookies must be obtained separately from customers.
Answer: D
NEW QUESTION # 175
According to the GDPR, when should the processing of photographs be considered processing of special categories of personal data?
- A. When processed with the intent to uniquely identify or authenticate a natural person.
- B. When processed with the intent to comply with a law.
- C. When processed with the intent to publish information regarding a natural person on publicly accessible media.
- D. When processed with the intent to proceed to scientific or historical research projects.
Answer: A
Explanation:
Reference: https://www.privacy-regulation.eu/en/recital-51-GDPR.htm
According to the GDPR, the processing of photographs should not systematically be considered as processing of special categories of personal data, unless they are covered by the definition of biometric data1. Biometric data is defined as personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification or authentication of that natural person, such as facial images or dactyloscopic data2. Therefore, the processing of photographs is considered processing of special categories of personal data when it involves the use of specific technical means, such as facial recognition, that allow or confirm the unique identification or authentication of a natural person3. References: 1: Recital 51 of the GDPR2: Article 4(14) of the GDPR3:
GDPR, Photographs, and Special Categories of Personal Data.
NEW QUESTION # 176
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?
- A. The nature, sensitivity and volume of personal data.
- B. The special characteristics of the data controller.
- C. The ease of identification of individuals.
- D. The size of any data processor involved.
Answer: D
Explanation:
When assessing the level of risk created by a data breach, the size of any data processor involved would not have to be taken into consideration. According to the GDPR, a data breach is "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed" 1. The GDPR requires data controllers and processors to notify the relevant supervisory authority of a data breach within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons 2. The GDPR also requires data controllers to communicate the data breach to the affected data subjects without undue delay, if the breach is likely to result in a high risk to their rights and freedoms 3.
The GDPR does not specify the exact criteria for determining the level of risk, but it provides some guidance in Recital 85, which states that "the likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the processing" . The recital also mentions some factors that could increase the risk, such as the ease of identification of individuals, the special categories of personal data, the large scale of the processing, or the special characteristics of the data controller . Therefore, these factors should be taken into consideration when assessing the level of risk created by a data breach.
However, the size of any data processor involved is not relevant for the risk assessment, as it does not affect the impact of the breach on the data subjects. The data processor is only responsible for processing the personal data on behalf of the data controller, and has no direct relationship with the data subjects . The data processor's obligations in case of a data breach are to notify the data controller without undue delay, and to assist the data controller in complying with its obligations under the GDPR . The data processor's size may affect its ability to fulfill these obligations, but it does not change the level of risk created by the data breach itself. Reference: 1: Article 4(12) of the GDPR 2: Article 33 of the GDPR 3: Article 34 of the GDPR : Recital 85 of the GDPR : Article 4(8) of the GDPR : Article 28 of the GDPR I hope this helps. If you have any other questions, please feel free to ask.
NEW QUESTION # 177
SCENARIO
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
Based on the GDPR's position on the use of personal data for direct marketing purposes, which of the following is true about Louis's rights as a data subject?
- A. Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.
- B. Louis has the right to object to the use of his data, unless his data is required by Bedrock for the purpose of exercising a legal claim.
- C. Louis does not have the right to object to the use of his data if Bedrock can demonstrate compelling legitimate grounds for the processing.
- D. Louis does not have the right to object to the use of his data because he previously consented to it.
Answer: A
Explanation:
Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.
The GDPR states that "where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing" and that "where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes."3 This right applies regardless of whether the data subject has previously consented to the use of his or her data, or whether the data are required for a legal claim or a legitimate interest. The data subject must be informed of this right clearly and separately from any other information at the time of the first communication with him or her, and must be provided with an easy way to exercise it.2 Therefore, Louis can object to the use of his data by Bedrock and Accidentable for direct marketing purposes, and they must stop processing his data for such purposes as soon as they receive his objection. Louis can also withdraw his consent for any other processing of his data that he has previously agreed to, such as sharing his data with Bedrock's affiliates.4
NEW QUESTION # 178
The origin of privacy as a fundamental human right can be found in which document?
- A. European Convention of Human Rights 1953.
- B. OECD Guidelines on the Protection of Privacy 1980.
- C. Universal Declaration of Human Rights 1948.
- D. Charier of Fundamental Rights of the European Union 2000.
Answer: C
NEW QUESTION # 179
Which of the following would NOT be relevant when determining if a processing activity would be considered profiling?
- A. If the processing involves data that is considered personal data
- B. If the processing of the data is done through automated means
- C. If the processing is to be performed by a third-party vendor
- D. If the processing is used to predict the behavior of data subjects
Answer: C
Explanation:
The GDPR defines profiling as any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements12. Therefore, the relevant factors when determining if a processing activity would be considered profiling are:
whether the processing involves data that is considered personal data;
whether the processing of the data is done through automated means; and whether the processing is used to predict the behavior of data subjects.
The identity of the processor, whether it is the controller or a third-party vendor, is not relevant for the definition of profiling. However, it may have implications for the accountability and responsibility of the parties involved, as well as the data protection rights of the data subjects34. Reference: CIPP/E Certification - International Association of Privacy Professionals, Free CIPP/E Study Guide - International Association of Privacy Professionals, GDPR - EUR-Lex, What is automated individual decision-making and profiling? | ICO, WP29 releases guidelines on profiling under the GDPR, UK: A Guide To GDPR Profiling And Automated Decision-Making - Mondaq
NEW QUESTION # 180
A data controller appoints a data protection officer. Which of the following conditions would NOT result in an infringement of Articles 37 to 39 of the GDPR?
- A. If the data protection officer receives instructions from the data controller.
- B. If the data protection officer is provided by the data processor.
- C. If the data protection officer lacks ISO 27001 auditor certification.
- D. If the data protection officer also manages the marketing budget.
Answer: C
Explanation:
Reference: https://www.itgovernance.eu/fr-lu/data-protection-officer-dpo-under-the-gdpr-lu A data controller appointing a data protection officer who lacks ISO 27001 auditor certification would not result in an infringement of Articles 37 to 39 of the GDPR. According to Article 37 (5) of the GDPR, the data protection officer must bedesignated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39 1. However, the GDPR does not specify any formal qualifications or certifications that the data protection officer must have, and leaves it to the discretion of the controller or the processor to determine the level of expertise required, depending on the complexity and sensitivity of the data processing activities 2. Therefore, the lack of ISO
27001 auditor certification, which is a standard for information security management systems, does not necessarily mean that the data protection officer is not qualified or competent for the role.
The other options are incorrect because they would result in an infringement of Articles 37 to 39 of the GDPR. According to Article 37 (6) of the GDPR, the data protection officer may be a staff member of the controller or the processor, or fulfil the tasks on the basis of a service contract 1. However, the data protection officer must be independent and report directly to the highest management level of the controller or theprocessor 3. Therefore, if the data protection officer is provided by the data processor, there may be a conflict of interest or a lack of autonomy, which would violate Article 38 (3) and (6) of the GDPR 4.
According to Article 38 (6) of the GDPR, the data protection officer may fulfil other tasks and duties, provided that they do not result in a conflict of interests 4. However, managing the marketing budget would likely involve a conflict of interests, as the data protection officer would have to oversee and advise on the data processing activities related to marketing, which may not be compatible with his or her role as a data protection officer 5. Therefore, if the data protection officer also manages the marketing budget, this would infringe Article 38 (6) of the GDPR 4.
According to Article 38 (3) of the GDPR, the data protection officer must not receive any instructions regarding the exercise of his or her tasks 4. The data protection officer must act in an independent manner and perform the tasks assigned by the GDPR, such as informing and advising the controller or the processor and the employees, monitoring compliance, cooperating with the supervisory authority, and acting as the contact point for data subjects and the supervisory authority 6. Therefore, if the data protection officer receives instructions from the data controller, this would infringe Article 38 (3) of the GDPR 4. References: 1: Article
37 of the GDPR 2: Guidelines on Data Protection Officers ('DPOs') 3: Article 38 (2) of the GDPR 4: Article
38 of the GDPR 5: Data protection officer (DPO) | European Commission 6: Article 39 of the GDPR
NEW QUESTION # 181
When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in compliance with the European Union (EU) level?
- A. Every three (3) years.
- B. On an ongoing basis.
- C. Every year.
- D. After a personal data breach.
Answer: B
Explanation:
Reference:
According to the EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, exporters of personal data to third countries must monitor, on an ongoing basis, developments in those third countries that could affect the level of protection of the personal data they transfer1. This means that exporters must reevaluate whether the transfer tool they rely on, such as standard contractual clauses, binding corporate rules, codes of conduct, or certification mechanisms, is effectively providing a level of personal data protection that is in compliance with the EU level. The EDPB recommends that exporters document this reevaluation and any changes that result from it1. The EDPB does not specify a fixed time interval for this reevaluation, but rather states that it should be done on an ongoing basis, taking into account the specific circumstances of each transfer and any relevant developments in the third country.
1: EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, Version 2.0, adopted on 18 June 2021, paragraphs 85-86.
NEW QUESTION # 182
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data on the stick is unencrypted and in clear text. It is uncertain what has happened to the stick at this stage, but it likely was lost during the travel of an employee. What should the company do?
- A. Invoke the "disproportionate effort" exception under Article 33 to postpone notifying data subjects until more information can be gathered.
- B. Notify as soon as possible the data protection supervisory authority that a data breach may have taken place.
- C. Launch an investigation and if nothing is found within one month, notify the data protection supervisory authority.
- D. Immediately notify all the customers of the company that their information has been accessed by an unauthorized person.
Answer: B
NEW QUESTION # 183
A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?
- A. Obtain specific consent for the new processing
- B. Proceed no further, as such repurposing is unlawful
- C. Only inform the data subjects of the new purpose.
- D. Update the privacy notice upon which consent was given
Answer: A
Explanation:
According to the GDPR, consent is one of the lawful bases for processing personal data1. Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her2. Therefore, consent must be specific to each purpose of processing and cannot be bundled with other purposes3. If a company wants to use personal data for a new purpose that is not compatible with the original purpose for which consent was given, it must obtain a new consent from the data subjects for the new processing4. Simply informing the data subjects of the new purpose or updating the privacy notice is not sufficient, as it does not imply the data subject's agreement to the new processing. Proceeding with the new processing without obtaining a new consent would be unlawful and could result in fines and sanctions5. Reference:
Free CIPP/E Study Guide, page 23, section 4.1.1
GDPR, Article 4 (11)
GDPR, Recital 32
GDPR, Article 6 (4)
GDPR, Article 83 (5) (a)
NEW QUESTION # 184
SCENARIO
Please use the following to answer the next question:
Why was Jackie correct in not completing a transfer impact assessment for HRYourWay?
- A. ProStorage will obtain consent for all transfers.
- B. ProStorage can rely on its Binding Corporate Rules
- C. HRYourWay was ultimately not selected
- D. HRYourWay is not located in a third country.
Answer: D
Explanation:
According to the GDPR, a transfer of personal data to a third country or an international organisation may take place only if the conditions laid down in Chapter V of the GDPR are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation1. A third country is any country outside of the European Union (EU) and the European Economic Area (EEA)2. Therefore, a transfer impact assessment is only required when personal data is transferred to a third country or an international organisation that does not provide an adequate level of data protection, as recognised by the European Commission3. HRYourWay is a German based company, and Germany is a member state of the EU and the EEA. Thus, HRYourWay is not located in a third country, and no transfer impact assessment is needed for transferring personal data to it. The other options are incorrect, as they are not relevant to the question of whether a transfer impact assessment is required or not. Reference:
GDPR, Chapter V
GDPR, Article 4 (24)
GDPR, Article 45
NEW QUESTION # 185
According to the GDPR, when should the processing of photographs be considered processing of special categories of personal data?
- A. When processed with the intent to uniquely identify or authenticate a natural person.
- B. When processed with the intent to comply with a law.
- C. When processed with the intent to publish information regarding a natural person on publicly accessible media.
- D. When processed with the intent to proceed to scientific or historical research projects.
Answer: A
NEW QUESTION # 186
If a company is planning to use closed-circuit television (CCTV) on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?
- A. Perform a data protection impact assessment (DPIA).
- B. Ensure that safeguards are in place to prevent unauthorized access to the footage.
- C. Notify the appropriate data protection authority.
- D. Create an information retention policy for those who operate the system.
Answer: C
Explanation:
Under the GDPR, using CCTV on business premises involves the processing of personal data, which requires compliance with the data protection principles and obligations. However, notifying the appropriate data protection authority (DPA) is not one of the steps that a company should take before using CCTV, unless the DPA has specifically requested it or the CCTV involves high-risk processing that requires prior consultation. The other steps are necessary to ensure GDPR compliance, as explained below:
Performing a data protection impact assessment (DPIA) is a mandatory requirement for any type of processing that is likely to result in a high risk to the rights and freedoms of individuals, such as large-scale or systematic monitoring of public areas. A DPIA is a process that helps identify and mitigate the potential privacy risks of using CCTV, and document the measures taken to address them. A DPIA should include a description of the processing, its purpose and necessity, its risks and benefits, the safeguards and security measures, and the consultation with stakeholders. A DPIA should be carried out before the CCTV system is installed or upgraded, and reviewed regularly or whenever there is a significant change in the processing.
Creating an information retention policy for those who operate the system is a good practice to ensure that the personal data collected by CCTV is not kept longer than necessary for the purpose for which it was collected, and that it is securely deleted or anonymised when no longer needed. The retention period should be determined by the specific purpose and context of using CCTV, and take into account any legal or contractual obligations, as well as the expectations and rights of the data subjects. The retention policy should also specify who is responsible for managing and deleting the CCTV footage, and how the deletion process is verified and documented.
Ensuring that safeguards are in place to prevent unauthorized access to the footage is an essential requirement to comply with the GDPR principle of integrity and confidentiality, which states that personal data must be processed in a manner that ensures appropriate security of the data, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage. The safeguards may include technical and organisational measures, such as encryption, access control, logging, audit, training, policies and procedures, that aim to protect the CCTV footage from unauthorized or unlawful access, disclosure, alteration, or destruction, both during transmission and storage. Reference: GDPR Article 35, GDPR Article 36, GDPR Article 5, CCTV and video surveillance | ICO, 5 Step Guide to Check if Your CCTV is GDPR Compliant
NEW QUESTION # 187
Which of the following is NOT an explicit right granted to data subjects under the GDPR?
- A. The right to request restriction of processing of personal data, under certain scenarios.
- B. The right to opt-out of the sale of their personal data to third parties.
- C. The right to request access to the personal data a controller holds about them.
- D. The right to request the deletion of data a controller holds about them.
Answer: C
NEW QUESTION # 188
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?
- A. A state law requires facial recognition to verify attendance.
- B. The school gets explicit consent from the students.
- C. The school places a notice near each camera.
- D. Processing is necessary for the legitimate interests pursed by the school.
Answer: B
NEW QUESTION # 189
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?
- A. Switzerland
- B. Australia
- C. Norway
- D. Greece
Answer: A
Explanation:
Explanation/Reference: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/ adequacy-decisions_en
NEW QUESTION # 190
As per the GDPR, which legal basis would be the most appropriate for an online shop that wishes to process personal data for the purpose of fraud prevention?
- A. Performance of a contact
- B. Consent
- C. Legitimate interest
- D. Protection of the interests of the data subjects.
Answer: C
Explanation:
According to the GDPR, legitimate interest is one of the possible legal bases for processing personal data, which means that the data controller has a valid reason to process the data that is not overridden by the interests or rights of the data subject1. The GDPR specifically mentions fraud prevention as a potential legitimate interest of the data controller, as it serves both the interests of the online shop and the data subjects who may be victims of fraud1. However, the data controller must conduct a balancing test to ensure that the legitimate interest is not outweighed by the potential harm or intrusion to the data subject's privacy1. The data controller must also provide clear and transparent information to the data subject about the processing of their data for fraud prevention purposes, and respect their right to object to such processing1.
The other options are incorrect because:
A) Protection of the interests of the data subjects is not a legal basis for processing personal data, but rather a condition for processing special categories of personal data under Article 9 of the GDPR2. Moreover, fraud prevention does not necessarily protect the interests of the data subjects, but rather the interests of the online shop and the general public.
B) Performance of a contract is a legal basis for processing personal data that is necessary for the execution or fulfilment of a contract between the data controller and the data subject2. However, fraud prevention is not strictly necessary for the performance of a contract, as it is not directly related to the delivery of goods or services that the data subject has purchased from the online shop.
D) Consent is a legal basis for processing personal data that requires the data subject to give their informed, specific, and freely given agreement to the processing of their data for one or more purposes2. However, consent is not the most appropriate legal basis for fraud prevention, as it may not be freely given by the data subject, who may feel pressured to agree to the processing of their data in order to complete their purchase. Moreover, consent may not be reliable or effective for fraud prevention, as it can be withdrawn by the data subject at any time, or may be given by a fraudster who is not the legitimate owner of the data.
NEW QUESTION # 191
Read the following steps:
* Discover which employees are accessing cloud services and from which devices and apps
* Lock down the data in those apps and devices
* Monitor and analyze the apps and devices for compliance
* Manage application life cycles
* Monitor data sharing
An organization should perform these steps to do which of the following?
- A. Pursue a GDPR-compliant Privacy by Design process.
- B. Maintain a secure Bring Your Own Device (BYOD) program.
- C. Institute a GDPR-compliant employee monitoring process.
- D. Ensure cloud vendors are complying with internal data use policies.
Answer: B
Explanation:
Explanation/Reference: https://www.itproportal.com/features/heading-off-the-spectre-of-gdpr-compliance-with-secure-byod/
NEW QUESTION # 192
A news website based m (he United Slates reports primarily on North American events The website is accessible to any user regardless of location, as the website operator does not block connections from outside of the U.S. The website offers a pad subscription that requires the creation of a user account; this subscription can only be paid in U.S. dollars.
Which of the following explains why the website operator, who is the responsible for all processing related to account creation and subscriptions, is NOT required to comply with the GDPR?
- A. The website is not available in several official languages of European Un on Member States
- B. The controller does not have an establishment in the European Union.
- C. Payments cannot be made in a European Union currency.
- D. The website cannot block connections from outside the U.S. that use a Virtual Private Network (VPN) to simulate a US location.
Answer: C
Explanation:
The GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not1.
This means that the GDPR applies to any controller or processor that has a branch, office, subsidiary, or other stable arrangement in the EU, even if the data processing occurs outside the EU. However, the GDPR also applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union1. This means that the GDPR applies to any controller or processor that targets or tracks EU data subjects, even if they do not have a presence in the EU. In this case, the website operator is not required to comply with the GDPR because it does not have an establishment in the EU (option B), and it does not offer goods or services or monitor the behaviour of EU data subjects. The website operator reports primarily on North American events, does not block connections from outside the U.S., and only accepts payments in U.S. dollars, which indicate that it does not intend to target or track EU data subjects. Therefore, option B is the correct answer.
References: Art. 3 GDPR - Territorial scope, Guidelines 3/2018 on the territorial scope of the GDPR (Article
3), [What does territorial scope mean under the GDPR?]
NEW QUESTION # 193
A controller in the EU is planning to transfer personal data, via a processor, to a third country. What is the recommended first step according to the EDPB Opinion 22/2024?
- A. Review the legal basis for the transfer to the processor.
- B. Conduct a Transfer Impact Assessment regarding the processor.
- C. Identify appropriate safeguards with the processor.
- D. Ensure transfer mapping is carried out by the processor.
Answer: D
Explanation:
According to theEDPB Recommendations 01/2020 (as updated and later built into Opinion 22/2024), the first step for any international transfer is to "know your transfers."This meansmapping all transfersof personal data to third countries, including those made through processors or sub-processors.
The logic is:
* Step 1 - Map transfers:Identify and document whether personal data leaves the EEA, and through which entities (controllers, processors, or sub-processors).
* Step 2 - Verify transfer tool:Check if the transfer relies on adequacy, SCCs, BCRs, or derogations.
* Step 3 - Assess third country law (TIA):Conduct a Transfer Impact Assessment onlyafterthe transfer mapping.
* Step 4 - Supplementary measures:Adopt technical, contractual, or organisational safeguards if needed.
Therefore, the recommendedfirst stepin line with EDPB guidance istransfer mapping(Option C).
#Reference:EDPB Recommendations 01/2020 on supplementary transfer measures, Step 1 "Know your transfers"; CIPP/E Textbook (3rd ed.), Chapter 12 "International Data Transfers".
NEW QUESTION # 194
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?
- A. Only where the personal data is to be subjected to specific computerized processing, such as image scanning or optical character recognition.
- B. Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.
- C. Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.
- D. Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.
Answer: B
Explanation:
Explanation/Reference: https://www.zimmerslaw.com/english-1/data-protection/
NEW QUESTION # 195
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?
- A. A state law requires facial recognition to verify attendance.
- B. Processing is necessary for the legitimate interests pursed by the school.
- C. The school gets explicit consent from the students.
- D. The school places a notice near each camera.
Answer: D
NEW QUESTION # 196
......
Verified & Correct CIPP-E Practice Test Reliable Source Dec 09, 2025 Updated: https://pass4sure.validdumps.top/CIPP-E-exam-torrent.html