View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps
Question 1: Under the EU General Data Protection Regulation (GDPR), which concept requires personal data to be processed fairly and lawfully in relation to the data subject?
- Data minimization
- Fairness and lawfulness of processing
- Storage limitation
- Purpose limitation
Correct Answer: 2. Fairness and lawfulness of processing
Explanation:
The GDPR requires personal data to be processed lawfully, fairly, and transparently in relation to the data subject. These principles form part of the core data protection requirements in Article 5. Data minimization requires that data be adequate, relevant, and limited to what is necessary. Purpose limitation requires collection for specified, explicit, and legitimate purposes, while storage limitation concerns retaining data only for as long as necessary. The fairness and lawfulness requirement therefore directly addresses whether processing is conducted on a legally valid and fair basis from the perspective of the data subject.
Question 2: Which EU institution is primarily responsible for proposing new EU legislation and policies, including legislative proposals concerning data protection?
- European Commission
- European Court of Justice
- European Data Protection Board
- Council of Europe
Correct Answer: 1. European Commission
Explanation:
The European Commission has the right of legislative initiative within the EU and is responsible for proposing new EU legislation and policies. The European Parliament and Council of the European Union then participate in adopting legislation under the applicable legislative procedure. The European Data Protection Board has an important role in ensuring consistent application of EU data protection law but is not the EU institution responsible for proposing legislation. The Court of Justice of the European Union interprets and applies EU law through judicial decisions. The Council of Europe is a separate international organization from the European Union.
Question 3: Which of the following is considered personal data under the GDPR?
- Anonymized information that can no longer be linked to an individual
- A company’s registered office address
- An individual’s online identifier that can be linked to that person
- A completely fictional identity created for testing purposes
Correct Answer: 3. An individual’s online identifier that can be linked to that person
Explanation:
Personal data under the GDPR includes information relating to an identified or identifiable natural person. An online identifier can constitute personal data when it can be associated, directly or indirectly, with an individual. Properly anonymized information is no longer personal data because the individual can no longer be identified using reasonably available means. A company’s registered office address generally concerns a legal entity rather than a natural person. A fictional test identity that has no relationship to a real individual would generally not constitute personal data.
Question 4: Which GDPR principle requires personal data to be collected for specified, explicit and legitimate purposes?
- Accuracy
- Storage limitation
- Data minimization
- Purpose limitation
Correct Answer: 4. Purpose limitation
Explanation:
The purpose limitation principle requires personal data to be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes, subject to applicable legal provisions. This principle helps ensure that organizations do not collect information for vague or undefined purposes and later use it for unrelated activities without an appropriate legal basis. Data minimization addresses the amount of data collected, accuracy concerns correctness and currency, and storage limitation concerns how long data is retained.
Question 5: Under the GDPR, which entity generally determines the purposes and means of processing personal data?
- Data controller
- Data subject
- Data protection officer
- Data processor
Correct Answer: 1. Data controller
Explanation:
The GDPR defines a controller as the entity that determines the purposes and means of processing personal data. A processor processes personal data on behalf of the controller and generally follows the controller’s documented instructions. A data protection officer has specific advisory and monitoring responsibilities but does not normally determine the purposes and means of processing. The data subject is the individual to whom the personal data relates. Correctly identifying the controller is important because the controller carries primary responsibility for ensuring that processing complies with applicable GDPR requirements.
Question 6: Which legal basis under Article 6 of the GDPR applies when processing is necessary to perform a contract with the data subject?
- Consent
- Legitimate interests
- Contract
- Public task
Correct Answer: 3. Contract
Explanation:
Article 6(1)(b) provides a lawful basis where processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject before entering into a contract. This basis should not be used simply because processing is convenient for an organization; the processing must have the necessary connection to the contractual relationship. Other Article 6 bases include consent, legal obligation, vital interests, public task, and legitimate interests. Organizations must select the basis that genuinely applies to the specific processing activity.
Question 7: Which GDPR principle requires organizations to keep personal data accurate and, where necessary, up to date?
- Accuracy
- Accountability
- Purpose limitation
- Confidentiality
Correct Answer: 1. Accuracy
Explanation:
The accuracy principle requires personal data to be accurate and, where necessary, kept up to date. Organizations should take reasonable steps to correct or erase personal data that is inaccurate in relation to the purposes for which it is processed. This principle is particularly important when inaccurate information could affect individuals, such as information used for eligibility decisions, employment records, customer accounts, or regulatory reporting. Accountability requires organizations to demonstrate compliance, while purpose limitation concerns why data is collected and used. Accuracy focuses specifically on the quality and correctness of personal data.
Question 8: What is the primary purpose of the GDPR’s transparency requirement?
- To eliminate all automated processing
- To ensure individuals receive clear information about how their personal data is processed
- To require organizations to publish all personal data they hold
- To prevent organizations from transferring data outside the EU
Correct Answer: 2. To ensure individuals receive clear information about how their personal data is processed
Explanation:
Transparency requires organizations to provide data subjects with information about the processing of their personal data in a concise, intelligible, and easily accessible form using clear and plain language. Privacy information may include the identity of the controller, purposes and legal bases, recipients, retention periods, rights, and other information required by the GDPR. Transparency does not require organizations to publish personal data. It also does not prohibit all international transfers or eliminate automated processing. Its central purpose is to enable individuals to understand how their personal data is being handled.
Question 9: Which right allows a data subject to request confirmation as to whether personal data concerning them is being processed and, where applicable, obtain access to that data?
- Right to object
- Right to restriction
- Right to data portability
- Right of access
Correct Answer: 4. Right of access
Explanation:
The GDPR’s right of access allows a data subject to obtain confirmation as to whether personal data concerning them is being processed and, where applicable, access to that personal data and specified information about the processing. The information may include purposes, categories of personal data, recipients, retention information, and other details described in Article 15. The right to object concerns certain processing activities, restriction limits how data may be processed, and portability concerns receiving certain personal data in a structured, commonly used, machine-readable format and transmitting it to another controller in applicable circumstances.
Question 10: Which GDPR right allows an individual, in certain circumstances, to require a controller to delete personal data concerning them?
- Right to rectification
- Right to erasure
- Right to access
- Right to portability
Correct Answer: 2. Right to erasure
Explanation:
The right to erasure, commonly known as the “right to be forgotten,” allows individuals to request deletion of personal data in specified circumstances. These include situations where the data is no longer necessary for the purposes for which it was collected or where processing is unlawfully conducted, subject to applicable exceptions. The right is not absolute. Controllers may be required or permitted to retain information for reasons such as compliance with legal obligations or the establishment, exercise, or defense of legal claims. Rectification instead concerns correcting inaccurate or incomplete personal data.
Question 11: Under the GDPR, what is a data processor?
- A natural person whose data is being processed
- An independent supervisory authority
- A person or organization that processes personal data on behalf of a controller
- An organization that determines the purposes of processing
Correct Answer: 3. A person or organization that processes personal data on behalf of a controller
Explanation:
A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. The processor acts under the controller’s instructions and is subject to specific obligations under the GDPR. A controller determines the purposes and means of processing, while a supervisory authority independently oversees compliance within its jurisdiction. The data subject is the individual to whom the personal data relates. Understanding the distinction between controllers and processors is fundamental because their respective responsibilities and contractual obligations differ under the GDPR.
Question 12: Which GDPR principle requires organizations to limit personal data collection to what is adequate, relevant and necessary for the stated purposes?
- Data minimization
- Accuracy
- Storage limitation
- Accountability
Correct Answer: 1. Data minimization
Explanation:
The data minimization principle requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Organizations should therefore assess whether each category of data collected is genuinely needed rather than collecting excessive information simply because it may be useful in the future. Accuracy focuses on correctness, storage limitation concerns retention periods, and accountability concerns demonstrating compliance. Data minimization supports privacy by reducing unnecessary collection and limiting the amount of personal information that could be exposed or misused.
Question 13: Which statement best describes the GDPR concept of accountability?
- Organizations only need to comply when a supervisory authority investigates them
- Organizations must be able to demonstrate compliance with data protection principles
- Only processors are responsible for documenting compliance
- Individuals are responsible for proving that an organization violated the GDPR
Correct Answer: 2. Organizations must be able to demonstrate compliance with data protection principles
Explanation:
The accountability principle requires the controller to be responsible for, and be able to demonstrate, compliance with the GDPR principles. Demonstrating compliance can involve appropriate policies, records, risk assessments, contracts, technical and organizational measures, training, procedures, and other evidence depending on the processing activity. Compliance is not limited to situations where a regulator begins an investigation. Processors also have direct obligations under the GDPR, but accountability is a broader responsibility of controllers. Organizations should therefore be able to show how their processing activities comply with applicable data protection requirements.
Question 14: Under the GDPR, which organization is generally responsible for monitoring compliance with the regulation within its respective Member State?
- The European Parliament
- The European Commission
- The relevant national supervisory authority
- The data subject’s employer
Correct Answer: 3. The relevant national supervisory authority
Explanation:
Each EU Member State has one or more independent supervisory authorities responsible for monitoring and enforcing the application of the GDPR within its jurisdiction. Supervisory authorities have powers that can include investigations, corrective measures, and administrative fines as provided by the regulation. The European Data Protection Board promotes consistent application of the GDPR across the EU but does not replace national supervisory authorities. The European Parliament and Commission have important EU institutional roles but are not the ordinary national enforcement authorities for individual organizations’ processing activities.
Question 15: Which of the following is an example of processing personal data?
- Collecting customer email addresses for an account registration process
- Looking at a blank template with no personal information
- Reading a fictional character’s name in a novel
- Designing an empty database table without entering personal data
Correct Answer: 1. Collecting customer email addresses for an account registration process
Explanation:
The GDPR defines processing broadly and includes operations such as collection, recording, organization, storage, alteration, retrieval, consultation, use, disclosure, transmission, restriction, erasure, and destruction of personal data. Collecting customer email addresses is therefore clearly a processing activity. Activities involving no personal data generally do not constitute processing of personal data. The broad definition is important because GDPR obligations can apply across many stages of the data lifecycle rather than only when an organization actively uses personal information.
Question 16: What is the main function of the European Data Protection Board (EDPB)?
- To issue employment contracts for privacy professionals
- To approve every organization’s privacy policy
- To replace all national supervisory authorities
- To contribute to consistent application of EU data protection rules and promote cooperation among supervisory authorities
Correct Answer: 4. To contribute to consistent application of EU data protection rules and promote cooperation among supervisory authorities
Explanation:
The European Data Protection Board promotes consistent application of the GDPR across the European Economic Area and supports cooperation among supervisory authorities. It can issue guidelines, recommendations, and other relevant materials and can play a role in resolving certain disputes between supervisory authorities under the GDPR’s consistency mechanisms. It does not replace national supervisory authorities or approve every organization’s privacy policy. Its role is primarily to promote consistent interpretation and enforcement of EU data protection law and facilitate cooperation among the authorities responsible for supervising compliance.
Question 17: Which GDPR principle concerns retaining personal data only for as long as necessary for the purposes for which it is processed, subject to applicable exceptions?
- Purpose limitation
- Storage limitation
- Data minimization
- Accuracy
Correct Answer: 2. Storage limitation
Explanation:
The storage limitation principle requires personal data to be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed, subject to applicable exceptions. Organizations should therefore consider retention periods and establish appropriate deletion, anonymization, or review processes where appropriate. Data minimization limits the amount of data collected, purpose limitation governs the purposes for processing, and accuracy concerns correctness. Storage limitation specifically addresses how long identifiable personal data should be retained.
Question 18: Which statement best describes consent as a legal basis for processing under the GDPR?
- Consent must always be obtained for every processing activity
- Consent is valid even when the individual has no genuine choice
- Consent must meet GDPR requirements, including being freely given, specific, informed and unambiguous
- Consent can never be withdrawn once given
Correct Answer: 3. Consent must meet GDPR requirements, including being freely given, specific, informed and unambiguous
Explanation:
GDPR consent is subject to specific conditions. It must be freely given, specific, informed, and unambiguous, and the individual must be able to withdraw consent under the applicable rules. Consent is not required for every processing activity because other legal bases may apply. Where an individual has no genuine choice or faces inappropriate consequences for refusing consent, the validity of consent may be affected. Organizations relying on consent should therefore ensure that the consent mechanism meets the GDPR requirements and that evidence of consent can be maintained where necessary.
Question 19: What does the GDPR’s principle of privacy by design generally require organizations to do?
- Consider data protection requirements and safeguards when designing processing activities and systems
- Add privacy controls only after a security incident occurs
- Prohibit all processing of sensitive personal data
- Require every system to use the same technical architecture
Correct Answer: 1. Consider data protection requirements and safeguards when designing processing activities and systems
Explanation:
Data protection by design requires controllers to implement appropriate technical and organizational measures designed to implement data protection principles and safeguard individual rights from the outset of processing design. Privacy considerations should therefore be incorporated into systems, processes, policies, and workflows rather than added only after implementation or an incident. The exact measures depend on factors such as the state of technology, cost, nature, scope, context, and purposes of processing, as well as risks to individuals. The principle does not require every organization to use identical technology or prohibit all sensitive-data processing.
Question 20: Under the GDPR, which principle requires organizations to implement appropriate technical and organizational measures to protect personal data against risks such as unauthorized processing or accidental loss?
- Purpose limitation
- Integrity and confidentiality
- Data portability
- Accuracy
Correct Answer: 2. Integrity and confidentiality
Explanation:
The integrity and confidentiality principle requires personal data to be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Appropriate technical and organizational measures should be selected based on the circumstances and risks involved. Examples may include access controls, encryption, resilience measures, security procedures, and incident management processes. Purpose limitation concerns the purposes for processing, data portability concerns a specific individual right, and accuracy concerns the quality of personal data. Security therefore falls primarily under the integrity and confidentiality principle.