IAPP CIPP-E Practice Test Questions and Exam Dumps Part 2 Q21-40

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 21: Under the GDPR, which requirement applies when an organization relies on legitimate interests as its lawful basis for processing personal data?

  1. The processing must always be approved by a supervisory authority.
  2. The organization must obtain explicit consent from every data subject.
  3. The organization must balance its legitimate interests against the interests and fundamental rights and freedoms of the data subject.
  4. The organization may process any category of personal data without restrictions.

Correct Answer: 3. The organization must balance its legitimate interests against the interests and fundamental rights and freedoms of the data subject.

Explanation: Legitimate interests under Article 6(1)(f) can provide a lawful basis for processing when the controller or a third party has a legitimate interest that is not overridden by the interests or fundamental rights and freedoms of the data subject. Organizations should identify the legitimate interest, assess whether processing is necessary for that interest, and perform a balancing assessment. Certain situations, such as processing by public authorities in the performance of their tasks, are subject to specific limitations. The assessment should also consider reasonable expectations and appropriate safeguards.

Question 22: Which GDPR provision establishes the territorial scope for organizations established outside the European Union that offer goods or services to individuals in the EU?

  1. Article 3
  2. Article 12
  3. Article 25
  4. Article 44

Correct Answer: 1. Article 3

Explanation: Article 3 of the GDPR establishes its territorial scope. The GDPR can apply to organizations outside the EU when their processing activities relate to offering goods or services to individuals in the Union or monitoring their behavior when that behavior takes place within the Union. The provision is important because an organization does not necessarily need an establishment in the EU for the GDPR to apply. Organizations assessing applicability should therefore consider the nature of their processing activities, their targeting of individuals in the Union, and whether the relevant territorial-scope conditions are satisfied.

Question 23: Which of the following is considered a special category of personal data under the GDPR?

  1. A customer’s postal address
  2. An employee’s favorite color
  3. A company’s registration number
  4. An individual’s biometric data used for the purpose of uniquely identifying that person

Correct Answer: 4. An individual’s biometric data used for the purpose of uniquely identifying that person

Explanation: Article 9 identifies special categories of personal data that receive additional protection. These include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for uniquely identifying a person, health data, and certain information concerning sex life or sexual orientation. Processing such data is generally prohibited unless a specific Article 9 exception applies. Not every piece of information about a person is special category data, and the context and purpose of processing can be important when determining whether the enhanced Article 9 rules apply.

Question 24: What is the primary purpose of a Data Protection Impact Assessment (DPIA) under the GDPR?

  1. To identify and assess risks to individuals arising from certain processing activities and determine measures to address those risks
  2. To replace the organization’s records of processing activities
  3. To obtain automatic approval from the supervisory authority before all processing begins
  4. To determine the financial value of personal data

Correct Answer: 1. To identify and assess risks to individuals arising from certain processing activities and determine measures to address those risks

Explanation: A DPIA is required when processing is likely to result in a high risk to the rights and freedoms of natural persons, particularly when new technologies or certain types of large-scale or systematic processing are involved. The assessment describes the processing, evaluates necessity and proportionality, assesses risks to individuals, and identifies measures to address those risks. A DPIA is therefore a risk-management and accountability tool rather than a general approval mechanism. If high residual risk remains and cannot be sufficiently mitigated, the controller may need to consult the competent supervisory authority before proceeding.

Question 25: Under the GDPR, what is generally required when a controller engages a processor to process personal data on its behalf?

  1. A written or otherwise legally binding contract or legal act containing specified requirements
  2. Approval from every individual whose data will be processed
  3. Transfer of all controller responsibilities to the processor
  4. A requirement that the processor become a joint controller

Correct Answer: 1. A written or otherwise legally binding contract or legal act containing specified requirements

Explanation: Article 28 requires processing by a processor to be governed by a contract or other legal act that binds the processor to the controller. The arrangement must address matters such as processing only on documented instructions, confidentiality, security measures, assistance with data-subject rights, support for compliance obligations, deletion or return of personal data, and audit-related requirements. The contract does not transfer the controller’s overall GDPR responsibilities to the processor. The processor also has direct obligations under the GDPR, including requirements concerning security, sub-processors, and processing instructions.

Question 26: Which GDPR right allows an individual, in certain circumstances, to obtain a copy of their personal data and information about how it is being processed?

  1. Right to restriction of processing
  2. Right to data portability
  3. Right of access
  4. Right to object

Correct Answer: 3. Right of access

Explanation: Article 15 provides the right of access. A data subject can request confirmation as to whether personal data concerning them is being processed and, where applicable, access to that data along with specified information about the processing. This can include purposes of processing, categories of personal data, recipients, retention information, and information about the individual’s rights. The right is subject to certain limitations and exceptions, so access is not necessarily unlimited in every circumstance. The right of access should be distinguished from data portability, which has different conditions and concerns receiving certain data in a structured, commonly used, machine-readable format.

Question 27: Which GDPR principle requires a controller to demonstrate that its processing activities comply with the Regulation?

  1. Accountability
  2. Purpose limitation
  3. Storage limitation
  4. Data minimization

Correct Answer: 1. Accountability

Explanation: The accountability principle requires controllers to be responsible for compliance with the GDPR and to be able to demonstrate that compliance. This goes beyond simply following individual rules. Organizations may use measures such as policies, records of processing activities, privacy impact assessments, contracts, security controls, training, audits, and documented decision-making to demonstrate compliance. Accountability also supports a risk-based approach in which organizations implement measures appropriate to their processing activities. The principle therefore connects substantive data protection requirements with evidence that an organization has actively implemented and maintained appropriate compliance measures.

Question 28: What is the general GDPR deadline for responding to a valid data-subject request under Articles 15 to 22?

  1. 7 calendar days
  2. 30 calendar days with no possibility of extension
  3. 60 calendar days in every circumstance
  4. One month, subject to certain conditions allowing an extension of up to two further months

Correct Answer: 4. One month, subject to certain conditions allowing an extension of up to two further months

Explanation: Under Article 12, controllers generally must respond to requests under Articles 15 to 22 without undue delay and in any event within one month of receiving the request. The period can be extended by up to two further months when necessary, taking into account the complexity and number of requests. The controller must inform the data subject of the extension and the reasons for the delay within the initial one-month period. If the controller does not act on the request, it must generally explain the reasons and inform the individual about the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Question 29: Which organization is responsible for enforcing the GDPR within its national jurisdiction, subject to the Regulation’s rules on supervisory authorities and cross-border processing?

  1. The European Commission exclusively
  2. The competent national supervisory authority
  3. The European Parliament exclusively
  4. The European Council exclusively

Correct Answer: 2. The competent national supervisory authority

Explanation: Each EU Member State has one or more independent supervisory authorities responsible for monitoring and enforcing GDPR compliance within its jurisdiction. Their powers include investigating complaints, conducting investigations, obtaining information, and imposing corrective measures and administrative fines where appropriate. Cross-border processing can involve the GDPR’s cooperation and consistency mechanisms, including the lead supervisory authority concept. The European Data Protection Board supports consistency and cooperation among supervisory authorities but does not replace national supervisory authorities as the ordinary enforcement bodies for individual jurisdictions.

Question 30: Which statement best describes the GDPR’s principle of purpose limitation?

  1. Personal data must always be stored permanently.
  2. Personal data may only be collected with the individual’s written consent.
  3. Personal data should be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
  4. Personal data can be used for any purpose once it has been lawfully collected.

Correct Answer: 3. Personal data should be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.

Explanation: Purpose limitation requires organizations to define the purposes for which personal data is collected and to avoid incompatible secondary uses. A controller should be able to explain why the data is being collected and how subsequent processing relates to the original purpose. Further processing for another purpose is not automatically prohibited in every circumstance; the GDPR provides rules for assessing compatibility and identifies situations in which further processing may be permitted. Organizations should therefore evaluate purpose compatibility rather than assuming that lawful initial collection permits unrestricted future use.

Question 31: Which of the following is an example of pseudonymisation rather than anonymisation?

  1. Replacing a person’s name with a code while retaining a separate key that can reconnect the code to the individual
  2. Permanently deleting all information that could reasonably identify an individual
  3. Publishing statistics that cannot be linked back to identifiable individuals
  4. Destroying all identifiers and the information needed to reconstruct them

Correct Answer: 1. Replacing a person’s name with a code while retaining a separate key that can reconnect the code to the individual

Explanation: Pseudonymisation involves processing personal data so that it can no longer be attributed to a specific individual without the use of additional information, which is kept separately and protected by appropriate technical and organizational measures. Because the data can potentially be re-linked to an individual, pseudonymised information remains personal data under the GDPR. Anonymisation is different because properly anonymised information is no longer identifiable and therefore falls outside the GDPR’s definition of personal data. Pseudonymisation is specifically recognized as a security and privacy-enhancing technique under the Regulation.

Question 32: Which right allows a data subject to receive certain personal data in a structured, commonly used and machine-readable format and transmit it to another controller in qualifying circumstances?

  1. Right to erasure
  2. Right to data portability
  3. Right to object
  4. Right to restriction of processing

Correct Answer: 2. Right to data portability

Explanation: Article 20 establishes the right to data portability. It applies to personal data concerning the data subject that the individual has provided to a controller and is processed by automated means on the basis of consent or a contract. Where the conditions are met, the individual can receive the data in a structured, commonly used and machine-readable format and may have the right to transmit it directly to another controller where technically feasible. The right is distinct from the broader right of access and is intended to support individual control and movement of qualifying personal data between service providers.

Question 33: What does the GDPR generally require regarding the appointment of a Data Protection Officer (DPO)?

  1. Every organization processing any personal data must appoint a DPO.
  2. Only public authorities are ever required to appoint a DPO.
  3. A DPO is required in specified circumstances, including certain large-scale regular and systematic monitoring or large-scale processing of special categories of data.
  4. A DPO is required only when a data breach has occurred.

Correct Answer: 3. A DPO is required in specified circumstances, including certain large-scale regular and systematic monitoring or large-scale processing of special categories of data.

Explanation: Article 37 requires controllers and processors to designate a DPO in specified circumstances. These include situations where the core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of personal data or certain criminal-conviction and offence data. Public authorities and bodies generally also have DPO requirements, subject to the Regulation’s terms. Organizations should assess their actual processing activities against the Article 37 criteria rather than assuming that organizational size alone determines whether a DPO is mandatory.

Question 34: Which of the following is a core responsibility of a GDPR Data Protection Officer?

  1. Making all final commercial decisions involving personal data
  2. Serving as the organization’s external auditor
  3. Replacing the supervisory authority in enforcement matters
  4. Informing and advising the controller or processor and monitoring compliance with GDPR obligations

Correct Answer: 4. Informing and advising the controller or processor and monitoring compliance with GDPR obligations

Explanation: Article 39 describes several DPO tasks, including informing and advising the controller or processor and employees who carry out processing, monitoring compliance with the GDPR and relevant policies, providing advice concerning DPIAs, and cooperating with the supervisory authority. The DPO may also act as a contact point for the supervisory authority and for data subjects on processing-related matters. The DPO does not replace management or assume the controller’s ultimate responsibility for compliance. Organizations must also ensure that the DPO can perform the role with appropriate independence and without improper conflicts of interest.

Question 35: When can a controller generally rely on consent as a GDPR legal basis?

  1. When consent is freely given, specific, informed and unambiguous through a clear affirmative action
  2. Whenever a privacy notice is displayed, regardless of the individual’s action
  3. Whenever processing is commercially useful to the controller
  4. Only when consent is provided through a handwritten document

Correct Answer: 1. When consent is freely given, specific, informed and unambiguous through a clear affirmative action

Explanation: GDPR consent must satisfy defined conditions. It should be freely given, specific, informed and unambiguous, and it must involve a clear affirmative action. Silence, pre-ticked boxes, or inactivity generally do not constitute valid consent. Individuals must also be able to withdraw consent, and withdrawal should generally be as easy as giving it. Where there is a significant imbalance between the parties, such as certain employment contexts, consent may not always be considered freely given. Controllers relying on consent must also be able to demonstrate that valid consent was obtained.

Question 36: What is the main purpose of maintaining Records of Processing Activities (ROPA) under Article 30?

  1. To replace all privacy notices provided to data subjects
  2. To document relevant processing activities and support organizational accountability and compliance
  3. To guarantee that every processing activity is lawful
  4. To serve as a public database containing all personal data held by an organization

Correct Answer: 2. To document relevant processing activities and support organizational accountability and compliance

Explanation: Article 30 requires controllers and processors in specified circumstances to maintain records of processing activities. These records can include information such as the purposes of processing, categories of data subjects and personal data, recipients, international transfers, and relevant retention or security information, depending on whether the record is maintained by a controller or processor. ROPA supports accountability by giving the organization a structured overview of its processing activities. It does not itself make processing lawful, replace privacy notices, or require organizations to publish personal data.

Question 37: Under the GDPR, what is generally considered a personal data breach?

  1. Any complaint submitted by a data subject
  2. Any processing activity involving sensitive information
  3. A breach of a commercial contract unrelated to personal data
  4. A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data

Correct Answer: 4. A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data

Explanation: Article 4 defines a personal data breach broadly as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed. The definition covers confidentiality, integrity, and availability impacts. A breach can result from malicious activity, human error, system failure, or other security incidents. Once a controller becomes aware of a qualifying breach, it must assess the risks to individuals and determine whether notification to the supervisory authority and affected individuals is required under Articles 33 and 34.

Question 38: What is the general GDPR deadline for notifying a supervisory authority of a personal data breach when notification is required?

  1. Without undue delay and, where feasible, not later than 72 hours after becoming aware of it
  2. Within seven calendar days in every case
  3. Within one month after completing the internal investigation
  4. Only after the affected individuals have been notified

Correct Answer: 1. Without undue delay and, where feasible, not later than 72 hours after becoming aware of it

Explanation: Article 33 generally requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification occurs after 72 hours, the controller must generally provide reasons for the delay. A processor that becomes aware of a personal data breach must notify the controller without undue delay. The 72-hour rule concerns notification to the supervisory authority, not an automatic requirement to notify individuals in every breach.

Question 39: Which factor is particularly relevant when determining whether affected individuals must be notified of a personal data breach?

  1. Whether the organization has experienced a breach before
  2. Whether the breach is likely to result in a high risk to the rights and freedoms of natural persons
  3. Whether the organization has cyber insurance
  4. Whether the incident occurred during business hours

Correct Answer: 2. Whether the breach is likely to result in a high risk to the rights and freedoms of natural persons

Explanation: Article 34 requires communication of a personal data breach to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. The communication should describe the nature of the breach in clear and plain language and provide relevant information such as likely consequences and measures taken or proposed to address the breach. Certain exceptions apply, including situations where appropriate technical and organizational measures have made the data unintelligible or subsequent measures have removed the high risk. The assessment therefore focuses on risk to individuals rather than the organization’s inconvenience or financial exposure.

Question 40: Which statement best describes the GDPR principle of storage limitation?

  1. Personal data must always be deleted immediately after collection.
  2. Personal data may be retained indefinitely if the controller has a legitimate interest.
  3. Personal data should be kept in identifiable form for no longer than necessary for the purposes for which it is processed, subject to applicable exceptions.
  4. Personal data must be retained for exactly five years.

Correct Answer: 3. Personal data should be kept in identifiable form for no longer than necessary for the purposes for which it is processed, subject to applicable exceptions.

Explanation: The storage limitation principle requires personal data to be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed. Organizations should therefore establish appropriate retention periods and review them periodically. Longer retention can sometimes be justified by specific legal obligations or other applicable grounds, and data may be retained for certain purposes under appropriate safeguards. The GDPR does not impose one universal retention period for all personal data. Retention decisions should be linked to the relevant purpose, legal requirements, and organizational policies.