View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps
Question 41: Which GDPR requirement applies when a controller determines that a type of processing is likely to result in a high risk to the rights and freedoms of natural persons?
- The controller must permanently delete all personal data involved.
- The controller must transfer responsibility for the processing to a processor.
- The controller must generally carry out a Data Protection Impact Assessment before processing.
- The controller must automatically obtain consent from every data subject.
Correct Answer: 3. The controller must generally carry out a Data Protection Impact Assessment before processing.
Explanation: Article 35 requires a controller to carry out a Data Protection Impact Assessment when processing is likely to result in a high risk to the rights and freedoms of natural persons. The assessment should occur before processing begins and should describe the processing, assess necessity and proportionality, evaluate risks, and identify measures to address those risks. A DPIA is particularly relevant for certain systematic monitoring, large-scale processing, and processing involving new technologies. It is a risk-assessment mechanism rather than a general requirement for every processing activity. Where high residual risk remains, prior consultation with the supervisory authority may be required.
Question 42: Which GDPR principle requires personal data to be processed in a manner that ensures appropriate security?
- Integrity and confidentiality
- Accuracy
- Purpose limitation
- Data minimization
Correct Answer: 1. Integrity and confidentiality
Explanation: Article 5(1)(f) requires personal data to be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. This principle is closely connected with the security obligations in Article 32, which require controllers and processors to implement appropriate technical and organizational measures. Security measures should take account of risks and can include encryption, pseudonymisation, resilience, access controls, testing, and recovery capabilities. The objective is to protect personal data throughout its lifecycle while maintaining safeguards appropriate to the nature and risks of the processing.
Question 43: What is the role of the European Data Protection Board (EDPB) under the GDPR?
- To directly replace every national supervisory authority
- To approve every organization’s privacy policy before publication
- To promote consistent application of the GDPR and cooperation among supervisory authorities
- To issue criminal penalties against individuals who violate privacy laws
Correct Answer: 3. To promote consistent application of the GDPR and cooperation among supervisory authorities
Explanation: The EDPB contributes to the consistent application of the GDPR throughout the European Union. Its responsibilities include providing general guidance, recommendations, and best-practice advice, promoting cooperation among supervisory authorities, and adopting certain binding decisions in disputes between supervisory authorities under the GDPR’s consistency mechanism. The EDPB does not function as a universal replacement for national supervisory authorities and does not approve every organization’s privacy policy. Its work supports a harmonized European approach to data protection while national supervisory authorities continue to exercise their enforcement powers within the framework established by EU law.
Question 44: Under the GDPR, what does the term “controller” primarily describe?
- A person or organization that determines the purposes and means of processing personal data
- A person or organization that processes data exclusively on another organization’s instructions
- An organization that only stores encrypted data
- A supervisory authority responsible for enforcement
Correct Answer: 1. A person or organization that determines the purposes and means of processing personal data
Explanation: Under Article 4, a controller is the natural or legal person, public authority, agency, or other body that determines the purposes and means of processing personal data, either alone or jointly with others. The controller has primary responsibility for ensuring that its processing complies with applicable GDPR requirements. A processor, by contrast, processes personal data on behalf of the controller and generally acts according to documented instructions. Correctly identifying the roles is important because it determines which obligations apply to each party and how contractual, security, transparency, and accountability responsibilities should be allocated.
Question 45: Which statement best describes joint controllers under the GDPR?
- Joint controllers have no responsibility toward data subjects.
- Two or more entities jointly determine the purposes and means of processing.
- Two entities can never be controllers for the same processing activity.
- Joint controllers are always considered processors of one another.
Correct Answer: 2. Two or more entities jointly determine the purposes and means of processing.
Explanation: Article 26 applies where two or more controllers jointly determine the purposes and means of processing. Joint controllership does not necessarily mean that the parties make every decision together or share responsibilities equally in every respect. Instead, their roles arise from their actual involvement in determining the purposes and means of the processing. Joint controllers must transparently determine their respective responsibilities for compliance, including matters concerning data-subject rights and transparency, while the essential substance of the arrangement must be made available to data subjects. The allocation should reflect the parties’ actual roles and relationships.
Question 46: Which of the following is an example of processing based on the legal obligation ground under Article 6?
- A company analyzing customer data solely because the analysis is interesting
- An employer retaining payroll records because applicable employment or tax law requires it
- A retailer sending optional promotional emails because customers enjoy receiving them
- A website collecting optional profile information without identifying a lawful purpose
Correct Answer: 2. An employer retaining payroll records because applicable employment or tax law requires it
Explanation: Article 6(1)(c) permits processing when it is necessary for compliance with a legal obligation to which the controller is subject. The obligation must have a basis in applicable EU or Member State law, and the relevant legal requirement should establish the processing obligation or provide an appropriate basis for it. This legal basis differs from consent, contract, and legitimate interests. Controllers should identify the specific legal obligation supporting the processing rather than simply describing compliance as generally beneficial. Processing must also remain within the scope of what is necessary to satisfy the applicable legal requirement.
Question 47: What does the GDPR generally require when a controller wants to process personal data for a new purpose that is different from the original collection purpose?
- The controller should assess whether the further processing is compatible with the original purpose or whether another lawful basis and applicable requirements are needed.
- The controller can always use the data for any new purpose without assessment.
- The controller must automatically obtain authorization from the European Commission.
- The controller must always delete the original data first.
Correct Answer: 1. The controller should assess whether the further processing is compatible with the original purpose or whether another lawful basis and applicable requirements are needed.
Explanation: Purpose limitation does not mean that every secondary use is automatically prohibited, but it requires controllers to assess whether further processing is compatible with the original purpose. Article 6(4) identifies factors relevant to that assessment, including the relationship between the original and new purposes, the context of collection, the nature of the data, possible consequences for individuals, and appropriate safeguards. If the new processing is not compatible, the controller generally needs another lawful basis or another applicable legal route. Transparency obligations and other GDPR requirements must also be considered before commencing the new processing.
Question 48: Which GDPR right allows an individual, in certain circumstances, to request that processing of their personal data be limited without requiring immediate deletion?
- Right to data portability
- Right to restriction of processing
- Right to object
- Right to access
Correct Answer: 2. Right to restriction of processing
Explanation: The right to restriction of processing under Article 18 allows individuals to obtain a temporary limitation on how their personal data is processed in specified circumstances. These can include situations where the individual contests the accuracy of the data, where processing is unlawful but the individual requests restriction instead of erasure, where the controller no longer needs the data but the individual requires it for legal claims, or where the individual has objected to processing pending verification of the applicable grounds. Restricted data may generally be stored but processed only in permitted circumstances, such as with the individual’s consent or for legal claims.
Question 49: Which statement correctly describes the GDPR right to object?
- It prevents every form of processing regardless of the lawful basis.
- It automatically deletes all personal data held by the controller.
- It applies only to processing based on consent.
- It allows an individual to object to certain processing, including processing based on legitimate interests, subject to applicable conditions and exceptions.
Correct Answer: 4. It allows an individual to object to certain processing, including processing based on legitimate interests, subject to applicable conditions and exceptions.
Explanation: Article 21 provides a right to object in specified circumstances. Where processing is based on legitimate interests or performance of a task in the public interest or exercise of official authority, an individual may object on grounds relating to their particular situation, subject to the GDPR’s rules and exceptions. A particularly strong rule applies to direct marketing: individuals have an unconditional right to object to processing of their personal data for direct marketing purposes, including profiling related to such marketing. The right to object therefore depends on the processing purpose and lawful basis rather than applying identically to every activity.
Question 50: Which statement best describes automated individual decision-making under Article 22 of the GDPR?
- Automated decision-making is prohibited in all circumstances.
- Organizations may always make legally significant decisions solely through automated processing.
- Individuals generally have a right not to be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects, subject to specified exceptions.
- Article 22 applies only to anonymous data.
Correct Answer: 3. Individuals generally have a right not to be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects, subject to specified exceptions.
Explanation: Article 22 addresses decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect them. The GDPR establishes a general right not to be subject to such decisions, while also providing specific exceptions, including circumstances involving contractual necessity, authorization by Union or Member State law, or explicit consent. Additional safeguards can apply, particularly when special categories of personal data are involved. Organizations using automated decision-making should therefore identify whether Article 22 applies, determine the relevant exception if one exists, and implement required safeguards for individual rights.
Question 51: Which information is generally required in a GDPR privacy notice to support transparency?
- The controller’s identity and contact details, purposes of processing, lawful basis, and other information required by the applicable transparency provision
- Only the organization’s annual revenue
- Only the organization’s company name
- The names of every employee who can access the data
Correct Answer: 1. The controller’s identity and contact details, purposes of processing, lawful basis, and other information required by the applicable transparency provision
Explanation: Articles 13 and 14 establish information requirements for data subjects depending on whether personal data is collected directly from them or obtained from another source. Required information can include the controller’s identity and contact details, purposes and legal bases, recipients or categories of recipients, retention information, data-subject rights, and relevant information about transfers. Additional information may be required depending on the circumstances, including the source of the data under Article 14. Transparency information should be concise, transparent, intelligible, and easily accessible, using clear and plain language appropriate to the intended audience.
Question 52: What is the primary difference between Articles 13 and 14 of the GDPR?
- Article 13 applies only to public authorities, while Article 14 applies only to private companies.
- Article 13 concerns security, while Article 14 concerns international transfers.
- Article 13 applies when personal data is collected from the data subject, while Article 14 generally applies when it is obtained from another source.
- Article 13 applies only to special category data, while Article 14 applies to ordinary personal data.
Correct Answer: 3. Article 13 applies when personal data is collected from the data subject, while Article 14 generally applies when it is obtained from another source.
Explanation: Article 13 establishes transparency information requirements where personal data is collected directly from the data subject. Article 14 applies where personal data has not been obtained from the data subject, such as when information is received from another organization or publicly available source. Article 14 therefore includes additional information concerning the categories of personal data and, where applicable, the source from which the data originated. Both provisions are intended to ensure that individuals understand how their data is being processed and can exercise their rights effectively. Specific exceptions to the Article 14 information obligation also exist.
Question 53: Under the GDPR, which principle is most directly concerned with ensuring that personal data is not excessive in relation to the purposes for which it is processed?
- Storage limitation
- Accountability
- Data minimization
- Accuracy
Correct Answer: 3. Data minimization
Explanation: Data minimization requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Organizations should therefore evaluate what information they genuinely need rather than collecting additional data merely because it might become useful later. Applying data minimization can reduce privacy risks, simplify retention and security management, and support compliance with the GDPR. The principle does not require an organization to collect the smallest amount of information imaginable; rather, the information collected should be proportionate and necessary for the stated processing purposes.
Question 54: Which GDPR principle requires organizations to take reasonable steps to ensure that inaccurate personal data is corrected or erased?
- Accuracy
- Storage limitation
- Purpose limitation
- Integrity and confidentiality
Correct Answer: 1. Accuracy
Explanation: The accuracy principle requires personal data to be accurate and, where necessary, kept up to date. Organizations should take every reasonable step to ensure that personal data that is inaccurate, having regard to the purposes of processing, is erased or rectified without delay. Accuracy is particularly important where decisions affecting individuals depend on the information being processed. Controllers should establish appropriate processes for updating and correcting data and should consider the source, age, relevance, and intended use of information. The GDPR also provides individuals with a specific right to rectification of inaccurate personal data under Article 16.
Question 55: What is the primary purpose of the GDPR’s accountability principle?
- To eliminate the need for supervisory authorities
- To require controllers to be responsible for compliance and demonstrate that their processing complies with the GDPR
- To require organizations to publish every internal privacy document
- To ensure that all organizations use identical security technologies
Correct Answer: 2. To require controllers to be responsible for compliance and demonstrate that their processing complies with the GDPR
Explanation: Accountability is a central GDPR principle requiring controllers to take responsibility for compliance and demonstrate it. Organizations can demonstrate accountability through appropriate policies, governance structures, records, assessments, contracts, training, technical and organizational measures, and monitoring activities. Accountability is not satisfied merely by having a privacy policy on paper. The organization should be able to show that its practices correspond to GDPR requirements and that controls are implemented in practice. The principle also supports a risk-based approach, encouraging controllers to adopt measures proportionate to the nature, scope, context, and purposes of processing.
Question 56: Which statement about processing special categories of personal data under Article 9 is correct?
- Special category data has no additional requirements if the information is publicly available.
- Special category data is never permitted to be processed under the GDPR.
- Processing special category data is generally prohibited unless a specific Article 9 condition applies, in addition to an applicable Article 6 lawful basis.
- Special category data can always be processed whenever a controller has a legitimate commercial interest.
Correct Answer: 3. Processing special category data is generally prohibited unless a specific Article 9 condition applies, in addition to an applicable Article 6 lawful basis.
Explanation: Article 9 establishes enhanced protection for special categories of personal data. Processing is generally prohibited unless one of the specified exceptions applies, such as explicit consent, certain employment and social protection circumstances, protection of vital interests where the individual is incapable of consent, substantial public interest grounds established by law, health-related circumstances, or certain public-interest research purposes. The existence of an Article 9 exception does not eliminate the need for an Article 6 lawful basis where required. Controllers must therefore consider both the general lawful basis and the additional condition permitting special-category processing.
Question 57: Which of the following is an example of processing necessary to protect a person’s vital interests?
- A hospital accessing essential medical information to provide emergency treatment when the individual cannot provide consent
- A company sending a newsletter to former customers
- A retailer analyzing shopping preferences for optional advertising
- An organization collecting optional demographic information for a marketing campaign
Correct Answer: 1. A hospital accessing essential medical information to provide emergency treatment when the individual cannot provide consent
Explanation: Article 6(1)(d) permits processing when it is necessary to protect the vital interests of the data subject or another natural person where the individual is physically or legally incapable of giving consent. The concept is intended for situations involving essential interests, particularly life and serious threats to physical integrity. Additional rules may apply if special categories of personal data, such as health data, are processed, including the relevant Article 9 condition. Organizations should not treat any business interest as a vital interest. The legal basis is narrowly connected to situations where processing is genuinely necessary to protect essential individual interests.
Question 58: Which statement about the GDPR’s rules on international transfers is most accurate?
- Transfers to third countries are permitted only when the recipient is a government authority.
- The GDPR permits international transfers only when the data subject signs a separate contract.
- Personal data can never be transferred outside the European Economic Area.
- Transfers to third countries require compliance with the GDPR’s Chapter V transfer rules, such as an adequacy decision or appropriate safeguards, subject to applicable conditions.
Correct Answer: 4. Transfers to third countries require compliance with the GDPR’s Chapter V transfer rules, such as an adequacy decision or appropriate safeguards, subject to applicable conditions.
Explanation: Chapter V of the GDPR governs transfers of personal data to third countries and international organizations. Depending on the circumstances, a transfer may rely on an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a specific derogation where its requirements are met. Organizations must assess the applicable transfer mechanism and comply with the relevant conditions rather than assuming that a general lawful basis under Article 6 is sufficient. International transfer compliance is a separate consideration from the general lawfulness of processing and must be addressed whenever Chapter V applies.
Question 59: Which mechanism is specifically recognized by the GDPR as an appropriate safeguard for certain transfers of personal data to third countries?
- A company’s ordinary marketing policy
- Binding Corporate Rules, where the GDPR requirements for their use are satisfied
- A standard employee handbook
- A verbal promise by the recipient
Correct Answer: 2. Binding Corporate Rules, where the GDPR requirements for their use are satisfied
Explanation: Binding Corporate Rules (BCRs) are one of the appropriate safeguards recognized under Article 46 for certain transfers of personal data to third countries. They are designed for multinational groups or groups of enterprises engaged in a joint economic activity and establish legally binding and enforceable data protection commitments for transfers within the group. BCRs must satisfy specific GDPR requirements and generally require approval through the applicable regulatory process. They are distinct from informal internal policies because they must provide enforceable rights and effective legal remedies for data subjects. Organizations should select the transfer mechanism appropriate to the specific circumstances.
Question 60: What is the purpose of Standard Contractual Clauses (SCCs) in the GDPR context?
- To establish standardized contractual safeguards for certain international transfers of personal data
- To authorize unlimited transfers of personal data without further assessment
- To provide automatic immunity from supervisory authority investigations
- To replace all GDPR privacy notices
Correct Answer: 1. To establish standardized contractual safeguards for certain international transfers of personal data
Explanation: Standard Contractual Clauses are contractual mechanisms recognized under the GDPR framework for providing appropriate safeguards for certain transfers of personal data to third countries. The European Commission has adopted modern SCCs that contain modular provisions addressing different transfer scenarios. Using SCCs does not mean that an organization can ignore the circumstances of the transfer. The parties must comply with the clauses and consider whether the legal and practical circumstances of the destination country affect the protection of the transferred data. Additional measures may be necessary where appropriate to ensure an essentially equivalent level of protection.