IAPP CIPP-E Practice Test Questions and Exam Dumps Part 6 Q101-120

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 101. Under the GDPR, which condition is required for processing personal data based on the data subject’s consent?

  1. Consent is valid only when provided in writing.
  2. Consent cannot be withdrawn once processing begins.
  3. Consent must be freely given, specific, informed, and unambiguous.
  4. Consent must be bundled with every service agreement.

Correct Answer: 3. Consent must be freely given, specific, informed, and unambiguous.

Explanation:
GDPR consent must meet specific conditions to be valid. It must be freely given, meaning the individual has a genuine choice and can refuse or withdraw without inappropriate consequences. It must also be specific to the processing purposes, informed through clear information, and expressed through an unambiguous indication of the individual’s wishes. Consent should not automatically be assumed from silence, inactivity, or pre-ticked boxes. Where consent is relied upon as the lawful basis, controllers must also be able to demonstrate that valid consent was obtained and provide an effective mechanism for withdrawal.

Question 102. Which GDPR right allows an individual to receive personal data concerning them in a structured, commonly used, and machine-readable format and transmit it to another controller?

  1. Right to restriction of processing
  2. Right to erasure
  3. Right to object
  4. Right to data portability

Correct Answer: 4. Right to data portability

Explanation:
The right to data portability under Article 20 allows individuals, in certain circumstances, to receive personal data concerning them in a structured, commonly used, and machine-readable format. Individuals may also transmit that data to another controller without hindrance from the original controller. The right generally applies where processing is based on consent or a contract and is carried out by automated means. It is intended to enhance individual control over personal data and facilitate movement of data between service providers, while remaining subject to the conditions and limitations established by the GDPR.

Question 103. Which situation most clearly demonstrates the GDPR principle of data minimization?

  1. Collecting only the personal data necessary to complete the requested service
  2. Sharing customer data with all internal departments
  3. Keeping all customer information indefinitely for possible future use
  4. Collecting every available identifier from a customer

Correct Answer: 1. Collecting only the personal data necessary to complete the requested service

Explanation:
The data minimization principle requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. A controller should therefore identify the information genuinely required for a specific processing activity and avoid collecting unnecessary data merely because it might become useful later. For example, if an online service only needs an email address to create an account, collecting unrelated information such as a customer’s marital status would generally be difficult to justify under data minimization. The principle supports both privacy protection and responsible data governance.

Question 104. What is the primary purpose of a Data Protection Impact Assessment under the GDPR?

  1. To determine the amount of an administrative fine
  2. To identify and address risks to individuals arising from high-risk processing
  3. To document every employee who accesses personal data
  4. To replace the requirement for technical security measures

Correct Answer: 2. To identify and address risks to individuals arising from high-risk processing

Explanation:
A Data Protection Impact Assessment, or DPIA, is designed to help controllers identify, assess, and mitigate risks to individuals when processing is likely to result in a high risk to their rights and freedoms. It should be performed before the relevant processing begins and should consider the nature, scope, context, and purposes of processing. A DPIA also evaluates proposed safeguards and demonstrates how identified risks will be addressed. It is therefore a proactive privacy-management tool rather than a substitute for security controls, a mechanism for calculating fines, or simply an inventory of personnel.

Question 105. Which statement best describes the GDPR concept of a processor?

  1. A person or organization that processes personal data on behalf of a controller
  2. A person or organization that determines the purposes of processing
  3. The individual to whom personal data relates
  4. A supervisory authority responsible for enforcing the GDPR

Correct Answer: 1. A person or organization that processes personal data on behalf of a controller

Explanation:
A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of a controller. The controller determines the purposes and means of processing, while the processor acts according to the controller’s documented instructions, subject to the requirements of the GDPR. Processor relationships must generally be governed by a legally binding arrangement containing specified provisions. A processor may have direct GDPR obligations, including requirements concerning security, subprocessors, assistance to the controller, and records or cooperation where applicable.

Question 106. What is generally required when a controller intends to use a processor?

  1. The processor must become the controller automatically
  2. A written contract or other legal act must govern the processing
  3. The data subject must personally negotiate the processor agreement
  4. The processor must be established outside the European Economic Area

Correct Answer: 2. A written contract or other legal act must govern the processing

Explanation:
Article 28 requires processing carried out by a processor on behalf of a controller to be governed by a contract or other legal act that is binding on the processor. The arrangement must set out matters such as the subject matter and duration of processing, nature and purpose, types of personal data, categories of data subjects, and the controller’s obligations and rights. It must also contain specified processor obligations, including processing only on documented instructions, confidentiality, security, assistance with compliance obligations, and appropriate handling of personal data after the processing relationship ends.

Question 107. Which right allows a data subject to request correction of inaccurate personal data?

  1. Right to rectification
  2. Right to object
  3. Right to erasure
  4. Right to data portability

Correct Answer: 1. Right to rectification

Explanation:
The right to rectification allows individuals to have inaccurate personal data corrected without undue delay. Where personal data is incomplete, individuals may also have the right to request completion, taking into account the purposes of the processing. Accuracy is itself a fundamental GDPR principle, so controllers should take reasonable steps to ensure that inaccurate personal data is corrected or deleted. The right to rectification differs from the right to erasure, which concerns deletion of personal data in specified circumstances. Controllers must also communicate applicable rectifications to relevant recipients where required.

Question 108. Which circumstance can permit a controller to process special categories of personal data under the GDPR?

  1. An applicable Article 9 exception permits the processing
  2. The controller has stored the data for more than one year
  3. The data is interesting to the organization
  4. The information was obtained from a public website

Correct Answer: 1. An applicable Article 9 exception permits the processing

Explanation:
Special categories of personal data receive enhanced protection under Article 9 GDPR. These include information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for uniquely identifying a person, health data, and information concerning sex life or sexual orientation. Processing is generally prohibited unless a specific Article 9 condition applies, such as explicit consent or another recognized exception. In many cases, the controller must also identify an appropriate lawful basis under Article 6. The public availability of information does not automatically remove Article 9 protection.

Question 109. What is the primary function of a GDPR supervisory authority?

  1. To monitor and enforce the application of data protection law within its competence
  2. To provide commercial insurance to controllers
  3. To represent all controllers in contractual disputes
  4. To approve every privacy notice before publication

Correct Answer: 1. To monitor and enforce the application of data protection law within its competence

Explanation:
A supervisory authority is an independent public authority responsible for monitoring and enforcing the application of the GDPR within its jurisdiction and competence. Its responsibilities can include handling complaints, conducting investigations, providing guidance, exercising corrective powers, and imposing administrative fines where appropriate. Supervisory authorities also cooperate with one another under the GDPR’s consistency and cooperation mechanisms. They do not function as commercial representatives of controllers or approve every privacy notice in advance. Their role is primarily regulatory and supervisory, supporting effective enforcement of data protection requirements.

Question 110. Which statement best describes pseudonymisation under the GDPR?

  1. It permanently removes any possibility of linking data to an individual
  2. It reduces direct identifiability while additional information can potentially enable re-identification
  3. It makes all GDPR obligations automatically disappear
  4. It processes data so it can no longer be personal data under any circumstances

Correct Answer: 2. It reduces direct identifiability while additional information can potentially enable re-identification

Explanation:
Pseudonymisation is a security and privacy-enhancing technique in which personal data is processed so that it can no longer be attributed to a specific individual without the use of additional information. That additional information must generally be kept separately and protected through appropriate technical and organizational measures. Unlike true anonymisation, pseudonymised information remains personal data under the GDPR when it can be linked to an identifiable person using additional information. Pseudonymisation can reduce risks associated with processing and is specifically recognized by the GDPR as a useful safeguard.

Question 111. When must a controller generally notify the competent supervisory authority of a personal data breach?

  1. Only when the breach involves encrypted data
  2. Where the breach is likely to result in a risk to the rights and freedoms of individuals
  3. Only when every affected individual requests notification
  4. Where the breach is unlikely to create any risk

Correct Answer: 2. Where the breach is likely to result in a risk to the rights and freedoms of individuals

Explanation:
Under Article 33, a controller generally must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it when the breach is likely to result in a risk to the rights and freedoms of natural persons. The notification requirement therefore depends on the level of risk rather than simply whether a breach occurred. If notification takes place after 72 hours, the controller should provide reasons for the delay. Processors generally have their own obligation to notify the controller without undue delay after becoming aware of a breach.

Question 112. What is the purpose of the GDPR’s accountability principle?

  1. To transfer all compliance responsibility to processors
  2. To require supervisory authorities to approve every processing activity
  3. To require controllers to demonstrate compliance with data protection obligations
  4. To eliminate the need for privacy policies

Correct Answer: 3. To require controllers to demonstrate compliance with data protection obligations

Explanation:
The accountability principle requires controllers to comply with the GDPR’s data protection principles and to be able to demonstrate that compliance. This moves beyond simply following rules and requires organizations to maintain evidence and governance mechanisms showing how obligations are being addressed. Examples can include policies, records of processing activities, DPIAs, contracts, training, security measures, audits, and documentation supporting lawful processing. Accountability does not eliminate privacy documentation or transfer the controller’s responsibilities to processors. It establishes an ongoing organizational responsibility to implement and demonstrate appropriate data protection practices.

Question 113. Which GDPR principle requires personal data to be kept in a form that permits identification only for as long as necessary?

  1. Storage limitation
  2. Purpose limitation
  3. Accuracy
  4. Lawfulness

Correct Answer: 1. Storage limitation

Explanation:
The storage limitation principle requires personal data to be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed. Controllers should therefore establish appropriate retention periods and review whether continued storage remains justified. Longer retention may be permitted in circumstances recognized by the GDPR, such as certain archiving, scientific or historical research, or statistical purposes when appropriate safeguards are applied. Storage limitation does not necessarily require immediate deletion once the original operational purpose ends, but continued retention must have a lawful justification.

Question 114. Which activity is most directly associated with the GDPR principle of privacy by design?

  1. Collecting as much personal data as technically possible
  2. Considering data protection safeguards when designing a new processing system
  3. Waiting until a data breach occurs before implementing security controls
  4. Publishing personal data to increase transparency

Correct Answer: 2. Considering data protection safeguards when designing a new processing system

Explanation:
Privacy by design requires data protection to be incorporated into the design of processing activities and systems rather than addressed only after implementation. Article 25 requires controllers to implement appropriate technical and organizational measures designed to implement data protection principles effectively and integrate necessary safeguards into processing. Depending on the circumstances, measures may include data minimization, access controls, pseudonymisation, encryption, retention controls, and privacy-friendly defaults. The concept is proactive: organizations should consider privacy risks and safeguards when planning and developing processing operations instead of treating privacy as an afterthought.

Question 115. Which statement correctly distinguishes a controller from a processor?

  1. A processor always determines the purposes of processing
  2. A controller only stores personal data and never makes processing decisions
  3. A controller and processor are legally identical roles under the GDPR
  4. A controller determines the purposes and means of processing, while a processor acts on behalf of the controller

Correct Answer: 4. A controller determines the purposes and means of processing, while a processor acts on behalf of the controller

Explanation:
The distinction between controller and processor is fundamental to GDPR compliance. A controller determines the purposes and means of processing personal data, although EU or Member State law may sometimes determine those elements. A processor processes personal data on behalf of the controller and generally follows the controller’s documented instructions. The parties have different responsibilities under the GDPR, although processors also have direct obligations in specified areas. Determining which role an organization actually performs depends on the substance of its activities and decision-making rather than simply the terminology used in a contract.

Question 116. Which requirement is associated with the GDPR right of access?

  1. Individuals can access personal data only if a supervisory authority approves the request
  2. Individuals may request confirmation of whether their personal data is being processed
  3. Individuals may access only anonymised statistical information
  4. Individuals can require every organization to delete all data immediately

Correct Answer: 2. Individuals may request confirmation of whether their personal data is being processed

Explanation:
The right of access under Article 15 gives individuals the right to obtain confirmation as to whether personal data concerning them is being processed. Where processing occurs, they can generally obtain access to the personal data and specified information about the processing, such as purposes, categories of personal data, recipients, retention information, and available information about the source of the data. The right is an important transparency mechanism that enables individuals to understand and verify how their personal information is being processed. It does not automatically provide an unrestricted right to deletion or access to every organization’s records.

Question 117. What is generally required before transferring personal data from the EEA to a third country when no adequacy decision applies?

  1. An appropriate transfer mechanism or applicable derogation must be identified
  2. The recipient must automatically become a joint controller
  3. The transfer must always be prohibited
  4. The controller must obtain a court order

Correct Answer: 1. An appropriate transfer mechanism or applicable derogation must be identified

Explanation:
Transfers of personal data to third countries or international organizations are governed by Chapter V GDPR. Where an adequacy decision does not apply, the controller or processor generally needs to rely on an appropriate safeguard under the GDPR, such as Standard Contractual Clauses, Binding Corporate Rules, or another recognized transfer mechanism. In limited circumstances, a transfer may rely on a derogation under Article 49. Organizations must also consider the requirements associated with the selected mechanism and the circumstances of the transfer. A transfer is therefore not automatically prohibited simply because the destination country lacks an adequacy decision.

Question 118. Which of the following is an example of a technical measure that can help protect personal data under Article 32 GDPR?

  1. Written privacy notice
  2. Organizational retention policy
  3. Encryption of personal data
  4. Employee awareness training

Correct Answer: 3. Encryption of personal data

Explanation:
Article 32 requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Encryption is a recognized technical measure that can help protect personal data, particularly against unauthorized access or disclosure. Other measures may include pseudonymisation, resilience of processing systems, restoration capabilities, and processes for regularly testing security effectiveness. Organizational measures can include policies, procedures, training, and governance controls. The specific measures should be selected based on factors such as the state of the art, implementation costs, the nature of processing, and the risks to individuals.

Question 119. Which situation is most likely to require a controller to consider appointing a Data Protection Officer under the GDPR?

  1. The controller processes only one employee’s contact details
  2. The controller uses an external accounting service
  3. The controller’s core activities involve regular and systematic monitoring of individuals on a large scale
  4. The controller has a publicly accessible website

Correct Answer: 3. The controller’s core activities involve regular and systematic monitoring of individuals on a large scale

Explanation:
Article 37 identifies circumstances in which designation of a Data Protection Officer is required. One key circumstance is where the core activities of the controller or processor consist of processing operations that require regular and systematic monitoring of data subjects on a large scale. Another involves large-scale processing of special categories of data or personal data relating to criminal convictions and offences, subject to the applicable requirements. The DPO’s role includes advising on GDPR obligations, monitoring compliance, providing advice concerning DPIAs, and cooperating with the supervisory authority. The requirement depends on the nature and scale of processing, not simply having a website.

Question 120. Under the GDPR, what is the primary purpose of the right to object under Article 21?

  1. To require controllers to provide a copy of every internal business record
  2. To prevent all processing based on a contract
  3. To allow individuals to challenge certain processing based on grounds relating to their particular situation
  4. To automatically erase all personal data

Correct Answer: 3. To allow individuals to challenge certain processing based on grounds relating to their particular situation

Explanation:
The right to object allows individuals, in specified circumstances, to object to processing of their personal data based on grounds relating to their particular situation when processing relies on certain legal bases, including public task or legitimate interests. The controller must generally stop the processing unless it demonstrates compelling legitimate grounds that override the individual’s interests, rights, and freedoms, or the processing is required for legal claims. The right has particular rules for direct marketing, where individuals have an unconditional right to object to processing for that purpose. The right is therefore context-dependent rather than a universal deletion mechanism.