View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps
Question 161: Under the GDPR, which principle requires personal data to be processed in a manner that ensures appropriate security?
- Purpose limitation
- Data minimization
- Integrity and confidentiality
- Accuracy
Correct Answer: 3. Integrity and confidentiality
Explanation:
The integrity and confidentiality principle requires personal data to be processed with appropriate security safeguards. Controllers and processors must protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. The GDPR links this principle closely with Article 32, which requires appropriate technical and organizational measures based on the risks associated with processing. Examples can include encryption, access controls, resilience measures, and procedures for restoring availability after an incident. Purpose limitation concerns the purposes for which data is collected, minimization concerns the amount of data processed, and accuracy concerns keeping data correct and up to date.
Question 162: A company wants to process customer information for a new purpose that is not directly compatible with the original purpose. What should it generally assess before relying on the original collection?
- Whether the further processing is compatible under Article 6(4)
- Whether the data can simply be retained indefinitely
- Whether the processor has appointed a DPO
- Whether the organization has received an administrative fine
Correct Answer: 1. Whether the further processing is compatible under Article 6(4)
Explanation:
When a controller intends to process personal data for a purpose different from the original purpose, the GDPR requires consideration of whether the further processing is compatible with the original purpose. Article 6(4) identifies factors such as the relationship between the original and new purposes, the context in which the data was collected, the nature of the data, possible consequences for individuals, and appropriate safeguards. If the new purpose is not compatible, the controller generally needs another legal basis or must otherwise establish lawful grounds for the new processing. The assessment helps protect the purpose-limitation principle.
Question 163: Which GDPR right allows an individual, in certain circumstances, to request that processing of personal data be limited without requiring the data to be erased?
- Right to data portability
- Right to restriction of processing
- Right to object
- Right of access
Correct Answer: 2. Right to restriction of processing
Explanation:
The right to restriction of processing allows an individual to require a controller to limit how personal data is processed in specified circumstances. For example, restriction may apply while the accuracy of data is being contested, when processing is unlawful but the individual prefers restriction rather than erasure, or when the controller no longer needs the data but the individual requires it for legal claims. During restriction, processing is generally limited except in specified circumstances, such as with the individual’s consent or for legal claims. This right is distinct from erasure, because the data is not necessarily deleted.
Question 164: Which situation most clearly illustrates the GDPR’s right to data portability?
- Asking a controller to stop processing data for direct marketing
- Requesting correction of an incorrect address
- Requesting deletion of obsolete personal data
- Receiving certain personal data in a structured, commonly used, machine-readable format for transmission to another controller
Correct Answer: 4. Receiving certain personal data in a structured, commonly used, machine-readable format for transmission to another controller
Explanation:
The right to data portability allows an individual, under the conditions in Article 20, to receive certain personal data concerning them in a structured, commonly used, and machine-readable format. The right also permits transmission of that data to another controller where technically feasible. It generally applies when processing is based on consent or a contract and carried out by automated means. Portability differs from access, which provides broader information about processing and a copy of personal data. It also differs from rectification, erasure, and objection, which address different individual rights.
Question 165: A controller receives a valid request to rectify inaccurate personal data. What GDPR principle is most directly supported by fulfilling that request?
- Accuracy
- Purpose limitation
- Storage limitation
- Data minimization
Correct Answer: 1. Accuracy
Explanation:
The GDPR’s accuracy principle requires personal data to be accurate and, where necessary, kept up to date. Controllers must take reasonable steps to ensure that inaccurate personal data is corrected or erased without undue delay, considering the purposes for which the data is processed. The right of rectification gives individuals an important mechanism for helping controllers meet this obligation. Although other GDPR principles may also be relevant to responsible data management, correcting inaccurate information directly addresses the accuracy requirement. Organizations should therefore maintain processes that allow individuals to identify and correct inaccurate personal information.
Question 166: Which of the following is a core responsibility of a Data Protection Officer under the GDPR?
- Approving every employee’s annual leave
- Advising the organization on GDPR obligations
- Setting the organization’s product prices
- Acting as the organization’s external auditor in every case
Correct Answer: 2. Advising the organization on GDPR obligations
Explanation:
A Data Protection Officer has several responsibilities under the GDPR, including informing and advising the controller or processor and employees who carry out processing about their obligations under the GDPR and other applicable data protection requirements. The DPO also monitors compliance, provides advice regarding data protection impact assessments, and cooperates with supervisory authorities. The DPO’s role is not to manage unrelated business functions such as pricing or employee leave. The GDPR also establishes requirements concerning the DPO’s independence and access to relevant resources. Organizations must avoid improperly instructing the DPO about how to perform their statutory tasks.
Question 167: Which circumstance can trigger a controller’s obligation to notify a personal data breach to the competent supervisory authority?
- Every minor technical problem, regardless of its effect
- Any system maintenance activity
- A personal data breach that is unlikely to result in a risk to individuals
- A personal data breach likely to result in a risk to the rights and freedoms of natural persons
Correct Answer: 4. A personal data breach likely to result in a risk to the rights and freedoms of natural persons
Explanation:
Under Article 33, a controller generally must notify a personal data breach to the competent supervisory authority unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification should generally be made without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach. The notification requirement therefore depends on the level of risk rather than simply on whether a security incident occurred. Controllers should assess the nature, scope, context, and potential consequences of the breach when determining whether notification is required.
Question 168: Which transfer mechanism is specifically recognized by the GDPR for certain international transfers when approved contractual safeguards are used?
- Standard Contractual Clauses
- Internal company policy alone
- A verbal agreement between employees
- A general website privacy statement
Correct Answer: 1. Standard Contractual Clauses
Explanation:
Standard Contractual Clauses, or SCCs, are a recognized mechanism under the GDPR for transferring personal data to recipients in third countries or international organizations in circumstances covered by the GDPR’s international-transfer framework. The clauses establish contractual commitments intended to provide appropriate safeguards for transferred personal data. Their use does not mean that every transfer automatically becomes lawful; controllers and importers must satisfy the applicable requirements and assess the circumstances of the transfer. Other mechanisms can also apply, including adequacy decisions and certain derogations. Organizations should therefore identify the specific transfer mechanism and ensure that its requirements are fulfilled.
Question 169: What is the primary purpose of a Record of Processing Activities (ROPA)?
- To replace all privacy notices
- To document an organization’s processing activities and relevant information about them
- To provide marketing content to customers
- To determine employee salaries
Correct Answer: 2. To document an organization’s processing activities and relevant information about them
Explanation:
A Record of Processing Activities helps an organization document its processing operations and demonstrate accountability under the GDPR. Depending on whether it is maintained by a controller or processor, the record can include information such as purposes of processing, categories of personal data, categories of individuals, recipients, international transfers, retention information, and security measures. Article 30 contains specific requirements concerning records of processing activities, subject to applicable exceptions. A ROPA is an internal accountability and governance tool rather than a replacement for an external-facing privacy notice. Maintaining accurate records can also help organizations respond to compliance inquiries and manage privacy risks.
Question 170: Which statement best describes pseudonymisation under the GDPR?
- It always makes information anonymous
- It permanently removes all security risks
- It replaces identifying information so that attribution requires additional information kept separately
- It means that the GDPR no longer applies
Correct Answer: 3. It replaces identifying information so that attribution requires additional information kept separately
Explanation:
Pseudonymisation is a security and privacy-enhancing technique in which personal data is processed so that it can no longer be attributed to a specific individual without the use of additional information. That additional information must be kept separately and protected through appropriate technical and organizational measures. Pseudonymised information remains personal data when it can be linked back to an individual. This differs from anonymisation, where information is rendered sufficiently irreversible so that individuals are no longer identifiable. The GDPR specifically recognizes pseudonymisation as an example of a safeguard that can help reduce risks associated with processing.
Question 171: When must a controller generally provide information to an individual when personal data is collected directly from that individual?
- At the time the personal data is obtained
- Only after a supervisory authority requests it
- Only after the first data breach
- After the data has been stored for one year
Correct Answer: 1. At the time the personal data is obtained
Explanation:
Article 13 establishes information requirements when personal data is collected directly from the individual. The controller generally must provide the required information at the time the personal data is obtained. The information can include the controller’s identity and contact details, the purposes and legal basis for processing, retention information, rights available to the individual, recipients, international transfers where applicable, and other required details. Providing this information promptly supports transparency and allows individuals to understand how their personal data will be used. The specific notice must be clear and accessible and should contain the information required by the GDPR.
Question 172: Which GDPR principle requires organizations to avoid collecting personal data that is excessive for the stated processing purposes?
- Accountability
- Data minimization
- Transparency
- Accuracy
Correct Answer: 2. Data minimization
Explanation:
The data minimization principle requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Organizations should therefore avoid collecting information merely because it might become useful in the future when that information is not necessary for the stated purpose. Minimization can influence data-collection forms, system design, access permissions, and retention practices. It does not mean that organizations must always collect the smallest technically possible amount of information; rather, the amount and categories of data should be appropriate and necessary for the legitimate purposes of processing.
Question 173: Under the GDPR, which circumstance can justify processing special categories of personal data?
- The data is commercially valuable
- The company wants better advertising results
- The data is publicly interesting
- A specific Article 9 condition applies, in addition to an applicable Article 6 lawful basis
Correct Answer: 4. A specific Article 9 condition applies, in addition to an applicable Article 6 lawful basis
Explanation:
Special categories of personal data receive enhanced protection under Article 9 of the GDPR. Processing is generally prohibited unless one of the specific conditions in Article 9(2) applies, such as explicit consent in applicable circumstances, employment and social protection obligations, vital interests when the individual is incapable of giving consent, or certain substantial public-interest grounds. In addition, the controller must identify an applicable lawful basis under Article 6. The two provisions serve different functions: Article 6 establishes a lawful basis for processing personal data generally, while Article 9 establishes an additional condition for processing special categories.
Question 174: Which statement best describes the GDPR accountability principle?
- Controllers must be able to demonstrate compliance with the GDPR
- Controllers are exempt from documenting processing activities
- Processors may ignore the controller’s documented instructions
- Compliance is required only after a supervisory authority conducts an inspection
Correct Answer: 1. Controllers must be able to demonstrate compliance with the GDPR
Explanation:
The accountability principle requires controllers to be responsible for, and able to demonstrate, compliance with the GDPR’s requirements. Demonstrating compliance can involve policies, records, risk assessments, data protection impact assessments where required, contracts, training, technical measures, privacy notices, and other evidence appropriate to the processing activities. Accountability therefore goes beyond simply asserting that an organization follows the law. It encourages organizations to build privacy requirements into governance and operational processes and maintain evidence showing how obligations are addressed. Supervisory authorities may consider such documentation when evaluating an organization’s compliance and data protection practices.
Question 175: Which situation most directly involves the GDPR’s transparency principle?
- Encrypting data at rest
- Restricting database administrator access
- Giving individuals clear information about how their personal data is processed
- Deleting duplicate customer records
Correct Answer: 3. Giving individuals clear information about how their personal data is processed
Explanation:
Transparency requires processing information to be communicated to individuals in a concise, transparent, intelligible, and easily accessible form, using clear and plain language where appropriate. Privacy notices are a key mechanism for meeting this obligation. Individuals should be able to understand relevant matters such as who processes their data, why it is processed, the applicable legal basis, retention information, and their rights. Encryption and access controls are primarily security measures, while deleting duplicate records can support data quality or minimization. Transparency is therefore closely connected with effective communication and enabling individuals to understand the processing of their personal data.
Question 176: A controller determines that a processing activity is likely to result in a high risk to individuals’ rights and freedoms. What GDPR measure may be required before processing begins?
- A mandatory administrative fine
- A data protection impact assessment
- Automatic anonymisation of all data
- A permanent deletion schedule
Correct Answer: 2. A data protection impact assessment
Explanation:
A Data Protection Impact Assessment, or DPIA, is required before processing where it is likely to result in a high risk to the rights and freedoms of natural persons. The assessment should describe the processing operations and purposes, assess necessity and proportionality, evaluate risks to individuals, and identify measures addressing those risks. DPIAs are particularly relevant to processing involving new technologies or other activities that may create significant risks. The purpose is preventive: privacy risks should be identified and addressed before the processing begins. If high residual risk remains after mitigation, consultation with the supervisory authority may be required.
Question 177: Which GDPR principle is most directly concerned with retaining personal data only for as long as necessary for the purposes for which it is processed?
- Purpose limitation
- Fairness
- Storage limitation
- Data portability
Correct Answer: 3. Storage limitation
Explanation:
The storage limitation principle requires personal data to be kept in a form that permits identification of individuals for no longer than is necessary for the purposes for which the data is processed, subject to specified exceptions. Organizations should therefore establish retention periods or criteria that reflect the purposes, legal obligations, and risks associated with the information. Keeping data indefinitely simply because storage is inexpensive can conflict with this principle when there is no continuing justification. Effective retention schedules, deletion procedures, and periodic reviews can help organizations determine when personal data should be deleted, anonymised, or otherwise removed from active processing.
Question 178: Which organization is primarily responsible for adopting binding decisions when resolving certain disputes between supervisory authorities under the GDPR cooperation mechanism?
- The European Data Protection Board
- The European Parliament
- The European Commission
- The European Court of Auditors
Correct Answer: 1. The European Data Protection Board
Explanation:
The European Data Protection Board plays a role in ensuring consistent application of the GDPR across the European Economic Area. Under the cooperation and consistency mechanisms, certain disputes between supervisory authorities can be referred to the EDPB, which may adopt binding decisions in the circumstances specified by the GDPR. This helps address disagreements concerning matters such as objections to draft decisions or competence issues. The EDPB is distinct from the European Commission and the European Parliament, which have different institutional roles. The EDPB is composed of representatives of the relevant supervisory authorities and the European Data Protection Supervisor.
Question 179: Which action is most consistent with the principle of privacy by design?
- Adding privacy controls only after a major data incident
- Designing systems so appropriate privacy and data-protection safeguards are incorporated from the outset
- Collecting every available category of personal information
- Removing all security controls to improve convenience
Correct Answer: 2. Designing systems so appropriate privacy and data-protection safeguards are incorporated from the outset
Explanation:
Privacy by design, reflected in Article 25, requires controllers to implement appropriate technical and organizational measures designed to implement data protection principles and integrate necessary safeguards into processing. The concept encourages privacy considerations to be addressed during the design and development of systems, products, and processes rather than being treated solely as an afterthought. Measures can include data minimization, pseudonymisation, access controls, and privacy-conscious architecture. The appropriate measures depend on factors such as the state of the art, implementation costs, the nature and scope of processing, the context, purposes, and risks to individuals.
Question 180: Which statement about consent under the GDPR is correct?
- Consent can always be inferred from silence
- Consent cannot be withdrawn after it has been given
- Consent must always be the only lawful basis available
- Consent must be freely given, specific, informed, and unambiguous, and individuals can withdraw it**
Correct Answer: 4. Consent must be freely given, specific, informed, and unambiguous, and individuals can withdraw it
Explanation:
GDPR consent must meet specific requirements. It must be freely given, specific, informed, and unambiguous, and it generally requires a clear affirmative action. Silence, inactivity, or pre-ticked boxes do not normally constitute valid consent. Individuals also have the right to withdraw consent at any time, and withdrawal must be as easy as giving consent. Withdrawal does not automatically make earlier processing unlawful when that processing was lawfully based on consent. Organizations should therefore maintain appropriate consent mechanisms and records and provide clear information about what the individual is consenting to and how consent can be withdrawn.