View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps
Question 181: Which GDPR principle requires personal data to be processed lawfully, fairly, and transparently?
- Storage limitation
- Lawfulness, fairness, and transparency
- Data minimization
- Accuracy
Correct Answer: 2. Lawfulness, fairness, and transparency
Explanation:
Article 5 requires personal data to be processed lawfully, fairly, and transparently in relation to the data subject. Lawfulness means that processing must have an applicable legal basis under the GDPR. Fairness requires processing to be handled in a way that does not unjustifiably disadvantage or mislead individuals. Transparency requires individuals to receive understandable information about relevant processing activities. These requirements operate together and are foundational to GDPR compliance. Other principles, such as accuracy, minimization, and storage limitation, address additional aspects of responsible processing but do not replace the requirement that processing itself be lawful, fair, and transparent.
Question 182: A company wants to rely on legitimate interests as its lawful basis for processing. What should it generally do before proceeding?
- Automatically assume the interests override all individual rights
- Obtain approval from every supervisory authority in the EU
- Conduct a balancing assessment between its legitimate interests and the individual’s interests or fundamental rights and freedoms
- Treat legitimate interests as equivalent to consent
Correct Answer: 3. Conduct a balancing assessment between its legitimate interests and the individual’s interests or fundamental rights and freedoms
Explanation:
Where legitimate interests are relied upon under Article 6(1)(f), the controller must identify a legitimate interest, establish that processing is necessary for that interest, and balance it against the interests or fundamental rights and freedoms of the individual. The assessment should consider the nature of the data, the individual’s reasonable expectations, the relationship between the parties, and the potential impact of processing. Appropriate safeguards can also influence the assessment. Legitimate interests therefore cannot simply be asserted without analysis. Organizations should document their reasoning and consider whether another lawful basis would be more appropriate.
Question 183: Which GDPR provision is primarily concerned with the territorial scope of the Regulation?
- Article 3
- Article 9
- Article 20
- Article 32
Correct Answer: 1. Article 3
Explanation:
Article 3 establishes the territorial scope of the GDPR. It covers processing carried out in the context of the activities of an establishment of a controller or processor in the European Union, regardless of whether the processing itself takes place in the EU. It can also apply to organizations outside the EU when their processing relates to offering goods or services to individuals in the EU or monitoring their behavior there, subject to the requirements of the provision. Territorial scope is therefore not determined solely by where an organization is incorporated or where its servers are located. Organizations must assess their activities against Article 3.
Question 184: Which situation is most likely to involve processing of biometric data as a special category of personal data?
- Recording a customer’s postal address
- Storing a customer’s preferred language
- Maintaining a list of product categories viewed by users
- Using facial characteristics to uniquely identify individuals**
Correct Answer: 4. Using facial characteristics to uniquely identify individuals
Explanation:
The GDPR treats biometric data as a special category of personal data when it is processed for the purpose of uniquely identifying a natural person. Examples can include certain facial recognition or fingerprint-identification systems. Special categories receive enhanced protection under Article 9, meaning an Article 9 condition must generally apply in addition to an applicable Article 6 lawful basis. Not every photograph or biometric-related technology automatically falls within the special-category definition. The purpose and nature of the processing matter. Organizations should therefore distinguish ordinary visual information from biometric processing intended to uniquely identify individuals.
Question 185: Under the GDPR, what is one important requirement when a controller uses a processor to process personal data?
- The processor must be allowed to use the data for unrelated purposes
- The processor must process personal data only on documented instructions from the controller, subject to applicable legal requirements
- The controller no longer has any responsibility for the processing
- The processor automatically becomes a joint controller
Correct Answer: 2. The processor must process personal data only on documented instructions from the controller, subject to applicable legal requirements
Explanation:
Article 28 requires processors to process personal data only on documented instructions from the controller, unless EU or Member State law requires otherwise. The processor must also comply with other contractual and organizational requirements established by the GDPR. A processor does not automatically become a controller merely because it processes personal data. The controller remains responsible for selecting processors that provide sufficient guarantees and for establishing an appropriate data processing arrangement. Clear instructions help define the processor’s permitted activities and reduce the risk that personal data will be used for unauthorized purposes.
Question 186: Which right allows an individual to request deletion of personal data in specified circumstances?
- Right to erasure
- Right to data portability
- Right to information
- Right to object to automated processing only
Correct Answer: 1. Right to erasure
Explanation:
The right to erasure, often called the right to be forgotten, allows individuals to request deletion of personal data in circumstances established by Article 17. These circumstances can include situations where the data is no longer necessary for the purposes for which it was collected, consent has been withdrawn and there is no other legal ground for processing, or the data has been unlawfully processed. The right is not absolute. Exceptions can apply, including situations involving freedom of expression, legal obligations, public interest, or the establishment, exercise, or defense of legal claims. Controllers must therefore assess each request against the applicable conditions and exceptions.
Question 187: Which circumstance is most relevant when determining whether a Data Protection Officer must be designated under the GDPR?
- Whether the organization has more than ten employees
- Whether the organization sells products online
- Whether core activities consist of processing that requires regular and systematic monitoring of individuals on a large scale
- Whether the organization has customers outside Europe
Correct Answer: 3. Whether core activities consist of processing that requires regular and systematic monitoring of individuals on a large scale
Explanation:
Article 37 identifies circumstances in which controllers and processors must designate a Data Protection Officer. One important circumstance is where the core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale. Another applies where core activities involve large-scale processing of special categories of personal data or certain criminal-conviction data. The obligation is therefore not determined simply by employee count, online sales, or having international customers. Organizations should evaluate the nature, scope, context, and purposes of their core processing activities against the GDPR’s DPO requirements.
Question 188: What is the main function of a supervisory authority under the GDPR?
- To operate every private company’s security infrastructure
- To establish commercial prices for controllers
- To provide marketing approval for all European businesses
- To monitor and enforce application of the GDPR within its jurisdiction**
Correct Answer: 4. To monitor and enforce application of the GDPR within its jurisdiction
Explanation:
Supervisory authorities are independent public authorities responsible for monitoring and enforcing the application of the GDPR within their respective jurisdictions. Their powers can include investigating complaints, obtaining information, conducting audits, ordering controllers or processors to comply with GDPR requirements, and imposing administrative fines where appropriate. Supervisory authorities also cooperate with one another under the GDPR’s cooperation and consistency mechanisms. Their role is distinct from the internal compliance responsibilities of controllers and processors. Organizations remain responsible for complying with the Regulation even when they have not been contacted or investigated by a supervisory authority.
Question 189: Which statement correctly describes the GDPR’s one-month period for responding to an individual’s rights request?
- The controller generally has one month from receipt of the request, with a possible extension of up to two further months for complex or numerous requests
- The controller always has exactly 90 days
- The controller must respond within seven calendar days
- The controller can delay the response indefinitely if identity verification is requested
Correct Answer: 1. The controller generally has one month from receipt of the request, with a possible extension of up to two further months for complex or numerous requests
Explanation:
Under Article 12, a controller generally must provide information on action taken on an individual’s request under Articles 15 to 22 without undue delay and in any event within one month of receiving the request. That period may be extended by up to two further months when necessary because of the complexity and number of requests. The controller must inform the individual of the extension and the reasons for the delay within the initial one-month period. Organizations should therefore maintain procedures for logging requests, verifying identity where appropriate, assessing complexity, and ensuring that statutory response deadlines are monitored.
Question 190: Which statement best describes a joint controller relationship under the GDPR?
- Two organizations jointly determine the purposes and means of processing
- One organization processes data only under another organization’s instructions
- A processor provides technical services without determining processing purposes
- An individual decides how a company processes customer data
Correct Answer: 1. Two organizations jointly determine the purposes and means of processing
Explanation:
Joint controllers exist where two or more controllers jointly determine the purposes and means of processing personal data. Article 26 requires joint controllers to transparently determine their respective responsibilities for complying with GDPR obligations, particularly regarding individuals’ rights and information requirements. The arrangement should reflect the parties’ actual roles rather than simply relying on contractual labels. A processor, by contrast, generally processes personal data on behalf of a controller and according to documented instructions. Correctly identifying controller, joint-controller, and processor roles is important because it determines which GDPR obligations apply to each organization.
Question 191: Which of the following is an example of an appropriate technical measure for protecting personal data?
- Publishing internal passwords on a noticeboard
- Removing all authentication requirements
- Encrypting personal data where appropriate to the risks
- Allowing every employee unrestricted database access
Correct Answer: 3. Encrypting personal data where appropriate to the risks
Explanation:
Article 32 requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Encryption can be an important technical measure because it can reduce the consequences of unauthorized access to personal data. The GDPR does not prescribe one identical security configuration for every organization. Instead, measures should take account of factors such as the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks to individuals. Other measures can include access controls, resilience, testing, and procedures for restoring availability after incidents.
Question 192: Which situation can make consent unsuitable as the lawful basis for processing?
- The individual can freely refuse without disadvantage
- The organization provides clear information before requesting consent
- The individual can withdraw consent easily
- There is a clear imbalance between the parties that prevents consent from being genuinely freely given**
Correct Answer: 4. There is a clear imbalance between the parties that prevents consent from being genuinely freely given
Explanation:
Consent must be freely given under the GDPR. Where there is a clear imbalance between the individual and the controller, particularly in relationships such as certain public-authority or employment contexts, consent may not provide a valid lawful basis if the individual cannot genuinely refuse or withdraw without disadvantage. The assessment depends on the circumstances rather than merely the existence of a formal consent checkbox. Controllers should consider whether the individual has a real choice and whether refusing consent could produce negative consequences. Where consent is not genuinely voluntary, another appropriate Article 6 lawful basis may need to be identified.
Question 193: What is one purpose of the GDPR’s requirement for appropriate technical and organizational measures?
- To guarantee that no data breach can ever occur
- To ensure a level of security appropriate to the risk
- To eliminate all business processing activities
- To require every organization to use identical security technology
Correct Answer: 2. To ensure a level of security appropriate to the risk
Explanation:
The GDPR follows a risk-based approach to security. Article 32 requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The assessment can consider risks such as accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data. Measures may include pseudonymisation, encryption, confidentiality and resilience controls, restoration capabilities, and regular testing of security measures. The GDPR does not require every organization to use identical technologies. Instead, organizations should select safeguards that are appropriate to their processing activities and the risks they create.
Question 194: Which GDPR mechanism is designed to facilitate consistency among supervisory authorities when applying the Regulation?
- The consistency mechanism involving the European Data Protection Board
- The commercial licensing mechanism
- The employee consultation mechanism
- The product certification mechanism
Correct Answer: 1. The consistency mechanism involving the European Data Protection Board
Explanation:
The GDPR establishes cooperation and consistency mechanisms to promote consistent application across the European Union. The European Data Protection Board plays a central role in this framework, including issuing guidelines, recommendations, and best practices and adopting binding decisions in specified circumstances. The consistency mechanism can become relevant where supervisory authorities need to resolve disagreements or ensure that important matters are handled consistently. This framework supports harmonized interpretation and enforcement while preserving the responsibilities of national supervisory authorities. Organizations operating across multiple jurisdictions should therefore consider both local supervisory authority requirements and the broader consistency framework.
Question 195: Which of the following is a valid example of processing necessary for compliance with a legal obligation under Article 6?
- Sending unrelated promotional messages because the company prefers to do so
- Collecting information required by applicable tax law
- Retaining every customer record forever
- Monitoring employees for entertainment purposes
Correct Answer: 2. Collecting information required by applicable tax law
Explanation:
Article 6(1)(c) permits processing when it is necessary for compliance with a legal obligation to which the controller is subject. A typical example is processing information required by applicable tax, accounting, employment, or regulatory law. The obligation must arise from applicable law rather than simply from the controller’s internal preference. The processing must also be necessary for compliance with that obligation. Organizations should identify the relevant legal requirement and ensure that the data collected and retained is appropriate for fulfilling it. Other processing activities, such as unrelated marketing, cannot automatically rely on the legal-obligation basis merely because an organization considers them useful.
Question 196: Which statement about administrative fines under the GDPR is accurate?
- Fines are automatically imposed for every minor violation
- Only individuals can receive GDPR administrative fines
- Administrative fines can be imposed on controllers or processors in accordance with the GDPR and must be determined with regard to specified factors
- Supervisory authorities have no enforcement powers
Correct Answer: 3. Administrative fines can be imposed on controllers or processors in accordance with the GDPR and must be determined with regard to specified factors
Explanation:
The GDPR empowers supervisory authorities to impose administrative fines on controllers and processors in appropriate circumstances. Article 83 identifies factors relevant to determining whether and how a fine should be imposed, including the nature, gravity, and duration of the infringement, its intentional or negligent character, steps taken to mitigate damage, technical and organizational measures implemented, and other relevant circumstances. The Regulation establishes maximum fine levels for different categories of infringements. Fines are therefore part of a broader enforcement framework and are not automatically imposed for every compliance issue. Supervisory authorities exercise their powers according to the GDPR’s requirements and applicable procedural rules.
Question 197: An individual objects to processing of their personal data for direct marketing. What is the general GDPR rule?
- The controller may continue the marketing indefinitely
- The objection is effective only if approved by a court
- The controller must generally stop processing the personal data for direct marketing purposes
- The individual must first delete their account
Correct Answer: 3. The controller must generally stop processing the personal data for direct marketing purposes
Explanation:
The GDPR gives individuals a specific and strong right to object to processing of their personal data for direct marketing purposes. Where an individual objects to processing for direct marketing, the personal data should no longer be processed for those purposes. This applies to direct marketing-related profiling as well. The controller should provide information about the right to object clearly and separately from other information. Unlike some other objection situations, the controller does not generally have the option of demonstrating overriding legitimate grounds to continue direct marketing after a valid objection. Effective opt-out mechanisms are therefore an important part of compliant marketing practices.
Question 198: Which statement best describes an adequacy decision under the GDPR?
- It automatically applies to every country in the world
- It is a decision recognizing that a third country, territory, specified sector, or international organization provides an adequate level of protection
- It is a contract between every controller and processor
- It replaces all GDPR security obligations
Correct Answer: 2. It is a decision recognizing that a third country, territory, specified sector, or international organization provides an adequate level of protection
Explanation:
An adequacy decision under Article 45 allows personal data to be transferred to a recognized third country, territory, specified sector, or international organization where the European Commission has determined that an adequate level of protection is provided. Where a valid adequacy decision applies to the relevant transfer, additional transfer safeguards under Articles 46 and 49 are generally not required for that transfer mechanism. Adequacy does not mean that the receiving organization is exempt from all GDPR obligations, nor does it remove the need to comply with other applicable requirements. Organizations should verify the scope and continuing validity of the relevant adequacy decision.
Question 199: Which GDPR concept requires organizations to consider privacy safeguards when determining what personal data should be accessible by default?
- Privacy by default
- Data portability
- Supervisory cooperation
- Administrative enforcement
Correct Answer: 1. Privacy by default
Explanation:
Privacy by default requires controllers to implement appropriate technical and organizational measures so that, by default, only personal data necessary for each specific processing purpose is processed. This includes considerations such as the amount of data collected, the extent of processing, the period of storage, and accessibility. Systems should not automatically expose more personal data than is necessary simply because broader access is technically convenient. Privacy by default works together with privacy by design under Article 25. The controller should build appropriate privacy settings and safeguards into systems and processes rather than relying solely on individuals to configure protective settings themselves.
Question 200: Which statement best reflects the GDPR’s approach to children’s consent for information society services?
- Children can never provide consent under any circumstances
- Consent is always valid regardless of the child’s age
- The GDPR requires parental authorization for every type of processing involving children
- Where processing is based on consent and relates to an information society service offered directly to a child, Article 8 establishes a specific age threshold and Member States may set a lower age within the permitted range**
Correct Answer: 4. Where processing is based on consent and relates to an information society service offered directly to a child, Article 8 establishes a specific age threshold and Member States may set a lower age within the permitted range
Explanation:
Article 8 establishes specific rules for situations where processing is based on consent and an information society service is offered directly to a child. The GDPR sets the threshold at 16 years, while allowing Member States to provide by law for a lower age, provided it is not below 13. Where the child is below the applicable threshold, consent must generally be given or authorized by the holder of parental responsibility, taking account of available technology. The rule applies to the specific context described by Article 8 and does not mean that parental authorization is automatically required for every processing activity involving children.