IAPP CIPP-E Practice Test Questions and Exam Dumps Part 11 Q201-220

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 201: Which GDPR principle requires personal data to be collected for specified, explicit, and legitimate purposes?

  1. Purpose limitation
  2. Accuracy
  3. Storage limitation
  4. Accountability

Correct Answer: 1. Purpose limitation

Explanation:
The purpose limitation principle requires personal data to be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Controllers should therefore identify and communicate the purposes of processing before or when data is collected. When considering further processing, organizations may need to assess compatibility under Article 6(4), taking into account factors such as the relationship between the original and new purposes, the context of collection, the nature of the data, and potential consequences for individuals. Purpose limitation helps prevent organizations from using personal data for unrelated purposes without an appropriate legal justification.

Question 202: Which GDPR right allows an individual to obtain confirmation as to whether personal data concerning them is being processed?

  1. Right to object
  2. Right of access
  3. Right to erasure
  4. Right to data portability

Correct Answer: 2. Right of access

Explanation:
The right of access under Article 15 allows an individual to obtain confirmation as to whether personal data concerning them is being processed. Where processing occurs, the individual can generally obtain access to the personal data and information about matters such as the purposes of processing, categories of personal data, recipients, retention periods, and available rights. The controller must generally respond within one month, subject to the GDPR’s rules concerning extensions and other circumstances. The right of access is broader than simply receiving a copy of personal data because it also provides transparency about how and why the information is processed.

Question 203: A company collects customer information directly from customers. Which GDPR article primarily establishes the information that must be provided at collection?

  1. Article 32
  2. Article 45
  3. Article 13
  4. Article 83

Correct Answer: 3. Article 13

Explanation:
Article 13 applies when personal data is collected directly from the data subject. It requires controllers to provide specified information at the time the personal data is obtained. This can include the controller’s identity and contact details, the purposes and legal basis of processing, recipients, retention information, data-subject rights, and information concerning international transfers where applicable. Providing this information supports the GDPR principles of transparency and fairness. Article 14 addresses situations where personal data has not been obtained from the individual. Organizations should therefore determine whether data was collected directly or indirectly when identifying the applicable information requirements.

Question 204: Which statement about the GDPR’s right to object to processing based on legitimate interests is generally correct?

  1. An objection can never be made against legitimate-interest processing
  2. The controller must always erase all data immediately
  3. The individual must obtain a court order before objecting
  4. The controller may continue processing if it demonstrates compelling legitimate grounds that override the individual’s interests, rights, and freedoms, subject to applicable exceptions**

Correct Answer: 4. The controller may continue processing if it demonstrates compelling legitimate grounds that override the individual’s interests, rights, and freedoms, subject to applicable exceptions

Explanation:
Under Article 21, individuals can object to processing based on grounds relating to their particular situation when processing is based on certain legal grounds, including legitimate interests or a task carried out in the public interest. The controller must generally stop processing unless it demonstrates compelling legitimate grounds that override the individual’s interests, rights, and freedoms, or unless processing is required for the establishment, exercise, or defense of legal claims. Direct marketing is treated differently: an objection to direct marketing generally requires the controller to stop processing for that purpose. The specific legal basis therefore matters when assessing an objection.

Question 205: Which of the following is an example of personal data under the GDPR?

  1. A truly anonymous statistical dataset that cannot reasonably be linked to individuals
  2. An individual’s identifiable employee identification number
  3. A completely fictional name with no connection to a person
  4. A permanently anonymized dataset

Correct Answer: 2. An individual’s identifiable employee identification number

Explanation:
Personal data includes information relating to an identified or identifiable natural person. An employee identification number can qualify as personal data when it can be linked to a particular employee, even if the number does not directly reveal the person’s name. Identification can occur through information held by the controller or through information reasonably available to it. By contrast, genuinely anonymized information that can no longer be linked to an identifiable individual falls outside the GDPR’s definition of personal data. Organizations should therefore assess whether information can reasonably be connected to a natural person rather than relying only on whether a person’s name appears in the dataset.

Question 206: Which circumstance can constitute a lawful basis for processing personal data under Article 6?

  1. The controller considers the data interesting
  2. The processing is necessary for performance of a contract with the individual
  3. The organization has stored the data for a long time
  4. The data has commercial value

Correct Answer: 2. The processing is necessary for performance of a contract with the individual

Explanation:
Article 6 provides several lawful bases for processing personal data. One is that processing is necessary for the performance of a contract to which the individual is party or for taking steps at the individual’s request before entering into a contract. The controller must assess whether the processing is genuinely necessary for the contractual purpose rather than merely useful or convenient. Other Article 6 bases include consent, legal obligation, vital interests, public task, and legitimate interests where applicable. Identifying the correct lawful basis should occur before processing and should be reflected appropriately in the organization’s privacy information and accountability documentation.

Question 207: What is the primary purpose of a Data Protection Impact Assessment?

  1. To calculate an organization’s annual revenue
  2. To replace all security testing
  3. To identify and address risks to individuals arising from high-risk processing
  4. To automatically authorize international transfers

Correct Answer: 3. To identify and address risks to individuals arising from high-risk processing

Explanation:
A Data Protection Impact Assessment is a preventive risk-management tool required where processing is likely to result in a high risk to individuals’ rights and freedoms. Article 35 requires the assessment to describe the processing and its purposes, evaluate necessity and proportionality, assess risks to individuals, and identify measures intended to address those risks. A DPIA does not itself authorize international transfers or replace all other compliance and security activities. Its purpose is to help controllers identify and mitigate privacy risks before processing begins. Where significant residual risk remains despite mitigation, prior consultation with the supervisory authority may be required under Article 36.

Question 208: Which organization is responsible for issuing guidelines, recommendations, and best practices to promote consistent application of the GDPR?

  1. The European Data Protection Board
  2. The European Central Bank
  3. The European Court of Auditors
  4. The European Investment Bank

Correct Answer: 1. The European Data Protection Board

Explanation:
The European Data Protection Board, or EDPB, contributes to the consistent application of the GDPR across the European Union. Its responsibilities include providing guidelines, recommendations, and best practices on important data-protection issues. The EDPB also has roles in resolving certain disputes between supervisory authorities and adopting binding decisions in specified circumstances. It is composed primarily of representatives of national supervisory authorities, together with the European Data Protection Supervisor in the circumstances established by EU law. The EDPB does not replace national supervisory authorities; rather, it works within the GDPR’s cooperation and consistency framework to support harmonized interpretation and enforcement.

Question 209: Which measure is most directly associated with data protection by default?

  1. Making all collected data publicly accessible
  2. Automatically retaining all information indefinitely
  3. Configuring systems so that only the personal data necessary for each purpose is processed by default
  4. Requiring individuals to manually disable every privacy feature

Correct Answer: 3. Configuring systems so that only the personal data necessary for each purpose is processed by default

Explanation:
Article 25 requires controllers to implement data protection by design and by default. Privacy by default means that, by default, only personal data that is necessary for each specific processing purpose should be processed. This can concern the amount of data collected, the extent of processing, the retention period, and accessibility. Appropriate settings should therefore limit unnecessary exposure rather than requiring individuals to take additional steps to protect their information. Controllers must determine suitable technical and organizational measures based on factors such as the state of the art, implementation costs, the nature and risks of processing, and the purposes involved.

Question 210: Which requirement applies to processors under Article 28 when engaging another processor?

  1. The processor can appoint any subprocessor without informing the controller
  2. The processor must obtain the required authorization from the controller before engaging a subprocessor
  3. The subprocessor automatically becomes the controller
  4. The controller loses responsibility for all processing

Correct Answer: 2. The processor must obtain the required authorization from the controller before engaging a subprocessor

Explanation:
Article 28 establishes requirements for processors that engage another processor, commonly called a subprocessor. The processor must generally obtain prior specific or general written authorization from the controller, depending on the arrangement. Where general authorization is used, the processor must inform the controller about intended changes and provide an opportunity to object where required. The processor must also impose data-protection obligations on the subprocessor that provide an equivalent level of protection required under the controller-processor arrangement. The original processor remains responsible to the controller for the subprocessor’s performance of those obligations under the GDPR framework.

Question 211: Which GDPR requirement is most closely associated with maintaining appropriate records that demonstrate compliance?

  1. Accountability
  2. Data portability
  3. Purpose limitation
  4. Direct marketing

Correct Answer: 1. Accountability

Explanation:
The accountability principle requires controllers to be responsible for compliance with the GDPR and able to demonstrate that compliance. Appropriate records and documentation can be important evidence, including records of processing activities, policies, contracts, risk assessments, DPIAs, training, security measures, and procedures for handling data-subject rights. Accountability is not limited to maintaining one particular document; it involves establishing governance and controls that allow an organization to demonstrate how its obligations are being met. The documentation should be appropriate to the organization’s processing activities and risks. A strong accountability framework also helps organizations identify gaps and respond effectively to regulatory inquiries.

Question 212: Which type of processing generally requires a controller to provide information under Article 14 rather than Article 13?

  1. Personal data collected directly from the individual
  2. Personal data collected from another source rather than directly from the individual
  3. Data collected exclusively from the controller’s own employees
  4. Data that has already been erased

Correct Answer: 2. Personal data collected from another source rather than directly from the individual

Explanation:
Article 14 applies when personal data has not been obtained from the data subject. In such circumstances, the controller must provide specified information about the processing, including the controller’s identity, purposes, legal basis, categories of personal data, recipients, retention, rights, and source of the personal data, subject to applicable requirements and exceptions. Article 13 applies when data is collected directly from the individual. The distinction is important because the timing and content of information requirements can differ. Controllers using information obtained from public sources, data brokers, partners, or other third parties should therefore assess whether Article 14 applies.

Question 213: Which of the following is a special category of personal data under Article 9?

  1. A customer’s delivery preference
  2. A company’s registered office address
  3. An individual’s health information
  4. A product serial number unrelated to an individual

Correct Answer: 3. An individual’s health information

Explanation:
Health data is included among the special categories of personal data listed in Article 9. Other special categories include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for uniquely identifying a person, and data concerning sex life or sexual orientation. Processing special-category data is generally prohibited unless one of the specific Article 9 conditions applies. In addition, the controller generally needs an appropriate Article 6 lawful basis. The enhanced protection reflects the potentially sensitive nature of these categories and the potential consequences of their misuse or unauthorized disclosure.

Question 214: Which statement best describes the GDPR’s requirement for fairness in processing?

  1. Controllers may process data in any manner if they provide a privacy notice
  2. Fairness requires processing to avoid unjustified adverse or unexpected treatment of individuals
  3. Fairness applies only to children’s data
  4. Fairness is relevant only when a supervisory authority imposes a fine

Correct Answer: 2. Fairness requires processing to avoid unjustified adverse or unexpected treatment of individuals

Explanation:
Fairness is part of the core Article 5 principle requiring processing to be lawful, fair, and transparent. Fair processing involves considering how the processing affects individuals and whether they could reasonably expect it in the circumstances. A controller should not use personal data in ways that unjustifiably disadvantage, deceive, or otherwise negatively affect individuals. Transparency supports fairness but does not automatically make unfair processing lawful. Fairness can be particularly important when organizations use profiling, make decisions affecting individuals, or process data in ways that differ from what people would reasonably expect based on the context in which their information was collected.

Question 215: What is the main purpose of standard contractual clauses in international data transfers?

  1. To provide contractual safeguards for certain transfers of personal data to third countries
  2. To eliminate the need for any security measures
  3. To replace all national supervisory authorities
  4. To establish employment contracts for EU workers

Correct Answer: 1. To provide contractual safeguards for certain transfers of personal data to third countries

Explanation:
Standard Contractual Clauses are contractual safeguards recognized by the GDPR for certain transfers of personal data to third countries or international organizations. The clauses establish obligations for the parties involved in the transfer and are intended to provide appropriate protection for personal data outside the European Economic Area framework. Their use does not automatically resolve every transfer issue. Organizations must consider the circumstances of the transfer and comply with applicable GDPR requirements, including relevant safeguards and assessments. Other transfer mechanisms, such as adequacy decisions, binding corporate rules, and certain derogations, may also apply depending on the circumstances.

Question 216: Which statement about a personal data breach is correct under the GDPR?

  1. A breach occurs only when personal data is published online
  2. A breach can include accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal data
  3. A breach always requires that an employee acted intentionally
  4. A breach is limited to theft of physical documents

Correct Answer: 2. A breach can include accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal data

Explanation:
The GDPR defines a personal data breach broadly as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed. A breach therefore does not require malicious intent or publication on the internet. Examples can include sending personal data to the wrong recipient, losing an unencrypted device, unauthorized access to a database, or accidental deletion where personal data is affected. Controllers should have procedures for detecting, assessing, documenting, and responding to breaches because the GDPR imposes specific notification requirements depending on the risk.

Question 217: Which GDPR mechanism can permit international transfers when a third country has been formally recognized as providing an adequate level of protection?

  1. An adequacy decision
  2. A data-subject access request
  3. A processor’s internal policy
  4. A retention schedule

Correct Answer: 1. An adequacy decision

Explanation:
An adequacy decision under Article 45 allows personal data to be transferred to a third country, territory, specified sector, or international organization where the European Commission has determined that an adequate level of protection is provided. The decision applies within its defined scope and can be subject to review or modification. Where a valid adequacy decision covers the relevant transfer, the organization generally does not need to rely on an Article 46 transfer safeguard for that same transfer mechanism. Organizations should still comply with other GDPR obligations applicable to the processing and verify that the transfer falls within the scope of the relevant adequacy decision.

Question 218: Which statement about the GDPR right to rectification is correct?

  1. Individuals can request correction of inaccurate personal data
  2. Individuals may only request deletion and never correction
  3. Rectification applies only to paper records
  4. Controllers may always refuse to correct inaccurate information

Correct Answer: 1. Individuals can request correction of inaccurate personal data

Explanation:
Article 16 provides individuals with the right to obtain rectification of inaccurate personal data concerning them without undue delay. Individuals may also have the right to have incomplete personal data completed, taking into account the purposes of the processing. Rectification supports the GDPR’s accuracy principle and helps ensure that decisions and other processing activities are based on reliable information. Controllers should maintain processes that allow requests to be received, assessed, and implemented appropriately. The right is distinct from erasure because the objective is to correct or complete the information rather than necessarily remove it from the controller’s systems.

Question 219: Which factor is particularly relevant when determining whether a processing activity is likely to result in a high risk requiring a DPIA?

  1. Whether the company has a large advertising budget
  2. Whether the organization’s website has a modern design
  3. The nature, scope, context, and purposes of the processing and its potential risks to individuals
  4. Whether the organization has operated for more than five years

Correct Answer: 3. The nature, scope, context, and purposes of the processing and its potential risks to individuals

Explanation:
The GDPR’s DPIA requirement is based on risk to the rights and freedoms of natural persons. When assessing whether processing is likely to result in high risk, controllers should consider the nature, scope, context, and purposes of the processing. Factors such as systematic monitoring, large-scale processing of sensitive information, or innovative technologies can contribute to risk depending on the circumstances. A DPIA should not be triggered simply by unrelated business characteristics such as company age or advertising expenditure. The assessment should focus on the processing itself and the potential consequences for individuals, allowing appropriate safeguards and mitigation measures to be identified.

Question 220: Which statement best describes the role of the European Data Protection Board in relation to GDPR consistency?

  1. It directly manages every organization’s daily privacy operations
  2. It replaces all national supervisory authorities
  3. It determines the commercial pricing of privacy services
  4. It promotes consistent application of EU data-protection rules through guidance, cooperation, and specified binding decisions**

Correct Answer: 4. It promotes consistent application of EU data-protection rules through guidance, cooperation, and specified binding decisions

Explanation:
The European Data Protection Board supports consistent application of EU data-protection rules through a range of functions established by the GDPR. It issues guidelines, recommendations, and best practices, promotes cooperation among supervisory authorities, and can adopt binding decisions in specific circumstances established by the Regulation. National supervisory authorities continue to perform their supervisory and enforcement responsibilities within their jurisdictions. The EDPB therefore operates as part of a broader European data-protection governance structure rather than replacing national authorities or directly managing individual organizations. Its work helps reduce divergent interpretations and supports greater consistency in GDPR application.