IAPP CIPP-E Practice Test Questions and Exam Dumps Part 18 Q341-360

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 341: Under Article 24 of the GDPR, what is a key responsibility of the controller?

  1. To ensure and be able to demonstrate that processing is performed in accordance with the GDPR
  2. To obtain approval from every data subject before processing
  3. To transfer all processing activities to a processor
  4. To appoint a supervisory authority for its organisation

Correct Answer: 1. To ensure and be able to demonstrate that processing is performed in accordance with the GDPR

Explanation: Article 24 establishes the controller’s responsibility for implementing appropriate technical and organisational measures to ensure and demonstrate that processing is performed in accordance with the GDPR. These measures must take into account the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of individuals. Where proportionate, controllers should review and update those measures. Adherence to approved codes of conduct or certification mechanisms may be used as an element to demonstrate compliance. The provision reflects the GDPR’s accountability principle: controllers are responsible not only for compliance but also for being able to demonstrate that compliance.

Question 342: What does Article 26 of the GDPR require joint controllers to determine between themselves?

  1. The nationality of all data subjects
  2. Their respective responsibilities for compliance with GDPR obligations
  3. The amount of every administrative fine
  4. The identity of the competent court in every Member State

Correct Answer: 2. Their respective responsibilities for compliance with GDPR obligations

Explanation: Article 26 applies where two or more controllers jointly determine the purposes and means of processing and therefore qualify as joint controllers. They must transparently determine their respective responsibilities for compliance with GDPR obligations, particularly regarding the exercise of data subject rights and transparency requirements under Articles 13 and 14. The arrangement should reflect the respective roles and relationships of the joint controllers toward data subjects. The essence of the arrangement must be made available to the data subjects. Importantly, the GDPR does not allow joint controllers to use their internal allocation of responsibilities to remove the data subject’s rights against them; each data subject may exercise rights in relation to each controller.

Question 343: Which requirement is associated with Article 29 of the GDPR?

  1. Persons acting under the authority of a controller or processor must process personal data only on instructions, unless required by Union or Member State law
  2. Every employee must obtain certification before accessing personal data
  3. Every processor becomes a joint controller automatically
  4. Controllers must publish all employee instructions online

Correct Answer: 1. Persons acting under the authority of a controller or processor must process personal data only on instructions, unless required by Union or Member State law

Explanation: Article 29 establishes an important organisational control over processing. Persons acting under the authority of the controller or processor who have access to personal data must not process that data except on instructions from the controller, unless Union or Member State law requires them to do so. This helps ensure that access to personal data is governed by defined authority and lawful instructions rather than individual discretion. In practice, organisations commonly support this requirement through internal policies, role-based access controls, confidentiality arrangements, training, and documented instructions. The provision applies to persons under the authority of both controllers and processors.

Question 344: What must a controller generally communicate to the supervisory authority when a personal data breach is subject to Article 33?

  1. The complete employment records of every affected employee
  2. Only the name of the organisation’s DPO
  3. The nature of the personal data breach and relevant information specified by Article 33
  4. A guarantee that no data subject was affected

Correct Answer: 3. The nature of the personal data breach and relevant information specified by Article 33

Explanation: Article 33 requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification must contain specified information, including the nature of the breach, categories and approximate numbers of affected data subjects and records, likely consequences, and measures taken or proposed to address the breach. Where all information cannot be supplied at once, it may be provided in phases without undue further delay. Processors have a separate duty to notify the controller without undue delay.

Question 345: When is a controller generally required to communicate a personal data breach to affected data subjects under Article 34?

  1. Whenever any breach occurs, regardless of risk
  2. When the breach is likely to result in a high risk to the rights and freedoms of natural persons
  3. Only when the supervisory authority imposes a fine
  4. Only when the breach involves paper records

Correct Answer: 2. When the breach is likely to result in a high risk to the rights and freedoms of natural persons

Explanation: Article 34 requires a controller to communicate a personal data breach to the affected data subject without undue delay when the breach is likely to result in a high risk to their rights and freedoms. The communication must describe the nature of the breach in clear and plain language and provide relevant information such as likely consequences and measures taken or proposed to address the breach. Article 34 also provides circumstances where individual communication is not required, including where appropriate technical and organisational measures have rendered the data unintelligible, such as encryption, or where subsequent measures ensure that the high risk is no longer likely to materialise.

Question 346: Which circumstance can trigger the requirement to conduct a DPIA under Article 35?

  1. Any processing of a single email address
  2. Processing likely to result in a high risk to the rights and freedoms of natural persons
  3. Every processing operation carried out by a small organisation
  4. Any processing involving a processor

Correct Answer: 2. Processing likely to result in a high risk to the rights and freedoms of natural persons

Explanation: Article 35 requires a data protection impact assessment where a type of processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. The GDPR identifies examples including systematic and extensive evaluation of personal aspects based on automated processing, processing on a large scale of special categories of data or criminal-conviction data, and systematic monitoring of a publicly accessible area on a large scale. The DPIA should assess the necessity and proportionality of processing, risks to individuals, and measures addressing those risks. It is therefore a risk-management tool rather than a general requirement for every processing activity.

Question 347: Under Article 36, what is the purpose of prior consultation with a supervisory authority?

  1. To obtain consultation where a DPIA indicates that processing would result in a high risk that cannot be sufficiently mitigated
  2. To obtain permission for every international data transfer
  3. To replace the controller’s obligation to conduct a DPIA
  4. To avoid implementing security measures

Correct Answer: 1. To obtain consultation where a DPIA indicates that processing would result in a high risk that cannot be sufficiently mitigated

Explanation: Article 36 establishes prior consultation where the controller’s DPIA indicates that processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. Consultation is particularly relevant where the controller considers that the identified risks cannot be sufficiently addressed through available measures. The supervisory authority may provide written advice and may use its powers under Article 58. The purpose is preventive: it allows the authority to become involved before high-risk processing begins. Prior consultation does not replace the controller’s responsibility for assessing risks, implementing safeguards, or complying with the other GDPR requirements.

Question 348: Which condition is relevant when determining whether an organisation must designate a data protection officer under Article 37?

  1. The organisation has exactly ten employees
  2. The organisation’s website uses cookies
  3. The core activities consist of processing requiring regular and systematic monitoring of data subjects on a large scale
  4. The organisation has customers outside the EU

Correct Answer: 3. The core activities consist of processing requiring regular and systematic monitoring of data subjects on a large scale

Explanation: Article 37 requires designation of a data protection officer in specified circumstances. One trigger is where the core activities of the controller or processor consist of processing operations that, by their nature, scope, or purposes, require regular and systematic monitoring of data subjects on a large scale. Another trigger concerns core activities involving large-scale processing of special categories of personal data or certain criminal-conviction and offence data. Public authorities and bodies are generally subject to a separate mandatory DPO requirement, except courts acting in their judicial capacity. The DPO requirement therefore depends on the nature and scale of processing rather than simply the number of employees.

Question 349: Which of the following is a task of the data protection officer under Article 39?

  1. Determining the amount of administrative fines
  2. Advising the controller or processor and employees on their GDPR obligations
  3. Replacing the supervisory authority
  4. Approving all contracts signed by the organisation

Correct Answer: 2. Advising the controller or processor and employees on their GDPR obligations

Explanation: Article 39 identifies several tasks for the data protection officer. These include informing and advising the controller or processor and employees who carry out processing about their obligations under the GDPR and other applicable data protection law. The DPO also monitors compliance, including allocation of responsibilities, awareness-raising, training, and audits; provides advice regarding DPIAs and monitors their performance; cooperates with the supervisory authority; and acts as the contact point for the authority on processing-related issues. The DPO does not replace management or the supervisory authority. Responsibility for compliance remains with the controller or processor.

Question 350: What is a key requirement concerning the independence of a DPO under Article 38?

  1. The DPO must receive instructions on how to perform DPO tasks
  2. The DPO may be dismissed or penalised for performing DPO tasks
  3. The DPO must report directly to every employee
  4. The DPO must not receive any resources

Correct Answer: 2. The DPO may be dismissed or penalised for performing DPO tasks

Explanation: Article 38 protects the independence of the DPO. The controller and processor must ensure that the DPO does not receive instructions regarding the exercise of the DPO’s tasks. The DPO must not be dismissed or penalised by the controller or processor for performing those tasks. The DPO should report directly to the highest management level and must be appropriately involved in all issues relating to protection of personal data. The organisation must also provide resources necessary to maintain expertise and perform the tasks. These safeguards are intended to allow the DPO to give independent advice and monitor compliance without improper organisational pressure.

Question 351: Which statement best describes the GDPR’s approach to international transfers under Article 44?

  1. Transfers outside the EEA are always prohibited
  2. Transfers to third countries may take place only when the GDPR’s transfer requirements are satisfied
  3. Any company may transfer personal data internationally without safeguards
  4. Transfers are governed exclusively by the law of the destination country

Correct Answer: 2. Transfers to third countries may take place only when the GDPR’s transfer requirements are satisfied

Explanation: Article 44 establishes the general principle governing transfers of personal data to third countries or international organisations. Such transfers, including onward transfers, may occur only where the conditions in Chapter V of the GDPR are complied with, ensuring that the level of protection guaranteed by the Regulation is not undermined. The relevant mechanisms include adequacy decisions under Article 45, appropriate safeguards under Article 46, and specified derogations under Article 49. Transfer analysis therefore requires consideration of the particular legal mechanism being relied upon. The mere fact that the recipient is a legitimate organisation or that the destination country has its own privacy law does not automatically satisfy Chapter V.

Question 352: Which of the following is an example of an appropriate safeguard under Article 46?

  1. An adequacy decision under Article 45
  2. Standard contractual clauses adopted in accordance with the GDPR
  3. A verbal promise from an employee
  4. A data subject’s nationality

Correct Answer: 2. Standard contractual clauses adopted in accordance with the GDPR

Explanation: Article 46 permits transfers to third countries where appropriate safeguards are provided and enforceable data subject rights and effective legal remedies are available. One recognised safeguard is standard data protection clauses adopted by the European Commission. Other mechanisms include binding corporate rules, approved codes of conduct with binding commitments, approved certification mechanisms with binding commitments, and certain legally binding instruments between public authorities or bodies. Appropriate safeguards generally do not require prior specific authorisation from a supervisory authority where the relevant GDPR conditions are satisfied. The transfer mechanism must be analysed together with the particular circumstances and any applicable requirements concerning the protection of individuals.

Question 353: What is the main function of an adequacy decision under Article 45?

  1. To declare that a third country or organisation provides an adequate level of data protection
  2. To impose an administrative fine on every foreign recipient
  3. To eliminate the need for any GDPR compliance within the EU
  4. To authorise all processing activities in the third country

Correct Answer: 1. To declare that a third country or organisation provides an adequate level of data protection

Explanation: Article 45 provides a transfer mechanism based on an adequacy decision adopted by the European Commission. Where the Commission has decided that a third country, a territory or specified sector within a third country, or an international organisation ensures an adequate level of protection, transfers to that destination can generally take place without the need for a separate Article 46 safeguard or Article 49 derogation for the transfer itself. Adequacy decisions are subject to review and may be amended, suspended, or repealed where developments affect the required level of protection. An adequacy decision concerns the protection of personal data, not blanket authorisation of all activities undertaken by an organisation.

Question 354: Which mechanism is specifically designed for transfers of personal data within a multinational corporate group under Article 47?

  1. Binding corporate rules
  2. Employment contracts
  3. Public registers
  4. National tax agreements

Correct Answer: 1. Binding corporate rules

Explanation: Article 47 recognises binding corporate rules as an appropriate safeguard for certain transfers of personal data to third countries or international organisations. These rules are intended for groups of undertakings or groups of enterprises engaged in a joint economic activity and must be legally binding and apply to and be enforced by every relevant member of the group, including employees. They must provide enforceable rights for data subjects and satisfy detailed content requirements, including information about processing, data subject rights, liability, complaint mechanisms, and cooperation with supervisory authorities. Binding corporate rules require approval through the GDPR’s supervisory authority framework before they can be relied upon as an appropriate safeguard.

Question 355: Which statement about Article 48 of the GDPR is correct?

  1. A judgment or administrative decision from a third-country authority automatically authorises a transfer
  2. A third-country authority’s decision requiring transfer may be recognised or enforceable only where based on an international agreement or other applicable legal ground
  3. Article 48 applies only to transfers between EU Member States
  4. Article 48 abolishes all international transfer safeguards

Correct Answer: 2. A third-country authority’s decision requiring transfer may be recognised or enforceable only where based on an international agreement or other applicable legal ground

Explanation: Article 48 addresses transfers or disclosures of personal data in response to a judgment of a court or tribunal or a decision of an administrative authority of a third country. Such a judgment or decision requiring a controller or processor to transfer or disclose personal data may be recognised or enforceable only if based on an international agreement, such as a mutual legal assistance treaty, or another applicable legal ground under Union or Member State law. The provision prevents a foreign authority’s demand from automatically becoming a lawful GDPR transfer mechanism. Controllers and processors must therefore examine the applicable international or domestic legal framework before making the disclosure.

Question 356: Which Article 49 mechanism may apply when a transfer to a third country is necessary to protect the vital interests of the data subject or another person and the data subject is physically or legally incapable of giving consent?

  1. A derogation based on vital interests
  2. A certification mechanism
  3. A DPO appointment
  4. A code of conduct

Correct Answer: 1. A derogation based on vital interests

Explanation: Article 49 contains specific derogations from the general transfer mechanisms in certain circumstances. One is where the transfer is necessary to protect the vital interests of the data subject or another person and the data subject is physically or legally incapable of giving consent. The derogations are exceptions to the general Chapter V framework and therefore must be applied according to their specific conditions. Other Article 49 situations include explicit consent in specified circumstances, contractual necessity in certain cases, important public interest, establishment or defence of legal claims, protection of vital interests, and limited transfers from public registers. Controllers should carefully document the applicable conditions.

Question 357: Which GDPR article addresses cooperation between supervisory authorities in relation to cross-border processing?

  1. Article 60
  2. Article 17
  3. Article 8
  4. Article 35

Correct Answer: 1. Article 60

Explanation: Article 60 sets out cooperation between the lead supervisory authority and other supervisory authorities concerned in cases involving cross-border processing. The lead authority communicates relevant information and submits a draft decision to the other concerned authorities. Those authorities can provide relevant and reasoned objections, and the GDPR establishes procedures for addressing such objections. This cooperation mechanism supports consistent and coordinated enforcement where processing affects individuals or establishments in multiple Member States. It operates within the broader one-stop-shop framework, which identifies a lead supervisory authority for qualifying cross-border processing while preserving the roles and rights of other concerned supervisory authorities.

Question 358: What is the role of the European Data Protection Board under the GDPR?

  1. It replaces all national supervisory authorities
  2. It ensures consistent application of the GDPR and performs tasks assigned by the Regulation
  3. It acts as the criminal court for data protection offences
  4. It directly manages every controller in the EU

Correct Answer: 2. It ensures consistent application of the GDPR and performs tasks assigned by the Regulation

Explanation: The European Data Protection Board, established by Article 68, contributes to the consistent application of the GDPR across the European Union. It is composed of the heads of the supervisory authorities of each Member State and the European Data Protection Supervisor, or their representatives as specified by the Regulation. The Board has numerous tasks under Article 70, including issuing guidelines, recommendations, and best practices, advising the European Commission on data protection matters, resolving certain disputes between supervisory authorities, and promoting cooperation. It does not replace national supervisory authorities. Instead, it provides an EU-level framework for consistency, cooperation, and coordinated interpretation.

Question 359: Under Article 63, what is the objective of the GDPR consistency mechanism?

  1. To ensure a consistent application of the GDPR
  2. To create a single private-sector regulator
  3. To prevent individuals from making complaints
  4. To remove national variations permitted by the GDPR

Correct Answer: 1. To ensure a consistent application of the GDPR

Explanation: Article 63 establishes the consistency mechanism with the objective of contributing to the consistent application of the GDPR throughout the Union. The mechanism is relevant to situations where supervisory authorities need a coordinated approach or where the GDPR assigns responsibilities to the European Data Protection Board. Depending on the issue, the process can involve opinions from the Board or binding decisions intended to resolve disagreements between supervisory authorities. The mechanism does not eliminate national supervisory authorities or prevent Member States from adopting national rules in areas where the GDPR permits them. Instead, it helps coordinate the application of common GDPR requirements across the EU.

Question 360: What does Article 95 provide concerning the relationship between the GDPR and the ePrivacy framework?

  1. The GDPR completely replaces all electronic communications privacy rules
  2. The GDPR does not impose additional obligations on certain processing already subject to specific obligations under the ePrivacy Directive where those obligations have the same objective
  3. The ePrivacy Directive automatically overrides the GDPR
  4. Electronic communications are excluded from the GDPR entirely

Correct Answer: 2. The GDPR does not impose additional obligations on certain processing already subject to specific obligations under the ePrivacy Directive where those obligations have the same objective

Explanation: Article 95 addresses the relationship between the GDPR and Directive 2002/58/EC, commonly known as the ePrivacy Directive. Where processing in connection with the provision of publicly available electronic communications services in public communications networks is subject to specific obligations under the ePrivacy Directive that have the same objective as obligations under the GDPR, the GDPR does not impose additional obligations on that processing to the extent addressed by the specific ePrivacy requirements. This is not a blanket exclusion of electronic communications from GDPR requirements. The interaction depends on the particular processing and whether the relevant ePrivacy provision has the same objective.