View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps
Question 361: Under Article 82 of the GDPR, when several controllers or processors are responsible for the same damage, what principle generally applies to their liability toward the data subject?
- Each party is automatically exempt from liability
- Only the party that collected the data can be liable
- Each party is responsible only for administrative fines
- Each controller or processor may be held liable for the entire damage to ensure effective compensation
Correct Answer: 4. Each controller or processor may be held liable for the entire damage to ensure effective compensation
Explanation: Article 82 establishes a framework designed to ensure that a data subject can obtain effective compensation for damage caused by GDPR-infringing processing. Where more than one controller or processor, or both, are involved in the same processing and are responsible for damage, each may be held liable for the entire damage in order to ensure effective compensation. A party that pays the full compensation may subsequently seek a contribution from the other responsible parties for the portion corresponding to their responsibility. This allocation mechanism separates the data subject’s ability to obtain compensation from the internal distribution of responsibility between controllers and processors.
Question 362: Which requirement applies to a processor under Article 28 when engaging another processor?
- The processor may appoint another processor without any conditions
- The processor must obtain the controller’s prior specific or general written authorisation
- The processor automatically becomes a joint controller
- The processor must obtain consent from every data subject
Correct Answer: 2. The processor must obtain the controller’s prior specific or general written authorisation
Explanation: Article 28 regulates the use of sub-processors. A processor may not engage another processor without prior specific or general written authorisation from the controller. Where general written authorisation is provided, the processor must inform the controller of intended changes concerning the addition or replacement of other processors, giving the controller the opportunity to object. The processor must also ensure that the sub-processor is bound by data protection obligations providing at least the same level of protection required under the controller-processor arrangement. The original processor remains responsible to the controller for the performance of the sub-processor’s obligations under the relevant contractual framework.
Question 363: What does Article 30 generally require controllers to maintain?
- A record of processing activities
- A public list of every data subject
- A record of all employee salaries
- A register of supervisory authority employees
Correct Answer: 1. A record of processing activities
Explanation: Article 30 generally requires controllers and processors to maintain records of processing activities under their responsibility. Controller records include information such as the controller’s contact details, purposes of processing, categories of data subjects and personal data, categories of recipients, transfers to third countries where applicable, and envisaged retention periods where possible. Processors maintain records concerning categories of processing carried out on behalf of each controller. Article 30 contains limited exemptions for certain organisations with fewer than 250 employees, but those exemptions do not apply where the processing is likely to result in a risk, is not occasional, or includes special-category or criminal-conviction data in the circumstances specified by the GDPR.
Question 364: Which statement correctly describes the controller’s obligation under Article 25 concerning data protection by default?
- All personal data must be collected regardless of necessity
- Data protection by default applies only after a security breach
- By default, only personal data necessary for each specific processing purpose should be processed
- Controllers may determine default settings solely according to advertising interests
Correct Answer: 3. By default, only personal data necessary for each specific processing purpose should be processed
Explanation: Article 25 requires controllers to implement data protection by default. This means that, by default, appropriate technical and organisational measures should ensure that only personal data necessary for each specific processing purpose is processed. The requirement concerns factors such as the amount of personal data collected, the extent of processing, the period of storage, and accessibility. Data should not automatically be made available to an indefinite number of people merely because doing so is technically possible. Data protection by default complements data protection by design, requiring privacy considerations to be incorporated into systems and organisational practices rather than added only after processing arrangements have been established.
Question 365: Under Article 27, which organisation may fall within an exception to the requirement to designate an EU representative?
- A non-EU organisation carrying out occasional processing that does not involve certain large-scale or high-risk processing
- Every non-EU organisation subject to the GDPR
- Every multinational organisation with EU customers
- Every organisation monitoring behaviour in the EU
Correct Answer: 1. A non-EU organisation carrying out occasional processing that does not involve certain large-scale or high-risk processing
Explanation: Article 27 contains an exception to the general EU representative requirement for certain controllers and processors not established in the Union. The exception can apply where processing is only occasional, does not include, on a large scale, processing of special categories of data or criminal-conviction and offence data, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope, and purposes of the processing. The exception is therefore not based simply on an organisation being small or having no physical EU establishment. The specific statutory conditions must be considered together.
Question 366: What must a controller generally do when responding to a data subject’s request under Article 12?
- Require the data subject to submit the request through a lawyer
- Respond within one month, subject to the GDPR’s rules on extensions
- Automatically reject requests involving electronic communications
- Respond only after receiving approval from the supervisory authority
Correct Answer: 2. Respond within one month, subject to the GDPR’s rules on extensions
Explanation: Article 12 generally requires a controller to provide information on action taken on a data subject request without undue delay and in any event within one month of receipt. The period may be extended by two further months where necessary, taking into account the complexity and number of requests. If an extension is needed, the controller must inform the data subject within the initial one-month period and provide reasons for the delay. The GDPR also requires communications to be concise, transparent, intelligible, and easily accessible, using clear and plain language. Controllers may request additional information necessary to confirm the identity of the person making a request where they have reasonable doubts.
Question 367: Under Article 13, which information must generally be provided when personal data is collected directly from the data subject?
- Only the controller’s company name
- Only the categories of personal data collected
- Only the retention period
- Information such as the controller’s identity, purposes, legal basis, and applicable data subject rights
Correct Answer: 4. Information such as the controller’s identity, purposes, legal basis, and applicable data subject rights
Explanation: Article 13 sets out transparency information that must generally be provided when personal data is collected directly from the data subject. This includes the identity and contact details of the controller, contact details of the DPO where applicable, purposes and legal basis for processing, legitimate interests where relied upon, recipients or categories of recipients, and information concerning international transfers where relevant. The controller must also provide information about retention periods or the criteria used to determine them and the relevant rights of data subjects. The notice must be presented in a concise, transparent, intelligible, and easily accessible form using clear and plain language.
Question 368: What is a key difference between Articles 13 and 14 of the GDPR?
- Article 13 applies when personal data is collected from the data subject, while Article 14 generally applies when it is obtained from another source
- Article 13 applies only to processors
- Article 14 applies only to special-category data
- Article 14 eliminates all transparency obligations
Correct Answer: 1. Article 13 applies when personal data is collected from the data subject, while Article 14 generally applies when it is obtained from another source
Explanation: Articles 13 and 14 establish transparency requirements in different collection situations. Article 13 applies where personal data is obtained directly from the data subject, while Article 14 applies where the personal data has not been obtained from the data subject, such as when information is received from another organisation or source. Article 14 generally requires additional information about the categories of personal data concerned and the source from which the data originated, including whether the source is publicly accessible. Article 14 also establishes specific timing requirements for providing the information, subject to exceptions and restrictions set out in the GDPR.
Question 369: Which condition is relevant to processing special categories of personal data under Article 9?
- Special-category data may always be processed without a legal basis
- A controller can process it whenever the information is publicly available
- Processing generally requires both an Article 6 lawful basis and a separate Article 9 condition
- Article 9 applies only to paper records
Correct Answer: 3. Processing generally requires both an Article 6 lawful basis and a separate Article 9 condition
Explanation: Article 9 establishes a general prohibition on processing special categories of personal data, subject to specified exceptions. When an exception applies, the controller still needs an applicable lawful basis under Article 6 unless another specific legal framework provides otherwise. Article 9 includes conditions such as explicit consent, employment and social protection law requirements, vital interests where the data subject cannot consent, legitimate activities of certain organisations, information manifestly made public by the data subject, legal claims, substantial public interest, healthcare, public health, and archiving, research, or statistical purposes subject to their conditions. The two-step analysis is important for GDPR compliance.
Question 370: What does the GDPR’s principle of storage limitation generally require?
- Personal data must always be retained permanently
- Personal data should be kept for no longer than necessary for the purposes for which it is processed
- Controllers may never establish retention periods
- Personal data must be deleted immediately after collection
Correct Answer: 2. Personal data should be kept for no longer than necessary for the purposes for which it is processed
Explanation: The storage limitation principle in Article 5 requires personal data to be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. Longer storage may be permitted where the data is processed solely for specified purposes such as archiving in the public interest, scientific or historical research, or statistical purposes, subject to appropriate safeguards. Organisations should therefore establish retention periods or criteria for determining them and periodically review stored information. The principle does not require a single universal retention period; the appropriate period depends on the purpose, legal requirements, and circumstances of the processing.
Question 371: Which Article 6 lawful basis requires that processing be necessary for the performance of a contract to which the data subject is party?
- Article 6(1)(b)
- Article 6(1)(f)
- Article 6(1)(c)
- Article 6(1)(e)
Correct Answer: 1. Article 6(1)(b)
Explanation: Article 6(1)(b) provides a lawful basis where processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. The requirement of necessity is important: the processing must have a genuine and objectively necessary connection to the contractual performance or pre-contractual steps. Organisations should not automatically rely on contractual necessity merely because processing is convenient or commercially useful. Other processing activities associated with a contractual relationship may require a different lawful basis. The European data protection framework distinguishes necessary contractual processing from processing undertaken for separate purposes.
Question 372: Which requirement is associated with legitimate interests under Article 6(1)(f)?
- Legitimate interests can always override data subject rights
- The processing must be necessary for the legitimate interests pursued, with the interests or fundamental rights and freedoms of the data subject appropriately considered
- Legitimate interests can be used only by public authorities
- Legitimate interests require prior approval from the European Commission in every case
Correct Answer: 2. The processing must be necessary for the legitimate interests pursued, with the interests or fundamental rights and freedoms of the data subject appropriately considered
Explanation: Article 6(1)(f) permits processing where it is necessary for the legitimate interests pursued by the controller or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring protection of personal data, particularly where the data subject is a child. Organisations commonly assess this basis through a structured legitimate interests assessment, considering the legitimate interest, necessity of the processing, and balancing of interests and rights. The basis is not available to public authorities when performing their tasks. It also does not automatically override data subject rights or other GDPR obligations.
Question 373: What is one characteristic of consent under Article 4 and Article 7 of the GDPR?
- Consent must be freely given, specific, informed, and unambiguous
- Consent can always be inferred from silence
- Consent cannot be withdrawn
- Consent is valid only when given verbally
Correct Answer: 1. Consent must be freely given, specific, informed, and unambiguous
Explanation: GDPR consent must meet specific conditions. It must be freely given, specific, informed, and unambiguous through a statement or clear affirmative action. Where consent is given through a written declaration concerning other matters, the request for consent must be distinguishable from those other matters in an intelligible and easily accessible form using clear and plain language. The data subject has the right to withdraw consent at any time, and it must be as easy to withdraw as to give it. Consent is therefore not simply an indication of agreement; the controller must be able to demonstrate that valid consent was obtained and must respect the conditions governing its use.
Question 374: What does the GDPR require concerning withdrawal of consent?
- Withdrawal is permitted only once per year
- Withdrawal can be more difficult than giving consent
- The data subject may withdraw consent at any time, and withdrawal must be as easy as giving consent
- Withdrawal is permitted only through a court
Correct Answer: 3. The data subject may withdraw consent at any time, and withdrawal must be as easy as giving consent
Explanation: Article 7 provides that a data subject has the right to withdraw consent at any time. The withdrawal does not affect the lawfulness of processing based on consent before the withdrawal. The controller must make withdrawal as easy as giving consent. This requirement prevents organisations from creating unnecessary procedural barriers after obtaining consent. Once consent is withdrawn, the controller must determine whether another lawful basis exists for continued processing. If no alternative basis applies, processing relying on that consent must cease. The rules therefore distinguish the effects of withdrawal from the lawfulness of processing that occurred while valid consent remained in place.
Question 375: Which GDPR right allows a data subject to obtain a copy of personal data being processed about them?
- Right to object
- Right to data portability
- Right of access
- Right to restriction only
Correct Answer: 3. Right of access
Explanation: Article 15 establishes the right of access. A data subject can obtain confirmation as to whether personal data concerning them is being processed and, where that is the case, access to the personal data and specified information about the processing. This includes purposes, categories of personal data, recipients or categories of recipients, retention information, relevant rights, available complaint mechanisms, information about the source where the data was not collected from the data subject, and information concerning automated decision-making where applicable. The controller must generally provide a copy of the personal data being processed. Reasonable measures may be used to verify identity where necessary.
Question 376: Under Article 16, what does the right to rectification concern?
- Deleting all personal data automatically
- Correcting inaccurate personal data and completing incomplete personal data
- Preventing every future processing operation
- Transferring data to any third country
Correct Answer: 2. Correcting inaccurate personal data and completing incomplete personal data
Explanation: Article 16 provides data subjects with the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of processing, the data subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement. The right reflects the accuracy principle in Article 5, which requires personal data to be accurate and, where necessary, kept up to date. Controllers should therefore have processes allowing individuals to challenge inaccurate information and should take reasonable steps to correct relevant data when an error is identified.
Question 377: Which circumstance can limit the application of the right to erasure under Article 17?
- Processing is necessary for exercising the right of freedom of expression and information
- The controller prefers to retain the data for convenience
- The data subject has used the service more than once
- The controller has changed its privacy policy
Correct Answer: 1. Processing is necessary for exercising the right of freedom of expression and information
Explanation: Article 17 provides a right to erasure in specified circumstances, but it is not absolute. One exception applies where processing is necessary for exercising the right of freedom of expression and information. Other exceptions include compliance with a legal obligation requiring processing, reasons of public interest in areas such as public health, archiving or research under specified conditions, establishment or defence of legal claims, and certain public-interest tasks. Controllers must therefore assess both whether an Article 17 ground for erasure applies and whether one of the statutory exceptions prevents erasure. A general preference for retaining information is not itself sufficient.
Question 378: What is the main effect of the right to restriction of processing under Article 18?
- The controller must permanently delete all data
- The data becomes publicly accessible
- Processing of the relevant personal data is limited, subject to specified exceptions
- The controller automatically loses its legal personality
Correct Answer: 3. Processing of the relevant personal data is limited, subject to specified exceptions
Explanation: Article 18 gives data subjects the right to obtain restriction of processing in specified circumstances. These include cases where the accuracy of personal data is contested, for a period enabling the controller to verify its accuracy; where processing is unlawful and the data subject requests restriction instead of erasure; where the controller no longer needs the data but the data subject requires it for legal claims; and where the data subject has objected to processing under Article 21, pending verification of whether the controller’s legitimate grounds override the data subject’s interests. During restriction, the data generally may be stored but may be processed only under the conditions specified by Article 18, subject to limited exceptions.
Question 379: What is a key feature of the right to data portability under Article 20?
- It applies to all personal data regardless of legal basis
- It permits data subjects to receive certain personal data in a structured, commonly used, and machine-readable format
- It requires controllers to publish personal data online
- It applies only to paper records
Correct Answer: 2. It permits data subjects to receive certain personal data in a structured, commonly used, and machine-readable format
Explanation: Article 20 provides the right to data portability in specified circumstances. Where processing is based on consent or a contract and is carried out by automated means, the data subject has the right to receive personal data concerning them that they have provided to a controller in a structured, commonly used, and machine-readable format. They may also have the right to transmit that data to another controller where technically feasible. The right is distinct from the general right of access because it is designed to facilitate movement and reuse of certain personal data. It does not apply to every processing activity or every category of personal information.
Question 380: What is the specific significance of Article 21(2) concerning direct marketing?
- Data subjects may never object to direct marketing
- The controller may continue direct marketing indefinitely after an objection
- The data subject has the right to object at any time to processing of personal data for direct marketing purposes
- Objection to direct marketing requires approval from a supervisory authority
Correct Answer: 3. The data subject has the right to object at any time to processing of personal data for direct marketing purposes
Explanation: Article 21 provides a specific and strong objection right for direct marketing. Where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to processing of personal data concerning them for such marketing, including profiling to the extent that it is related to direct marketing. Once the data subject objects, the personal data must no longer be processed for those direct marketing purposes. The controller must explicitly bring this right to the data subject’s attention and present it clearly and separately from other information. This rule applies regardless of whether direct marketing processing initially relied on legitimate interests or another applicable lawful basis.