IAPP CIPP-E Practice Test Questions and Exam Dumps Part 12 Q221-240

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 221: Which GDPR requirement is most directly associated with ensuring that personal data is not retained longer than necessary?

  1. Lawfulness
  2. Data portability
  3. Storage limitation
  4. Purpose limitation

Correct Answer: 3. Storage limitation

Explanation:
The storage limitation principle requires personal data to be kept in a form that permits identification of individuals for no longer than is necessary for the purposes for which the data is processed, subject to applicable exceptions. Organizations should therefore establish appropriate retention periods or criteria based on the purposes of processing, legal requirements, and relevant risks. A retention schedule can help determine when information should be deleted, anonymised, or otherwise removed from active processing. Storage limitation does not necessarily require immediate deletion after the original operational purpose ends because other lawful retention requirements may apply. Controllers should document and periodically review their retention practices.

Question 222: Which of the following is required for valid GDPR consent?

  1. It must be freely given, specific, informed, and unambiguous
  2. It must be permanent and impossible to withdraw
  3. It must always be obtained verbally
  4. It must be inferred from silence

Correct Answer: 1. It must be freely given, specific, informed, and unambiguous

Explanation:
The GDPR establishes specific requirements for valid consent. Consent must be freely given, specific, informed, and unambiguous, and it generally requires a clear affirmative action. Controllers should provide individuals with sufficient information to understand what they are agreeing to and should avoid mechanisms that make consent difficult to refuse or withdraw. Silence or inactivity does not normally constitute valid consent. Individuals must also be able to withdraw consent at any time, and withdrawal should be as easy as giving it. Where consent is used as the lawful basis, organizations should maintain appropriate evidence demonstrating that valid consent was obtained.

Question 223: Which situation most clearly demonstrates the GDPR principle of data minimization?

  1. Sharing all available customer information with every department
  2. Collecting additional information simply because storage is inexpensive
  3. Keeping every piece of information indefinitely
  4. Collecting only the information necessary to provide the requested service

Correct Answer: 4. Collecting only the information necessary to provide the requested service

Explanation:
Data minimization requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. For example, a business providing a delivery service may need a customer’s name and delivery address, but it should not automatically collect unrelated information merely because the information might become useful later. Minimization should be considered when designing forms, databases, applications, and business processes. It also concerns the extent of access and processing, not simply initial collection. Controllers should periodically review whether the information they hold remains necessary for the purposes for which it was collected.

Question 224: A controller experiences a personal data breach that is likely to result in a risk to individuals. What is the general supervisory-authority notification deadline?

  1. One month from completing the investigation
  2. 72 hours from becoming aware of the breach, where feasible
  3. 30 days from discovery
  4. Seven business days from discovery

Correct Answer: 2. 72 hours from becoming aware of the breach, where feasible

Explanation:
Under Article 33, a controller generally must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification occurs after 72 hours, the controller must generally provide reasons for the delay. Controllers should therefore maintain incident-response procedures that allow breaches to be identified, assessed, documented, and escalated promptly. The 72-hour period concerns notification to the supervisory authority and is distinct from the separate requirements concerning communication to affected individuals.

Question 225: Which GDPR principle requires controllers to be able to demonstrate compliance with the Regulation?

  1. Data portability
  2. Purpose limitation
  3. Accountability
  4. Fairness

Correct Answer: 3. Accountability

Explanation:
The accountability principle requires controllers to be responsible for compliance with the GDPR and able to demonstrate that compliance. This can involve maintaining records, implementing policies, conducting risk assessments, completing DPIAs where required, establishing appropriate contracts, training personnel, and maintaining technical and organizational safeguards. Accountability is therefore broader than simply complying with individual requirements when a regulator asks questions. Organizations should be able to provide evidence showing how their privacy obligations are incorporated into their governance and operational processes. The documentation and controls should be proportionate to the organization’s processing activities, risks, and applicable GDPR obligations.

Question 226: Which statement about the right to erasure under the GDPR is correct?

  1. It allows individuals to request deletion of personal data in specified circumstances
  2. It applies only to inaccurate information
  3. It automatically requires deletion of all legally required records
  4. It applies without any exceptions

Correct Answer: 1. It allows individuals to request deletion of personal data in specified circumstances

Explanation:
The right to erasure under Article 17 allows individuals to request deletion of personal data in specified circumstances. Examples include situations where the data is no longer necessary for the original purposes, consent has been withdrawn and there is no other legal ground for processing, or the data has been unlawfully processed. The right is not absolute. Controllers may retain information where an applicable exception exists, such as compliance with a legal obligation, reasons relating to freedom of expression, public interest, or the establishment, exercise, or defense of legal claims. Controllers must therefore assess both the request and any applicable exceptions before deciding what action is required.

Question 227: Which of the following is a lawful basis under Article 6 of the GDPR?

  1. Data availability
  2. Protection of vital interests of the data subject or another natural person
  3. Commercial convenience
  4. Customer popularity

Correct Answer: 2. Protection of vital interests of the data subject or another natural person

Explanation:
Protection of vital interests is one of the lawful bases listed in Article 6. It can apply where processing is necessary to protect the vital interests of the data subject or another natural person and the applicable conditions are met. Other Article 6 lawful bases include consent, performance of a contract, compliance with a legal obligation, performance of a task carried out in the public interest or official authority, and legitimate interests where applicable. Controllers should select the lawful basis before processing and ensure that the processing is actually necessary for that basis. The vital-interests basis should not be treated as a general substitute for other available lawful grounds.

Question 228: What is the main purpose of the GDPR requirement for privacy by design?

  1. To require personal data to be stored permanently
  2. To eliminate the need for privacy notices
  3. To require all organizations to purchase identical security software
  4. To ensure privacy and data-protection safeguards are considered when processing systems and activities are designed

Correct Answer: 4. To ensure privacy and data-protection safeguards are considered when processing systems and activities are designed

Explanation:
Article 25 requires controllers to implement data protection by design and by default. Privacy by design means that appropriate technical and organizational measures should be integrated into processing activities from the planning and development stages. Examples can include data minimization, pseudonymisation, encryption, access controls, and privacy-conscious system architecture. The appropriate measures depend on the state of the art, implementation costs, the nature and scope of processing, the purposes, and the risks to individuals. The concept is preventive: organizations should address privacy risks during system design rather than waiting until a compliance problem or security incident occurs.

Question 229: Under the GDPR, which organization generally has responsibility for determining the purposes and means of processing personal data?

  1. The controller
  2. The data subject
  3. The processor’s employee
  4. The supervisory authority

Correct Answer: 1. The controller

Explanation:
The GDPR defines a controller as the natural or legal person, public authority, agency, or other body that determines the purposes and means of processing personal data. The controller is therefore generally responsible for deciding why personal data is processed and the essential means used to accomplish those purposes. A processor, by contrast, processes personal data on behalf of the controller and generally follows documented instructions. Correctly identifying the controller is important because it determines which GDPR obligations and responsibilities apply. The contractual label used by organizations is not necessarily decisive; actual roles and decision-making should be considered.

Question 230: Which situation may require a controller to consult the supervisory authority before commencing processing?

  1. The organization has completed every possible privacy training course
  2. The organization has no employees
  3. A DPIA indicates that high residual risk remains despite measures planned to mitigate the risk
  4. The processing involves no personal data

Correct Answer: 3. A DPIA indicates that high residual risk remains despite measures planned to mitigate the risk

Explanation:
Article 36 provides for prior consultation with the supervisory authority where a DPIA indicates that processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. If the controller considers that the residual risk remains high after planned safeguards, consultation may be required before processing begins. The supervisory authority can provide written advice and exercise its relevant powers under the GDPR. Prior consultation is therefore part of the GDPR’s preventive risk-management framework. Controllers should not treat a completed DPIA as automatically authorizing processing when significant unresolved risks remain.

Question 231: Which statement best describes the GDPR’s right to data portability?

  1. It gives individuals ownership of a controller’s entire database
  2. It allows individuals to require deletion of all personal data
  3. It applies to every type of processing regardless of lawful basis
  4. It can allow individuals to receive certain personal data in a structured, commonly used, machine-readable format

Correct Answer: 4. It can allow individuals to receive certain personal data in a structured, commonly used, machine-readable format

Explanation:
Article 20 provides a right to data portability under specific conditions. Individuals can receive personal data concerning them that they have provided to a controller in a structured, commonly used, and machine-readable format and, where technically feasible, transmit that information to another controller. The right generally applies when processing is based on consent or a contract and carried out by automated means. It does not give individuals ownership or control over an organization’s entire database. Nor does it automatically apply to all forms of processing. Controllers should assess the relevant legal basis, nature of the data, and technical requirements before responding to a portability request.

Question 232: Which statement about the GDPR’s territorial scope is correct?

  1. The location of the organization’s headquarters is always the only relevant factor
  2. The GDPR can apply to certain organizations outside the EU when they offer goods or services to individuals in the EU or monitor their behavior there
  3. The GDPR applies only to companies physically incorporated in the EU
  4. The GDPR never applies to organizations processing data outside Europe

Correct Answer: 2. The GDPR can apply to certain organizations outside the EU when they offer goods or services to individuals in the EU or monitor their behavior there

Explanation:
Article 3 provides circumstances in which the GDPR can apply to organizations established outside the European Union. In particular, the Regulation can apply where processing activities relate to offering goods or services to individuals in the EU or monitoring their behavior as far as that behavior takes place within the EU, subject to the conditions of Article 3. Territorial scope therefore depends on the nature of the processing and the activities involved, not simply on the organization’s place of incorporation or server location. Organizations outside the EU should assess their activities carefully to determine whether the GDPR applies.

Question 233: Which GDPR requirement applies when a controller receives a request from an individual but has reasonable doubts about the person’s identity?

  1. The controller must transfer the request to another controller
  2. The controller must automatically reject the request
  3. The controller may request additional information necessary to confirm the identity of the requester
  4. The controller must publish the request publicly

Correct Answer: 3. The controller may request additional information necessary to confirm the identity of the requester

Explanation:
The GDPR allows controllers to request additional information necessary to confirm the identity of an individual where they have reasonable doubts concerning the identity of the person making a rights request. This safeguard helps prevent unauthorized disclosure of personal data to someone pretending to be the data subject. Identity verification should remain proportionate to the circumstances and should not be used as an unnecessary obstacle to exercising rights. Controllers should establish appropriate procedures for verifying identity while still respecting the GDPR’s requirements for timely responses. The objective is to protect both the individual’s rights and the security of personal information.

Question 234: Which statement about international transfers under the GDPR is most accurate?

  1. The GDPR provides several mechanisms for lawful transfers to third countries, including adequacy decisions and appropriate safeguards
  2. A privacy notice alone always makes an international transfer lawful
  3. International transfers are permitted only when the recipient is another EU controller
  4. Any transfer outside the EU is automatically prohibited

Correct Answer: 1. The GDPR provides several mechanisms for lawful transfers to third countries, including adequacy decisions and appropriate safeguards

Explanation:
Chapter V of the GDPR establishes rules for transfers of personal data to third countries and international organizations. Depending on the circumstances, organizations can rely on an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or certain derogations for specific situations. A transfer is therefore not automatically prohibited merely because data leaves the EU, but organizations must satisfy the applicable requirements. A general privacy notice by itself does not normally provide the required transfer mechanism. Controllers should identify the destination, transfer circumstances, applicable mechanism, and relevant safeguards before transferring personal data internationally.

Question 235: Which principle requires personal data to be accurate and, where necessary, kept up to date?

  1. Purpose limitation
  2. Data portability
  3. Accuracy
  4. Confidentiality

Correct Answer: 3. Accuracy

Explanation:
The accuracy principle requires personal data to be accurate and, where necessary, kept up to date. Controllers should take reasonable steps to ensure that inaccurate personal data is corrected or erased without undue delay, considering the purposes for which the information is processed. The right of rectification provides individuals with an important mechanism for correcting inaccurate or incomplete information. Accuracy can be particularly important when personal data is used for decisions, legal obligations, customer services, or other activities that may affect individuals. Organizations should therefore have procedures for maintaining data quality and responding appropriately when inaccurate information is identified.

Question 236: Which activity is most closely associated with the GDPR principle of integrity and confidentiality?

  1. Choosing how long a company should retain tax records
  2. Establishing appropriate security measures to protect personal data from unauthorized access
  3. Providing a customer with a copy of their data
  4. Defining the business purpose of a marketing campaign

Correct Answer: 2. Establishing appropriate security measures to protect personal data from unauthorized access

Explanation:
The integrity and confidentiality principle requires personal data to be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Article 32 further requires controllers and processors to implement technical and organizational measures appropriate to the risks. Examples include access controls, encryption, resilience measures, secure authentication, testing, and procedures for restoring availability after an incident. The precise controls should reflect the nature, scope, context, purposes, and risks of processing. Security is therefore an essential component of GDPR compliance rather than a separate concern unrelated to data protection.

Question 237: Which of the following is an example of processing based on compliance with a legal obligation?

  1. Collecting information required by employment or tax legislation
  2. Creating a customer profile solely for entertainment
  3. Sending a birthday advertisement to a customer
  4. Storing data because the company may someday find it useful

Correct Answer: 1. Collecting information required by employment or tax legislation

Explanation:
Article 6(1)(c) permits processing when it is necessary for compliance with a legal obligation to which the controller is subject. Examples can include processing information required under applicable tax, accounting, employment, or regulatory laws. The legal obligation must be grounded in applicable law, and the processing must be necessary for compliance with that obligation. An organization’s internal preference or commercial interest does not by itself create a legal obligation. Controllers should document the relevant legal requirement and ensure that the information processed is appropriate for fulfilling it. Other processing purposes may require a different Article 6 lawful basis.

Question 238: Which statement best describes the GDPR concept of pseudonymisation?

  1. It removes the data from the GDPR entirely
  2. It permanently makes personal data anonymous
  3. It can reduce the linkability of data to individuals while additional information capable of re-identifying them is kept separately
  4. It guarantees that no unauthorized access can occur

Correct Answer: 3. It can reduce the linkability of data to individuals while additional information capable of re-identifying them is kept separately

Explanation:
Pseudonymisation is a technique in which personal data is processed so that it can no longer be attributed to a specific individual without the use of additional information. The additional information must be kept separately and protected by appropriate technical and organizational measures. Pseudonymised data can still constitute personal data because re-identification remains possible. The technique can reduce risks and is specifically recognized by the GDPR as a potential security and privacy-enhancing measure. It should not be confused with anonymisation, where information is processed so that individuals are no longer identifiable within the applicable legal and technical assessment.

Question 239: Which requirement applies specifically to processing for direct marketing under the GDPR right to object?

  1. The individual must obtain permission from a supervisory authority before objecting
  2. The controller may continue direct marketing whenever it has a legitimate interest
  3. Individuals have the right to object to processing of their personal data for direct marketing purposes
  4. Individuals may object only after receiving three marketing messages

Correct Answer: 3. Individuals have the right to object to processing of their personal data for direct marketing purposes

Explanation:
The GDPR provides a specific right to object to processing for direct marketing. Individuals should be informed clearly about this right and it should be presented distinctly from other information. When an individual objects to processing for direct marketing, the controller must generally stop processing the personal data for those purposes. This also covers related profiling to the extent it is connected with direct marketing. The direct-marketing objection is stronger than the general objection framework because the controller does not normally have the option of demonstrating overriding legitimate grounds to continue the marketing processing after a valid objection.

Question 240: Which statement about the role of a Data Protection Officer is correct?

  1. The DPO must personally make every privacy decision for the organization
  2. The DPO is automatically the organization’s chief executive
  3. The DPO can be instructed to determine which political party employees support
  4. The DPO’s responsibilities can include monitoring compliance and advising the organization on data-protection obligations

Correct Answer: 4. The DPO’s responsibilities can include monitoring compliance and advising the organization on data-protection obligations

Explanation:
Under Articles 38 and 39, the Data Protection Officer has defined responsibilities including informing and advising the controller or processor and employees about their data-protection obligations, monitoring compliance with the GDPR and relevant policies, providing advice concerning data protection impact assessments, and cooperating with the supervisory authority. The DPO should perform these tasks with appropriate independence and must not receive instructions regarding the exercise of those tasks. The DPO does not automatically become the organization’s executive decision-maker. Controllers and processors retain their own responsibilities for compliance, while the DPO performs the advisory, monitoring, and cooperation functions established by the GDPR.