View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps
Question 241: Which GDPR principle requires personal data to be processed only for specified, explicit, and legitimate purposes?
- Accountability
- Purpose limitation
- Accuracy
- Storage limitation
Correct Answer: 2. Purpose limitation
Explanation:
The purpose limitation principle requires personal data to be collected for specified, explicit, and legitimate purposes and not subsequently processed in a manner incompatible with those purposes. Controllers should therefore identify the purposes of processing before collecting personal data and communicate relevant information to individuals. When considering further processing, the controller should assess whether the new purpose is compatible with the original purpose, taking into account the factors identified in Article 6(4). Purpose limitation helps prevent organizations from repurposing personal data without appropriate justification. It works together with other GDPR principles, including transparency, minimization, fairness, and accountability.
Question 242: Which right allows an individual to obtain a copy of their personal data from a controller?
- Right to object
- Right to erasure
- Right to restriction
- Right of access
Correct Answer: 4. Right of access
Explanation:
The right of access under Article 15 allows individuals to obtain confirmation as to whether personal data concerning them is being processed and, where applicable, access to that personal data. Individuals can also receive information about the purposes of processing, categories of personal data, recipients, retention periods, and other relevant matters. The controller generally must respond within one month, subject to applicable extension rules. The right of access is distinct from data portability because access can apply more broadly, while portability has specific conditions concerning the lawful basis, automated processing, and the format of the information.
Question 243: Which of the following is an example of processing based on a legal obligation under Article 6?
- Processing employee information required by applicable employment law
- Sending optional promotional emails because the company wants more sales
- Collecting unrelated personal information for future convenience
- Creating entertainment profiles about customers
Correct Answer: 1. Processing employee information required by applicable employment law
Explanation:
Article 6(1)(c) permits processing when it is necessary for compliance with a legal obligation to which the controller is subject. For example, an employer may need to process certain employee information because applicable employment, tax, accounting, or social-security legislation requires it. The obligation must arise from applicable law, and the processing must be necessary for compliance. A controller cannot simply describe an internal business preference as a legal obligation. The organization should identify the relevant legal requirement and ensure that the amount and type of personal data processed are appropriate for fulfilling that obligation.
Question 244: What is the primary purpose of a Record of Processing Activities?
- To replace the organization’s privacy policy
- To obtain automatic approval from a supervisory authority
- To document relevant processing activities and support accountability
- To provide marketing information to customers
Correct Answer: 3. To document relevant processing activities and support accountability
Explanation:
A Record of Processing Activities, or ROPA, helps an organization document its processing operations and demonstrate accountability. Article 30 identifies information that may need to be included, such as purposes of processing, categories of individuals and personal data, recipients, international transfers, retention information, and security measures. Controllers and processors have different recordkeeping requirements under the GDPR. Maintaining an accurate ROPA can help organizations understand their data flows, identify compliance obligations, respond to regulatory inquiries, and support privacy assessments. A ROPA is an internal accountability document and does not replace externally facing privacy information provided to individuals.
Question 245: Which GDPR right enables an individual to request correction of inaccurate personal data?
- Right to restriction
- Right to rectification
- Right to portability
- Right to object
Correct Answer: 2. Right to rectification
Explanation:
Article 16 provides individuals with the right to obtain rectification of inaccurate personal data concerning them without undue delay. Individuals may also have the right to have incomplete personal data completed, taking into account the purposes of processing. This right supports the GDPR’s accuracy principle, which requires personal data to be accurate and, where necessary, kept up to date. Controllers should maintain procedures that allow individuals to submit rectification requests and ensure that appropriate corrections are made. The right to rectification differs from erasure because its objective is to correct or complete information rather than necessarily delete it.
Question 246: Which factor is relevant when determining whether processing is likely to require a DPIA?
- Whether the organization has a large marketing budget
- Whether the company has operated for more than ten years
- Whether the processing is likely to result in a high risk to individuals’ rights and freedoms
- Whether the organization’s website contains advertisements
Correct Answer: 3. Whether the processing is likely to result in a high risk to individuals’ rights and freedoms
Explanation:
A Data Protection Impact Assessment is required where processing is likely to result in a high risk to the rights and freedoms of natural persons. Controllers should consider the nature, scope, context, and purposes of the processing and evaluate its potential impact on individuals. Certain processing activities, such as systematic monitoring or large-scale processing of sensitive information, may present significant risks depending on the circumstances. The DPIA should assess necessity and proportionality, identify risks, and establish measures to address those risks. The requirement is therefore based on privacy risk rather than unrelated characteristics of the organization or its commercial activities.
Question 247: Which statement best describes the controller-processor relationship under the GDPR?
- A processor generally processes personal data on behalf of a controller
- A processor always determines the purposes of processing independently
- A controller must follow every instruction issued by its processor
- A processor automatically becomes a joint controller
Correct Answer: 1. A processor generally processes personal data on behalf of a controller
Explanation:
A processor processes personal data on behalf of a controller. The controller determines the purposes and means of processing, while the processor generally acts according to documented instructions from the controller. Article 28 establishes specific requirements for the relationship, including contractual obligations concerning confidentiality, security, subprocessors, assistance with GDPR obligations, and deletion or return of personal data where appropriate. A processor does not automatically become a controller or joint controller merely because it handles personal data. The actual roles and decisions concerning the processing should be assessed when determining whether an organization is a controller, processor, or joint controller.
Question 248: Which of the following is an example of a technical measure under GDPR security requirements?
- Publishing passwords for all employees
- Allowing unrestricted access to customer databases
- Removing authentication controls
- Encrypting personal data where appropriate to the risks
Correct Answer: 4. Encrypting personal data where appropriate to the risks
Explanation:
Article 32 requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Encryption is one example of a technical measure that can help protect personal data against unauthorized access or disclosure. Other measures can include pseudonymisation, access controls, resilience mechanisms, secure authentication, testing, and recovery procedures. The GDPR does not require every organization to use exactly the same technology. Instead, security measures should reflect factors such as the state of the art, implementation costs, the nature and scope of processing, and the risks to individuals. Organizations should periodically evaluate whether their measures remain appropriate.
Question 249: What is one important requirement for valid consent under the GDPR?
- Consent must be impossible to withdraw
- Consent must be freely given, specific, informed, and unambiguous
- Consent can always be inferred from silence
- Consent is automatically valid whenever a privacy notice exists
Correct Answer: 2. Consent must be freely given, specific, informed, and unambiguous
Explanation:
GDPR consent must meet several conditions. It must be freely given, specific, informed, and unambiguous, generally through a clear affirmative action. Individuals must understand what they are consenting to and must have a genuine choice. Silence, inactivity, or pre-ticked boxes do not normally constitute valid consent. Individuals also have the right to withdraw consent at any time, and withdrawing consent must be as easy as providing it. Controllers relying on consent should maintain evidence demonstrating that consent was obtained appropriately. Where an imbalance or other circumstances prevent genuine choice, another lawful basis may need to be considered instead.
Question 250: Which statement correctly describes the GDPR’s storage limitation principle?
- Personal data must always be deleted immediately after collection
- Organizations may retain personal data indefinitely if storage is inexpensive
- Personal data should be kept in identifiable form no longer than necessary for the processing purposes, subject to applicable exceptions
- Storage limitation applies only to paper documents
Correct Answer: 3. Personal data should be kept in identifiable form no longer than necessary for the processing purposes, subject to applicable exceptions
Explanation:
The storage limitation principle requires personal data to be kept in a form that permits identification of individuals for no longer than is necessary for the purposes for which the data is processed. Organizations should establish appropriate retention periods or criteria and consider applicable legal or regulatory requirements that may require longer retention. Storage limitation does not mean that all information must be deleted immediately after its initial use. Controllers may need to retain information for legitimate legal, regulatory, or other permitted purposes. Effective retention schedules, periodic reviews, deletion procedures, and anonymisation can help organizations comply with this principle.
Question 251: Which organization has primary responsibility for monitoring and enforcing the GDPR within its jurisdiction?
- A supervisory authority
- The European Parliament
- The European Central Bank
- A private certification organization
Correct Answer: 1. A supervisory authority
Explanation:
Supervisory authorities are independent public authorities responsible for monitoring and enforcing the application of the GDPR within their respective jurisdictions. Their powers can include investigating complaints, conducting audits, obtaining information, ordering compliance, and imposing administrative fines where appropriate. Supervisory authorities also cooperate with one another under the GDPR’s cooperation and consistency mechanisms. Their role is distinct from that of the European Data Protection Board, which supports consistency across the EU and performs specified coordination and decision-making functions. Controllers and processors remain responsible for their own compliance and cannot rely on the absence of regulatory investigation as evidence that their processing is lawful.
Question 252: Which situation best illustrates the GDPR principle of transparency?
- Encrypting a database
- Giving individuals clear information about how their personal data is processed
- Restricting administrator privileges
- Deleting duplicate records
Correct Answer: 2. Giving individuals clear information about how their personal data is processed
Explanation:
Transparency requires controllers to provide individuals with information about processing in a concise, transparent, intelligible, and easily accessible form, using clear and plain language where appropriate. Privacy notices are an important tool for meeting this requirement. Individuals should generally be able to understand who is processing their information, why it is being processed, the applicable lawful basis, retention information, recipients, and their relevant rights. Security measures such as encryption and access controls are important but address different GDPR requirements. Transparency supports informed participation and helps individuals understand how organizations use their personal data.
Question 253: Which circumstance can require notification of a personal data breach to affected individuals?
- Every security incident regardless of risk
- Any failed login attempt
- A breach that is likely to result in a high risk to the rights and freedoms of natural persons
- A routine system update
Correct Answer: 3. A breach that is likely to result in a high risk to the rights and freedoms of natural persons
Explanation:
Under Article 34, when a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller generally must communicate the breach to affected individuals without undue delay, subject to the exceptions in the GDPR. The communication should describe the nature of the breach and provide relevant information about likely consequences and measures taken or proposed to address it. This requirement differs from the supervisory-authority notification rule under Article 33, which generally applies where the breach is likely to result in a risk. Organizations should therefore separately assess whether notification to the authority and communication to individuals are required.
Question 254: Which statement about Binding Corporate Rules is correct?
- They are designed only for domestic data transfers
- They can provide an appropriate safeguard for certain international transfers within a group of undertakings
- They eliminate all GDPR obligations for multinational organizations
- They are informal employee guidelines with no regulatory relevance
Correct Answer: 2. They can provide an appropriate safeguard for certain international transfers within a group of undertakings
Explanation:
Binding Corporate Rules, or BCRs, are internal data-protection rules used by certain groups of undertakings or groups of enterprises engaged in a joint economic activity to provide appropriate safeguards for international transfers. They must satisfy the requirements of Article 47 and are subject to an approval process involving competent supervisory authorities. BCRs typically establish enforceable rights and obligations concerning the processing and protection of personal data throughout the relevant group. They do not remove the group’s other GDPR responsibilities. Organizations considering BCRs must ensure that the rules meet the applicable substantive requirements and are properly approved before relying on them as a transfer mechanism.
Question 255: Which GDPR principle is most directly concerned with protecting personal data against unauthorized access and accidental loss?
- Integrity and confidentiality
- Purpose limitation
- Data minimization
- Accuracy
Correct Answer: 1. Integrity and confidentiality
Explanation:
The integrity and confidentiality principle requires personal data to be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage. Article 32 further requires appropriate technical and organizational measures based on the risks associated with processing. Measures can include encryption, pseudonymisation, access controls, resilience, secure authentication, testing, and recovery procedures. The appropriate level of security depends on the nature, scope, context, and purposes of processing and the risks to individuals. This principle therefore connects the GDPR’s general requirements with practical information-security and organizational controls.
Question 256: Which statement about the GDPR right to restriction of processing is correct?
- It always requires permanent deletion of the personal data
- It can require a controller to limit processing in specified circumstances
- It applies only to marketing emails
- It allows a controller to ignore all other GDPR obligations
Correct Answer: 2. It can require a controller to limit processing in specified circumstances
Explanation:
The right to restriction of processing allows individuals to require a controller to limit processing in specified circumstances. These can include situations where the individual contests the accuracy of personal data, where processing is unlawful but the individual prefers restriction rather than erasure, or where the controller no longer needs the data but the individual requires it for legal claims. During restriction, processing is generally limited except in circumstances permitted by the GDPR, such as with the individual’s consent or for legal claims. Restriction is therefore different from erasure because the information is not necessarily deleted from the controller’s systems.
Question 257: Which Article 6 lawful basis may apply when processing is necessary to perform a contract with the individual?
- Legitimate interests
- Consent
- Performance of a contract
- Publicly available information
Correct Answer: 3. Performance of a contract
Explanation:
Article 6(1)(b) provides a lawful basis where processing is necessary for the performance of a contract to which the individual is party or for taking steps at the individual’s request before entering into a contract. The controller should assess whether the processing is genuinely necessary for the contractual purpose rather than simply useful or commercially convenient. For example, processing a customer’s delivery address may be necessary to fulfill an order. Other activities associated with the customer relationship may require a different lawful basis. Controllers should identify the appropriate legal basis for each processing purpose rather than assuming that all processing connected with a contract automatically falls under Article 6(1)(b).
Question 258: Which statement best describes the role of the European Data Protection Board?
- It directly manages the privacy programs of private companies
- It replaces all national supervisory authorities
- It issues guidance and supports consistent application of EU data-protection law
- It acts as a commercial regulator for European businesses
Correct Answer: 3. It issues guidance and supports consistent application of EU data-protection law
Explanation:
The European Data Protection Board contributes to consistent application of the GDPR across the European Union. Its functions include issuing guidelines, recommendations, and best practices and supporting cooperation between supervisory authorities. In specified circumstances, it can also adopt binding decisions, including in certain disputes between supervisory authorities. The EDPB does not replace national supervisory authorities, which retain their supervisory and enforcement responsibilities. Its role is part of the GDPR’s broader cooperation and consistency framework. Organizations operating across multiple EU jurisdictions should consider EDPB guidance alongside applicable national supervisory-authority positions and the text of the GDPR itself.
Question 259: Which statement about special categories of personal data is correct?
- Health data is never subject to enhanced GDPR protection
- Special-category processing generally requires an Article 9 condition in addition to an applicable Article 6 lawful basis
- Article 9 automatically makes all processing of special-category data lawful
- Special categories include every type of customer information
Correct Answer: 2. Special-category processing generally requires an Article 9 condition in addition to an applicable Article 6 lawful basis
Explanation:
Article 9 provides enhanced protection for special categories of personal data, including health data, genetic data, certain biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and information concerning sex life or sexual orientation. Processing is generally prohibited unless one of the specific Article 9 conditions applies. In addition, the controller generally needs an applicable lawful basis under Article 6. The two provisions serve different functions and should be assessed separately. Organizations must therefore identify both the general lawful basis and the additional condition that permits processing of the relevant special category.
Question 260: Which statement best describes the GDPR accountability principle in practice?
- Controllers only need to demonstrate compliance after receiving a regulatory investigation
- Accountability means processors automatically determine all processing purposes
- Accountability requires organizations to be responsible for compliance and able to demonstrate it
- Accountability eliminates the need for privacy policies and records
Correct Answer: 3. Accountability requires organizations to be responsible for compliance and able to demonstrate it
Explanation:
The accountability principle requires controllers to take responsibility for complying with the GDPR and to be able to demonstrate compliance. Practical accountability measures can include maintaining records of processing activities, implementing privacy policies and procedures, conducting DPIAs where required, establishing appropriate processor contracts, documenting lawful bases, training personnel, and implementing technical and organizational safeguards. Accountability is therefore an ongoing governance responsibility rather than something that begins only after regulatory scrutiny. The measures should be proportionate to the organization’s processing activities and risks. Demonstrable compliance can also help an organization identify weaknesses and respond effectively to supervisory-authority inquiries.