IAPP CIPP-E Practice Test Questions and Exam Dumps Part 14 Q261-280

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 261: Which information is generally required in a controller’s record of processing activities under Article 30?

  1. The organization’s annual advertising budget
  2. The purposes of the processing
  3. The personal preferences of every employee
  4. The controller’s future marketing slogans

Correct Answer: 2. The purposes of the processing

Explanation:
Article 30 requires controllers to maintain records of processing activities containing specified information, subject to applicable exceptions. This can include the name and contact details of the controller and, where applicable, the joint controller, representative, and data protection officer; the purposes of processing; categories of data subjects and personal data; categories of recipients; information about transfers to third countries or international organizations; and envisaged time limits for erasure where possible. The record can also describe the general technical and organizational security measures. The ROPA is an accountability tool that helps an organization understand and document its processing operations.

Question 262: Under the GDPR, which requirement generally applies when a controller engages a processor?

  1. The relationship must be governed by a contract or other legal act meeting Article 28 requirements
  2. The processor must determine all purposes of processing
  3. The controller must transfer ownership of the personal data to the processor
  4. The processor may use the data for any independent purpose

Correct Answer: 1. The relationship must be governed by a contract or other legal act meeting Article 28 requirements

Explanation:
Article 28 requires processing by a processor to be governed by a contract or other legal act that sets out specified requirements. These include processing only on documented instructions from the controller, confidentiality obligations, appropriate security measures, assistance with data-subject rights and other GDPR obligations, rules concerning subprocessors, and provisions concerning deletion or return of personal data. The processor must also provide sufficient guarantees regarding appropriate technical and organizational measures. A processor does not obtain unrestricted rights to use the personal data for its own purposes merely because it has access to the information. The contractual arrangement should clearly establish the parties’ responsibilities.

Question 263: What is a key requirement concerning a processor’s use of a subprocessor under Article 28?

  1. Subprocessors are exempt from GDPR security requirements
  2. The processor can appoint any subprocessor without informing the controller
  3. The controller must provide the processor with appropriate authorization for subprocessors
  4. The subprocessor automatically becomes the controller

Correct Answer: 3. The controller must provide the processor with appropriate authorization for subprocessors

Explanation:
Under Article 28, a processor may not engage another processor without prior specific or general written authorization from the controller. Where general written authorization is used, the processor must inform the controller of intended changes concerning the addition or replacement of subprocessors, giving the controller an opportunity to object. The subprocessor must be subject to data-protection obligations equivalent to those imposed on the processor under the relevant controller-processor arrangement. The initial processor remains responsible to the controller for the performance of the subprocessor’s obligations. These requirements help maintain accountability throughout a processing chain.

Question 264: Which statement about a Data Protection Officer’s independence is consistent with the GDPR?

  1. The DPO should not receive instructions regarding the exercise of DPO tasks
  2. The DPO must personally approve every business decision
  3. The DPO should receive instructions from management about how to perform DPO tasks
  4. The DPO may be penalized for performing DPO duties

Correct Answer: 1. The DPO should not receive instructions regarding the exercise of DPO tasks

Explanation:
Article 38 establishes safeguards for the independence of the data protection officer. The DPO must be involved properly and in a timely manner in issues relating to personal-data protection and must be supported with the resources necessary to perform the role. The DPO should not receive instructions regarding the exercise of DPO tasks and should report to the highest management level. The DPO may perform other tasks, but the organization must ensure that those duties do not result in a conflict of interests. The DPO’s independence helps ensure that privacy advice, monitoring, and compliance activities can be carried out without inappropriate operational interference.

Question 265: Which activity is specifically associated with the responsibilities of a DPO under Article 39?

  1. Managing all corporate finances
  2. Setting the company’s annual sales targets
  3. Approving every employee’s vacation
  4. Monitoring compliance with the GDPR and organizational data-protection policies

Correct Answer: 4. Monitoring compliance with the GDPR and organizational data-protection policies

Explanation:
Article 39 identifies several responsibilities for the DPO. These include informing and advising the controller or processor and employees about their obligations under data-protection law, monitoring compliance with the GDPR and organizational policies, assigning responsibilities, raising awareness, and providing training. The DPO also cooperates with the supervisory authority and acts as the contact point on issues relating to processing, including prior consultation where applicable. The DPO’s role is primarily advisory, monitoring, and coordination rather than general operational management. Organizations must provide the DPO with sufficient resources and access to personal-data processing operations so the role can be performed effectively.

Question 266: Which statement best describes the GDPR’s rules on data-protection certification mechanisms?

  1. Certification mechanisms may demonstrate compliance with specified GDPR requirements
  2. Certification automatically removes all GDPR obligations
  3. Certification is mandatory for every controller
  4. Certification permits organizations to ignore supervisory authorities

Correct Answer: 1. Certification mechanisms may demonstrate compliance with specified GDPR requirements

Explanation:
The GDPR provides for data-protection certification mechanisms, seals, and marks that can demonstrate that processing operations by controllers or processors comply with specified GDPR requirements. Certification is voluntary unless EU or Member State law provides otherwise and does not reduce the controller’s or processor’s responsibility for compliance. Certification criteria may be approved or recognized through the GDPR framework, and certification bodies must meet relevant requirements. An organization should therefore not treat certification as a general exemption from GDPR duties. Instead, certification can provide evidence of compliance with particular requirements and may help demonstrate accountability where appropriately applied.

Question 267: What is one purpose of GDPR-approved codes of conduct?

  1. To eliminate the role of supervisory authorities
  2. To replace the GDPR entirely for participating organizations
  3. To establish sector-specific guidance that can help demonstrate appropriate GDPR application
  4. To permit unrestricted international data transfers

Correct Answer: 3. To establish sector-specific guidance that can help demonstrate appropriate GDPR application

Explanation:
Article 40 provides for codes of conduct intended to contribute to the proper application of the GDPR while taking account of the specific features of different processing sectors and the particular needs of micro, small, and medium-sized enterprises. Codes may address matters such as fair and transparent processing, legitimate interests, information provided to individuals, pseudonymisation, security measures, breach notification, and international transfers. They do not replace the GDPR or remove an organization’s underlying legal obligations. Approved codes can provide practical sector-specific guidance and, where relevant, mechanisms for demonstrating compliance with certain requirements.

Question 268: Which power may a supervisory authority exercise under the GDPR?

  1. Ordering a controller or processor to bring processing operations into compliance
  2. Rewriting the GDPR without legislative approval
  3. Automatically dissolving every non-compliant business
  4. Creating private employment contracts for companies

Correct Answer: 1. Ordering a controller or processor to bring processing operations into compliance

Explanation:
Supervisory authorities have a range of investigative, corrective, and authorization powers under the GDPR. Corrective powers can include ordering a controller or processor to bring processing operations into compliance with the GDPR, imposing temporary or definitive limitations or bans on processing, ordering rectification or erasure, and imposing administrative fines where applicable. Supervisory authorities also have investigative powers, such as obtaining information and conducting audits. Their powers are exercised within the legal framework established by the GDPR and applicable national law. Organizations subject to supervision should maintain appropriate records and procedures to respond to regulatory inquiries and demonstrate compliance.

Question 269: Which statement correctly describes the GDPR’s one-stop-shop mechanism?

  1. It eliminates cooperation between supervisory authorities
  2. It applies automatically to every processing activity involving multiple countries
  3. It transfers all enforcement responsibilities to the European Commission
  4. It can provide a lead supervisory authority for certain cross-border processing activities

Correct Answer: 4. It can provide a lead supervisory authority for certain cross-border processing activities

Explanation:
The GDPR’s one-stop-shop mechanism is designed to facilitate consistent supervision of certain cross-border processing activities. For qualifying processing, the supervisory authority of the controller’s or processor’s main establishment or single establishment can act as the lead supervisory authority, while other concerned authorities participate through the cooperation mechanism. The mechanism does not apply to every processing activity involving more than one country, and local supervisory authorities can retain responsibilities in specified circumstances. The system is intended to coordinate regulatory oversight while preserving the role of concerned supervisory authorities and the GDPR’s consistency mechanisms.

Question 270: What is the main establishment of a controller relevant to under the GDPR’s one-stop-shop framework?

  1. It generally relates to where decisions on the purposes and means of processing are made and implemented
  2. It is the location selected by the company for tax purposes
  3. It is always the location of the company’s largest office
  4. It is necessarily the country where the company was incorporated

Correct Answer: 1. It generally relates to where decisions on the purposes and means of processing are made and implemented

Explanation:
For a controller, the main establishment generally relates to the place where decisions on the purposes and means of processing personal data are taken and the power to have those decisions implemented is located. The concept is relevant to identifying the lead supervisory authority for certain cross-border processing. It is not automatically determined by the company’s registered office, largest building, or preferred tax jurisdiction. The factual circumstances of the organization’s decision-making and processing operations are important. Where decisions concerning different processing activities are made in different establishments, the relevant analysis may need to be performed separately.

Question 271: Which mechanism allows supervisory authorities to cooperate when a processing activity affects individuals in multiple Member States?

  1. The commercial arbitration procedure
  2. The GDPR cooperation procedure
  3. The consumer pricing procedure
  4. The corporate tax procedure

Correct Answer: 2. The GDPR cooperation procedure

Explanation:
The GDPR establishes cooperation mechanisms requiring supervisory authorities to exchange relevant information, provide mutual assistance, and cooperate to ensure consistent application of the Regulation. In cross-border cases, the lead supervisory authority and concerned supervisory authorities communicate and work together through the relevant procedures. The European Data Protection Board can also play a role in resolving certain disputes and ensuring consistency. Cooperation is particularly important where processing affects individuals in multiple Member States. The framework is designed to prevent fragmented regulatory approaches while allowing authorities to address local concerns where the GDPR provides for their involvement.

Question 272: What is one remedy available to an individual who believes a controller has violated the GDPR?

  1. The individual can unilaterally impose a GDPR administrative fine
  2. The individual may lodge a complaint with a competent supervisory authority
  3. The individual can rewrite the controller’s privacy policy
  4. The individual automatically receives a criminal conviction against the controller

Correct Answer: 2. The individual may lodge a complaint with a competent supervisory authority

Explanation:
Article 77 provides individuals with the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work, or place of the alleged infringement. The complaint mechanism allows individuals to bring alleged GDPR violations to the attention of a competent data-protection authority. Individuals may also have judicial remedies under the GDPR, depending on the circumstances. The supervisory authority independently determines how to handle the complaint under its applicable powers and procedures. The right to complain is an important part of the GDPR’s enforcement framework and does not require the individual to prove the violation before filing.

Question 273: Which statement about compensation under the GDPR is correct?

  1. Compensation can only be ordered by a supervisory authority
  2. Individuals may have a right to compensation for material or non-material damage resulting from a GDPR infringement
  3. Compensation automatically applies to every unsuccessful access request
  4. Compensation is available only when a company intentionally violated the GDPR

Correct Answer: 2. Individuals may have a right to compensation for material or non-material damage resulting from a GDPR infringement

Explanation:
Article 82 provides a right to compensation for individuals who have suffered material or non-material damage as a result of an infringement of the GDPR. Controllers can be responsible for damage caused by processing that infringes the Regulation, subject to the conditions and defenses established by the GDPR. Processors can also have liability in circumstances specified by Article 82. Compensation is distinct from administrative fines imposed by supervisory authorities. Whether compensation is available in a particular case depends on the relevant facts, including the existence of an infringement and damage. Courts or other competent judicial bodies determine claims according to applicable procedural rules.

Question 274: Which GDPR article establishes a right to an effective judicial remedy against a legally binding supervisory-authority decision?

  1. Article 89
  2. Article 78
  3. Article 83
  4. Article 77

Correct Answer: 2. Article 78

Explanation:
Article 78 establishes the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning an individual. It also addresses situations where a supervisory authority does not handle a complaint or does not inform the complainant within the required timeframe about the progress or outcome of the complaint. This judicial remedy is distinct from the right to lodge a complaint with a supervisory authority under Article 77. The GDPR therefore provides multiple layers of protection: individuals can bring concerns to supervisory authorities and, where applicable, seek judicial review through competent courts.

Question 275: Which GDPR provision addresses judicial remedies against a controller or processor?

  1. Article 79
  2. Article 61
  3. Article 44
  4. Article 30

Correct Answer: 1. Article 79

Explanation:
Article 79 provides individuals with the right to an effective judicial remedy where they consider that their rights under the GDPR have been infringed as a result of processing of their personal data in non-compliance with the Regulation. Proceedings can generally be brought before the courts of the Member State where the controller or processor has an establishment or, subject to the GDPR’s conditions, where the individual has their habitual residence. This judicial remedy operates alongside the right to lodge a complaint with a supervisory authority. The distinction is important because Article 78 concerns remedies against supervisory-authority decisions, while Article 79 concerns remedies against controllers or processors.

Question 276: Which statement best describes representative actions under the GDPR?

  1. They concern only international data transfers
  2. They automatically result in criminal penalties
  3. They can allow certain authorized bodies or organizations to exercise rights on behalf of data subjects under specified conditions
  4. They allow any company to avoid individual complaints

Correct Answer: 3. They can allow certain authorized bodies or organizations to exercise rights on behalf of data subjects under specified conditions

Explanation:
Article 80 permits data subjects to mandate a not-for-profit body, organization, or association that has properly constituted statutory objectives in the public interest and is active in the field of protecting data-subject rights to lodge a complaint or exercise specified rights on their behalf. Member State law may also provide for broader arrangements under the conditions described in the GDPR. Representative mechanisms can help individuals pursue rights collectively or through organizations that specialize in data protection. They do not automatically result in penalties or replace the individual’s own rights. The precise scope can depend on the applicable national implementation of the relevant provisions.

Question 277: Which condition is relevant to the GDPR’s rules on automated individual decision-making under Article 22?

  1. Article 22 applies only to paper-based decisions
  2. The GDPR provides safeguards where a decision based solely on automated processing produces legal or similarly significant effects
  3. The individual must always accept every automated decision
  4. The controller may never use automated processing for any purpose

Correct Answer: 2. The GDPR provides safeguards where a decision based solely on automated processing produces legal or similarly significant effects

Explanation:
Article 22 addresses decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect an individual. Subject to the applicable exceptions and safeguards, individuals have a right not to be subject to such decisions. Certain exceptions may apply, including where the decision is necessary for entering into or performing a contract, authorized by EU or Member State law, or based on explicit consent. Where applicable, safeguards include measures allowing human intervention, expressing a point of view, and contesting the decision. Special requirements also apply when special categories of personal data are involved.

Question 278: Which GDPR principle is particularly relevant when presenting privacy information to children?

  1. Automatic consent
  2. Transparency and the use of clear, plain language
  3. Unlimited retention
  4. Unrestricted profiling

Correct Answer: 2. Transparency and the use of clear, plain language

Explanation:
When information is addressed specifically to children, the GDPR emphasizes that communications should be in clear and plain language that the child can easily understand. This reflects the broader transparency requirement and the GDPR’s recognition that children may require particular protection in relation to their personal data. Organizations should consider the age and understanding of the intended audience when designing notices, consent requests, and other privacy communications. Child-friendly language does not remove other GDPR obligations. Controllers must still provide the information required by the relevant transparency provisions and identify an appropriate lawful basis for the processing.

Question 279: Which statement best describes the relationship between the GDPR and national Member State law?

  1. National law automatically overrides every GDPR provision
  2. The GDPR completely eliminates every national privacy provision
  3. The GDPR permits certain areas to be specified or supplemented by Member State law
  4. Member States can never adopt any additional data-protection rules

Correct Answer: 3. The GDPR permits certain areas to be specified or supplemented by Member State law

Explanation:
Although the GDPR is directly applicable throughout the European Union, it allows Member States some discretion in specified areas. For example, Member State law can provide more specific rules in certain contexts, including employment-related processing, freedom of expression and information, and other areas where the GDPR expressly permits national provisions. The scope of this flexibility varies by provision and is subject to the requirements of EU law. Organizations operating across Member States should therefore consider both the GDPR and applicable national data-protection legislation. National rules do not generally override the GDPR; rather, they operate within the areas where the Regulation permits or requires national specification.

Question 280: Which statement best describes the GDPR’s approach to processing personal data for scientific research?

  1. Scientific research is always exempt from the GDPR
  2. The GDPR contains specific provisions and safeguards that may apply to processing for scientific research
  3. Research organizations may process any personal data without safeguards
  4. Research purposes can never justify processing personal data

Correct Answer: 2. The GDPR contains specific provisions and safeguards that may apply to processing for scientific research

Explanation:
The GDPR recognizes scientific research as an important context and contains specific provisions that may provide flexibility for certain processing activities while maintaining safeguards for individuals. Article 89 requires appropriate safeguards for processing for archiving in the public interest, scientific or historical research, or statistical purposes. These safeguards can include technical and organizational measures, particularly to respect the principle of data minimization. Member State law may also establish certain derogations from specified data-subject rights where the relevant conditions are met. Research processing is therefore not automatically exempt from the GDPR; organizations must identify the applicable legal basis, safeguards, and any relevant national provisions.