IAPP CIPP-E Practice Test Questions and Exam Dumps Part 17 Q321-340

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 321: Under Article 82 of the GDPR, who may be entitled to compensation for material or non-material damage caused by an infringement of the GDPR?

  1. Only supervisory authorities
  2. Only processors
  3. Any person who suffered material or non-material damage
  4. Only data protection officers

Correct Answer: 3. Any person who suffered material or non-material damage

Explanation: Article 82 establishes a right to compensation where a person suffers material or non-material damage as a result of an infringement of the GDPR. The obligation can apply to controllers and, in certain circumstances, processors. A processor is liable when it has failed to comply with obligations specifically directed to processors or has acted outside or contrary to lawful instructions from the controller. The provision therefore focuses on the affected person and the damage suffered, rather than limiting compensation to a particular category of data subject or requiring the involvement of a supervisory authority. National procedural rules may govern how compensation claims are brought before courts.

Question 322: Which factor is expressly relevant when determining the amount of an administrative fine under Article 83 of the GDPR?

  1. The number of employees who work for the controller
  2. The nature, gravity, and duration of the infringement
  3. The nationality of the data subjects
  4. The age of the controller’s website

Correct Answer: 2. The nature, gravity, and duration of the infringement

Explanation: Article 83 requires supervisory authorities to consider a range of factors when determining whether and how much to impose an administrative fine. These include the nature, gravity, and duration of the infringement, as well as the intentional or negligent character of the infringement, actions taken to mitigate damage, the degree of responsibility, relevant technical and organisational measures, previous infringements, cooperation with the supervisory authority, categories of personal data affected, notification of the infringement, compliance with corrective measures, adherence to approved codes or certification mechanisms, and other relevant aggravating or mitigating circumstances. The purpose is to make the sanction proportionate to the circumstances of the specific infringement.

Question 323: What is the primary purpose of Article 22 of the GDPR concerning automated individual decision-making?

  1. To prohibit all automated processing of personal data
  2. To require every controller to use artificial intelligence
  3. To give individuals protection against certain decisions based solely on automated processing
  4. To permit automated decisions without restrictions when data is public

Correct Answer: 3. To give individuals protection against certain decisions based solely on automated processing

Explanation: Article 22 provides data subjects with a right not to be subject to a decision based solely on automated processing, including profiling, when the decision produces legal effects concerning them or similarly significantly affects them. The GDPR provides exceptions where the decision is necessary for entering into or performing a contract, is authorised by Union or Member State law, or is based on the data subject’s explicit consent. Certain safeguards apply to the contractual and consent situations, including the ability to obtain human intervention, express a point of view, and contest the decision. Special-category data can trigger additional requirements.

Question 324: Under Article 8 of the GDPR, what age generally applies to a child’s consent in relation to information society services offered directly to a child?

  1. 13 years
  2. 21 years
  3. 16 years
  4. 18 years

Correct Answer: 3. 16 years

Explanation: Article 8 establishes 16 years as the general EU-level threshold for a child’s own consent to processing of personal data in connection with information society services offered directly to a child, where consent is the applicable legal basis. Member States may lower this age, but not below 13 years. Where the child is below the applicable threshold, consent must be given or authorised by the holder of parental responsibility, subject to the conditions specified by the GDPR. Controllers are also required to make reasonable efforts to verify that consent is given or authorised in accordance with the applicable requirements, taking available technology into account.

Question 325: Which GDPR provision allows Member States to establish more specific rules for processing personal data in the employment context?

  1. Article 88
  2. Article 49
  3. Article 35
  4. Article 17

Correct Answer: 1. Article 88

Explanation: Article 88 permits Member States to provide, by law or collective agreements, more specific rules to ensure protection of employees’ rights and freedoms in relation to the processing of personal data in the employment context. These rules may address areas such as recruitment, performance of employment contracts, management, planning and organisation of work, equality and diversity, health and safety at work, protection of employer or employee property, and termination of employment. Such national rules must include suitable and specific measures to safeguard data subjects’ dignity, legitimate interests, and fundamental rights, with particular attention to transparency and workplace monitoring systems.

Question 326: What is one important requirement when personal data is processed for scientific or historical research purposes under Article 89 of the GDPR?

  1. The processing must always be based on consent
  2. Appropriate safeguards must be implemented
  3. All research data must be deleted immediately after collection
  4. Research processing is completely outside the GDPR

Correct Answer: 2. Appropriate safeguards must be implemented

Explanation: Article 89 requires processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes to be subject to appropriate safeguards for the rights and freedoms of data subjects. Those safeguards should ensure that technical and organisational measures are in place, in particular to respect the principle of data minimisation. Where appropriate, pseudonymisation is specifically identified as a possible safeguard. Union or Member State law may provide derogations from certain GDPR rights and obligations where those provisions are necessary to achieve the relevant research, archiving, or statistical purposes and the statutory conditions are satisfied.

Question 327: Under Article 85 of the GDPR, what must Member States reconcile with the right to protection of personal data?

  1. The right to property ownership
  2. The freedom of expression and information
  3. The freedom of movement only
  4. The right to establish a business

Correct Answer: 2. The freedom of expression and information

Explanation: Article 85 requires Member States to reconcile the right to protection of personal data under the GDPR with the right to freedom of expression and information, including processing for journalistic purposes and purposes of academic, artistic, or literary expression. Member States must provide exemptions or derogations from specified GDPR provisions where necessary to reconcile these rights. The exact national rules can therefore vary across Member States. This provision recognises that data protection must operate alongside other fundamental rights rather than automatically taking precedence in every situation. National implementing laws are particularly important when analysing processing carried out for journalistic or expressive purposes.

Question 328: Which situation is most directly relevant to the GDPR’s territorial scope under Article 3(2)?

  1. A company established outside the EU offers goods or services to individuals in the EU
  2. A company operates only within a country outside Europe and has no EU-related activity
  3. A European citizen travels outside the EU for a holiday
  4. A non-EU company processes only anonymous information

Correct Answer: 1. A company established outside the EU offers goods or services to individuals in the EU

Explanation: Article 3(2) can apply the GDPR to processing by a controller or processor that is not established in the EU where the processing activities relate to offering goods or services to data subjects in the EU or monitoring their behaviour as far as their behaviour takes place within the EU. The provision focuses on the processing activity and its connection with individuals in the EU rather than simply the nationality of the individuals involved. The territorial scope therefore can extend beyond EU-established organisations when the statutory conditions are met. Determining whether an activity constitutes an offering or behavioural monitoring requires assessment of the specific circumstances.

Question 329: What is the main purpose of the GDPR consistency mechanism?

  1. To eliminate all national data protection authorities
  2. To ensure consistent application of the GDPR across the EU
  3. To replace national employment laws
  4. To establish a single European court for every complaint

Correct Answer: 2. To ensure consistent application of the GDPR across the EU

Explanation: The consistency mechanism is designed to promote consistent application of the GDPR throughout the European Union. It involves the European Data Protection Board and can apply where supervisory authorities need to cooperate on matters with cross-border implications or where an authority proposes certain measures requiring an EU-level approach. The mechanism can involve opinions, dispute resolution, and binding decisions depending on the circumstances. Its purpose is not to eliminate national supervisory authorities. Instead, it provides a framework for coordinating their activities and resolving disagreements so that materially similar GDPR issues can be handled consistently across Member States.

Question 330: Under Article 42, what is one purpose of GDPR certification mechanisms?

  1. To replace all supervisory authorities
  2. To demonstrate compliance with the GDPR
  3. To make processing automatically lawful
  4. To exempt controllers from security obligations

Correct Answer: 2. To demonstrate compliance with the GDPR

Explanation: Article 42 encourages the establishment of data protection certification mechanisms, data protection seals, and marks to demonstrate the existence of appropriate safeguards by controllers and processors. Certification is voluntary unless Union or Member State law provides otherwise and does not reduce the responsibility of the controller or processor for compliance with the GDPR. It also does not prevent supervisory authorities from exercising their powers. Certification may be particularly useful as a transparency and accountability tool because it can provide evidence that specified processing operations or organisational practices have been assessed against defined GDPR-related criteria.

Question 331: Which body is responsible for accrediting certification bodies under the GDPR, subject to the applicable accreditation framework?

  1. Only the European Commission
  2. The European Parliament
  3. The competent supervisory authority or national accreditation body, as applicable
  4. Any private company without oversight

Correct Answer: 3. The competent supervisory authority or national accreditation body, as applicable

Explanation: Article 43 provides the framework for accreditation of certification bodies. Depending on the applicable arrangement, accreditation may be carried out by the competent supervisory authority or by the national accreditation body established under the relevant EU accreditation framework, subject to the GDPR’s conditions. Certification bodies must demonstrate appropriate expertise and independence and satisfy the requirements established for certification activities. Accreditation does not mean that certification bodies can operate without supervision or that every private organisation automatically qualifies. The GDPR therefore establishes institutional and procedural safeguards intended to support the reliability and credibility of certification mechanisms.

Question 332: What is one of the tasks assigned to supervisory authorities under Article 57?

  1. Issuing passports to EU citizens
  2. Monitoring and enforcing the application of the GDPR
  3. Approving every employment contract
  4. Managing national tax systems

Correct Answer: 2. Monitoring and enforcing the application of the GDPR

Explanation: Article 57 sets out a range of tasks for supervisory authorities. These include monitoring and enforcing the application of the GDPR, promoting public awareness of data protection risks and rights, advising national institutions, handling complaints, cooperating with other supervisory authorities, and conducting investigations where appropriate. Supervisory authorities also contribute to the consistent application of the GDPR and may exercise the corrective and authorisation powers specified in Article 58. Their responsibilities therefore extend beyond imposing fines. They have regulatory, investigative, advisory, awareness-raising, and cooperative functions within the European data protection framework.

Question 333: Which power is expressly available to a supervisory authority under Article 58?

  1. The power to order a controller or processor to comply with a data subject’s request
  2. The power to amend national constitutions
  3. The power to issue criminal convictions
  4. The power to rewrite EU treaties

Correct Answer: 1. The power to order a controller or processor to comply with a data subject’s request

Explanation: Article 58 gives supervisory authorities a range of corrective powers. These include ordering controllers or processors to comply with data subjects’ requests to exercise their GDPR rights. Other powers include issuing warnings and reprimands, ordering compliance with processing requirements, imposing limitations or bans on processing, ordering rectification or erasure, and imposing administrative fines where appropriate. Supervisory authorities may also have investigative powers such as obtaining information and conducting audits. These powers are administrative and regulatory in nature and should not be confused with the criminal jurisdiction of national courts or prosecuting authorities.

Question 334: Under Article 77, what right does a data subject generally have in relation to a supervisory authority?

  1. The right to appoint the authority’s staff
  2. The right to lodge a complaint
  3. The right to impose a fine directly
  4. The right to veto national legislation

Correct Answer: 2. The right to lodge a complaint

Explanation: Article 77 gives every data subject the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if they consider that processing of personal data relating to them infringes the GDPR. This provides an administrative avenue for raising concerns about potentially unlawful processing. The supervisory authority must handle complaints in accordance with the applicable procedural framework and inform the complainant about progress and outcome where required. The right to complain does not itself mean that the complainant can impose a sanction or determine the supervisory authority’s final decision.

Question 335: Which statement accurately describes the right to an effective judicial remedy under Article 79?

  1. It applies only to controllers
  2. It allows a data subject to bring proceedings against a controller or processor in certain circumstances
  3. It replaces the right to complain to a supervisory authority
  4. It is available only after an administrative fine has been imposed

Correct Answer: 2. It allows a data subject to bring proceedings against a controller or processor in certain circumstances

Explanation: Article 79 provides data subjects with the right to an effective judicial remedy where they consider that their rights under the GDPR have been infringed as a result of processing of their personal data in non-compliance with the Regulation. Proceedings may generally be brought against a controller or processor before the courts of the Member State where the controller or processor has an establishment or, alternatively, where the data subject has their habitual residence, subject to the conditions in the provision. This judicial remedy exists alongside, rather than simply replacing, the right to lodge a complaint with a supervisory authority.

Question 336: Under Article 82, when can a processor be liable for damage caused by processing?

  1. Whenever any processing occurs anywhere in the world
  2. Only when the data subject gives written permission
  3. When the processor has failed to comply with processor-specific GDPR obligations or acted outside or contrary to lawful instructions
  4. Only when the controller has been fined first

Correct Answer: 3. When the processor has failed to comply with processor-specific GDPR obligations or acted outside or contrary to lawful instructions

Explanation: Article 82 distinguishes the liability of controllers and processors. A processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller. This does not mean that processors are generally immune from liability. Where several controllers or processors are involved in the same processing and are responsible for the damage, the GDPR also contains rules addressing liability toward the affected person. The provision is designed to ensure that individuals can obtain effective compensation while allocating responsibility according to the parties’ legal roles.

Question 337: Which GDPR article addresses the conditions under which a controller may restrict certain data subject rights through Union or Member State law?

  1. Article 23
  2. Article 12
  3. Article 45
  4. Article 90

Correct Answer: 1. Article 23

Explanation: Article 23 permits Union or Member State law to restrict the scope of certain GDPR obligations and data subject rights when the restriction respects the essence of fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard specified objectives. These objectives can include national security, defence, public security, prevention and investigation of criminal offences, important economic or financial interests, judicial independence, and other protected interests identified in the provision. Such restrictions cannot simply be introduced without legal authority. The relevant legislative measure must include specific provisions addressing matters such as the purposes, categories of processing, safeguards, and applicable risks.

Question 338: Which principle is most directly associated with Article 25 of the GDPR?

  1. Data protection by design and by default
  2. Freedom of information
  3. International criminal cooperation
  4. Administrative penalties

Correct Answer: 1. Data protection by design and by default

Explanation: Article 25 requires controllers to implement appropriate technical and organisational measures designed to implement data protection principles effectively and integrate necessary safeguards into processing. This is commonly described as data protection by design. The provision also requires data protection by default, meaning that, by default, only personal data necessary for each specific processing purpose should be processed. Relevant considerations include the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risks to individuals’ rights and freedoms. The provision therefore connects privacy principles with practical organisational and technical measures from the outset.

Question 339: What is the purpose of Article 27 when a controller or processor not established in the EU is subject to Article 3(2)?

  1. To require the appointment of an EU representative in specified circumstances
  2. To require the appointment of a national judge
  3. To transfer all processing to an EU data centre
  4. To exempt the organisation from supervisory authority oversight

Correct Answer: 1. To require the appointment of an EU representative in specified circumstances

Explanation: Article 27 generally requires a controller or processor not established in the EU that falls within the GDPR’s territorial scope under Article 3(2) to designate in writing a representative in the Union. The representative must be established in one of the Member States where the relevant data subjects whose personal data are processed in relation to the offering of goods or services or monitoring of behaviour are located. The GDPR contains exceptions, including situations where processing is occasional, does not involve large-scale processing of special categories or criminal-conviction data, and is unlikely to result in a risk to individuals’ rights and freedoms. The representative acts as a contact point for supervisory authorities and data subjects.

Question 340: What does Article 31 of the GDPR require controllers and processors to do in relation to supervisory authorities?

  1. Obtain approval before every routine processing activity
  2. Cooperate with the supervisory authority on request
  3. Transfer all personal data to the supervisory authority
  4. Publish every internal security document

Correct Answer: 2. Cooperate with the supervisory authority on request

Explanation: Article 31 establishes a general duty for controllers and processors, and their representatives where applicable, to cooperate with the supervisory authority on request in the performance of its tasks. This obligation supports effective regulatory oversight and complements the authority’s investigative powers under Article 58. Cooperation does not mean that organisations must automatically transfer all personal data or publish confidential internal material. Instead, the organisation must respond appropriately to lawful requests connected with the authority’s GDPR functions. Failure to cooperate can also be relevant when supervisory authorities assess compliance and exercise their corrective or sanctioning powers under the Regulation.