IAPP CIPP-E Practice Test Questions and Exam Dumps Part 5 Q81-100

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 81: Which GDPR provision establishes the principle that processing must have a valid legal basis?

  1. Article 6
  2. Article 25
  3. Article 32
  4. Article 44

Correct Answer: 1. Article 6

Explanation: Article 6 identifies the principal lawful bases for processing personal data under the GDPR. These include consent, necessity for performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or exercise of official authority, and legitimate interests where the applicable conditions are satisfied. A controller should identify the appropriate lawful basis before processing begins and ensure that the processing remains consistent with that basis. Selecting a lawful basis is distinct from satisfying other GDPR requirements, such as transparency, purpose limitation, data minimization, security, and data-subject rights.

Question 82: Which legal basis is generally relevant when processing is necessary to perform a contract with the data subject?

  1. Legitimate interests
  2. Consent
  3. Contract
  4. Vital interests

Correct Answer: 3. Contract

Explanation: Article 6(1)(b) permits processing when it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the individual’s request before entering into a contract. The processing must genuinely be necessary for the contractual purpose. Organizations should not automatically treat every processing activity associated with a customer relationship as contractually necessary. Optional analytics, unrelated advertising, or other activities may require a different lawful basis. Controllers should therefore identify the specific contractual obligation and assess whether the proposed processing is objectively necessary to fulfill it.

Question 83: Which statement best describes the GDPR lawful basis of legitimate interests?

  1. It can only be used by public authorities performing official duties.
  2. It always overrides the rights and freedoms of data subjects.
  3. It requires the individual’s explicit consent in every case.
  4. It may apply where the controller or a third party has a legitimate interest, the processing is necessary, and the individual’s interests or fundamental rights and freedoms do not override that interest.

Correct Answer: 4. It may apply where the controller or a third party has a legitimate interest, the processing is necessary, and the individual’s interests or fundamental rights and freedoms do not override that interest.

Explanation: Legitimate interests under Article 6(1)(f) require a structured assessment. The controller should identify a legitimate interest, establish that processing is necessary for that interest, and balance it against the interests and fundamental rights and freedoms of the data subject. The assessment should consider the context of the processing, the individual’s reasonable expectations, the nature of the data, and potential impacts. Appropriate safeguards may reduce risks. Legitimate interests cannot simply be invoked because processing is convenient or commercially useful. Public authorities also face restrictions when relying on this ground in the performance of their tasks.

Question 84: Which of the following is NOT one of the six principal lawful bases listed in Article 6 of the GDPR?

  1. Consent
  2. Data minimization
  3. Contract
  4. Legal obligation

Correct Answer: 2. Data minimization

Explanation: Data minimization is one of the GDPR’s fundamental processing principles under Article 5, not a lawful basis under Article 6. The six principal Article 6 bases are consent, contract, legal obligation, vital interests, public task or official authority, and legitimate interests. A controller must identify an appropriate Article 6 lawful basis while also complying with the other GDPR principles. For example, an organization may lawfully process certain information under a contractual basis but still violate the data minimization principle if it collects excessive information. Lawfulness and the broader principles therefore operate together rather than replacing one another.

Question 85: What is an important characteristic of valid GDPR consent?

  1. Consent must be freely given, specific, informed, and unambiguous.
  2. Consent is valid whenever the organization includes it in a lengthy privacy policy.
  3. Consent cannot be withdrawn after it has been provided.
  4. Silence always constitutes consent.

Correct Answer: 1. Consent must be freely given, specific, informed, and unambiguous.

Explanation: Article 4 and Article 7 establish requirements for valid consent. Consent must be freely given, specific, informed, and unambiguous, and it should involve a clear affirmative action. Controllers must be able to demonstrate that consent was obtained and must ensure that withdrawal is possible. Withdrawal should generally be as easy as giving consent. Where consent is bundled with unnecessary conditions or individuals face an imbalance that prevents a genuinely free choice, its validity may be questioned. Consent should therefore be treated as an active data-protection mechanism rather than merely a checkbox included in a general privacy notice.

Question 86: Which statement about withdrawing consent under the GDPR is correct?

  1. Consent can be withdrawn only with the approval of the controller.
  2. Withdrawal is permitted only after the original processing period ends.
  3. A data subject may withdraw consent at any time, and it should generally be as easy to withdraw as to give consent.
  4. Withdrawal automatically makes all earlier processing unlawful.

Correct Answer: 3. A data subject may withdraw consent at any time, and it should generally be as easy to withdraw as to give consent.

Explanation: Article 7 requires controllers relying on consent to ensure that individuals can withdraw consent at any time. Withdrawal must be as easy as giving consent. Withdrawal does not retroactively invalidate processing that was lawful on the basis of consent before withdrawal occurred. Once consent is withdrawn, however, the controller must generally stop processing based solely on that consent unless another lawful basis applies. Organizations should therefore provide practical and accessible withdrawal mechanisms and ensure that systems can distinguish current consent status from historical processing. They should also communicate relevant consequences of withdrawal where appropriate.

Question 87: Which GDPR principle requires organizations to specify the purposes for which personal data is collected?

  1. Accuracy
  2. Purpose limitation
  3. Integrity and confidentiality
  4. Storage limitation

Correct Answer: 2. Purpose limitation

Explanation: Purpose limitation requires personal data to be collected for specified, explicit, and legitimate purposes. Controllers should establish clear purposes before or at the time of collection and should not subsequently process the information in a way that is incompatible with those purposes. The principle helps prevent organizations from collecting personal data without a defined objective and later using it for unrelated activities. When assessing further processing, controllers should consider the compatibility criteria in Article 6(4), including the relationship between the original and new purposes, the context of collection, the nature of the data, possible consequences, and appropriate safeguards.

Question 88: Which of the following is most directly associated with the GDPR’s fairness principle?

  1. Keeping personal data forever
  2. Collecting the maximum amount of information available
  3. Processing personal data in a way that individuals would reasonably expect and that does not unjustifiably harm or mislead them
  4. Requiring every organization to use the same privacy technology

Correct Answer: 3. Processing personal data in a way that individuals would reasonably expect and that does not unjustifiably harm or mislead them

Explanation: Fairness requires controllers to consider how their processing affects individuals and whether the processing is consistent with reasonable expectations, applicable rights, and the circumstances in which the information was obtained. Processing that is technically lawful may still raise fairness concerns if it unexpectedly or unjustifiably disadvantages individuals. Fairness is especially relevant in profiling, automated decision-making, data reuse, and other activities that can significantly affect people. The principle works alongside lawfulness and transparency: an organization should have a valid legal basis, communicate relevant information clearly, and ensure that the overall processing is not unfair to the individuals concerned.

Question 89: What is the main purpose of the GDPR’s data minimization principle?

  1. To require organizations to delete all data immediately
  2. To ensure that personal data collected and processed is adequate, relevant, and limited to what is necessary
  3. To prohibit organizations from using any personal data
  4. To require organizations to store all data in the EU

Correct Answer: 2. To ensure that personal data collected and processed is adequate, relevant, and limited to what is necessary

Explanation: Data minimization requires organizations to limit personal data to what is necessary for the relevant processing purposes. Controllers should examine whether each category of information is genuinely needed and avoid collecting excessive data simply because it may be useful later. Applying this principle can reduce privacy and security risks and make retention and governance easier. Data minimization is assessed in relation to the stated purposes, so the amount of information that is necessary can differ between processing activities. It also works closely with privacy by design and by default, encouraging organizations to build minimization into systems and processes.

Question 90: Which statement best describes the GDPR storage limitation principle?

  1. Personal data must always be deleted after one year.
  2. Organizations may keep identifiable personal data indefinitely if storage is inexpensive.
  3. Personal data should be kept in identifiable form for no longer than necessary for the purposes for which it is processed.
  4. All personal data must be permanently anonymized immediately after collection.

Correct Answer: 3. Personal data should be kept in identifiable form for no longer than necessary for the purposes for which it is processed.

Explanation: Storage limitation requires personal data to be kept in identifiable form for no longer than is necessary for the purposes for which it is processed. Controllers should establish appropriate retention periods and review them periodically. Retention may sometimes continue because of legal obligations, public-interest purposes, or other applicable grounds, provided the relevant requirements are satisfied. The GDPR does not impose a universal retention period for every type of information. Organizations should therefore connect retention schedules to processing purposes, legal requirements, business needs, and appropriate safeguards rather than retaining personal data indefinitely by default.

Question 91: Which statement about the GDPR principle of accountability is correct?

  1. Accountability applies only after a supervisory authority begins an investigation.
  2. Accountability requires controllers to be responsible for compliance and to demonstrate that processing complies with GDPR requirements.
  3. Accountability eliminates the need for technical security measures.
  4. Accountability means every organization must use identical compliance documentation.

Correct Answer: 2. Accountability requires controllers to be responsible for compliance and to demonstrate that processing complies with GDPR requirements.

Explanation: Article 5(2) establishes the accountability principle. Controllers are responsible for compliance with the GDPR’s principles and must be able to demonstrate that compliance. Demonstration can involve governance measures, policies, records, risk assessments, DPIAs, contracts, training, security controls, audits, and other appropriate evidence. Accountability is therefore broader than simply responding to regulatory investigations. Organizations should be able to explain how their processing complies with the Regulation and show that appropriate measures are actually implemented. The specific evidence required will depend on the nature, scope, context, purposes, and risks of the processing.

Question 92: Which GDPR principle requires personal data to be protected against unauthorized or unlawful processing and accidental loss, destruction, or damage?

  1. Purpose limitation
  2. Accuracy
  3. Integrity and confidentiality
  4. Data minimization

Correct Answer: 3. Integrity and confidentiality

Explanation: Article 5(1)(f) requires personal data to be processed with appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. This principle is closely connected to Article 32, which requires appropriate technical and organizational measures based on the risks associated with processing. Security controls can include encryption, pseudonymisation, access management, resilience, backup and recovery, testing, and organizational policies. Controllers and processors should assess the risks associated with their processing rather than applying a one-size-fits-all security standard. Effective protection should address confidentiality, integrity, and availability throughout the data lifecycle.

Question 93: What is the main purpose of Article 25 of the GDPR?

  1. To establish rules for administrative fines
  2. To regulate international transfers exclusively
  3. To establish data protection by design and by default
  4. To define the duties of supervisory authorities exclusively

Correct Answer: 3. To establish data protection by design and by default

Explanation: Article 25 requires controllers to implement data protection by design and by default. Controllers should integrate appropriate safeguards into processing activities and systems from the outset, taking account of the state of the art, implementation costs, the nature and purposes of processing, and risks to individuals. By default, only personal data necessary for each specific purpose should be processed. This can involve limiting collection, retention, access, and visibility. Privacy should therefore be incorporated into the architecture and operational design of products and services rather than treated solely as a compliance document created after the processing system has already been deployed.

Question 94: Which of the following is an example of data protection by default?

  1. Automatically making a user’s profile visible to everyone
  2. Collecting optional personal information unless the user manually disables it
  3. Setting a service so that only information necessary for the requested purpose is collected and accessible by default
  4. Storing every possible category of personal data indefinitely

Correct Answer: 3. Setting a service so that only information necessary for the requested purpose is collected and accessible by default

Explanation: Data protection by default means that appropriate privacy-protective settings should apply without requiring individuals to take additional action. Only personal data necessary for each specific purpose should ordinarily be processed by default, considering factors such as collection, storage duration, and accessibility. For example, a service could avoid making optional profile information public unless the user actively chooses that setting. The objective is to reduce unnecessary processing and place protective controls into the system’s default configuration. This approach complements data minimization and privacy by design and helps ensure that privacy protection does not depend entirely on user intervention.

Question 95: Which statement best describes a personal data breach under the GDPR?

  1. Any violation of a company’s internal HR policy
  2. Any customer complaint about a privacy notice
  3. A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data
  4. Any unsuccessful attempt to log in to a website

Correct Answer: 3. A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data

Explanation: Article 4 defines a personal data breach as a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed. Breaches can affect confidentiality, integrity, or availability. They may result from cyberattacks, human error, lost devices, misdirected communications, system failures, or other incidents. Once a controller becomes aware of a qualifying breach, it should assess the risks to individuals and determine whether notification to a supervisory authority or affected data subjects is required. Not every security event automatically requires notification.

Question 96: When is a controller generally required to notify the competent supervisory authority of a personal data breach?

  1. Only when the breach affects more than 1,000 people
  2. Whenever the breach is likely to result in a risk to the rights and freedoms of natural persons, subject to the GDPR’s notification requirements
  3. Only when the media reports the incident
  4. Only after affected individuals have sued the organization

Correct Answer: 2. Whenever the breach is likely to result in a risk to the rights and freedoms of natural persons, subject to the GDPR’s notification requirements

Explanation: Article 33 generally requires controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it when the breach is likely to result in a risk to the rights and freedoms of natural persons. Notification is not required where the breach is unlikely to result in such a risk. If notification is made after the 72-hour period, the controller should provide reasons for the delay. The risk assessment should consider factors such as the nature and volume of data, the circumstances of the breach, potential consequences, and the characteristics of affected individuals.

Question 97: Which statement about notification of a high-risk personal data breach to individuals is correct?

  1. Individuals must always be notified of every breach regardless of risk.
  2. Individual notification is generally required when the breach is likely to result in a high risk to the rights and freedoms of natural persons, subject to specified exceptions.
  3. Only the processor can notify affected individuals.
  4. Individual notification is never required under the GDPR.

Correct Answer: 2. Individual notification is generally required when the breach is likely to result in a high risk to the rights and freedoms of natural persons, subject to specified exceptions.

Explanation: Article 34 requires the controller to communicate a personal data breach to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. The communication should describe the nature of the breach in clear and plain language and provide relevant information about likely consequences and measures taken or proposed. Exceptions can apply, including where appropriate technical and organizational measures have made the data unintelligible or subsequent measures have removed the high risk. Controllers must therefore distinguish between the risk threshold for supervisory-authority notification and the higher threshold generally relevant to communication with affected individuals.

Question 98: Which of the following is a common purpose of a Data Protection Impact Assessment?

  1. To determine the organization’s annual tax liability
  2. To identify and assess privacy risks arising from high-risk processing and identify measures to mitigate those risks
  3. To guarantee that the supervisory authority will approve the processing
  4. To replace all GDPR documentation

Correct Answer: 2. To identify and assess privacy risks arising from high-risk processing and identify measures to mitigate those risks

Explanation: A DPIA is a structured assessment used to identify and address risks to individuals arising from processing that is likely to result in a high risk to their rights and freedoms. It should describe the processing, assess necessity and proportionality, evaluate risks, and identify measures to address those risks. DPIAs support accountability and privacy by design because they encourage organizations to consider data protection before high-risk processing begins. They do not automatically guarantee regulatory approval and do not replace other GDPR documentation or compliance obligations. If high residual risk remains after mitigation, prior consultation with the supervisory authority may be necessary.

Question 99: Which of the following can be an appropriate safeguard for international transfers under Chapter V of the GDPR?

  1. A general statement on the organization’s website that it respects privacy
  2. A verbal assurance from the recipient
  3. Standard Contractual Clauses adopted or recognized under the applicable GDPR framework
  4. An ordinary marketing agreement with no data-protection provisions

Correct Answer: 3. Standard Contractual Clauses adopted or recognized under the applicable GDPR framework

Explanation: Chapter V provides several mechanisms for transferring personal data to third countries. Appropriate safeguards can include Standard Contractual Clauses, Binding Corporate Rules, approved codes of conduct with binding and enforceable commitments, and approved certification mechanisms with binding commitments, subject to their respective conditions. An ordinary commercial agreement or informal promise is not automatically an appropriate safeguard. Organizations using SCCs must also consider the circumstances of the transfer and whether additional safeguards are necessary. International transfer compliance is separate from identifying an Article 6 lawful basis and should be assessed whenever personal data is transferred to a third country or international organization.

Question 100: Which statement best describes an adequacy decision under the GDPR?

  1. It is a decision determining that a third country, territory, sector, or international organization provides an adequate level of data protection for qualifying transfers.
  2. It permanently exempts an organization from all GDPR obligations.
  3. It allows unlimited transfers to every country in the world.
  4. It is a contractual agreement signed between two private companies.

Correct Answer: 1. It is a decision determining that a third country, territory, sector, or international organization provides an adequate level of data protection for qualifying transfers.

Explanation: Under Article 45, the European Commission may determine that a third country, a territory or specified sector within a third country, or an international organization ensures an adequate level of protection. Where an applicable adequacy decision exists, qualifying transfers can generally take place without the controller needing to rely on an Article 46 safeguard or Article 49 derogation. An adequacy decision does not exempt the transferring organization from the rest of the GDPR. Controllers must still comply with principles such as lawfulness, transparency, security, accountability, and data-subject rights when processing personal data.