IAPP CIPP-E Practice Test Questions and Exam Dumps Part 8 Q141-160

View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps

 

Question 141. Which GDPR principle requires personal data to be accurate and, where necessary, kept up to date?

  1. Purpose limitation
  2. Accuracy
  3. Storage limitation
  4. Data minimization

Correct Answer: 2. Accuracy

Explanation:
The accuracy principle requires personal data to be accurate and, where necessary, kept up to date. Controllers should take reasonable steps to ensure that inaccurate personal data is erased or rectified without undue delay, taking into account the purposes for which the information is processed. The principle is particularly important where inaccurate information could adversely affect individuals, such as in employment, financial, healthcare, or identity-related contexts. Organizations should therefore establish processes for identifying and correcting inaccurate records. Accuracy is one of the core principles under Article 5 and forms part of the broader accountability framework.

Question 142. What is the main purpose of the GDPR transparency requirement?

  1. To ensure individuals receive clear information about how their personal data is processed
  2. To allow controllers to avoid documenting processing activities
  3. To require organizations to publish all personal data they hold
  4. To eliminate the need for lawful bases

Correct Answer: 1. To ensure individuals receive clear information about how their personal data is processed

Explanation:
Transparency requires controllers to provide individuals with information about the processing of their personal data in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. Privacy information can include the controller’s identity, purposes of processing, lawful bases, recipients, retention periods, data subject rights, and relevant information concerning international transfers. The precise information required depends on whether the data was collected directly from the individual or obtained from another source. Transparency supports informed decision-making and allows individuals to understand how organizations use their personal information.

Question 143. Which GDPR right allows an individual to obtain a copy of their personal data and information about its processing?

  1. Right to object
  2. Right to restriction
  3. Right of access
  4. Right to erasure

Correct Answer: 3. Right of access

Explanation:
The right of access under Article 15 allows individuals to obtain confirmation as to whether their personal data is being processed and, where it is, access to the personal data and specified information about the processing. This can include the purposes of processing, categories of personal data, recipients, retention information, and information about the source of the data where applicable. Individuals generally have the right to receive a copy of the personal data undergoing processing. Controllers may apply limited restrictions or exceptions where permitted by law, but the right is a fundamental mechanism for transparency and individual control over personal information.

Question 144. Which condition is generally required for a valid request to exercise a GDPR data subject right?

  1. The individual must obtain permission from a supervisory authority
  2. The organization must charge a mandatory processing fee
  3. The request must always be submitted by postal mail
  4. The controller may take reasonable steps to verify the identity of the requester when necessary

Correct Answer: 4. The controller may take reasonable steps to verify the identity of the requester when necessary

Explanation:
Controllers must handle data subject rights requests appropriately and may take reasonable steps to verify the identity of the person making a request when there are reasonable doubts concerning identity. This is particularly important because responding to a request without appropriate verification could result in personal data being disclosed to the wrong person. However, identity verification should itself be proportionate and should not create unnecessary barriers to exercising rights. GDPR procedures should therefore balance security and accessibility. Controllers should also respond within the applicable deadlines and explain any refusal or limitation where required.

Question 145. Which of the following is an example of processing based on performance of a contract?

  1. Processing a customer’s shipping address to deliver goods ordered under a sales contract
  2. Processing unrelated data for a future advertising campaign without additional justification
  3. Collecting employee health information solely because it may become useful
  4. Selling customer data to an unrelated company without a lawful basis

Correct Answer: 1. Processing a customer’s shipping address to deliver goods ordered under a sales contract

Explanation:
Article 6(1)(b) permits processing when it is necessary for the performance of a contract to which the data subject is party, or to take steps at the individual’s request before entering into a contract. Using a customer’s shipping address to deliver goods that the customer has ordered is a typical example because the information is necessary to perform the contractual obligation. The contract basis does not authorize every processing activity connected to the customer relationship. Processing that is not necessary for contract performance may require another lawful basis, such as consent or legitimate interests, depending on the circumstances.

Question 146. Which statement best describes the GDPR principle of integrity and confidentiality?

  1. Personal data may be accessed by anyone inside the organization
  2. Personal data should be protected against unauthorized or unlawful processing and accidental loss, destruction, or damage
  3. Personal data must always be publicly available
  4. Security obligations apply only after a breach occurs

Correct Answer: 2. Personal data should be protected against unauthorized or unlawful processing and accidental loss, destruction, or damage

Explanation:
The integrity and confidentiality principle requires personal data to be processed in a manner that ensures appropriate security. This includes protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures. Security controls should be proportionate to the risks associated with processing. Examples can include access controls, encryption, pseudonymisation, resilience measures, backup and recovery procedures, monitoring, and staff training. The requirement is preventive and ongoing rather than something that becomes relevant only after a security incident has occurred.

Question 147. What is a key requirement of the GDPR accountability principle?

  1. Controllers must be able to demonstrate compliance with the GDPR
  2. Controllers must eliminate all processing of personal data
  3. Controllers must obtain supervisory authority approval for every processing activity
  4. Controllers must appoint a DPO in every circumstance

Correct Answer: 1. Controllers must be able to demonstrate compliance with the GDPR

Explanation:
The accountability principle requires controllers to comply with the GDPR principles and to demonstrate that compliance. This can involve implementing appropriate policies, procedures, technical controls, governance mechanisms, records, training, audits, and documentation. Accountability is not limited to having written policies; organizations should be able to show that their measures are implemented and effective. The requirement does not mean that every organization must appoint a DPO or obtain prior supervisory authority approval for all processing. Instead, controllers must establish a governance framework appropriate to the nature, scope, context, and purposes of their processing activities.

Question 148. Which GDPR mechanism is specifically designed to support lawful international transfers within a multinational corporate group?

  1. Privacy notices
  2. Records of processing activities
  3. Binding Corporate Rules
  4. Data minimization

Correct Answer: 3. Binding Corporate Rules

Explanation:
Binding Corporate Rules, or BCRs, are one of the mechanisms recognized under Chapter V GDPR for transfers of personal data by a group of undertakings or group of enterprises engaged in a joint economic activity. BCRs establish legally binding and enforceable data protection commitments governing transfers within the group. They generally require approval through the relevant supervisory authority process and must contain specified elements concerning rights, responsibilities, complaint handling, liability, and compliance. BCRs are different from Standard Contractual Clauses, which are another recognized transfer mechanism and are not limited to multinational corporate groups.

Question 149. Under the GDPR, which body can issue guidelines and recommendations to promote consistent application of data protection law?

  1. European Data Protection Board
  2. European Central Bank
  3. European Court of Auditors
  4. European Investment Bank

Correct Answer: 1. European Data Protection Board

Explanation:
The European Data Protection Board plays an important role in promoting consistent application of the GDPR. Among its responsibilities, it issues guidelines, recommendations, and best practices on issues relating to data protection law. These materials help organizations, supervisory authorities, and other stakeholders interpret and apply GDPR requirements consistently. The EDPB also has responsibilities concerning cooperation among supervisory authorities and can adopt binding decisions in specified circumstances. Its guidance does not replace the GDPR itself or automatically resolve every organization-specific legal question, but it is an important source for understanding how European data protection requirements are interpreted and applied.

Question 150. Which processing activity would generally require an Article 9 condition in addition to an Article 6 lawful basis?

  1. Processing a customer’s postal address
  2. Processing a person’s health data
  3. Processing a company’s registration number
  4. Processing a product serial number

Correct Answer: 2. Processing a person’s health data

Explanation:
Health data is a special category of personal data under Article 9 GDPR. Processing it generally requires both an applicable lawful basis under Article 6 and a separate condition permitting processing under Article 9. This two-layer approach reflects the enhanced protection given to special categories of personal data. For example, explicit consent can potentially provide an Article 9 condition in appropriate circumstances, while another Article 9 exception may apply depending on the context. An Article 6 lawful basis by itself is not sufficient to authorize processing of special category data when Article 9 applies.

Question 151. What is the purpose of the GDPR cooperation procedure among supervisory authorities?

  1. To eliminate all national supervisory authorities
  2. To allow supervisory authorities to cooperate and exchange information in cross-border cases
  3. To transfer all enforcement powers to private organizations
  4. To prevent organizations from operating across EU Member States

Correct Answer: 2. To allow supervisory authorities to cooperate and exchange information in cross-border cases

Explanation:
The GDPR establishes cooperation and consistency mechanisms to support effective enforcement, particularly when processing activities affect individuals or establishments in multiple Member States. Supervisory authorities can cooperate, exchange information, conduct joint operations, and assist one another where appropriate. The lead supervisory authority can coordinate certain cross-border cases under the one-stop-shop mechanism, while concerned authorities remain involved where applicable. These mechanisms are intended to promote consistent enforcement without eliminating national supervisory authorities. The cooperation framework is especially relevant for organizations whose processing activities span multiple European jurisdictions.

Question 152. Which of the following is a recognized lawful basis under Article 6 GDPR?

  1. Organizational convenience
  2. Data minimization
  3. Commercial competitiveness
  4. Compliance with a legal obligation

Correct Answer: 4. Compliance with a legal obligation

Explanation:
Article 6 GDPR identifies several lawful bases for processing personal data. These include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or exercise of official authority, and legitimate interests where applicable. Data minimization is a GDPR principle rather than a lawful basis. Similarly, general commercial convenience or competitiveness does not automatically constitute an Article 6 basis. Controllers must identify an applicable lawful basis before processing and should document and communicate the basis where required.

Question 153. What is the primary purpose of a privacy notice provided under the GDPR?

  1. To inform individuals about relevant aspects of how their personal data is processed
  2. To create a lawful basis automatically
  3. To prevent individuals from exercising their rights
  4. To replace all security controls

Correct Answer: 1. To inform individuals about relevant aspects of how their personal data is processed

Explanation:
A privacy notice is an important transparency mechanism through which controllers provide individuals with information about the processing of their personal data. Depending on the circumstances, information can include the controller’s identity and contact details, purposes and lawful bases, recipients, retention periods, data subject rights, international transfers, and relevant information about automated decision-making. The notice itself does not create a lawful basis or replace other GDPR requirements. Effective privacy information should be concise, transparent, intelligible, easily accessible, and written in clear and plain language appropriate to the intended audience.

Question 154. Which situation most clearly illustrates a data protection by default measure?

  1. Making all optional data collection settings active automatically
  2. Requiring users to manually disable unnecessary data collection
  3. Configuring a service to collect only information necessary for its stated purpose by default
  4. Retaining every user’s information indefinitely

Correct Answer: 3. Configuring a service to collect only information necessary for its stated purpose by default

Explanation:
Data protection by default means that appropriate privacy protections should be built into the default settings of a processing system. Under Article 25, the controller should ensure that, by default, only personal data necessary for each specific purpose is processed. This can include limiting data collection, retention periods, accessibility, and the extent of processing. A privacy-friendly default does not require individuals to navigate complicated settings to protect themselves. The organization should establish the appropriate restrictive configuration from the outset and expand processing only where there is a valid reason and appropriate legal basis.

Question 155. Which statement about administrative fines under the GDPR is correct?

  1. Every GDPR violation automatically results in the maximum fine
  2. Fines can never be imposed on organizations
  3. Supervisory authorities may impose administrative fines in accordance with the GDPR and the circumstances of the infringement
  4. Fines are determined solely by the number of employees in an organization

Correct Answer: 3. Supervisory authorities may impose administrative fines in accordance with the GDPR and the circumstances of the infringement

Explanation:
The GDPR gives supervisory authorities corrective powers that can include administrative fines. The amount depends on the applicable infringement category and factors such as the nature, gravity, and duration of the infringement, its intentional or negligent character, measures taken to mitigate damage, degree of cooperation, categories of personal data affected, and other relevant circumstances. Certain infringements can attract fines of up to €20 million or, for an undertaking, up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. The maximum level is not automatically imposed for every violation.

Question 156. Which right allows an individual to object to processing for direct marketing purposes?

  1. Right to data portability
  2. Right to object
  3. Right to rectification
  4. Right to restriction

Correct Answer: 2. Right to object

Explanation:
Under Article 21 GDPR, individuals have a specific right to object to processing of their personal data for direct marketing purposes. Where an individual objects to processing for direct marketing, the personal data must no longer be processed for that purpose. This right applies to direct marketing, including profiling to the extent that it is related to such direct marketing. Unlike some other forms of objection under Article 21, the direct-marketing objection does not require the individual to demonstrate grounds relating to their particular situation. Organizations conducting direct marketing should therefore provide a clear and accessible way for individuals to exercise this right.

Question 157. Which statement best describes joint controllers under the GDPR?

  1. Two or more entities can jointly determine the purposes and means of processing
  2. Joint controllers are always processors of one another
  3. Joint controllers are created whenever two organizations exchange emails
  4. Joint controllers are required for every outsourcing arrangement

Correct Answer: 1. Two or more entities can jointly determine the purposes and means of processing

Explanation:
Joint controllership exists when two or more controllers jointly determine the purposes and means of processing. The entities do not necessarily need to determine every aspect of the processing together, but their decisions must demonstrate meaningful joint influence over the purposes and essential means. Article 26 requires joint controllers to determine their respective responsibilities for complying with GDPR obligations, including matters concerning data subject rights and transparency. The arrangement should reflect the parties’ actual roles rather than simply their contractual labels. Joint controllership is therefore different from a conventional controller-processor relationship.

Question 158. What is a key requirement when using Standard Contractual Clauses for international data transfers?

  1. The clauses eliminate all GDPR obligations after signing
  2. The parties must ensure that the transfer arrangement complies with applicable GDPR requirements
  3. The recipient automatically becomes established in the EEA
  4. The data subject must personally sign every transfer

Correct Answer: 2. The parties must ensure that the transfer arrangement complies with applicable GDPR requirements

Explanation:
Standard Contractual Clauses, or SCCs, are a recognized mechanism under Chapter V GDPR for certain international transfers. Using SCCs does not mean that an organization can ignore the wider GDPR framework. The parties must use the applicable clauses correctly, assess the circumstances of the transfer, and comply with relevant requirements concerning the destination country and safeguards. Depending on the circumstances, organizations may also need to assess whether supplementary measures are necessary to ensure an essentially equivalent level of protection. SCCs therefore form part of a broader transfer-compliance framework rather than acting as an automatic exemption from GDPR obligations.

Question 159. Which principle requires personal data to be limited to what is necessary for the relevant processing purpose?

  1. Accuracy
  2. Purpose limitation
  3. Data minimization
  4. Integrity and confidentiality

Correct Answer: 3. Data minimization

Explanation:
The data minimization principle requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Controllers should therefore assess what information is genuinely required before collecting or using personal data. Collecting additional information merely because it might be useful in the future can create unnecessary privacy risks and may conflict with the principle. Data minimization applies throughout the processing lifecycle, including collection, access, use, and retention decisions. It works together with purpose limitation and storage limitation to reduce unnecessary processing and exposure of personal information.

Question 160. Which circumstance can make a DPIA particularly important under the GDPR?

  1. Processing is likely to result in a high risk to the rights and freedoms of individuals
  2. An organization has fewer than ten employees
  3. The organization has a public website
  4. The processing involves only completely anonymous information

Correct Answer: 1. Processing is likely to result in a high risk to the rights and freedoms of individuals

Explanation:
A DPIA is required when a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, particularly when new technologies or certain large-scale or systematic processing activities are involved. The assessment should occur before processing begins and should describe the processing operations and purposes, assess necessity and proportionality, identify risks to individuals, and set out measures addressing those risks. A DPIA is not automatically required merely because an organization has a website or a particular number of employees. The focus is the nature and potential risk of the processing activity.