{"id":20736,"date":"2026-09-24T07:10:13","date_gmt":"2026-09-24T07:10:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20736"},"modified":"2026-09-24T07:10:13","modified_gmt":"2026-09-24T07:10:13","slug":"iapp-cipp-e-practice-test-questions-and-exam-dumps-part-2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-e-practice-test-questions-and-exam-dumps-part-2-q21-40\/","title":{"rendered":"IAPP CIPP-E Practice Test Questions and Exam Dumps Part 2 Q21-40"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-e-exam-dumps\"><b>IAPP CIPP-E Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 21: Under the GDPR, which requirement applies when an organization relies on legitimate interests as its lawful basis for processing personal data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The processing must always be approved by a supervisory authority.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The organization must obtain explicit consent from every data subject.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The organization must balance its legitimate interests against the interests and fundamental rights and freedoms of the data subject.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The organization may process any category of personal data without restrictions.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The organization must balance its legitimate interests against the interests and fundamental rights and freedoms of the data subject.<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Legitimate interests under Article 6(1)(f) can provide a lawful basis for processing when the controller or a third party has a legitimate interest that is not overridden by the interests or fundamental rights and freedoms of the data subject. Organizations should identify the legitimate interest, assess whether processing is necessary for that interest, and perform a balancing assessment. Certain situations, such as processing by public authorities in the performance of their tasks, are subject to specific limitations. The assessment should also consider reasonable expectations and appropriate safeguards.<\/span><\/p>\n<p><b>Question 22: Which GDPR provision establishes the territorial scope for organizations established outside the European Union that offer goods or services to individuals in the EU?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 3<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 12<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 25<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 44<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Article 3<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 3 of the GDPR establishes its territorial scope. The GDPR can apply to organizations outside the EU when their processing activities relate to offering goods or services to individuals in the Union or monitoring their behavior when that behavior takes place within the Union. The provision is important because an organization does not necessarily need an establishment in the EU for the GDPR to apply. Organizations assessing applicability should therefore consider the nature of their processing activities, their targeting of individuals in the Union, and whether the relevant territorial-scope conditions are satisfied.<\/span><\/p>\n<p><b>Question 23: Which of the following is considered a special category of personal data under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A customer&#8217;s postal address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An employee&#8217;s favorite color<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A company&#8217;s registration number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An individual&#8217;s biometric data used for the purpose of uniquely identifying that person<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. An individual&#8217;s biometric data used for the purpose of uniquely identifying that person<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 9 identifies special categories of personal data that receive additional protection. These include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for uniquely identifying a person, health data, and certain information concerning sex life or sexual orientation. Processing such data is generally prohibited unless a specific Article 9 exception applies. Not every piece of information about a person is special category data, and the context and purpose of processing can be important when determining whether the enhanced Article 9 rules apply.<\/span><\/p>\n<p><b>Question 24: What is the primary purpose of a Data Protection Impact Assessment (DPIA) under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify and assess risks to individuals arising from certain processing activities and determine measures to address those risks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace the organization&#8217;s records of processing activities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To obtain automatic approval from the supervisory authority before all processing begins<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine the financial value of personal data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To identify and assess risks to individuals arising from certain processing activities and determine measures to address those risks<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A DPIA is required when processing is likely to result in a high risk to the rights and freedoms of natural persons, particularly when new technologies or certain types of large-scale or systematic processing are involved. The assessment describes the processing, evaluates necessity and proportionality, assesses risks to individuals, and identifies measures to address those risks. A DPIA is therefore a risk-management and accountability tool rather than a general approval mechanism. If high residual risk remains and cannot be sufficiently mitigated, the controller may need to consult the competent supervisory authority before proceeding.<\/span><\/p>\n<p><b>Question 25: Under the GDPR, what is generally required when a controller engages a processor to process personal data on its behalf?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A written or otherwise legally binding contract or legal act containing specified requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approval from every individual whose data will be processed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer of all controller responsibilities to the processor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A requirement that the processor become a joint controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A written or otherwise legally binding contract or legal act containing specified requirements<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 28 requires processing by a processor to be governed by a contract or other legal act that binds the processor to the controller. The arrangement must address matters such as processing only on documented instructions, confidentiality, security measures, assistance with data-subject rights, support for compliance obligations, deletion or return of personal data, and audit-related requirements. The contract does not transfer the controller&#8217;s overall GDPR responsibilities to the processor. The processor also has direct obligations under the GDPR, including requirements concerning security, sub-processors, and processing instructions.<\/span><\/p>\n<p><b>Question 26: Which GDPR right allows an individual, in certain circumstances, to obtain a copy of their personal data and information about how it is being processed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to restriction of processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to data portability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right of access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Right of access<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 15 provides the right of access. A data subject can request confirmation as to whether personal data concerning them is being processed and, where applicable, access to that data along with specified information about the processing. This can include purposes of processing, categories of personal data, recipients, retention information, and information about the individual&#8217;s rights. The right is subject to certain limitations and exceptions, so access is not necessarily unlimited in every circumstance. The right of access should be distinguished from data portability, which has different conditions and concerns receiving certain data in a structured, commonly used, machine-readable format.<\/span><\/p>\n<p><b>Question 27: Which GDPR principle requires a controller to demonstrate that its processing activities comply with the Regulation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accountability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purpose limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Accountability<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The accountability principle requires controllers to be responsible for compliance with the GDPR and to be able to demonstrate that compliance. This goes beyond simply following individual rules. Organizations may use measures such as policies, records of processing activities, privacy impact assessments, contracts, security controls, training, audits, and documented decision-making to demonstrate compliance. Accountability also supports a risk-based approach in which organizations implement measures appropriate to their processing activities. The principle therefore connects substantive data protection requirements with evidence that an organization has actively implemented and maintained appropriate compliance measures.<\/span><\/p>\n<p><b>Question 28: What is the general GDPR deadline for responding to a valid data-subject request under Articles 15 to 22?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 7 calendar days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 30 calendar days with no possibility of extension<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 60 calendar days in every circumstance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One month, subject to certain conditions allowing an extension of up to two further months<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. One month, subject to certain conditions allowing an extension of up to two further months<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Under Article 12, controllers generally must respond to requests under Articles 15 to 22 without undue delay and in any event within one month of receiving the request. The period can be extended by up to two further months when necessary, taking into account the complexity and number of requests. The controller must inform the data subject of the extension and the reasons for the delay within the initial one-month period. If the controller does not act on the request, it must generally explain the reasons and inform the individual about the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.<\/span><\/p>\n<p><b>Question 29: Which organization is responsible for enforcing the GDPR within its national jurisdiction, subject to the Regulation&#8217;s rules on supervisory authorities and cross-border processing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Commission exclusively<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The competent national supervisory authority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Parliament exclusively<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Council exclusively<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The competent national supervisory authority<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Each EU Member State has one or more independent supervisory authorities responsible for monitoring and enforcing GDPR compliance within its jurisdiction. Their powers include investigating complaints, conducting investigations, obtaining information, and imposing corrective measures and administrative fines where appropriate. Cross-border processing can involve the GDPR&#8217;s cooperation and consistency mechanisms, including the lead supervisory authority concept. The European Data Protection Board supports consistency and cooperation among supervisory authorities but does not replace national supervisory authorities as the ordinary enforcement bodies for individual jurisdictions.<\/span><\/p>\n<p><b>Question 30: Which statement best describes the GDPR&#8217;s principle of purpose limitation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data must always be stored permanently.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data may only be collected with the individual&#8217;s written consent.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data should be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data can be used for any purpose once it has been lawfully collected.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Personal data should be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Purpose limitation requires organizations to define the purposes for which personal data is collected and to avoid incompatible secondary uses. A controller should be able to explain why the data is being collected and how subsequent processing relates to the original purpose. Further processing for another purpose is not automatically prohibited in every circumstance; the GDPR provides rules for assessing compatibility and identifies situations in which further processing may be permitted. Organizations should therefore evaluate purpose compatibility rather than assuming that lawful initial collection permits unrestricted future use.<\/span><\/p>\n<p><b>Question 31: Which of the following is an example of pseudonymisation rather than anonymisation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replacing a person&#8217;s name with a code while retaining a separate key that can reconnect the code to the individual<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanently deleting all information that could reasonably identify an individual<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publishing statistics that cannot be linked back to identifiable individuals<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Destroying all identifiers and the information needed to reconstruct them<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Replacing a person&#8217;s name with a code while retaining a separate key that can reconnect the code to the individual<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Pseudonymisation involves processing personal data so that it can no longer be attributed to a specific individual without the use of additional information, which is kept separately and protected by appropriate technical and organizational measures. Because the data can potentially be re-linked to an individual, pseudonymised information remains personal data under the GDPR. Anonymisation is different because properly anonymised information is no longer identifiable and therefore falls outside the GDPR&#8217;s definition of personal data. Pseudonymisation is specifically recognized as a security and privacy-enhancing technique under the Regulation.<\/span><\/p>\n<p><b>Question 32: Which right allows a data subject to receive certain personal data in a structured, commonly used and machine-readable format and transmit it to another controller in qualifying circumstances?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to erasure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to data portability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to restriction of processing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Right to data portability<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 20 establishes the right to data portability. It applies to personal data concerning the data subject that the individual has provided to a controller and is processed by automated means on the basis of consent or a contract. Where the conditions are met, the individual can receive the data in a structured, commonly used and machine-readable format and may have the right to transmit it directly to another controller where technically feasible. The right is distinct from the broader right of access and is intended to support individual control and movement of qualifying personal data between service providers.<\/span><\/p>\n<p><b>Question 33: What does the GDPR generally require regarding the appointment of a Data Protection Officer (DPO)?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every organization processing any personal data must appoint a DPO.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only public authorities are ever required to appoint a DPO.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A DPO is required in specified circumstances, including certain large-scale regular and systematic monitoring or large-scale processing of special categories of data.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A DPO is required only when a data breach has occurred.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A DPO is required in specified circumstances, including certain large-scale regular and systematic monitoring or large-scale processing of special categories of data.<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 37 requires controllers and processors to designate a DPO in specified circumstances. These include situations where the core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of personal data or certain criminal-conviction and offence data. Public authorities and bodies generally also have DPO requirements, subject to the Regulation&#8217;s terms. Organizations should assess their actual processing activities against the Article 37 criteria rather than assuming that organizational size alone determines whether a DPO is mandatory.<\/span><\/p>\n<p><b>Question 34: Which of the following is a core responsibility of a GDPR Data Protection Officer?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Making all final commercial decisions involving personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Serving as the organization&#8217;s external auditor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replacing the supervisory authority in enforcement matters<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Informing and advising the controller or processor and monitoring compliance with GDPR obligations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Informing and advising the controller or processor and monitoring compliance with GDPR obligations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 39 describes several DPO tasks, including informing and advising the controller or processor and employees who carry out processing, monitoring compliance with the GDPR and relevant policies, providing advice concerning DPIAs, and cooperating with the supervisory authority. The DPO may also act as a contact point for the supervisory authority and for data subjects on processing-related matters. The DPO does not replace management or assume the controller&#8217;s ultimate responsibility for compliance. Organizations must also ensure that the DPO can perform the role with appropriate independence and without improper conflicts of interest.<\/span><\/p>\n<p><b>Question 35: When can a controller generally rely on consent as a GDPR legal basis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> When consent is freely given, specific, informed and unambiguous through a clear affirmative action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever a privacy notice is displayed, regardless of the individual&#8217;s action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever processing is commercially useful to the controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when consent is provided through a handwritten document<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. When consent is freely given, specific, informed and unambiguous through a clear affirmative action<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> GDPR consent must satisfy defined conditions. It should be freely given, specific, informed and unambiguous, and it must involve a clear affirmative action. Silence, pre-ticked boxes, or inactivity generally do not constitute valid consent. Individuals must also be able to withdraw consent, and withdrawal should generally be as easy as giving it. Where there is a significant imbalance between the parties, such as certain employment contexts, consent may not always be considered freely given. Controllers relying on consent must also be able to demonstrate that valid consent was obtained.<\/span><\/p>\n<p><b>Question 36: What is the main purpose of maintaining Records of Processing Activities (ROPA) under Article 30?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all privacy notices provided to data subjects<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To document relevant processing activities and support organizational accountability and compliance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that every processing activity is lawful<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To serve as a public database containing all personal data held by an organization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To document relevant processing activities and support organizational accountability and compliance<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 30 requires controllers and processors in specified circumstances to maintain records of processing activities. These records can include information such as the purposes of processing, categories of data subjects and personal data, recipients, international transfers, and relevant retention or security information, depending on whether the record is maintained by a controller or processor. ROPA supports accountability by giving the organization a structured overview of its processing activities. It does not itself make processing lawful, replace privacy notices, or require organizations to publish personal data.<\/span><\/p>\n<p><b>Question 37: Under the GDPR, what is generally considered a personal data breach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any complaint submitted by a data subject<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any processing activity involving sensitive information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A breach of a commercial contract unrelated to personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 4 defines a personal data breach broadly as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed. The definition covers confidentiality, integrity, and availability impacts. A breach can result from malicious activity, human error, system failure, or other security incidents. Once a controller becomes aware of a qualifying breach, it must assess the risks to individuals and determine whether notification to the supervisory authority and affected individuals is required under Articles 33 and 34.<\/span><\/p>\n<p><b>Question 38: What is the general GDPR deadline for notifying a supervisory authority of a personal data breach when notification is required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Without undue delay and, where feasible, not later than 72 hours after becoming aware of it<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Within seven calendar days in every case<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Within one month after completing the internal investigation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after the affected individuals have been notified<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Without undue delay and, where feasible, not later than 72 hours after becoming aware of it<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 33 generally requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification occurs after 72 hours, the controller must generally provide reasons for the delay. A processor that becomes aware of a personal data breach must notify the controller without undue delay. The 72-hour rule concerns notification to the supervisory authority, not an automatic requirement to notify individuals in every breach.<\/span><\/p>\n<p><b>Question 39: Which factor is particularly relevant when determining whether affected individuals must be notified of a personal data breach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the organization has experienced a breach before<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the breach is likely to result in a high risk to the rights and freedoms of natural persons<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the organization has cyber insurance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the incident occurred during business hours<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Whether the breach is likely to result in a high risk to the rights and freedoms of natural persons<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 34 requires communication of a personal data breach to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. The communication should describe the nature of the breach in clear and plain language and provide relevant information such as likely consequences and measures taken or proposed to address the breach. Certain exceptions apply, including situations where appropriate technical and organizational measures have made the data unintelligible or subsequent measures have removed the high risk. The assessment therefore focuses on risk to individuals rather than the organization&#8217;s inconvenience or financial exposure.<\/span><\/p>\n<p><b>Question 40: Which statement best describes the GDPR principle of storage limitation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data must always be deleted immediately after collection.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data may be retained indefinitely if the controller has a legitimate interest.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data should be kept in identifiable form for no longer than necessary for the purposes for which it is processed, subject to applicable exceptions.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data must be retained for exactly five years.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Personal data should be kept in identifiable form for no longer than necessary for the purposes for which it is processed, subject to applicable exceptions.<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The storage limitation principle requires personal data to be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed. Organizations should therefore establish appropriate retention periods and review them periodically. Longer retention can sometimes be justified by specific legal obligations or other applicable grounds, and data may be retained for certain purposes under appropriate safeguards. The GDPR does not impose one universal retention period for all personal data. Retention decisions should be linked to the relevant purpose, legal requirements, and organizational policies.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps &nbsp; Question 21: Under the GDPR, which requirement applies when an organization relies on legitimate interests as its lawful basis for processing personal data? The processing must always be approved by a supervisory authority. The organization must obtain explicit consent from every data subject. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20736"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20736"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20736\/revisions"}],"predecessor-version":[{"id":20737,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20736\/revisions\/20737"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}