{"id":20744,"date":"2026-09-24T07:13:51","date_gmt":"2026-09-24T07:13:51","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20744"},"modified":"2026-09-24T07:13:51","modified_gmt":"2026-09-24T07:13:51","slug":"iapp-cipp-e-practice-test-questions-and-exam-dumps-part-6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-e-practice-test-questions-and-exam-dumps-part-6-q101-120\/","title":{"rendered":"IAPP CIPP-E Practice Test Questions and Exam Dumps Part 6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-e-exam-dumps\"><b>IAPP CIPP-E Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 101. Under the GDPR, which condition is required for processing personal data based on the data subject&#8217;s consent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent is valid only when provided in writing.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent cannot be withdrawn once processing begins.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent must be freely given, specific, informed, and unambiguous.<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent must be bundled with every service agreement.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Consent must be freely given, specific, informed, and unambiguous.<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">GDPR consent must meet specific conditions to be valid. It must be freely given, meaning the individual has a genuine choice and can refuse or withdraw without inappropriate consequences. It must also be specific to the processing purposes, informed through clear information, and expressed through an unambiguous indication of the individual&#8217;s wishes. Consent should not automatically be assumed from silence, inactivity, or pre-ticked boxes. Where consent is relied upon as the lawful basis, controllers must also be able to demonstrate that valid consent was obtained and provide an effective mechanism for withdrawal.<\/span><\/p>\n<p><b>Question 102. Which GDPR right allows an individual to receive personal data concerning them in a structured, commonly used, and machine-readable format and transmit it to another controller?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to restriction of processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to erasure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to data portability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Right to data portability<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right to data portability under Article 20 allows individuals, in certain circumstances, to receive personal data concerning them in a structured, commonly used, and machine-readable format. Individuals may also transmit that data to another controller without hindrance from the original controller. The right generally applies where processing is based on consent or a contract and is carried out by automated means. It is intended to enhance individual control over personal data and facilitate movement of data between service providers, while remaining subject to the conditions and limitations established by the GDPR.<\/span><\/p>\n<p><b>Question 103. Which situation most clearly demonstrates the GDPR principle of data minimization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collecting only the personal data necessary to complete the requested service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sharing customer data with all internal departments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keeping all customer information indefinitely for possible future use<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collecting every available identifier from a customer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Collecting only the personal data necessary to complete the requested service<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The data minimization principle requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. A controller should therefore identify the information genuinely required for a specific processing activity and avoid collecting unnecessary data merely because it might become useful later. For example, if an online service only needs an email address to create an account, collecting unrelated information such as a customer&#8217;s marital status would generally be difficult to justify under data minimization. The principle supports both privacy protection and responsible data governance.<\/span><\/p>\n<p><b>Question 104. What is the primary purpose of a Data Protection Impact Assessment under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine the amount of an administrative fine<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify and address risks to individuals arising from high-risk processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To document every employee who accesses personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace the requirement for technical security measures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To identify and address risks to individuals arising from high-risk processing<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A Data Protection Impact Assessment, or DPIA, is designed to help controllers identify, assess, and mitigate risks to individuals when processing is likely to result in a high risk to their rights and freedoms. It should be performed before the relevant processing begins and should consider the nature, scope, context, and purposes of processing. A DPIA also evaluates proposed safeguards and demonstrates how identified risks will be addressed. It is therefore a proactive privacy-management tool rather than a substitute for security controls, a mechanism for calculating fines, or simply an inventory of personnel.<\/span><\/p>\n<p><b>Question 105. Which statement best describes the GDPR concept of a processor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A person or organization that processes personal data on behalf of a controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A person or organization that determines the purposes of processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The individual to whom personal data relates<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A supervisory authority responsible for enforcing the GDPR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A person or organization that processes personal data on behalf of a controller<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of a controller. The controller determines the purposes and means of processing, while the processor acts according to the controller&#8217;s documented instructions, subject to the requirements of the GDPR. Processor relationships must generally be governed by a legally binding arrangement containing specified provisions. A processor may have direct GDPR obligations, including requirements concerning security, subprocessors, assistance to the controller, and records or cooperation where applicable.<\/span><\/p>\n<p><b>Question 106. What is generally required when a controller intends to use a processor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The processor must become the controller automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A written contract or other legal act must govern the processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The data subject must personally negotiate the processor agreement<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The processor must be established outside the European Economic Area<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A written contract or other legal act must govern the processing<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 28 requires processing carried out by a processor on behalf of a controller to be governed by a contract or other legal act that is binding on the processor. The arrangement must set out matters such as the subject matter and duration of processing, nature and purpose, types of personal data, categories of data subjects, and the controller&#8217;s obligations and rights. It must also contain specified processor obligations, including processing only on documented instructions, confidentiality, security, assistance with compliance obligations, and appropriate handling of personal data after the processing relationship ends.<\/span><\/p>\n<p><b>Question 107. Which right allows a data subject to request correction of inaccurate personal data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to rectification<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to erasure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to data portability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Right to rectification<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right to rectification allows individuals to have inaccurate personal data corrected without undue delay. Where personal data is incomplete, individuals may also have the right to request completion, taking into account the purposes of the processing. Accuracy is itself a fundamental GDPR principle, so controllers should take reasonable steps to ensure that inaccurate personal data is corrected or deleted. The right to rectification differs from the right to erasure, which concerns deletion of personal data in specified circumstances. Controllers must also communicate applicable rectifications to relevant recipients where required.<\/span><\/p>\n<p><b>Question 108. Which circumstance can permit a controller to process special categories of personal data under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An applicable Article 9 exception permits the processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller has stored the data for more than one year<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The data is interesting to the organization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The information was obtained from a public website<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. An applicable Article 9 exception permits the processing<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Special categories of personal data receive enhanced protection under Article 9 GDPR. These include information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for uniquely identifying a person, health data, and information concerning sex life or sexual orientation. Processing is generally prohibited unless a specific Article 9 condition applies, such as explicit consent or another recognized exception. In many cases, the controller must also identify an appropriate lawful basis under Article 6. The public availability of information does not automatically remove Article 9 protection.<\/span><\/p>\n<p><b>Question 109. What is the primary function of a GDPR supervisory authority?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To monitor and enforce the application of data protection law within its competence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide commercial insurance to controllers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To represent all controllers in contractual disputes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To approve every privacy notice before publication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To monitor and enforce the application of data protection law within its competence<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A supervisory authority is an independent public authority responsible for monitoring and enforcing the application of the GDPR within its jurisdiction and competence. Its responsibilities can include handling complaints, conducting investigations, providing guidance, exercising corrective powers, and imposing administrative fines where appropriate. Supervisory authorities also cooperate with one another under the GDPR&#8217;s consistency and cooperation mechanisms. They do not function as commercial representatives of controllers or approve every privacy notice in advance. Their role is primarily regulatory and supervisory, supporting effective enforcement of data protection requirements.<\/span><\/p>\n<p><b>Question 110. Which statement best describes pseudonymisation under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It permanently removes any possibility of linking data to an individual<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It reduces direct identifiability while additional information can potentially enable re-identification<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It makes all GDPR obligations automatically disappear<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It processes data so it can no longer be personal data under any circumstances<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It reduces direct identifiability while additional information can potentially enable re-identification<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Pseudonymisation is a security and privacy-enhancing technique in which personal data is processed so that it can no longer be attributed to a specific individual without the use of additional information. That additional information must generally be kept separately and protected through appropriate technical and organizational measures. Unlike true anonymisation, pseudonymised information remains personal data under the GDPR when it can be linked to an identifiable person using additional information. Pseudonymisation can reduce risks associated with processing and is specifically recognized by the GDPR as a useful safeguard.<\/span><\/p>\n<p><b>Question 111. When must a controller generally notify the competent supervisory authority of a personal data breach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when the breach involves encrypted data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Where the breach is likely to result in a risk to the rights and freedoms of individuals<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when every affected individual requests notification<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Where the breach is unlikely to create any risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Where the breach is likely to result in a risk to the rights and freedoms of individuals<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Under Article 33, a controller generally must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it when the breach is likely to result in a risk to the rights and freedoms of natural persons. The notification requirement therefore depends on the level of risk rather than simply whether a breach occurred. If notification takes place after 72 hours, the controller should provide reasons for the delay. Processors generally have their own obligation to notify the controller without undue delay after becoming aware of a breach.<\/span><\/p>\n<p><b>Question 112. What is the purpose of the GDPR&#8217;s accountability principle?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To transfer all compliance responsibility to processors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To require supervisory authorities to approve every processing activity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To require controllers to demonstrate compliance with data protection obligations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for privacy policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To require controllers to demonstrate compliance with data protection obligations<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The accountability principle requires controllers to comply with the GDPR&#8217;s data protection principles and to be able to demonstrate that compliance. This moves beyond simply following rules and requires organizations to maintain evidence and governance mechanisms showing how obligations are being addressed. Examples can include policies, records of processing activities, DPIAs, contracts, training, security measures, audits, and documentation supporting lawful processing. Accountability does not eliminate privacy documentation or transfer the controller&#8217;s responsibilities to processors. It establishes an ongoing organizational responsibility to implement and demonstrate appropriate data protection practices.<\/span><\/p>\n<p><b>Question 113. Which GDPR principle requires personal data to be kept in a form that permits identification only for as long as necessary?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purpose limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lawfulness<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Storage limitation<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The storage limitation principle requires personal data to be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed. Controllers should therefore establish appropriate retention periods and review whether continued storage remains justified. Longer retention may be permitted in circumstances recognized by the GDPR, such as certain archiving, scientific or historical research, or statistical purposes when appropriate safeguards are applied. Storage limitation does not necessarily require immediate deletion once the original operational purpose ends, but continued retention must have a lawful justification.<\/span><\/p>\n<p><b>Question 114. Which activity is most directly associated with the GDPR principle of privacy by design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collecting as much personal data as technically possible<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Considering data protection safeguards when designing a new processing system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Waiting until a data breach occurs before implementing security controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publishing personal data to increase transparency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Considering data protection safeguards when designing a new processing system<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Privacy by design requires data protection to be incorporated into the design of processing activities and systems rather than addressed only after implementation. Article 25 requires controllers to implement appropriate technical and organizational measures designed to implement data protection principles effectively and integrate necessary safeguards into processing. Depending on the circumstances, measures may include data minimization, access controls, pseudonymisation, encryption, retention controls, and privacy-friendly defaults. The concept is proactive: organizations should consider privacy risks and safeguards when planning and developing processing operations instead of treating privacy as an afterthought.<\/span><\/p>\n<p><b>Question 115. Which statement correctly distinguishes a controller from a processor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A processor always determines the purposes of processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller only stores personal data and never makes processing decisions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller and processor are legally identical roles under the GDPR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller determines the purposes and means of processing, while a processor acts on behalf of the controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A controller determines the purposes and means of processing, while a processor acts on behalf of the controller<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The distinction between controller and processor is fundamental to GDPR compliance. A controller determines the purposes and means of processing personal data, although EU or Member State law may sometimes determine those elements. A processor processes personal data on behalf of the controller and generally follows the controller&#8217;s documented instructions. The parties have different responsibilities under the GDPR, although processors also have direct obligations in specified areas. Determining which role an organization actually performs depends on the substance of its activities and decision-making rather than simply the terminology used in a contract.<\/span><\/p>\n<p><b>Question 116. Which requirement is associated with the GDPR right of access?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Individuals can access personal data only if a supervisory authority approves the request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Individuals may request confirmation of whether their personal data is being processed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Individuals may access only anonymised statistical information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Individuals can require every organization to delete all data immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Individuals may request confirmation of whether their personal data is being processed<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right of access under Article 15 gives individuals the right to obtain confirmation as to whether personal data concerning them is being processed. Where processing occurs, they can generally obtain access to the personal data and specified information about the processing, such as purposes, categories of personal data, recipients, retention information, and available information about the source of the data. The right is an important transparency mechanism that enables individuals to understand and verify how their personal information is being processed. It does not automatically provide an unrestricted right to deletion or access to every organization&#8217;s records.<\/span><\/p>\n<p><b>Question 117. What is generally required before transferring personal data from the EEA to a third country when no adequacy decision applies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An appropriate transfer mechanism or applicable derogation must be identified<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The recipient must automatically become a joint controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The transfer must always be prohibited<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller must obtain a court order<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. An appropriate transfer mechanism or applicable derogation must be identified<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Transfers of personal data to third countries or international organizations are governed by Chapter V GDPR. Where an adequacy decision does not apply, the controller or processor generally needs to rely on an appropriate safeguard under the GDPR, such as Standard Contractual Clauses, Binding Corporate Rules, or another recognized transfer mechanism. In limited circumstances, a transfer may rely on a derogation under Article 49. Organizations must also consider the requirements associated with the selected mechanism and the circumstances of the transfer. A transfer is therefore not automatically prohibited simply because the destination country lacks an adequacy decision.<\/span><\/p>\n<p><b>Question 118. Which of the following is an example of a technical measure that can help protect personal data under Article 32 GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Written privacy notice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Organizational retention policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encryption of personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Employee awareness training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Encryption of personal data<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 32 requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Encryption is a recognized technical measure that can help protect personal data, particularly against unauthorized access or disclosure. Other measures may include pseudonymisation, resilience of processing systems, restoration capabilities, and processes for regularly testing security effectiveness. Organizational measures can include policies, procedures, training, and governance controls. The specific measures should be selected based on factors such as the state of the art, implementation costs, the nature of processing, and the risks to individuals.<\/span><\/p>\n<p><b>Question 119. Which situation is most likely to require a controller to consider appointing a Data Protection Officer under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller processes only one employee&#8217;s contact details<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller uses an external accounting service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller&#8217;s core activities involve regular and systematic monitoring of individuals on a large scale<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller has a publicly accessible website<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The controller&#8217;s core activities involve regular and systematic monitoring of individuals on a large scale<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 37 identifies circumstances in which designation of a Data Protection Officer is required. One key circumstance is where the core activities of the controller or processor consist of processing operations that require regular and systematic monitoring of data subjects on a large scale. Another involves large-scale processing of special categories of data or personal data relating to criminal convictions and offences, subject to the applicable requirements. The DPO&#8217;s role includes advising on GDPR obligations, monitoring compliance, providing advice concerning DPIAs, and cooperating with the supervisory authority. The requirement depends on the nature and scale of processing, not simply having a website.<\/span><\/p>\n<p><b>Question 120. Under the GDPR, what is the primary purpose of the right to object under Article 21?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To require controllers to provide a copy of every internal business record<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent all processing based on a contract<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To allow individuals to challenge certain processing based on grounds relating to their particular situation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To automatically erase all personal data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To allow individuals to challenge certain processing based on grounds relating to their particular situation<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right to object allows individuals, in specified circumstances, to object to processing of their personal data based on grounds relating to their particular situation when processing relies on certain legal bases, including public task or legitimate interests. The controller must generally stop the processing unless it demonstrates compelling legitimate grounds that override the individual&#8217;s interests, rights, and freedoms, or the processing is required for legal claims. The right has particular rules for direct marketing, where individuals have an unconditional right to object to processing for that purpose. The right is therefore context-dependent rather than a universal deletion mechanism.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps &nbsp; Question 101. Under the GDPR, which condition is required for processing personal data based on the data subject&#8217;s consent? Consent is valid only when provided in writing. Consent cannot be withdrawn once processing begins. Consent must be freely given, specific, informed, and unambiguous. Consent [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20744"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20744"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20744\/revisions"}],"predecessor-version":[{"id":20745,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20744\/revisions\/20745"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20744"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20744"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}