{"id":20750,"date":"2026-09-24T07:15:05","date_gmt":"2026-09-24T07:15:05","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20750"},"modified":"2026-09-24T07:15:05","modified_gmt":"2026-09-24T07:15:05","slug":"iapp-cipp-e-practice-test-questions-and-exam-dumps-part-9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-e-practice-test-questions-and-exam-dumps-part-9-q161-180\/","title":{"rendered":"IAPP CIPP-E Practice Test Questions and Exam Dumps Part 9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-e-exam-dumps\"><b>IAPP CIPP-E Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 161: Under the GDPR, which principle requires personal data to be processed in a manner that ensures appropriate security?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purpose limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Integrity and confidentiality<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accuracy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Integrity and confidentiality<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The integrity and confidentiality principle requires personal data to be processed with appropriate security safeguards. Controllers and processors must protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. The GDPR links this principle closely with Article 32, which requires appropriate technical and organizational measures based on the risks associated with processing. Examples can include encryption, access controls, resilience measures, and procedures for restoring availability after an incident. Purpose limitation concerns the purposes for which data is collected, minimization concerns the amount of data processed, and accuracy concerns keeping data correct and up to date.<\/span><\/p>\n<p><b>Question 162: A company wants to process customer information for a new purpose that is not directly compatible with the original purpose. What should it generally assess before relying on the original collection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the further processing is compatible under Article 6(4)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the data can simply be retained indefinitely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the processor has appointed a DPO<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the organization has received an administrative fine<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Whether the further processing is compatible under Article 6(4)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">When a controller intends to process personal data for a purpose different from the original purpose, the GDPR requires consideration of whether the further processing is compatible with the original purpose. Article 6(4) identifies factors such as the relationship between the original and new purposes, the context in which the data was collected, the nature of the data, possible consequences for individuals, and appropriate safeguards. If the new purpose is not compatible, the controller generally needs another legal basis or must otherwise establish lawful grounds for the new processing. The assessment helps protect the purpose-limitation principle.<\/span><\/p>\n<p><b>Question 163: Which GDPR right allows an individual, in certain circumstances, to request that processing of personal data be limited without requiring the data to be erased?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to data portability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to restriction of processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right of access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Right to restriction of processing<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right to restriction of processing allows an individual to require a controller to limit how personal data is processed in specified circumstances. For example, restriction may apply while the accuracy of data is being contested, when processing is unlawful but the individual prefers restriction rather than erasure, or when the controller no longer needs the data but the individual requires it for legal claims. During restriction, processing is generally limited except in specified circumstances, such as with the individual&#8217;s consent or for legal claims. This right is distinct from erasure, because the data is not necessarily deleted.<\/span><\/p>\n<p><b>Question 164: Which situation most clearly illustrates the GDPR&#8217;s right to data portability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asking a controller to stop processing data for direct marketing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Requesting correction of an incorrect address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Requesting deletion of obsolete personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Receiving certain personal data in a structured, commonly used, machine-readable format for transmission to another controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Receiving certain personal data in a structured, commonly used, machine-readable format for transmission to another controller<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right to data portability allows an individual, under the conditions in Article 20, to receive certain personal data concerning them in a structured, commonly used, and machine-readable format. The right also permits transmission of that data to another controller where technically feasible. It generally applies when processing is based on consent or a contract and carried out by automated means. Portability differs from access, which provides broader information about processing and a copy of personal data. It also differs from rectification, erasure, and objection, which address different individual rights.<\/span><\/p>\n<p><b>Question 165: A controller receives a valid request to rectify inaccurate personal data. What GDPR principle is most directly supported by fulfilling that request?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purpose limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Accuracy<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The GDPR&#8217;s accuracy principle requires personal data to be accurate and, where necessary, kept up to date. Controllers must take reasonable steps to ensure that inaccurate personal data is corrected or erased without undue delay, considering the purposes for which the data is processed. The right of rectification gives individuals an important mechanism for helping controllers meet this obligation. Although other GDPR principles may also be relevant to responsible data management, correcting inaccurate information directly addresses the accuracy requirement. Organizations should therefore maintain processes that allow individuals to identify and correct inaccurate personal information.<\/span><\/p>\n<p><b>Question 166: Which of the following is a core responsibility of a Data Protection Officer under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approving every employee&#8217;s annual leave<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Advising the organization on GDPR obligations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Setting the organization&#8217;s product prices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Acting as the organization&#8217;s external auditor in every case<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Advising the organization on GDPR obligations<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A Data Protection Officer has several responsibilities under the GDPR, including informing and advising the controller or processor and employees who carry out processing about their obligations under the GDPR and other applicable data protection requirements. The DPO also monitors compliance, provides advice regarding data protection impact assessments, and cooperates with supervisory authorities. The DPO&#8217;s role is not to manage unrelated business functions such as pricing or employee leave. The GDPR also establishes requirements concerning the DPO&#8217;s independence and access to relevant resources. Organizations must avoid improperly instructing the DPO about how to perform their statutory tasks.<\/span><\/p>\n<p><b>Question 167: Which circumstance can trigger a controller&#8217;s obligation to notify a personal data breach to the competent supervisory authority?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every minor technical problem, regardless of its effect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any system maintenance activity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A personal data breach that is unlikely to result in a risk to individuals<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A personal data breach likely to result in a risk to the rights and freedoms of natural persons<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A personal data breach likely to result in a risk to the rights and freedoms of natural persons<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Under Article 33, a controller generally must notify a personal data breach to the competent supervisory authority unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification should generally be made without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach. The notification requirement therefore depends on the level of risk rather than simply on whether a security incident occurred. Controllers should assess the nature, scope, context, and potential consequences of the breach when determining whether notification is required.<\/span><\/p>\n<p><b>Question 168: Which transfer mechanism is specifically recognized by the GDPR for certain international transfers when approved contractual safeguards are used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Standard Contractual Clauses<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internal company policy alone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A verbal agreement between employees<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A general website privacy statement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Standard Contractual Clauses<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Standard Contractual Clauses, or SCCs, are a recognized mechanism under the GDPR for transferring personal data to recipients in third countries or international organizations in circumstances covered by the GDPR&#8217;s international-transfer framework. The clauses establish contractual commitments intended to provide appropriate safeguards for transferred personal data. Their use does not mean that every transfer automatically becomes lawful; controllers and importers must satisfy the applicable requirements and assess the circumstances of the transfer. Other mechanisms can also apply, including adequacy decisions and certain derogations. Organizations should therefore identify the specific transfer mechanism and ensure that its requirements are fulfilled.<\/span><\/p>\n<p><b>Question 169: What is the primary purpose of a Record of Processing Activities (ROPA)?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all privacy notices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To document an organization&#8217;s processing activities and relevant information about them<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide marketing content to customers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine employee salaries<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To document an organization&#8217;s processing activities and relevant information about them<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A Record of Processing Activities helps an organization document its processing operations and demonstrate accountability under the GDPR. Depending on whether it is maintained by a controller or processor, the record can include information such as purposes of processing, categories of personal data, categories of individuals, recipients, international transfers, retention information, and security measures. Article 30 contains specific requirements concerning records of processing activities, subject to applicable exceptions. A ROPA is an internal accountability and governance tool rather than a replacement for an external-facing privacy notice. Maintaining accurate records can also help organizations respond to compliance inquiries and manage privacy risks.<\/span><\/p>\n<p><b>Question 170: Which statement best describes pseudonymisation under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It always makes information anonymous<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It permanently removes all security risks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It replaces identifying information so that attribution requires additional information kept separately<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It means that the GDPR no longer applies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It replaces identifying information so that attribution requires additional information kept separately<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Pseudonymisation is a security and privacy-enhancing technique in which personal data is processed so that it can no longer be attributed to a specific individual without the use of additional information. That additional information must be kept separately and protected through appropriate technical and organizational measures. Pseudonymised information remains personal data when it can be linked back to an individual. This differs from anonymisation, where information is rendered sufficiently irreversible so that individuals are no longer identifiable. The GDPR specifically recognizes pseudonymisation as an example of a safeguard that can help reduce risks associated with processing.<\/span><\/p>\n<p><b>Question 171: When must a controller generally provide information to an individual when personal data is collected directly from that individual?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> At the time the personal data is obtained<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after a supervisory authority requests it<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after the first data breach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> After the data has been stored for one year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. At the time the personal data is obtained<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 13 establishes information requirements when personal data is collected directly from the individual. The controller generally must provide the required information at the time the personal data is obtained. The information can include the controller&#8217;s identity and contact details, the purposes and legal basis for processing, retention information, rights available to the individual, recipients, international transfers where applicable, and other required details. Providing this information promptly supports transparency and allows individuals to understand how their personal data will be used. The specific notice must be clear and accessible and should contain the information required by the GDPR.<\/span><\/p>\n<p><b>Question 172: Which GDPR principle requires organizations to avoid collecting personal data that is excessive for the stated processing purposes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accountability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transparency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accuracy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Data minimization<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The data minimization principle requires personal data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Organizations should therefore avoid collecting information merely because it might become useful in the future when that information is not necessary for the stated purpose. Minimization can influence data-collection forms, system design, access permissions, and retention practices. It does not mean that organizations must always collect the smallest technically possible amount of information; rather, the amount and categories of data should be appropriate and necessary for the legitimate purposes of processing.<\/span><\/p>\n<p><b>Question 173: Under the GDPR, which circumstance can justify processing special categories of personal data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The data is commercially valuable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The company wants better advertising results<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The data is publicly interesting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A specific Article 9 condition applies, in addition to an applicable Article 6 lawful basis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A specific Article 9 condition applies, in addition to an applicable Article 6 lawful basis<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Special categories of personal data receive enhanced protection under Article 9 of the GDPR. Processing is generally prohibited unless one of the specific conditions in Article 9(2) applies, such as explicit consent in applicable circumstances, employment and social protection obligations, vital interests when the individual is incapable of giving consent, or certain substantial public-interest grounds. In addition, the controller must identify an applicable lawful basis under Article 6. The two provisions serve different functions: Article 6 establishes a lawful basis for processing personal data generally, while Article 9 establishes an additional condition for processing special categories.<\/span><\/p>\n<p><b>Question 174: Which statement best describes the GDPR accountability principle?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controllers must be able to demonstrate compliance with the GDPR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controllers are exempt from documenting processing activities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Processors may ignore the controller&#8217;s documented instructions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Compliance is required only after a supervisory authority conducts an inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Controllers must be able to demonstrate compliance with the GDPR<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The accountability principle requires controllers to be responsible for, and able to demonstrate, compliance with the GDPR&#8217;s requirements. Demonstrating compliance can involve policies, records, risk assessments, data protection impact assessments where required, contracts, training, technical measures, privacy notices, and other evidence appropriate to the processing activities. Accountability therefore goes beyond simply asserting that an organization follows the law. It encourages organizations to build privacy requirements into governance and operational processes and maintain evidence showing how obligations are addressed. Supervisory authorities may consider such documentation when evaluating an organization&#8217;s compliance and data protection practices.<\/span><\/p>\n<p><b>Question 175: Which situation most directly involves the GDPR&#8217;s transparency principle?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypting data at rest<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restricting database administrator access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Giving individuals clear information about how their personal data is processed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deleting duplicate customer records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Giving individuals clear information about how their personal data is processed<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Transparency requires processing information to be communicated to individuals in a concise, transparent, intelligible, and easily accessible form, using clear and plain language where appropriate. Privacy notices are a key mechanism for meeting this obligation. Individuals should be able to understand relevant matters such as who processes their data, why it is processed, the applicable legal basis, retention information, and their rights. Encryption and access controls are primarily security measures, while deleting duplicate records can support data quality or minimization. Transparency is therefore closely connected with effective communication and enabling individuals to understand the processing of their personal data.<\/span><\/p>\n<p><b>Question 176: A controller determines that a processing activity is likely to result in a high risk to individuals&#8217; rights and freedoms. What GDPR measure may be required before processing begins?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A mandatory administrative fine<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A data protection impact assessment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic anonymisation of all data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A permanent deletion schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A data protection impact assessment<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A Data Protection Impact Assessment, or DPIA, is required before processing where it is likely to result in a high risk to the rights and freedoms of natural persons. The assessment should describe the processing operations and purposes, assess necessity and proportionality, evaluate risks to individuals, and identify measures addressing those risks. DPIAs are particularly relevant to processing involving new technologies or other activities that may create significant risks. The purpose is preventive: privacy risks should be identified and addressed before the processing begins. If high residual risk remains after mitigation, consultation with the supervisory authority may be required.<\/span><\/p>\n<p><b>Question 177: Which GDPR principle is most directly concerned with retaining personal data only for as long as necessary for the purposes for which it is processed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purpose limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Fairness<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data portability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Storage limitation<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The storage limitation principle requires personal data to be kept in a form that permits identification of individuals for no longer than is necessary for the purposes for which the data is processed, subject to specified exceptions. Organizations should therefore establish retention periods or criteria that reflect the purposes, legal obligations, and risks associated with the information. Keeping data indefinitely simply because storage is inexpensive can conflict with this principle when there is no continuing justification. Effective retention schedules, deletion procedures, and periodic reviews can help organizations determine when personal data should be deleted, anonymised, or otherwise removed from active processing.<\/span><\/p>\n<p><b>Question 178: Which organization is primarily responsible for adopting binding decisions when resolving certain disputes between supervisory authorities under the GDPR cooperation mechanism?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Data Protection Board<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Parliament<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Commission<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Court of Auditors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The European Data Protection Board<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The European Data Protection Board plays a role in ensuring consistent application of the GDPR across the European Economic Area. Under the cooperation and consistency mechanisms, certain disputes between supervisory authorities can be referred to the EDPB, which may adopt binding decisions in the circumstances specified by the GDPR. This helps address disagreements concerning matters such as objections to draft decisions or competence issues. The EDPB is distinct from the European Commission and the European Parliament, which have different institutional roles. The EDPB is composed of representatives of the relevant supervisory authorities and the European Data Protection Supervisor.<\/span><\/p>\n<p><b>Question 179: Which action is most consistent with the principle of privacy by design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Adding privacy controls only after a major data incident<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Designing systems so appropriate privacy and data-protection safeguards are incorporated from the outset<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collecting every available category of personal information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing all security controls to improve convenience<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Designing systems so appropriate privacy and data-protection safeguards are incorporated from the outset<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Privacy by design, reflected in Article 25, requires controllers to implement appropriate technical and organizational measures designed to implement data protection principles and integrate necessary safeguards into processing. The concept encourages privacy considerations to be addressed during the design and development of systems, products, and processes rather than being treated solely as an afterthought. Measures can include data minimization, pseudonymisation, access controls, and privacy-conscious architecture. The appropriate measures depend on factors such as the state of the art, implementation costs, the nature and scope of processing, the context, purposes, and risks to individuals.<\/span><\/p>\n<p><b>Question 180: Which statement about consent under the GDPR is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent can always be inferred from silence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent cannot be withdrawn after it has been given<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent must always be the only lawful basis available<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent must be freely given, specific, informed, and unambiguous, and individuals can withdraw it**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Consent must be freely given, specific, informed, and unambiguous, and individuals can withdraw it<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">GDPR consent must meet specific requirements. It must be freely given, specific, informed, and unambiguous, and it generally requires a clear affirmative action. Silence, inactivity, or pre-ticked boxes do not normally constitute valid consent. Individuals also have the right to withdraw consent at any time, and withdrawal must be as easy as giving consent. Withdrawal does not automatically make earlier processing unlawful when that processing was lawfully based on consent. Organizations should therefore maintain appropriate consent mechanisms and records and provide clear information about what the individual is consenting to and how consent can be withdrawn.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps &nbsp; Question 161: Under the GDPR, which principle requires personal data to be processed in a manner that ensures appropriate security? Purpose limitation Data minimization Integrity and confidentiality Accuracy Correct Answer: 3. Integrity and confidentiality Explanation: The integrity and confidentiality principle requires personal data to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20750"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20750"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20750\/revisions"}],"predecessor-version":[{"id":20751,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20750\/revisions\/20751"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20750"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20750"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20750"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}