{"id":20758,"date":"2026-09-24T07:16:29","date_gmt":"2026-09-24T07:16:29","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20758"},"modified":"2026-09-24T07:16:29","modified_gmt":"2026-09-24T07:16:29","slug":"iapp-cipp-e-practice-test-questions-and-exam-dumps-part-13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-e-practice-test-questions-and-exam-dumps-part-13-q241-260\/","title":{"rendered":"IAPP CIPP-E Practice Test Questions and Exam Dumps Part 13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-e-exam-dumps\"><b>IAPP CIPP-E Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 241: Which GDPR principle requires personal data to be processed only for specified, explicit, and legitimate purposes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accountability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purpose limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage limitation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Purpose limitation<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The purpose limitation principle requires personal data to be collected for specified, explicit, and legitimate purposes and not subsequently processed in a manner incompatible with those purposes. Controllers should therefore identify the purposes of processing before collecting personal data and communicate relevant information to individuals. When considering further processing, the controller should assess whether the new purpose is compatible with the original purpose, taking into account the factors identified in Article 6(4). Purpose limitation helps prevent organizations from repurposing personal data without appropriate justification. It works together with other GDPR principles, including transparency, minimization, fairness, and accountability.<\/span><\/p>\n<p><b>Question 242: Which right allows an individual to obtain a copy of their personal data from a controller?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to object<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to erasure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right of access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Right of access<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right of access under Article 15 allows individuals to obtain confirmation as to whether personal data concerning them is being processed and, where applicable, access to that personal data. Individuals can also receive information about the purposes of processing, categories of personal data, recipients, retention periods, and other relevant matters. The controller generally must respond within one month, subject to applicable extension rules. The right of access is distinct from data portability because access can apply more broadly, while portability has specific conditions concerning the lawful basis, automated processing, and the format of the information.<\/span><\/p>\n<p><b>Question 243: Which of the following is an example of processing based on a legal obligation under Article 6?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Processing employee information required by applicable employment law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sending optional promotional emails because the company wants more sales<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collecting unrelated personal information for future convenience<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Creating entertainment profiles about customers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Processing employee information required by applicable employment law<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 6(1)(c) permits processing when it is necessary for compliance with a legal obligation to which the controller is subject. For example, an employer may need to process certain employee information because applicable employment, tax, accounting, or social-security legislation requires it. The obligation must arise from applicable law, and the processing must be necessary for compliance. A controller cannot simply describe an internal business preference as a legal obligation. The organization should identify the relevant legal requirement and ensure that the amount and type of personal data processed are appropriate for fulfilling that obligation.<\/span><\/p>\n<p><b>Question 244: What is the primary purpose of a Record of Processing Activities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace the organization&#8217;s privacy policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To obtain automatic approval from a supervisory authority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To document relevant processing activities and support accountability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide marketing information to customers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To document relevant processing activities and support accountability<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A Record of Processing Activities, or ROPA, helps an organization document its processing operations and demonstrate accountability. Article 30 identifies information that may need to be included, such as purposes of processing, categories of individuals and personal data, recipients, international transfers, retention information, and security measures. Controllers and processors have different recordkeeping requirements under the GDPR. Maintaining an accurate ROPA can help organizations understand their data flows, identify compliance obligations, respond to regulatory inquiries, and support privacy assessments. A ROPA is an internal accountability document and does not replace externally facing privacy information provided to individuals.<\/span><\/p>\n<p><b>Question 245: Which GDPR right enables an individual to request correction of inaccurate personal data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to rectification<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to portability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Right to object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Right to rectification<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 16 provides individuals with the right to obtain rectification of inaccurate personal data concerning them without undue delay. Individuals may also have the right to have incomplete personal data completed, taking into account the purposes of processing. This right supports the GDPR&#8217;s accuracy principle, which requires personal data to be accurate and, where necessary, kept up to date. Controllers should maintain procedures that allow individuals to submit rectification requests and ensure that appropriate corrections are made. The right to rectification differs from erasure because its objective is to correct or complete information rather than necessarily delete it.<\/span><\/p>\n<p><b>Question 246: Which factor is relevant when determining whether processing is likely to require a DPIA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the organization has a large marketing budget<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the company has operated for more than ten years<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the processing is likely to result in a high risk to individuals&#8217; rights and freedoms<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the organization&#8217;s website contains advertisements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Whether the processing is likely to result in a high risk to individuals&#8217; rights and freedoms<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A Data Protection Impact Assessment is required where processing is likely to result in a high risk to the rights and freedoms of natural persons. Controllers should consider the nature, scope, context, and purposes of the processing and evaluate its potential impact on individuals. Certain processing activities, such as systematic monitoring or large-scale processing of sensitive information, may present significant risks depending on the circumstances. The DPIA should assess necessity and proportionality, identify risks, and establish measures to address those risks. The requirement is therefore based on privacy risk rather than unrelated characteristics of the organization or its commercial activities.<\/span><\/p>\n<p><b>Question 247: Which statement best describes the controller-processor relationship under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A processor generally processes personal data on behalf of a controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A processor always determines the purposes of processing independently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller must follow every instruction issued by its processor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A processor automatically becomes a joint controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A processor generally processes personal data on behalf of a controller<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A processor processes personal data on behalf of a controller. The controller determines the purposes and means of processing, while the processor generally acts according to documented instructions from the controller. Article 28 establishes specific requirements for the relationship, including contractual obligations concerning confidentiality, security, subprocessors, assistance with GDPR obligations, and deletion or return of personal data where appropriate. A processor does not automatically become a controller or joint controller merely because it handles personal data. The actual roles and decisions concerning the processing should be assessed when determining whether an organization is a controller, processor, or joint controller.<\/span><\/p>\n<p><b>Question 248: Which of the following is an example of a technical measure under GDPR security requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publishing passwords for all employees<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing unrestricted access to customer databases<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing authentication controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypting personal data where appropriate to the risks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Encrypting personal data where appropriate to the risks<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 32 requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Encryption is one example of a technical measure that can help protect personal data against unauthorized access or disclosure. Other measures can include pseudonymisation, access controls, resilience mechanisms, secure authentication, testing, and recovery procedures. The GDPR does not require every organization to use exactly the same technology. Instead, security measures should reflect factors such as the state of the art, implementation costs, the nature and scope of processing, and the risks to individuals. Organizations should periodically evaluate whether their measures remain appropriate.<\/span><\/p>\n<p><b>Question 249: What is one important requirement for valid consent under the GDPR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent must be impossible to withdraw<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent must be freely given, specific, informed, and unambiguous<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent can always be inferred from silence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent is automatically valid whenever a privacy notice exists<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Consent must be freely given, specific, informed, and unambiguous<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">GDPR consent must meet several conditions. It must be freely given, specific, informed, and unambiguous, generally through a clear affirmative action. Individuals must understand what they are consenting to and must have a genuine choice. Silence, inactivity, or pre-ticked boxes do not normally constitute valid consent. Individuals also have the right to withdraw consent at any time, and withdrawing consent must be as easy as providing it. Controllers relying on consent should maintain evidence demonstrating that consent was obtained appropriately. Where an imbalance or other circumstances prevent genuine choice, another lawful basis may need to be considered instead.<\/span><\/p>\n<p><b>Question 250: Which statement correctly describes the GDPR&#8217;s storage limitation principle?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data must always be deleted immediately after collection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Organizations may retain personal data indefinitely if storage is inexpensive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data should be kept in identifiable form no longer than necessary for the processing purposes, subject to applicable exceptions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage limitation applies only to paper documents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Personal data should be kept in identifiable form no longer than necessary for the processing purposes, subject to applicable exceptions<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The storage limitation principle requires personal data to be kept in a form that permits identification of individuals for no longer than is necessary for the purposes for which the data is processed. Organizations should establish appropriate retention periods or criteria and consider applicable legal or regulatory requirements that may require longer retention. Storage limitation does not mean that all information must be deleted immediately after its initial use. Controllers may need to retain information for legitimate legal, regulatory, or other permitted purposes. Effective retention schedules, periodic reviews, deletion procedures, and anonymisation can help organizations comply with this principle.<\/span><\/p>\n<p><b>Question 251: Which organization has primary responsibility for monitoring and enforcing the GDPR within its jurisdiction?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A supervisory authority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Parliament<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Central Bank<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A private certification organization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A supervisory authority<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Supervisory authorities are independent public authorities responsible for monitoring and enforcing the application of the GDPR within their respective jurisdictions. Their powers can include investigating complaints, conducting audits, obtaining information, ordering compliance, and imposing administrative fines where appropriate. Supervisory authorities also cooperate with one another under the GDPR&#8217;s cooperation and consistency mechanisms. Their role is distinct from that of the European Data Protection Board, which supports consistency across the EU and performs specified coordination and decision-making functions. Controllers and processors remain responsible for their own compliance and cannot rely on the absence of regulatory investigation as evidence that their processing is lawful.<\/span><\/p>\n<p><b>Question 252: Which situation best illustrates the GDPR principle of transparency?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypting a database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Giving individuals clear information about how their personal data is processed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restricting administrator privileges<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deleting duplicate records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Giving individuals clear information about how their personal data is processed<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Transparency requires controllers to provide individuals with information about processing in a concise, transparent, intelligible, and easily accessible form, using clear and plain language where appropriate. Privacy notices are an important tool for meeting this requirement. Individuals should generally be able to understand who is processing their information, why it is being processed, the applicable lawful basis, retention information, recipients, and their relevant rights. Security measures such as encryption and access controls are important but address different GDPR requirements. Transparency supports informed participation and helps individuals understand how organizations use their personal data.<\/span><\/p>\n<p><b>Question 253: Which circumstance can require notification of a personal data breach to affected individuals?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every security incident regardless of risk<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any failed login attempt<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A breach that is likely to result in a high risk to the rights and freedoms of natural persons<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A routine system update<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A breach that is likely to result in a high risk to the rights and freedoms of natural persons<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Under Article 34, when a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller generally must communicate the breach to affected individuals without undue delay, subject to the exceptions in the GDPR. The communication should describe the nature of the breach and provide relevant information about likely consequences and measures taken or proposed to address it. This requirement differs from the supervisory-authority notification rule under Article 33, which generally applies where the breach is likely to result in a risk. Organizations should therefore separately assess whether notification to the authority and communication to individuals are required.<\/span><\/p>\n<p><b>Question 254: Which statement about Binding Corporate Rules is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are designed only for domestic data transfers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They can provide an appropriate safeguard for certain international transfers within a group of undertakings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They eliminate all GDPR obligations for multinational organizations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are informal employee guidelines with no regulatory relevance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. They can provide an appropriate safeguard for certain international transfers within a group of undertakings<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Binding Corporate Rules, or BCRs, are internal data-protection rules used by certain groups of undertakings or groups of enterprises engaged in a joint economic activity to provide appropriate safeguards for international transfers. They must satisfy the requirements of Article 47 and are subject to an approval process involving competent supervisory authorities. BCRs typically establish enforceable rights and obligations concerning the processing and protection of personal data throughout the relevant group. They do not remove the group&#8217;s other GDPR responsibilities. Organizations considering BCRs must ensure that the rules meet the applicable substantive requirements and are properly approved before relying on them as a transfer mechanism.<\/span><\/p>\n<p><b>Question 255: Which GDPR principle is most directly concerned with protecting personal data against unauthorized access and accidental loss?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Integrity and confidentiality<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purpose limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accuracy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Integrity and confidentiality<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The integrity and confidentiality principle requires personal data to be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage. Article 32 further requires appropriate technical and organizational measures based on the risks associated with processing. Measures can include encryption, pseudonymisation, access controls, resilience, secure authentication, testing, and recovery procedures. The appropriate level of security depends on the nature, scope, context, and purposes of processing and the risks to individuals. This principle therefore connects the GDPR&#8217;s general requirements with practical information-security and organizational controls.<\/span><\/p>\n<p><b>Question 256: Which statement about the GDPR right to restriction of processing is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It always requires permanent deletion of the personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can require a controller to limit processing in specified circumstances<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It applies only to marketing emails<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It allows a controller to ignore all other GDPR obligations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It can require a controller to limit processing in specified circumstances<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The right to restriction of processing allows individuals to require a controller to limit processing in specified circumstances. These can include situations where the individual contests the accuracy of personal data, where processing is unlawful but the individual prefers restriction rather than erasure, or where the controller no longer needs the data but the individual requires it for legal claims. During restriction, processing is generally limited except in circumstances permitted by the GDPR, such as with the individual&#8217;s consent or for legal claims. Restriction is therefore different from erasure because the information is not necessarily deleted from the controller&#8217;s systems.<\/span><\/p>\n<p><b>Question 257: Which Article 6 lawful basis may apply when processing is necessary to perform a contract with the individual?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Legitimate interests<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Performance of a contract<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publicly available information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Performance of a contract<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 6(1)(b) provides a lawful basis where processing is necessary for the performance of a contract to which the individual is party or for taking steps at the individual&#8217;s request before entering into a contract. The controller should assess whether the processing is genuinely necessary for the contractual purpose rather than simply useful or commercially convenient. For example, processing a customer&#8217;s delivery address may be necessary to fulfill an order. Other activities associated with the customer relationship may require a different lawful basis. Controllers should identify the appropriate legal basis for each processing purpose rather than assuming that all processing connected with a contract automatically falls under Article 6(1)(b).<\/span><\/p>\n<p><b>Question 258: Which statement best describes the role of the European Data Protection Board?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It directly manages the privacy programs of private companies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It replaces all national supervisory authorities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It issues guidance and supports consistent application of EU data-protection law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It acts as a commercial regulator for European businesses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It issues guidance and supports consistent application of EU data-protection law<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The European Data Protection Board contributes to consistent application of the GDPR across the European Union. Its functions include issuing guidelines, recommendations, and best practices and supporting cooperation between supervisory authorities. In specified circumstances, it can also adopt binding decisions, including in certain disputes between supervisory authorities. The EDPB does not replace national supervisory authorities, which retain their supervisory and enforcement responsibilities. Its role is part of the GDPR&#8217;s broader cooperation and consistency framework. Organizations operating across multiple EU jurisdictions should consider EDPB guidance alongside applicable national supervisory-authority positions and the text of the GDPR itself.<\/span><\/p>\n<p><b>Question 259: Which statement about special categories of personal data is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Health data is never subject to enhanced GDPR protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Special-category processing generally requires an Article 9 condition in addition to an applicable Article 6 lawful basis<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 9 automatically makes all processing of special-category data lawful<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Special categories include every type of customer information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Special-category processing generally requires an Article 9 condition in addition to an applicable Article 6 lawful basis<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Article 9 provides enhanced protection for special categories of personal data, including health data, genetic data, certain biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and information concerning sex life or sexual orientation. Processing is generally prohibited unless one of the specific Article 9 conditions applies. In addition, the controller generally needs an applicable lawful basis under Article 6. The two provisions serve different functions and should be assessed separately. Organizations must therefore identify both the general lawful basis and the additional condition that permits processing of the relevant special category.<\/span><\/p>\n<p><b>Question 260: Which statement best describes the GDPR accountability principle in practice?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controllers only need to demonstrate compliance after receiving a regulatory investigation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accountability means processors automatically determine all processing purposes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accountability requires organizations to be responsible for compliance and able to demonstrate it<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accountability eliminates the need for privacy policies and records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Accountability requires organizations to be responsible for compliance and able to demonstrate it<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The accountability principle requires controllers to take responsibility for complying with the GDPR and to be able to demonstrate compliance. Practical accountability measures can include maintaining records of processing activities, implementing privacy policies and procedures, conducting DPIAs where required, establishing appropriate processor contracts, documenting lawful bases, training personnel, and implementing technical and organizational safeguards. Accountability is therefore an ongoing governance responsibility rather than something that begins only after regulatory scrutiny. The measures should be proportionate to the organization&#8217;s processing activities and risks. Demonstrable compliance can also help an organization identify weaknesses and respond effectively to supervisory-authority inquiries.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps &nbsp; Question 241: Which GDPR principle requires personal data to be processed only for specified, explicit, and legitimate purposes? Accountability Purpose limitation Accuracy Storage limitation Correct Answer: 2. Purpose limitation Explanation: The purpose limitation principle requires personal data to be collected for specified, explicit, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20758"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20758"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20758\/revisions"}],"predecessor-version":[{"id":20759,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20758\/revisions\/20759"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20758"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20758"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}