{"id":20772,"date":"2026-09-24T07:19:33","date_gmt":"2026-09-24T07:19:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20772"},"modified":"2026-09-24T07:19:33","modified_gmt":"2026-09-24T07:19:33","slug":"iapp-cipp-e-practice-test-questions-and-exam-dumps-part-20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-e-practice-test-questions-and-exam-dumps-part-20-q381-400\/","title":{"rendered":"IAPP CIPP-E Practice Test Questions and Exam Dumps Part 20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-e-exam-dumps\"><b>IAPP CIPP-E Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 381: Under Article 22 of the GDPR, which type of decision is subject to the specific protection against solely automated decision-making?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any decision made by an employee<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A decision based solely on automated processing that produces legal effects or similarly significantly affects the data subject<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every decision involving a computer system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only decisions concerning financial transactions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A decision based solely on automated processing that produces legal effects or similarly significantly affects the data subject<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 22 addresses decisions based solely on automated processing, including profiling, where the decision produces legal effects concerning the data subject or similarly significantly affects them. The provision gives individuals a right not to be subject to such decisions, subject to specific exceptions. Those exceptions include where the decision is necessary for entering into or performance of a contract, authorised by Union or Member State law, or based on the data subject&#8217;s explicit consent. Additional safeguards apply in the contractual and consent situations, including the right to obtain human intervention, express a point of view, and contest the decision. Special-category data creates additional restrictions.<\/span><\/p>\n<p><b>Question 382: Which GDPR provision specifically requires appropriate technical and organisational measures to ensure a level of security appropriate to the risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 32<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 18<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 49<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 77<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Article 32<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 32 establishes the GDPR&#8217;s principal security-of-processing requirement. Controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Measures may include pseudonymisation and encryption, the ability to ensure confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access to personal data following an incident, and processes for regularly testing and evaluating the effectiveness of security measures. The assessment should take account of the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risks to individuals&#8217; rights and freedoms.<\/span><\/p>\n<p><b>Question 383: Which statement correctly describes the processor&#8217;s breach-notification obligation under Article 33?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The processor must notify every affected data subject directly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The processor must notify the controller without undue delay after becoming aware of a personal data breach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The processor has no breach-related obligations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The processor must always notify the European Commission<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The processor must notify the controller without undue delay after becoming aware of a personal data breach<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 33 requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. The processor does not normally determine independently whether the supervisory authority must be notified; that notification obligation rests with the controller under Article 33, subject to the applicable risk threshold. The processor&#8217;s prompt notification enables the controller to assess the breach, determine whether notification to the supervisory authority is required, and assess whether communication to affected data subjects is necessary under Article 34. Processor-controller contracts should therefore establish procedures that facilitate rapid incident reporting and cooperation following a security event.<\/span><\/p>\n<p><b>Question 384: Which principle requires personal data to be adequate, relevant, and limited to what is necessary in relation to processing purposes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storage limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimisation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accountability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Data minimisation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 5(1)(c) establishes the principle of data minimisation. Personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. This principle requires controllers to consider whether each category of personal data is genuinely needed rather than collecting information simply because it might be useful later. Data minimisation can affect collection forms, database fields, retention practices, access permissions, and system design. It is closely connected with purpose limitation and storage limitation but is distinct from them: purpose limitation concerns why data is processed, while data minimisation concerns the amount and scope of data processed in relation to those purposes.<\/span><\/p>\n<p><b>Question 385: Which of the following is a core element of the GDPR principle of accountability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controllers must be able to demonstrate compliance with the GDPR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controllers may disregard documentation requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Processors automatically become controllers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data subjects must prove that processing is lawful before exercising rights<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Controllers must be able to demonstrate compliance with the GDPR<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The accountability principle in Article 5(2) requires the controller to be responsible for, and be able to demonstrate, compliance with the GDPR principles. Accountability therefore goes beyond simply following data protection rules in practice. Controllers should be able to demonstrate how compliance is achieved through measures such as policies, records of processing activities, data protection impact assessments where required, contracts, security measures, staff training, retention procedures, and documentation of relevant decisions. The principle supports a proactive compliance culture. It also means that an organisation should be prepared to provide evidence showing how it has implemented appropriate measures rather than relying solely on assertions that it complies.<\/span><\/p>\n<p><b>Question 386: What does the GDPR principle of purpose limitation generally require?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data may be collected for any purpose without restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data should be collected for specified, explicit, and legitimate purposes and not further processed incompatibly with those purposes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data must always be used for commercial purposes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data may only be processed once<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Personal data should be collected for specified, explicit, and legitimate purposes and not further processed incompatibly with those purposes<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 5(1)(b) requires personal data to be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. This means organisations should identify and communicate the purposes for which personal data is collected and assess whether subsequent uses are compatible. The GDPR contains specific rules for further processing, including processing for archiving in the public interest, scientific or historical research, or statistical purposes subject to safeguards. Purpose limitation works together with transparency and data minimisation: individuals should understand why their data is being processed, and organisations should avoid expanding processing purposes without a lawful and compatible basis.<\/span><\/p>\n<p><b>Question 387: Which requirement applies to the processing of personal data under Article 5&#8217;s accuracy principle?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data must never be updated<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Personal data must be accurate and, where necessary, kept up to date<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only financial information must be accurate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controllers may knowingly retain incorrect information indefinitely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Personal data must be accurate and, where necessary, kept up to date<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 5(1)(d) requires personal data to be accurate and, where necessary, kept up to date. Controllers must take every reasonable step to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay. Accuracy is particularly important where decisions about individuals depend on the information being processed. The principle does not mean that every piece of information must be continuously updated regardless of context. Instead, accuracy must be assessed in relation to the purposes and circumstances of processing. Article 16 further supports this principle by giving data subjects a right to rectification.<\/span><\/p>\n<p><b>Question 388: Which Article 6 lawful basis is specifically associated with compliance with a legal obligation to which the controller is subject?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(a)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(b)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(c)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(f)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Article 6(1)(c)<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 6(1)(c) provides a lawful basis where processing is necessary for compliance with a legal obligation to which the controller is subject. The obligation must have a basis in Union or Member State law, and the relevant legal requirement must determine or permit the processing in accordance with the GDPR&#8217;s conditions. This basis differs from the public-task basis in Article 6(1)(e), which concerns processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority. Controllers should identify the specific legal obligation supporting the processing rather than relying on a general statement that processing is required by law.<\/span><\/p>\n<p><b>Question 389: Which lawful basis under Article 6 is generally associated with protecting the vital interests of the data subject or another natural person?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(d)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(e)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(f)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 6(1)(c)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Article 6(1)(d)<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 6(1)(d) permits processing where it is necessary in order to protect the vital interests of the data subject or another natural person. This basis is generally relevant to situations where processing is necessary to protect life or another fundamental interest and the applicable conditions are satisfied. For special-category data, Article 9 also needs to be considered because the processing of such data is subject to additional restrictions and conditions. Controllers should therefore not assume that Article 6(1)(d) alone automatically authorises processing of special-category data. The legal basis analysis must reflect both the nature of the personal data and the specific purpose and circumstances of the processing.<\/span><\/p>\n<p><b>Question 390: What is one requirement for valid consent under Article 7 when the controller relies on consent as a lawful basis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller must be able to demonstrate that the data subject consented<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent must always be obtained through a paper form<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent cannot be withdrawn<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent may be bundled with unrelated terms without distinction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The controller must be able to demonstrate that the data subject consented<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 7 requires the controller to be able to demonstrate that the data subject has consented to processing of their personal data where consent is used as the lawful basis. Consent must also meet the GDPR&#8217;s requirements concerning freedom, specificity, information, and unambiguous affirmative action. If a written declaration includes other matters, the request for consent must be clearly distinguishable from those matters. The data subject has the right to withdraw consent at any time, and withdrawal must be as easy as giving consent. These requirements place a significant accountability burden on controllers: they should maintain appropriate evidence of what was consented to, when consent was obtained, and the circumstances in which it was provided.<\/span><\/p>\n<p><b>Question 391: Which GDPR provision specifically addresses processing of children&#8217;s personal data in relation to information society services offered directly to a child?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 8<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 23<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 31<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 52<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Article 8<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 8 establishes specific rules for a child&#8217;s consent where processing of personal data is based on consent in relation to information society services offered directly to a child. The general GDPR threshold is 16 years, although Member States may provide by law for a lower age, provided it is not below 13 years. Where the child is below the applicable threshold, consent must be given or authorised by the holder of parental responsibility. The controller must make reasonable efforts to verify that consent is given or authorised in accordance with the applicable requirements, taking available technology into account. Other GDPR provisions continue to apply to children&#8217;s data.<\/span><\/p>\n<p><b>Question 392: Which provision gives data subjects a right to object to processing based on Article 6(1)(e) or Article 6(1)(f) in specified circumstances?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 21(1)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 15<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 16<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 34<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Article 21(1)<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 21(1) provides a right to object, on grounds relating to the data subject&#8217;s particular situation, to processing based on Article 6(1)(e) or Article 6(1)(f), including profiling based on those provisions. The controller must stop processing unless it demonstrates compelling legitimate grounds that override the interests, rights, and freedoms of the data subject or unless processing is necessary for the establishment, exercise, or defence of legal claims. This right differs from the specific direct-marketing objection under Article 21(2), which applies at any time and does not require the data subject to provide grounds relating to their particular situation. The distinction is important when assessing objection requests.<\/span><\/p>\n<p><b>Question 393: Under Article 22, what additional protection applies when a solely automated decision is based on special categories of personal data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Special-category data automatically makes the decision lawful<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller must generally satisfy an additional condition, such as explicit consent or substantial public interest under applicable law, along with appropriate safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Article 22 no longer applies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The data subject loses the right to human intervention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The controller must generally satisfy an additional condition, such as explicit consent or substantial public interest under applicable law, along with appropriate safeguards<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 22 contains an additional restriction where a solely automated decision falling within its scope is based on special categories of personal data. Such processing is generally permitted only where the relevant requirements for processing special-category data are met, including explicit consent or processing that is necessary for substantial public interest on the basis of Union or Member State law, together with suitable measures to safeguard the data subject&#8217;s rights, freedoms, and legitimate interests. The safeguards associated with Article 22 include the possibility of obtaining human intervention, expressing a point of view, and contesting the decision in applicable situations. The special-category rules therefore add another layer of protection.<\/span><\/p>\n<p><b>Question 394: Which of the following is an example of a data subject right under the GDPR that is subject to specific exceptions and limitations rather than being absolute?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to erasure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to establish a supervisory authority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to appoint the controller&#8217;s employees<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to set administrative fines<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The right to erasure<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The right to erasure under Article 17 is an important data subject right, but it is not absolute. It applies when one of the specified grounds is present, such as where personal data is no longer necessary for the purposes for which it was collected, consent is withdrawn and there is no other legal ground, or the data has been unlawfully processed. However, Article 17 also establishes exceptions. These include situations involving freedom of expression and information, compliance with legal obligations, public interest in public health, archiving and research purposes subject to conditions, and establishment or defence of legal claims. Controllers must therefore assess both the erasure ground and any applicable exception.<\/span><\/p>\n<p><b>Question 395: What is the purpose of Article 48 in relation to third-country demands for personal data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To automatically validate every foreign government request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To establish that certain third-country judgments or administrative decisions require an international agreement or another applicable legal basis before recognition or enforceability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate Chapter V transfer safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To permit unrestricted transfers to public authorities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To establish that certain third-country judgments or administrative decisions require an international agreement or another applicable legal basis before recognition or enforceability<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 48 establishes a specific rule for disclosures or transfers made in response to a judgment of a court or tribunal or a decision of an administrative authority of a third country. Such a judgment or decision requiring a controller or processor to transfer or disclose personal data may be recognised or enforceable only where it is based on an international agreement, such as a mutual legal assistance treaty, or another applicable legal ground under Union or Member State law. The provision therefore prevents a foreign legal demand from automatically overriding the GDPR&#8217;s international transfer framework. Organisations must evaluate the legal basis for the disclosure before responding.<\/span><\/p>\n<p><b>Question 396: Which statement about the Article 49 derogations is most accurate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are the normal mechanism for routine, repeated transfers of large volumes of personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They provide specific exceptions from the general transfer mechanisms where their individual conditions are met<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They automatically apply to every transfer involving a multinational company<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They eliminate the need to assess the rights of data subjects<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. They provide specific exceptions from the general transfer mechanisms where their individual conditions are met<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 49 provides specific derogations for transfers to third countries or international organisations where the relevant conditions are satisfied. Examples include explicit consent in specified circumstances, necessity for contract performance or pre-contractual measures in certain cases, important reasons of public interest, establishment or defence of legal claims, protection of vital interests, transfers from certain public registers, and limited situations involving compelling legitimate interests. These derogations are not intended to function as a general substitute for the transfer mechanisms in Articles 45 and 46. Controllers must examine the exact conditions of the relevant derogation and ensure that other GDPR requirements, including accountability and data subject protections, continue to be observed.<\/span><\/p>\n<p><b>Question 397: Which supervisory authority is generally the lead authority for cross-border processing under the GDPR&#8217;s one-stop-shop mechanism?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The authority chosen by the controller after an infringement occurs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The authority in the Member State where the data subjects have the highest income<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The supervisory authority of the controller&#8217;s or processor&#8217;s main establishment or single establishment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The European Commission<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The supervisory authority of the controller&#8217;s or processor&#8217;s main establishment or single establishment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Under Article 56, for cross-border processing, the supervisory authority of the controller&#8217;s or processor&#8217;s main establishment or single establishment generally acts as the lead supervisory authority. The lead authority works with other supervisory authorities concerned under the cooperation mechanisms of the GDPR. The one-stop-shop system is designed to coordinate supervision where processing affects individuals across multiple Member States. Determining the correct lead authority requires identifying the relevant establishment and understanding where decisions concerning the purposes and means of processing are made and implemented. The mechanism does not mean that other concerned supervisory authorities have no role; the GDPR provides circumstances in which they may act or participate.<\/span><\/p>\n<p><b>Question 398: Which statement about the supervisory authority&#8217;s independence under Article 52 is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Supervisory authorities must be completely free from external influence when performing their tasks and exercising their powers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Supervisory authorities must follow instructions from every controller they investigate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Supervisory authorities are controlled by private companies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Supervisory authorities cannot receive public funding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Supervisory authorities must be completely free from external influence when performing their tasks and exercising their powers<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 52 establishes the independence of supervisory authorities. Each supervisory authority must act with complete independence when performing its tasks and exercising its powers under the GDPR. Members and staff must remain free from external influence, whether direct or indirect, and must neither seek nor take instructions from anyone. Member States must provide the supervisory authorities with the human, technical, and financial resources necessary for effective performance of their functions. Independence is fundamental to effective data protection supervision because authorities must be able to investigate and enforce the GDPR without inappropriate interference from governments, organisations, or other interested parties.<\/span><\/p>\n<p><b>Question 399: Which Article 58 power allows a supervisory authority to impose a temporary or definitive limitation, including a ban, on processing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Investigative power only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Corrective power<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Advisory power only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Legislative power<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Corrective power<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 58 distinguishes investigative, corrective, and authorisation powers available to supervisory authorities. Among its corrective powers is the ability to impose a temporary or definitive limitation, including a ban, on processing. Other corrective powers include issuing warnings or reprimands, ordering compliance with data subject requests, ordering controllers or processors to bring processing operations into compliance, ordering rectification or erasure, and imposing administrative fines where appropriate. These powers enable supervisory authorities to address non-compliant processing directly. They are exercised within the authority&#8217;s legal competence and subject to applicable procedural and legal safeguards.<\/span><\/p>\n<p><b>Question 400: What is one function of the European Data Protection Board&#8217;s dispute-resolution role under Article 65?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolving certain disputes between supervisory authorities to ensure the correct and consistent application of the GDPR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Setting national tax rates<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Appointing every national DPO<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replacing national courts in all data protection cases<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Resolving certain disputes between supervisory authorities to ensure the correct and consistent application of the GDPR<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Article 65 establishes a dispute-resolution mechanism within the European Data Protection Board for specified disagreements between supervisory authorities. This can include situations where a concerned supervisory authority objects to a draft decision of the lead supervisory authority and the objection is relevant and reasoned, or where authorities disagree about which authority should act as lead. The Board can adopt a binding decision within the framework established by the GDPR. This mechanism supports consistent enforcement across Member States while preserving the institutional role of national supervisory authorities. It does not turn the Board into a general court for all data protection disputes or replace national judicial remedies.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-E Exam Dumps and Practice Test Dumps &nbsp; Question 381: Under Article 22 of the GDPR, which type of decision is subject to the specific protection against solely automated decision-making? Any decision made by an employee A decision based solely on automated processing that produces legal effects or similarly significantly affects the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20772"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20772"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20772\/revisions"}],"predecessor-version":[{"id":20773,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20772\/revisions\/20773"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20772"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20772"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20772"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}