Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

All CIPP-E Test Inside IAPP Questions

Page: 19 / 22
Total 295 questions

Certified Information Privacy Professional/Europe (CIPP/E) Questions and Answers

Question 73

A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if it imports personal data from another organization in the European Economic Area (EEA) under standard contractual clauses?

Options:

A.

Submit the contract to its own government authority.

B.

Ensure that notice is given to and consent is obtained from data subjects.

C.

Supply any information requested by a data protection authority (DPA) within 30 days.

D.

Ensure that local laws do not impede the company from meeting its contractual obligations.

Question 74

According to the European Data Protection Board, which of the following concepts or practices does NOT follow from the principles relating to the processing of personal data under EU data protection law?

Options:

A.

Data ownership allocation.

B.

Access control management.

C.

Frequent pseudonymization key rotation.

D.

Error propagation avoidance along the processing chain.

Question 75

When does the GDPR provide more latitude for a company to process data beyond its original collection purpose?

Options:

A.

When the data has been pseudonymized.

B.

When the data is protected by technological safeguards.

C.

When the data serves legitimate interest of third parties.

D.

When the data subject has failed to use a provided opt-out mechanism.

Question 76

When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?

Options:

A.

Documenting due diligence steps taken in the pre-contractual stage.

B.

Conducting a risk assessment to analyze possible outsourcing threats.

C.

Requiring that the processor directly notify the appropriate supervisory authority.

D.

Maintaining evidence that the processor was the best possible market choice available.

Page: 19 / 22
Total 295 questions