Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Certified Information Privacy Professional CIPP-E Exam Questions and Answers PDF

Page: 5 / 22
Total 295 questions

Certified Information Privacy Professional/Europe (CIPP/E) Questions and Answers

Question 17

SCENARIO

Please use the following to answer the next question:

ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.

Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain’s locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.

Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.

What are ABC Hotel Chain and XYZ Travel Agency’s roles in this relationship?

Options:

A.

ABC Hotel Chain is the controller and XYZ Travel Agency is the processor.

B.

XYZ Travel Agency is the controller and ABC Hotel Chain is the processor.

C.

ABC Hotel Chain and XYZ Travel Agency are independent controllers.

D.

ABC Hotel Chain and XYZ Travel Agency are joint controllers.

Question 18

Which type of personal data does the GDPR define as a “special category” of personal data?

Options:

A.

Educational history.

B.

Trade-union membership.

C.

Closed Circuit Television (CCTV) footage.

D.

Financial information.

Question 19

A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?

Options:

A.

The school places a notice near each camera.

B.

The school gets explicit consent from the students.

C.

Processing is necessary for the legitimate interests pursed by the school.

D.

A state law requires facial recognition to verify attendance.

Question 20

Which of the following is NOT a role of works councils?

Options:

A.

Determining the monetary fines to be levied against employers for data breach violations of employee data.

B.

Determining whether to approve or reject certain decisions of the employer that affect employees.

C.

Determining whether employees’ personal data can be processed or not.

D.

Determining what changes will affect employee working conditions.

Page: 5 / 22
Total 295 questions