IAPP CIPP-E Practice Test - Questions Answers, Page 13
List of questions
Related questions
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
Incidents of personal data breaches, whether disclosed or not.
Data inventory or data mapping exercises that have been conducted.
Categories of recipients to whom the personal data have been disclosed.
Retention periods for erasure and deletion of categories of personal data.
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
When the controller is collecting email addresses from individuals via an online registration form for marketing purposes.
When personal data is being collected and combined with other personal data to profile the creditworthiness of individuals.
When the controller is required to have a Data Protection Officer.
When personal data is being transferred outside of the EEA.
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?
Anonymizing special categories of data.
Conducting regular audits of the data protection program.
Getting consent from the data subject for a cross border data transfer.
Encrypting data in transit and at rest using strong encryption algorithms.
SCENARIO
Please use the following to answer the next question:
Dynaroux Fashion ('Dynaroux') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that
Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux's business plan and associated processing activities.
Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?
The company will be undertaking processing activities involving sensitive data categories such as financial and children's data.
The company employs approximately 650 people and will therefore be carrying out extensive processing activities.
The company plans to undertake profiling of its customers through analysis of their purchasing patterns.
The company intends to shift their business model to rely more heavily on online shopping.
Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?
Approved certifications.
Binding corporate rules.
Law enforcement requests.
Standard contractual clauses.
Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?
Employees must sign an ad hoc contractual agreement each time personal data is exported.
All employees are subject to the rules in their entirety, regardless of where the work is taking place.
All employees must follow the privacy regulations of the jurisdictions where the current scope of their work is established.
Employees who control personal data must complete a rigorous certification procedure, as they are exempt from legal enforcement.
With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?
If the data controller has received preapproval from a Data Protection Authority (DPA), after submitting the appropriate documents.
When it has been determined that adequate protection can be performed.
Only if the Data Protection Impact Assessment (DPIA) shows low risk.
Only as a last resort and when interpreted restrictively.
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze's headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
Which of the following is T-Craze's lead supervisory authority?
Germany, because that is where T-Craze is headquartered.
France, because that is where T-Craze conducts processing of personal information.
Spain, because that is T-Craze's primary market based on its marketing campaigns.
T-Craze may choose its lead supervisory authority where any of its affiliates are based, because it has presence in several European countries.
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze's headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
Why does the Spanish supervisory authority notify the French supervisory authority when it opens an investigation into T-Craze based on Sofia's complaint?
T-Craze has a French affiliate.
The French affiliate procured the services of Right Target.
T-Craze conducts its marketing and sales activities in France.
The Spanish supervisory authority is providing a courtesy notification not required under the GDPR.
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany
Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
What is the best option for the lead regulator when responding to the Spanish supervisory authority's notice that it plans to take action regarding Sofia's complaint?
Accept, because it did not receive any complaints.
Accept, because GDPR permits non-lead authorities to take action for such complaints.
Reject, because Right Target's processing was conducted throughout Europe.
Reject, because GDPR does not allow other supervisory authorities to take action if there is a lead authority.
Question