IAPP CIPP-E Practice Test - Questions Answers, Page 14
List of questions
Related questions
Which of the following is one of the supervisory authority's investigative powers?
To notify the controller or the processor of an alleged infringement of the GDPR.
To require that controllers or processors adopt approved data protection certification mechanisms.
To determine whether a controller or processor has the right to a judicial remedy concerning a compensation decision made against them.
To require data controllers to provide them with written notification of all new processing activities.
Many businesses print their employees' photographs on building passes, so that employees can be identified by security staff. This is notwithstanding the fact that facial images potentially qualify as biometric data under the GDPR. Why would such practice be permitted?
Because use of biometric data to confirm the unique identification of data subjects benefits from an exemption.
Because photographs qualify as biometric data only when they undergo a "specific technical processing''.
Because employees are deemed to have given their explicit consent when they agree to be photographed by their employer.
Because photographic ID is a physical security measure which is "necessary for reasons of substantial public interest''.
A worker in a European Union (EU) member state has ceased his employment with a company. What should the employer most likely do in regard to the worker's personal data?
Destroy sensitive information and store the rest per applicable data protection rules.
Store all of the data in case the departing worker makes a subject access request.
Securely store the data that is required to be kept under local law.
Provide the employee the reasons for retaining the data.
Which of the following is NOT a role of works councils?
Determining the monetary fines to be levied against employers for data breach violations of employee data.
Determining whether to approve or reject certain decisions of the employer that affect employees.
Determining whether employees' personal data can be processed or not.
Determining what changes will affect employee working conditions.
Under the Data Protection Law Enforcement Directive of the EU, a government can carry out covert investigations involving personal data, as long it is set forth by law and constitutes a measure that is both necessary and what?
Prudent.
Important.
Proportionate.
DPA-approved.
Which GDPR requirement will present the most significant challenges for organizations with Bring Your Own Device (BYOD) programs?
Data subjects must be sufficiently informed of the purposes for which their personal data is processed.
Processing of special categories of personal data on a large scale requires appointing a DPO.
Personal data of data subjects must always be accurate and kept up to date.
Data controllers must be in control of the data they hold at all times.
A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, the company decides on a CCTV system to monitor for future incidents. Company technicians install cameras in the entrance of the building, hallways and offices. Footage is recorded continuously, and is monitored by the home office in the United States. What is the most realistic step the company could take to address their security concerns and comply with the personal data processing principles set out in Article 5 of the GDPR?
Seek informed consent from company employees.
Have cameras recording during work hours only.
Retain captured footage for no more than 30 days.
Restrict camera placement to building entrances only.
Which of the following is an example of direct marketing that would be subject to European data protection laws?
An updated privacy notice sent to an individual's personal email address.
A charity fundraising event notice sent to an individual at her business address.
A service outage notification provided to an individual by recorded telephone message.
A revision of contract terms conveyed to an individual by SMS from a marketing organization.
Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. Which of the following is NOT one of these exceptions?
The processing is done by a non-profit organization and the results are disclosed outside the organization.
The processing is necessary to protect the vital interests of the data subject when he or she is incapable of giving consent.
The processing is necessary for the establishment, exercise or defense of legal claims when courts are acting in a judicial capacity.
The processing is explicitly consented to by the data subject and he or she is allowed by Union or Member State law to lift the prohibition.
Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002/58/EC)?
Advertisements passively displayed on a website.
The use of cookies to collect data about an individual.
A text message to individuals from a company offering concert tickets for sale.
An email from a retail outlet promoting a sale to one of their previous customer.
Question