IAPP CIPP-E Practice Test - Questions Answers, Page 18
List of questions
Related questions
A data controller appoints a data protection officer. Which of the following conditions would NOT result in an infringement of Articles 37 to 39 of the GDPR?
If the data protection officer lacks ISO 27001 auditor certification.
If the data protection officer is provided by the data processor.
If the data protection officer also manages the marketing budget.
If the data protection officer receives instructions from the data controller.
Data retention in the EU was underpinned by a legal framework established by the Data Retention Directive (2006/24/EC). Why is the Directive no longer part of EU law?
The Directive was superseded by the EU Directive on Privacy and Electronic Communications.
The Directive was superseded by the General Data Protection Regulation.
The Directive was annulled by the Court of Justice of the European Union.
The Directive was annulled by the European Court of Human Rights.
Which of the following is the weakest lawful basis for processing employee personal data?
Processing based on fulfilling an employment contract.
Processing based on employee consent.
Processing based on legitimate interests.
Processing based on legal obligation.
An organization receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal data. Under what condition can the organization charge the data subject a fee for processing the request?
Only where the organization can show that it is reasonable to do so because more than one request was made.
Only to the extent this is allowed under the restrictions on data subjects' rights introduced under Art 23 of GDPR.
Only where the administrative costs of taking the action requested exceeds a certain threshold.
Only if the organization can demonstrate that the request is clearly excessive or misguided.
To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?
The Court of Justice of the European Union.
The European Data Protection Supervisor.
The European Court of Human Rights.
The European Data Protection Board.
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?
The school places a notice near each camera.
The school gets explicit consent from the students.
Processing is necessary for the legitimate interests pursed by the school.
A state law requires facial recognition to verify attendance.
SCENARIO
Please use the following to answer the next question:
ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
What is the time period in which Mike should receive a response to his request?
Not more than one month of receipt of Mike's request.
Not more than two months after verifying Mike's identity.
When all the information about Mike has been collected.
Not more than thirty days after submission of Mike's request.
SCENARIO
Please use the following to answer the next question:
ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
What are ABC Hotel Chain and XYZ Travel Agency's roles in this relationship?
ABC Hotel Chain is the controller and XYZ Travel Agency is the processor.
XYZ Travel Agency is the controller and ABC Hotel Chain is the processor.
ABC Hotel Chain and XYZ Travel Agency are independent controllers.
ABC Hotel Chain and XYZ Travel Agency are joint controllers.
SCENARIO
Please use the following to answer the next question:
ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
In which of the following situations would ABC Hotel Chain and XYZ Travel Agency NOT have to honor Mike's data access request?
The request is to obtain access and correct inaccurate personal data in his profile.
The request is to obtain access and information about the purpose of processing his personal data.
The request is to obtain access and erasure of his personal data while keeping his rewards membership.
The request is to obtain access and the categories of recipients who have received his personal data to process his rewards membership.
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
The obligation of companies to declare data breaches.
The requirement to demonstrate compliance to a supervisory authority.
The necessity of the bulk collection of personal data by the government.
Question