IAPP CIPP-E Practice Test - Questions Answers, Page 19
List of questions
Related questions
If a data subject puts a complaint before a DPA and receives no information about its progress or outcome, how long does the data subject have to wait before taking action in the courts?
1 month.
3 months.
5 months.
12 months.
For which of the following operations would an employer most likely be justified in requesting the data subject's consent?
Posting an employee's bicycle race photo on the company's social media.
Processing an employee's health certificate in order to provide sick leave.
Operating a CCTV system on company premises.
Assessing a potential employee's job application.
An entity's website stores text files on EU users' computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?
General Data Protection Regulation 2016/679.
E-Privacy Directive 2002/58/EC.
E-Commerce Directive 2000/31/EC.
Data Protection Directive 95/46/EC.
Which of the following is NOT considered a fair processing practice in relation to the transparency principle?
Providing a multi-layered privacy notice, in a website environment.
Providing a QR code linking to more detailed privacy notice, in a CCTV sign.
Providing a hyperlink to the organization's home page, in a hard copy application form.
Providing a "just-in-time" contextual pop-up privacy notice, in an online application from field.
Which of the following was the first to implement national law for data protection in 1973?
France
Sweden
Germany
United Kingdom
The GDPR forbids the practice of "forum shopping'', which occurs when companies do what?
Choose the data protection officer that is most sympathetic to their business concerns.
Designate their main establishment in member state with the most flexible practices.
File appeals of infringement judgments with more than one EU institution simultaneously.
Select third-party processors on the basis of cost rather than quality of privacy protection.
What is the most frequently used mechanism for legitimizing cross-border data transfer?
Standard Contractual Clauses.
Approved Code of Conduct.
Binding Corporate Rules.
Derogations.
If a French controller has a car-sharing app available only in Morocco, Algeria and Tunisia, but the data processing activities are carried out by the appointed processor in Spain, the GDPR will apply to the processing of the personal data so long as?
The individuals are European citizens or residents.
The data processing activities are in Spain.
The data controller is in France.
The EU individuals are targeted.
Select the answer below that accurately completes the following:
''The right to compensation and liability under the GDPR...
...provides for an exemption from liability if the data controller (or data processor) proves that it is not in any way responsible for the event giving rise to the damage.''
...precludes any subsequent recourse proceedings against other controllers or processors involved in the same processing.''
...can only be exercised against the data controller, even if a data processor was involved in the same processing.''
...is limited to a maximum amount of EUR 20 million per event of damage or loss.''
Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?
It cannot be attributed to a data subject without the use of additional information.
It cannot be attributed to a person under any circumstances.
It can only be attributed to a person by the controller.
It can only be attributed to a person by a third party.
Question