IAPP CIPP-E Practice Test - Questions Answers, Page 20
List of questions
Related questions
According to Article 84 of the GDPR, the rules on penalties applicable to infringements shall be laid down by?
The local Data Protection Supervisory Authorities.
The European Data Protection Board.
The EU Commission.
The Member States.
A company plans to transfer employee health information between two of its entities in France. To maintain the security of the processing, what would be the most important security measure to apply to the health data transmission?
Inform the data subject of the security measures in place.
Ensure that the receiving entity has signed a data processing agreement.
Encrypt the transferred data in transit and at rest.
Conduct a data protection impact assessment.
If a company chooses to ground an international data transfer on the contractual route, which of the following is NOT a valid set of standard contractual clauses?
Decision 2001/497/EC (EU controller to non-EU or EEA controller).
Decision 2004/915/EC (EU controller to non-EU or EEA controller).
Decision 2007/72/EC (EU processor to non-EU or EEA controller).
Decision 2010/87/EU (Non-EU or EEA processor from EU controller).
Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?
Legislative powers.
Corrective powers.
Investigatory powers.
Authorization and advisory powers.
According to the European Data Protection Board, which of the following concepts or practices does NOT follow from the principles relating to the processing of personal data under EU data protection law?
Data ownership allocation.
Access control management.
Frequent pseudonymization key rotation.
Error propagation avoidance along the processing chain.
According to the GDPR, when should the processing of photographs be considered processing of special categories of personal data?
When processed with the intent to publish information regarding a natural person on publicly accessible media.
When processed with the intent to proceed to scientific or historical research projects.
When processed with the intent to uniquely identify or authenticate a natural person.
When processed with the intent to comply with a law.
The origin of privacy as a fundamental human right can be found in which document?
Universal Declaration of Human Rights 1948.
European Convention of Human Rights 1953.
OECD Guidelines on the Protection of Privacy 1980.
Charier of Fundamental Rights of the European Union 2000.
Which statement provides an accurate description of a directive?
A directive speo5es certain results that must be achieved, but each member state is free to decide how to turn it into a national law
A directive has binding legal force throughout every member state and enters into force on a set date in all the member states.
A directive is a legal act relating to specific cases and directed towards member states, companies 0' private individuals.
A directive is a legal act that applies automatically and uniformly to all EU countries as soon as it enters into force.
Which of the following regulates the use of electronic communications services within the European Union?
Regulator (EU) 2015/2120 of the European Parliament and of the Council of 25 November 2015.
Regulation (EU) 2017/1953 of the European Parliament and of the Council of 25 October 2017.
Directive 2002/58'EC of the European Parliament and of the Council of 12 July 2002.
Directive (EU) 2019.789 of the European Parliament and of the Council of 17 April 2019.
What was the main failing of Convention 108 that led to the creation of the Data Protection Directive (Directive 95/46/EC)?
IT did not account for the rapid growth of the Internet
It did not include protections for sensitive personal data
It was implemented in a fragmented manner by a small number of states.
Its penalties for violations of data protection rights were widely viewed as r sufficient.
Question