Pass the IAPP Certified Information Privacy Professional CIPP-E Questions and answers with CertsForce

Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following is an accurate statement regarding the "one-stop-shop" mechanism of the GDPR?

Options:

A.

It can result in several lead supervisory authorities in the EU assuming competence over the same data processing activities of an organization.


B.

It applies only to direct enforcement of data protection supervisory authorities (e.g.. finding a breach), but not to initiating or engaging m court proceedings


C.

It gives competence to the lead supervisory authority to address privacy issues derived from processes carried out by public authorities established in different countries.


D.

It allows supervisory authorities concerned (other than the lead supervisory authority) to act against organizations m exceptional cases even if they do not have any type of establishment in the Member State of the respective authority.


Expert Solution
Questions # 12:

Start-up company MagicAl is developing an AI system that will be part of a medical device that detects skin cancer. To take measures against potential bias in its AI system, the IT team decides to collect data about users’ ethnic origin, nationality, and gender.

Which would be the most appropriate legal basis for this processing under GDPR, Article 9 (Processing of special categories of personal data)?

Options:

A.

Processing necessary for scientific or statistical purposes.


B.

Processing necessary for reasons of substantial public interest.


C.

Processing necessary for purposes of preventive or occupational medicine.


D.

Processing necessary for the defense of legal claims in potential negligence cases.


Expert Solution
Questions # 13:

What is the most frequently used mechanism for legitimizing cross-border data transfer?

Options:

A.

Standard Contractual Clauses.


B.

Approved Code of Conduct.


C.

Binding Corporate Rules.


D.

Derogations.


Expert Solution
Questions # 14:

SCENARIO

Please use the following to answer the next question:

Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in

Greece (5), Italy (15) and Spain (1), have registered their most profitable results

ever. To celebrate this achievement, ARRA Hotels' Human Resources office, based

in ARRA's main Italian establishment, has organized a team event for its 420

employees and their families at its hotel in Spain.

Upon arrival at the hotel, each employee and family member is given an electronic

wristband at the reception desk. The wristband serves a number of functions:

. Allows access to the "party zone" of the hotel, and emits a buzz if the user

approaches any unauthorized areas

. Allows up to three free drinks for each person of legal age, and emits a

buzz once this limit has been reached

. Grants a unique ID number for participating in the games and contests that

have been planned.

Along with the wristband, each guest receives a QR code that leads to the online

privacy notice describing the use of the wristband. The page also contains an

unchecked consent checkbox. In the case of employee family members under the

age of 16, consent must be given by a parent.

Among the various activities planned for the event, ARRA Hotels' HR office has

autonomously set up a photocall area, separate from the main event venue, where

employees can come and have their pictures taken in traditional carnival costume.

The photos will be posted on ARRA Hotels' main website for general marketing

purposes.

On the night of the event, an employee from one of ARRA's Greek hotels is

displeased with the results of the photos in which he appears. He intends to file a

complaint with the relevant supervisory authority in regard to the following:

. The lack of any privacy notice in the separate photocall area

The unlawful cross-border processing of his personal data

. The unacceptable aesthetic outcome of his photos

Which of the following is NOT necessarily considered a factor in identifying whether

the processing could be considered a "cross-border processing"?

Options:

A.

The total number of the data subjects interested.


B.

The potential harm for the data subjects affected.


C.

The limitation of rights of the data subjects concerned.


D.

The exposure of the information of the data subjects involved.


Expert Solution
Questions # 15:

What monitoring may lawfully be performed within the scope of Gentle Hedgehog's business?

Options:

A.

Everything offered by Sauron Eye's software in relation to activity by sales team contractors.


B.

Everything offered by Sauron Eye's software, assuming employees provide daily consent to the monitoring.


C.

Only emails, website browsing history, and camera for internal video calls conducted in a non-secure environment.


D.

Only emails, website browsing history, and camera for internal video calls that are expressly marked as monitored.


Expert Solution
Questions # 16:

An unforeseen power outage results in company Z’s lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29’s February, 2018 guidance, company Z should do which of the following?

Options:

A.

Notify affected individuals that their data was unavailable for a period of time.


B.

Document the loss of availability to demonstrate accountability


C.

Notify the supervisory authority about the loss of availability


D.

Conduct a thorough audit of all security systems


Expert Solution
Questions # 17:

The European Parliament jointly exercises legislative and budgetary functions with which of the following?

Options:

A.

The European Commission.


B.

The Article 29 Working Party.


C.

The Council of the European Union.


D.

The European Data Protection Board.


Expert Solution
Questions # 18:

SCENARIO

Please use the following to answer the next question:

Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta |EU).

People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.

The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.

The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a

Which of the following must be a component of the anti-money-laundering data-sharing practice of the platform?

Options:

A.

The terms of service shall also enumerate all applicable anti-money laundering few.


B.

Customers shall have an opt-out feature to restrict data sharing with law enforcement agencies after the registration.


C.

The terms of service shall include the address of the anti-money laundering agency and contacts of the investigators who may access me data.


D.

Customers snail receive a clear and conspicuous notice about such data sharing before submitting their data during the registration process.


Expert Solution
Questions # 19:

SCENARIO

Please use the following to answer the next question:

BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information – name, location, and prior purchase history – with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.

Prior to sharing its customer list, BHealthy conducted a review of Natural Insight’s security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy’s data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight’s machine learning algorithms.

In which case would Natural Insight’s use of BHealthy’s data for improvement of its algorithms be considered data processor activity?

Options:

A.

If Natural Insight uses BHealthy’s data for improving price point predictions only for BHealthy.


B.

If Natural Insight receives express contractual instructions from BHealthy to use its data for improving its algorithms.


C.

If Natural Insight agrees to be fully liable for its use of BHealthy’s customer information in its product improvement activities.


D.

If Natural Insight satisfies the transparency requirement by notifying BHealthy’s customers of its plans to use their information for its product improvement activities.


Expert Solution
Questions # 20:

Which of the following is the weakest lawful basis for processing employee personal data?

Options:

A.

Processing based on fulfilling an employment contract.


B.

Processing based on employee consent.


C.

Processing based on legitimate interests.


D.

Processing based on legal obligation.


Expert Solution
Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions