Pass the IAPP Certified Information Privacy Professional CIPP-E Questions and answers with CertsForce

Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions
Questions # 31:

Under Article 21 of the GDPR, a controller must stop profiling when requested by a data subject, unless it can demonstrate compelling legitimate grounds that override the interests of the individual. In the Guidelines on Automated individual decision-making and Profiling, the WP 29 says the controller needs to do all of the following to demonstrate that it has such legitimate grounds EXCEPT?

Options:

A.

Carry out an exercise that weighs the interests of the controller and the basis for the data subject’s objection.


B.

Consider the impact of the profiling on the data subject’s interest, rights and freedoms.


C.

Demonstrate that the profiling is for the purposes of direct marketing.


D.

Consider the importance of the profiling to their particular objective.


Expert Solution
Questions # 32:

A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?

Options:

A.

The school places a notice near each camera.


B.

The school gets explicit consent from the students.


C.

Processing is necessary for the legitimate interests pursed by the school.


D.

A state law requires facial recognition to verify attendance.


Expert Solution
Questions # 33:

SCENARIO

Please use the following to answer the next question:

BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information – name, location, and prior purchase history – with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.

Prior to sharing its customer list, BHealthy conducted a review of Natural Insight’s security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy’s data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight’s machine learning algorithms.

What is the nature of BHealthy and Natural Insight’s relationship?

Options:

A.

Natural Insight is BHealthy’s processor because the companies entered into data processing terms.


B.

Natural Insight is BHealthy’s processor because BHealthy is sharing its customer information with Natural Insight.


C.

Natural Insight is the controller because it determines the security measures to implement to protect data it processes; BHealthy is a co-controller because it engaged Natural Insight to determine pricing for the new sunscreens.


D.

Natural Insight is a controller because it is separately determine the purpose of processing when it uses BHealthy’s customer information to improve its machine learning algorithms.


Expert Solution
Questions # 34:

SCENARIO

Please use the following to answer the next question:

Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).

People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.

The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.

The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a

Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''

Options:

A.

No, the assessors do not quality as data processors as they only have access to encrypted data.


B.

No. the assessors do not quality as data processors as they do not copy the data to their facilities.


C.

Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.


D.

Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.


Expert Solution
Questions # 35:

SCENARIO

Please use the following to answer the next question:

T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.

T-Craze also opened various office locations throughout Europe to help expand its business. While Germany

Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.

The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.

What is the best option for the lead regulator when responding to the Spanish supervisory authority’s notice that it plans to take action regarding Sofia’s complaint?

Options:

A.

Accept, because it did not receive any complaints.


B.

Accept, because GDPR permits non-lead authorities to take action for such complaints.


C.

Reject, because Right Target’s processing was conducted throughout Europe.


D.

Reject, because GDPR does not allow other supervisory authorities to take action if there is a lead authority.


Expert Solution
Questions # 36:

When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?

Options:

A.

Inform the subjects about the collection


B.

Provide a public notice regarding the data


C.

Upgrade security to match that of the source


D.

Update the data within a reasonable timeframe


Expert Solution
Questions # 37:

Which of the following would NOT be relevant when determining if a processing activity would be considered profiling?

Options:

A.

If the processing is to be performed by a third-party vendor


B.

If the processing involves data that is considered personal data


C.

If the processing of the data is done through automated means


D.

If the processing is used to predict the behavior of data subjects


Expert Solution
Questions # 38:

Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?

Options:

A.

A company wants to combine location data with other data in order to offer more personalized service for the customer.


B.

A company wants to use location data to infer information on a person’s clothes purchasing habits.


C.

A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.


D.

A company wants to use location data to track delivery trucks in order to make the routes more efficient.


Expert Solution
Questions # 39:

SCENARIO

Please use the following to answer the next question:

Zandelay Fashion (‘Zandelay’) is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company’s compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.

The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.

In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company’s customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.

Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay’s business plan and associated processing activities.

What would MOST effectively assist Zandelay in conducting their data protection impact assessment?

Options:

A.

Information about DPIAs found in Articles 38 through 40 of the GDPR.


B.

Data breach documentation that data controllers are required to maintain.


C.

Existing DPIA guides published by local supervisory authorities.


D.

Records of processing activities that data controllers are required to maintain.


Expert Solution
Questions # 40:

In 2016’s Guidance, the United Kingdom’s Information Commissioner’s Office (ICO) reaffirmed the importance of using a “layered notice” to provide data subjects with what?

Options:

A.

A privacy notice containing brief information whilst offering access to further detail.


B.

A privacy notice explaining the consequences for opting out of the use of cookies on a website.


C.

An explanation of the security measures used when personal data is transferred to a third party.


D.

An efficient means of providing written consent in member states where they are required to do so.


Expert Solution
Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions