Pass the IAPP Certified Information Privacy Professional CIPP-E Questions and answers with CertsForce

Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions
Questions # 61:

Sanctions for non-compliance with the EU Artificial Intelligence Act (Al Act) could result in a maximum fine of?

Options:

A.

The higher of up to 10 million Euro or up to 2% of the entity's total worldwide turnover for the preceding financial year.


B.

The higher of up to 40 million Euro or up to 8% of the entity's total worldwide turnover for the preceding financial year.


C.

The higher of up to 20 million Euro or up to 4% of the entity's total worldwide turnover for the preceding financial year.


D.

The higher of up to 30 million Euro or up to 6% of the entity's total worldwide turnover for the preceding financial year.


Expert Solution
Questions # 62:

If a multi-national company wanted to conduct background checks on all current and potential employees, including those based in Europe, what key provision would the company have to follow?

Options:

A.

Background checks on employees could be performed only under prior notice to all employees.


B.

Background checks are only authorized with prior notice and express consent from all employees including those based in Europe.


C.

Background checks on European employees will stem from data protection and employment law, which can vary between member states.


D.

Background checks may not be allowed on European employees, but the company can create lists based on its legitimate interests, identifying individuals who are ineligible for employment.


Expert Solution
Questions # 63:

SCENARIO

Please use the following to answer the next question:

Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company’s IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father’s company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.

Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company’s online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers’ philosophical beliefs, political opinions and marital status.

If a customer identifies as single, Ben then copies all of that customer’s personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.

Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.

Joe also hires his best friend’s daughter, Alice, who just graduated from law school in the U.S., to be the company’s new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company’s operations in the European Union to the U.S.

Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company’s IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone’s information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.

In preparing the company for its impending lawsuit, Alice’s instruction to the company’s IT Department violated Article 5 of the GDPR because the company failed to first do what?

Options:

A.

Send out consent forms to all of its employees.


B.

Minimize the amount of data collected for the lawsuit.


C.

Inform all of its employees about the lawsuit.


D.

Encrypt the data from all of its employees.


Expert Solution
Questions # 64:

Which of the following is NOT one of the 4 principles developed by the European Al Alliance regarding the ethical use of Artificial Intelligence?

Options:

A.

It should be fair.


B.

It should be lawful


C.

It should prevent harm


D.

It should respect human autonomy.


Expert Solution
Questions # 65:

To receive a preliminary interpretation on provisions of the GDPR, a national court will refer its case to which of the following?

Options:

A.

The Court of Justice of the European Union.


B.

The European Data Protection Supervisor.


C.

The European Court of Human Rights.


D.

The European Data Protection Board.


Expert Solution
Questions # 66:

In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?

Options:

A.

The predicted consequences of the breach.


B.

The measures being taken to address the breach.


C.

The type of security safeguards used to protect the data.


D.

The contact details of the appropriate data protection officer.


Expert Solution
Questions # 67:

Which of the following was the first to implement national law for data protection in 1973?

Options:

A.

France


B.

Sweden


C.

Germany


D.

United Kingdom


Expert Solution
Questions # 68:

A mobile device application that uses cookies will be subject to the consent requirement of which of the

following?

Options:

A.

The ePrivacy Directive


B.

The E-Commerce Directive


C.

The Data Retention Directive


D.

The EU Cybersecurity Directive


Expert Solution
Questions # 69:

An entity’s website stores text files on EU users’ computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?

Options:

A.

General Data Protection Regulation 2016/679.


B.

E-Privacy Directive 2002/58/EC.


C.

E-Commerce Directive 2000/31/EC.


D.

Data Protection Directive 95/46/EC.


Expert Solution
Questions # 70:

How does the GDPR now define “processing”?

Options:

A.

Any act involving the collecting and recording of personal data.


B.

Any operation or set of operations performed on personal data or on sets of personal data.


C.

Any use or disclosure of personal data compatible with the purpose for which the data was collected.


D.

Any operation or set of operations performed by automated means on personal data or on sets of personal data.


Expert Solution
Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions