Question # 1 According to the GDPR, when should the processing of photographs be considered processing of special categories of personal data?
A. When processed with the intent to publish information regarding a natural person on publicly accessible media.
B. When processed with the intent to proceed to scientific or historical research projects.
C. When processed with the intent to uniquely identify or authenticate a natural person.
D. When processed with the intent to comply with a law.
Click for Answer
C. When processed with the intent to uniquely identify or authenticate a natural person.
Answer Description Reference: https://www.privacy-regulation.eu/en/recital-51-GDPR.htm
Question # 2 Please use the following to answer the next question: Dynaroux Fashion (‘Dynaroux’) is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company’s compliance with the General Data Protection Regulation (GDPR) and other privacy legislation. The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers. In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company’s customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme. Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux’s business plan and associated processing activities. Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?
A. The company will be undertaking processing activities involving sensitive data categories such as financial and children’s data.
B. The company employs approximately 650 people and will therefore be carrying out extensive processing activities.
C. The company plans to undertake profiling of its customers through analysis of their purchasing patterns.
D. The company intends to shift their business model to rely more heavily on online shopping.
Click for Answer
C. The company plans to undertake profiling of its customers through analysis of their purchasing patterns.
Question # 3 Many businesses print their employees’ photographs on building passes, so that employees can be identified by security staff. This is notwithstanding the fact that facial images potentially qualify as biometric data under the GDPR. Why would such practice be permitted?
A. Because use of biometric data to confirm the unique identification of data subjects benefits from an exemption.
B. Because photographs qualify as biometric data only when they undergo a “specific technical processing”.
C. Because employees are deemed to have given their explicit consent when they agree to be photographed by their employer.
D. Because photographic ID is a physical security measure which is “necessary for reasons of substantial public interest”.
Click for Answer
B. Because photographs qualify as biometric data only when they undergo a “specific technical processing”.
Answer Description Explanation: Reference https://ess.csa.canon.com/rs/206-CLL-191/images/IAPP-Top-10-Operational- Impacts-of- GDPR.pdf?TC=DM&CN=CSA_OMNIA_Partners&CS=CSA&CR=T1_Gov-GenNonProfi t (11)
Question # 4 Which of the following entities would most likely be exempt from complying with the GDPR?
A. A South American company that regularly collects European customers’ personal data.
B. A company that stores all customer data in Australia and is headquartered in a European Union (EU) member state.
C. A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.
D. A North American company servicing customers in South Africa that uses a cloud storage system made by a European company.
Click for Answer
C. A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.
Question # 5 Please use the following to answer the next question: Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry. Company B’s payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A’s factories. Company B won’t hold any biometric data itself, but the related data will be uploaded to Company B’s UK servers and used to provide the payroll service. Company B’s live systems will contain the following information for each of Company A’s employees: Name Address Date of Birth Payroll number National Insurance number Sick pay entitlement Maternity/paternity pay entitlement Holiday entitlement Pension and benefits contributions Trade union contributions Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn’t sure whether or not this is required. Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn’t have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract. Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B’s live systems in order to create a new database for Company B. This database will be stored in a test environment hosted on Company C’s U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes. Unfortunately, Company C’s U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A’s employees is visible to anyone visiting Company C’s website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees. The GDPR requires sufficient guarantees of a company’s ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?
A. Hiring companies whose measures are consistent with recommendations of accrediting bodies.
B. Requesting advice and technical support from Company A’s IT team.
C. Avoiding the use of another company’s data to improve their own services.
D. Vetting companies’ measures with the appropriate supervisory authority.
Click for Answer
A. Hiring companies whose measures are consistent with recommendations of accrediting bodies.
Answer Description Reference: https://www.knowyourcompliance.com/gdpr-technical-organisational-measures/
Question # 6 A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?
A. The school places a notice near each camera.
B. The school gets explicit consent from the students.
C. Processing is necessary for the legitimate interests pursed by the school.
D. A state law requires facial recognition to verify attendance.
Click for Answer
A. The school places a notice near each camera.
Answer Description Reference: https://www.jdsupra.com/legalnews/let-s-face-it-facial-recognition-1134180/
Question # 7 Article 29 Working Party has emphasized that the GDPR forbids “forum shopping”, which occurs when companies do what?
A. Choose the data protection officer that is most sympathetic to their business concerns.
B. Designate their main establishment in member state with the most flexible practices.
C. File appeals of infringement judgments with more than one EU institution simultaneously.
D. Select third-party processors on the basis of cost rather than quality of privacy protection.
Click for Answer
B. Designate their main establishment in member state with the most flexible practices.
Answer Description Reference: https://gdprinformer.com/gdpr-articles/forum-shopping-illegal-gdpr
Question # 8 Please use the following to answer the next question: Zandelay Fashion (‘Zandelay’) is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company’s compliance with the General Data Protection Regulation (GDPR) and other privacy legislation. The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers. In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company’s customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme. Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay’s business plan and associated processing activities. What would MOST effectively assist Zandelay in conducting their data protection impact assessment?
A. Information about DPIAs found in Articles 38 through 40 of the GDPR.
B. Data breach documentation that data controllers are required to maintain.
C. Existing DPIA guides published by local supervisory authorities.
D. Records of processing activities that data controllers are required to maintain
Click for Answer
A. Information about DPIAs found in Articles 38 through 40 of the GDPR.
Up-to-Date
We always provide up-to-date CIPP-E exam dumps to our clients. Keep checking website for updates and download.
Excellence
Quality and excellence of our Certified Information Privacy Professional/Europe (CIPP/E) practice questions are above customers expectations. Contact live chat to know more.
Success
Your SUCCESS is assured with the CIPP-E exam questions of passin1day.com. Just Buy, Prepare and PASS!
Quality
All our braindumps are verified with their correct answers. Download Certified Information Privacy Professional Practice tests in a printable PDF format.
Basic
$80
Any 3 Exams of Your Choice
3 Exams PDF + Online Test Engine
Buy Now
Premium
$100
Any 4 Exams of Your Choice
4 Exams PDF + Online Test Engine
Buy Now
Gold
$125
Any 5 Exams of Your Choice
5 Exams PDF + Online Test Engine
Buy Now
Passin1Day has a big success story in last 12 years with a long list of satisfied customers.
We are UK based company, selling CIPP-E practice test questions answers. We have a team of 34 people in Research, Writing, QA, Sales, Support and Marketing departments and helping people get success in their life.
We dont have a single unsatisfied IAPP customer in this time. Our customers are our asset and precious to us more than their money.
CIPP-E Dumps
We have recently updated IAPP CIPP-E dumps study guide. You can use our Certified Information Privacy Professional braindumps and pass your exam in just 24 hours. Our Certified Information Privacy Professional/Europe (CIPP/E) real exam contains latest questions. We are providing IAPP CIPP-E dumps with updates for 3 months. You can purchase in advance and start studying. Whenever IAPP update Certified Information Privacy Professional/Europe (CIPP/E) exam, we also update our file with new questions. Passin1day is here to provide real CIPP-E exam questions to people who find it difficult to pass exam
Certified Information Privacy Professional can advance your marketability and prove to be a key to differentiating you from those who have no certification and Passin1day is there to help you pass exam with CIPP-E dumps. IAPP Certifications demonstrate your competence and make your discerning employers recognize that Certified Information Privacy Professional/Europe (CIPP/E) certified employees are more valuable to their organizations and customers. We have helped thousands of customers so far in achieving their goals. Our excellent comprehensive IAPP exam dumps will enable you to pass your certification Certified Information Privacy Professional exam in just a single try. Passin1day is offering CIPP-E braindumps which are accurate and of high-quality verified by the IT professionals. Candidates can instantly download Certified Information Privacy Professional dumps and access them at any device after purchase. Online Certified Information Privacy Professional/Europe (CIPP/E) practice tests are planned and designed to prepare you completely for the real IAPP exam condition. Free CIPP-E dumps demos can be available on customer’s demand to check before placing an order.
What Our Customers Say
Jeff Brown
Thanks you so much passin1day.com team for all the help that you have provided me in my IAPP exam. I will use your dumps for next certification as well.
Mareena Frederick
You guys are awesome. Even 1 day is too much. I prepared my exam in just 3 hours with your CIPP-E exam dumps and passed it in first attempt :)
Ralph Donald
I am the fully satisfied customer of passin1day.com. I have passed my exam using your Certified Information Privacy Professional/Europe (CIPP/E) braindumps in first attempt. You guys are the secret behind my success ;)
Lilly Solomon
I was so depressed when I get failed in my Cisco exam but thanks GOD you guys exist and helped me in passing my exams. I am nothing without you.