Study with the several resources on Docsity
Earn points by helping other students or get them with a premium plan
Prepare for your exams
Study with the several resources on Docsity
Earn points to download
Earn points by helping other students or get them with a premium plan
Community
Ask the community for help and clear up your study doubts
Discover the best universities in your country according to Docsity users
Free resources
Download our free guides on studying techniques, anxiety management strategies, and thesis advice from Docsity tutors
CIPP/E Certification from IAPP Questions & with 100% Correct Answers 2023
Typology: Exams
1 / 37
Outliers work on their website to company x, employee of Company X steals the data -delete it - tells boss. Q: What is company x legally obliged to do? - Correct answer A: NotifyOutliers
Outliers work on their website to company x, employee of Company X steals the data -delete it - tells boss. Q: What does Outliers then need to do?
Privacy notice for new Health App collecting sensitive data. Q: What is the problem with the draft? - Correct answer A: Them form is asking for health information from the outset, which is not legal Privacy notice for new Health App collecting sensitive data Q: Potential problem with collecting children data? - Correct answer A: Need to demonstrate steps to gain parental consent
Anna is lawyer foruniversity tasked with Student Records. Frank is a professor. Four types of data:Student Data - personal infoEmployee Data - personal infoAlumni Data - personal infoDepartment of Education Data:demographic data - no personal identifiers (used to see how first year students progress, etc.)Frank wants to build a database to process data and see how first year students in his class progressed. Frank builds algorithm to process data without identifiers. All university systems are encrypted. Takes
data to his home laptop which is not encrypted. Loses laptop Q: Which types of data does Anna NOT have to include in her record of processing activities? - Correct answer Department of Education Records Q: What should the Anna/DPO checkto confirm he can process those data? - Correct answer More information about the algorithm he has developed Q: He losses the data, what should happen next? Should they inform the
students? - Correct answer Yes because potential high risk since data was not encrypted Case study on guy gets photo taken at a gym in Germany -consents to them using it for marketing -Gym HQ in France -Gyms all over EU -He lives in UK -Submits request to ICO in UK -ICO refers to CNIL (this is the SA in France)
Q: In effort of Cooperation (the lead SA, CNIL, gets their judgement) what should the they do now? - Correct answer Draft a draft decision and submit to supporting SAs for their opinion. What does he have to do for lawsuit? (each location is a controller!) - Correct answer Answer: Go to each gym branch... Question on what he should do if he wants tosue - Correct answer Sue ANY
relevant branch as each can be liable for entire damage ABC Insurance gives data to subsidiary which begins direct marketing to Jason. Jason decides to switch insurance companies. ABC Insurance is direct marketing to Jason. Jason asks them to stop but they say that there is a line in the contract he signed saying he consents to direct marketing and he doesn't stop. Wants to transfer data - they give it to him in PDF format. He asks for them to transfer and they can't
because it's too time-consuming and not feasible. Q: According to GDPR regulations on direct marketing(note:I think the wording here is key), can Jason stop ABC from direct marketing? - Correct answer Jason has right to object and ABC must immediately stop using his data. Q: If Jason asks to stop use of his data, what must the ABC insurance subsidiary do? - Correct answer A: Stop using the data unless for legal matters in which subsidiary is involved.
Q: Did ABC violate GDPR by not sending the data to the new insurance company? - Correct answer A: No, because sending it is not possible. Undue strain on the company to send it which infringes on their rights. PDF format is enough. Guy runs a social media company for small businesses along with a few other things. Sends data to Hermes for Sub Processing - they then use the data to create ads on their personal website.
Girl accidentally posts her business plan in the chat function of the website and leaves it for 2 weeks.Goes to SA about data breach. Serge posts a quote on his Social Media page and this ends up as a quotation on the main site attributed to Serge Q: Why would the girl who leaked her business plan likely not have a case with GDPR: - Correct answer A:Because of the nature of the data (I chose this one because it was a business plan and likely did not contain personal data)
Q: Whats concerning about Hermes? - Correct answer A: They are processing for anew purpose Q: What did he likely miss? - Correct answer A: Providing an opt out fortransfer Q: What's concerning about Serge's misuse of data? - Correct answer A: The data was used out of the context of the Social Media Service and outside of service.
Based in France but hosts website and data on US hosting company. Q: What should Wondermind include in the contract with hosting company: - Correct answer A: Ensure that they have appropriate technical and organizational measures Q: What should Wondermind include in the contract to data subjects - Correct answer A: Categories of Processing Recipients (no need to provide processor contact information).
Processing data to gather advert behaviors (irish clothing company)Markets to men, women, and children. Wants to do some big time profiling. Q: What would be the biggest thing to require a DPIA - Correct answer A: Doing Profiling to gather purchasing and other behaviour on customers. Q: When does a company not have to comply with right to portability? -
Correct answer Processed on basis of consent and/or contract Q: What did the convention and the directive have in common but unable to accomplish - Correct answer Enforcement Q: Who can propose new laws in EU? / Who can propose legislation in EU? - Correct answer EU commission Q: Who approves adequate countries? - Correct answer EU Commission -has
the ability to update, grant and remove the adequacy status of a country. Q: Why was data retention directive invalidated in 2014? - Correct answer It impacts everyone without exception (their privacy rights) Q: What wasthe goal of the original EU DP Directive 95/46? - Correct answer - To further reconcile the protection of fundamental rights with free flow of data from one-member state to another
Q: What best defines GDPR? - Correct answer - Comprehensive Q: What do GDPR and Convention have in common? - Correct answer - International Data Transfers Q: Question regarding right to privacy: - Correct answer - Must be balanced with other rights and freedoms Q: What is out of scope / not covered in the GDPR? - Correct answer - Anonymous
Pseudonymisation- which is NOT true? - Correct answer - Is a procedure by which ALL identifying fields are removed Q: What is true about Pseudonymisation? - Correct answer - Gives controllers a bit more leeway on if/how they can process data besides purpose of initial collection and processing. Q: Employee requesting information from employer? - Correct answer -
They have to comply unless there's an exemption Q: Why consent is not the best legal basis for employees? - Correct answer
Q: What is REQUIRED for a company to market to EU consumer via email? (bit of a trick question)? - Correct answer - Prior opt-in Consent or previous customer purchase Q: Special category? - Correct answer
Q: When would consent NOT be needed from a child? - Correct answer
GDPR? - Correct answer - American company, transacting with South African company using software built in the EU - Slightly different wording, but should be easy to spot Q: When is DPIA needed? - Correct answer - Type of processing is "likely to result in a high risk to the rights and freedoms of natural persons" Q: What is NOT needed in article of processing records? - Correct answer - Results from a DPIA
Q: What is the main purpose of the DPO
they need to include in their breach report. - Correct answer - Link to DPIA Q: Processor notifies controller for a breach? - Correct answer - Without undue delay after becoming aware of it Q: Which of the following is NOT included in processor contract? - Correct answer Purpose of processing Q: Data subject notice required? - Correct answer - With out undue delay
Only if this results in a HIGH risk to the rights and subjects of natural persons 4% or 20M Euros - Correct answer Tier 1 o violation ofConsent, Access, Purposes of Processing are the MOST SEVERE o keeping data subject from exercising his/her rights o international data transfer protocol violation 2% or 10M Euros - Correct answer Tier 2