
Jan-2022 IAPP CIPP-C Actual Questions and 100% Cover Real Exam Questions
CIPP-C Free Exam Questions & Answers PDF Updated on Jan-2022
NEW QUESTION 96
Under Article 9 of the GDPR, which of the following categories of data is NOT expressly prohibited from data processing?
- A. Personal data revealing genetic data.
- B. Personal data revealing trade union membership.
- C. Personal data revealing financial data.
- D. Personal data revealing ethnic origin.
Answer: C
NEW QUESTION 97
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?
- A. Name and contact details of each controller on behalf of which the processor is acting.
- B. Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.
- C. Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.
- D. Categories of processing carried out on behalf of each controller for which the processor is acting.
Answer: B
NEW QUESTION 98
What obligation does a data controller or processor have after appointing a data protection officer?
- A. To provide resources necessary to carry out the defined tasks of the data protection officer and to maintain his or her expert knowledge.
- B. To ensure that the data protection officer acts as the sole point of contact for individuals' Questions:
about their personal data. - C. To submit for approval to the data protection officer a code of conduct to govern organizational practices and demonstrate compliance with data protection principles.
- D. To ensure that the data protection officer receives sufficient instructions regarding the exercise of his or her defined tasks.
Answer: C
NEW QUESTION 99
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?
- A. The Council of the European Union.
- B. Approved data controllers.
- C. National data protection authorities.
- D. The European Data Protection Supervisor.
Answer: B
NEW QUESTION 100
SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years.
Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles.
Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Based on current trends in European privacy practices, which aspect of Brady Box' Online Behavioral Advertising (OBA) is most likely to be insufficient if the company becomes established in Europe?
- A. The need to have the contents of the advertising approved.
- B. The contract with the third-party advertising network.
- C. The lack of the option to opt in.
- D. The level of security within the website.
Answer: C
NEW QUESTION 101
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations.
TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?
- A. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
- B. The sensitivity of the categories of data involved in the incident was not substantial enough.
- C. The incident resulted from the actions of a third-party that were beyond their control.
- D. The resulting obligation to notify data subjects would involve disproportionate effort.
Answer: C
NEW QUESTION 102
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?
- A. The processor will be liable to pay compensation to affected data subjects
- B. The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved
- C. The processor will be considered to be a controller in respect of the processing concerned
- D. The controller will be liable to pay an administrative fine
Answer: A
NEW QUESTION 103
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Why would the consent provided by Ms. Iman NOT be considered valid in regard to JaphSoft?
- A. She only viewed the visual representations of the privacy notice Liem provided.
- B. She was not told which controller would be processing her personal data.
- C. She did not read the privacy notice stating that her personal data would be shared.
- D. She has never made any purchases from JaphSoft and has no relationship with the company.
Answer: C
NEW QUESTION 104
SCENARIO
Please use the following to answer the next QUESTION:
Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has become a grand event. It fills one of the large downtown conference hotels and overflows into the others, with several thousand attendees enjoying three days of presentations, panel discussions and networking. The convention is the centerpiece of the company's product rollout schedule and a great training opportunity for current users. The sales force also encourages prospective clients to attend to get a better sense of the ways in which the system can be customized to meet diverse needs and understand that when they buy into this system, they are joining a community that feels like family.
This year's conference is only three weeks away, and you have just heard news of a new initiative supporting it: a smartphone app for attendees. The app will support late registration, highlight the featured presentations and provide a mobile version of the conference program. It also links to a restaurant reservation system with the best cuisine in the areas featured. "It's going to be great," the developer, Deidre Hoffman, tells you, "if, that is, we actually get it working!" She laughs nervously but explains that because of the tight time frame she'd been given to build the app, she outsourced the job to a local firm. "It's just three young people," she says, "but they do great work." She describes some of the other apps they have built. When asked how they were selected for this job, Deidre shrugs. "They do good work, so I chose them." Deidre is a terrific employee with a strong track record. That's why she's been charged to deliver this rushed project. You're sure she has the best interests of the company at heart, and you don't doubt that she's under pressure to meet a deadline that cannot be pushed back. However, you have concerns about the app's handling of personal data and its security safeguards. Over lunch in the break room, you start to talk to her about it, but she quickly tries to reassure you, "I'm sure with your help we can fix any security issues if we have to, but I doubt there'll be any. These people build apps for a living, and they know what they're doing.
You worry too much, but that's why you're so good at your job!"
Which is the best first step in understanding the data security practices of a potential vendor?
- A. Examining investigation records of any breaches the vendor has experienced.
- B. Conducting a physical audit of the vendor's facilities.
- C. Requiring the vendor to complete a questionaire assessing International Organization for Standardization (ISO) 27001 compliance.
- D. Conducting a penetration test of the vendor's data security structure.
Answer: A
NEW QUESTION 105
Which GDPR requirement will present the most significant challenges for organizations with Bring Your Own Device (BYOD) programs?
- A. Processing of special categories of personal data on a large scale requires appointing a DPO.
- B. Data controllers must be in control of the data they hold at all times.
- C. Personal data of data subjects must always be accurate and kept up to date.
- D. Data subjects must be sufficiently informed of the purposes for which their personal data is processed.
Answer: B
NEW QUESTION 106
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location.
During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
In addition to notifying employees about the purpose of the monitoring, the potential uses of their data and their privacy rights, what information should Building Block have provided them before implementing the security measures?
- A. Information about how providing consent could affect them as employees.
- B. Information about who employees should contact with any queries.
- C. Information about how the measures are in the best interests of the company.
- D. Information about what is specified in the employment contract.
Answer: D
NEW QUESTION 107
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
- A. Data inventory or data mapping exercises that have been conducted.
- B. Categories of recipients to whom the personal data have been disclosed.
- C. Incidents of personal data breaches, whether disclosed or not.
- D. Retention periods for erasure and deletion of categories of personal data.
Answer: D
NEW QUESTION 108
A company is hesitating between Binding Corporate Rules and Standard Contractual Clauses as a global data transfer solution. Which of the following statements would help the company make an effective decision?
- A. The company will need the prior authorization of all EU data protection authorities for concluding Standard Contractual Clauses.
- B. Binding Corporate Rules are especially recommended for small and medium companies.
- C. The data exporter does not need to be located in the EU for the standard Contractual Clauses.
- D. Binding Corporate Rules provide a global solution for all the entities of a company that are bound by the intra-group agreement.
Answer: D
NEW QUESTION 109
Under the Data Protection Law Enforcement Directive of the EU, a government can carry out covert investigations involving personal data, as long it is set forth by law and constitutes a measure that is both necessary and what?
- A. Important.
- B. DPA-approved.
- C. Prudent.
- D. Proportionate.
Answer: D
NEW QUESTION 110
What must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?
- A. An obligation on the processor to assist the controller in complying with the controller's obligations to notify the supervisory authority about personal data breaches.
- B. An obligation on both parties to report any serious personal data breach to the supervisory authority.
- C. An obligation on both parties to agree to a termination of the agreement if the other party is responsible for a personal data breach.
- D. An obligation on the processor to report any personal data breach to the controller within 72 hours.
Answer: B
NEW QUESTION 111
Under Article 58 of the GDPR, which of the following describes a power of supervisory authorities in European Union (EU) member states?
- A. The discretion to carry out goals of elected officials within the member state.
- B. The ability to enact new laws by executive order.
- C. The right to access data for investigative purposes.
- D. The authority to select penalties when a controller is found guilty in a court of law.
Answer: C
NEW QUESTION 112
......
IAPP CIPP-C Real 2022 Braindumps Mock Exam Dumps: https://www.test4engine.com/CIPP-C_exam-latest-braindumps.html
Latest CIPP-C Exam Dumps Recently Updated 180 Questions: https://drive.google.com/open?id=1SYTGEPvrWg7W-GYDYaZs2sLFpOZZYQ8m