
Best Preparations of CIPP-C Exam 2021 Certified Information Privacy Professional Unlimited 180 Questions
Focus on CIPP-C All-in-One Exam Guide For Quick Preparation.
NEW QUESTION 44
How is the GDPR's position on consent MOST likely to affect future app design and implementation?
- A. Users will see fewer advertisements when using apps.
- B. App developers will expand the amount of data necessary to collect for an app's functionality.
- C. App developers' responsibilities as data controllers will increase.
- D. Users will be given granular types of consent for particular types of processing.
Answer: D
NEW QUESTION 45
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?
- A. Cross-border processing
- B. Special categories of data
- C. Data access disputes
- D. Data subject rights
Answer: A
NEW QUESTION 46
Article 29 Working Party has emphasized that the GDPR forbids "forum shopping", which occurs when companies do what?
- A. Choose the data protection officer that is most sympathetic to their business concerns.
- B. Select third-party processors on the basis of cost rather than quality of privacy protection.
- C. File appeals of infringement judgments with more than one EU institution simultaneously.
- D. Designate their main establishment in member state with the most flexible practices.
Answer: D
NEW QUESTION 47
SCENARIO
Please use the following to answer the next QUESTION:
Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has become a grand event. It fills one of the large downtown conference hotels and overflows into the others, with several thousand attendees enjoying three days of presentations, panel discussions and networking. The convention is the centerpiece of the company's product rollout schedule and a great training opportunity for current users. The sales force also encourages prospective clients to attend to get a better sense of the ways in which the system can be customized to meet diverse needs and understand that when they buy into this system, they are joining a community that feels like family.
This year's conference is only three weeks away, and you have just heard news of a new initiative supporting it: a smartphone app for attendees. The app will support late registration, highlight the featured presentations and provide a mobile version of the conference program. It also links to a restaurant reservation system with the best cuisine in the areas featured. "It's going to be great," the developer, Deidre Hoffman, tells you, "if, that is, we actually get it working!" She laughs nervously but explains that because of the tight time frame she'd been given to build the app, she outsourced the job to a local firm. "It's just three young people," she says, "but they do great work." She describes some of the other apps they have built. When asked how they were selected for this job, Deidre shrugs. "They do good work, so I chose them." Deidre is a terrific employee with a strong track record. That's why she's been charged to deliver this rushed project. You're sure she has the best interests of the company at heart, and you don't doubt that she's under pressure to meet a deadline that cannot be pushed back. However, you have concerns about the app's handling of personal data and its security safeguards. Over lunch in the break room, you start to talk to her about it, but she quickly tries to reassure you, "I'm sure with your help we can fix any security issues if we have to, but I doubt there'll be any. These people build apps for a living, and they know what they're doing. You worry too much, but that's why you're so good at your job!" You want to point out that normal protocols have not been followed in this matter. Which process in particular has been neglected?
- A. Vendor due diligence or vetting
- B. Privacy breach prevention
- C. Forensic inquiry
- D. Data mapping
Answer: A
NEW QUESTION 48
A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if it imports personal data from another organization in the European Economic Area (EEA) under standard contractual clauses?
- A. Submit the contract to its own government authority.
- B. Ensure that local laws do not impede the company from meeting its contractual obligations.
- C. Supply any information requested by a data protection authority (DPA) within 30 days.
- D. Ensure that notice is given to and consent is obtained from data subjects.
Answer: A
NEW QUESTION 49
A company is hesitating between Binding Corporate Rules and Standard Contractual Clauses as a global data transfer solution. Which of the following statements would help the company make an effective decision?
- A. Binding Corporate Rules provide a global solution for all the entities of a company that are bound by the intra-group agreement.
- B. The company will need the prior authorization of all EU data protection authorities for concluding Standard Contractual Clauses.
- C. Binding Corporate Rules are especially recommended for small and medium companies.
- D. The data exporter does not need to be located in the EU for the standard Contractual Clauses.
Answer: A
NEW QUESTION 50
SCENARIO
Please use the following to answer the next question:
Dynaroux Fashion ('Dynaroux') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux's business plan and associated processing activities.
Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?
- A. The company plans to undertake profiling of its customers through analysis of their purchasing patterns.
- B. The company intends to shift their business model to rely more heavily on online shopping.
- C. The company will be undertaking processing activities involving sensitive data categories such as financial and children's data.
- D. The company employs approximately 650 people and will therefore be carrying out extensive processing activities.
Answer: A
NEW QUESTION 51
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
- A. The type of security safeguards used to protect the data.
- B. The measures being taken to address the breach.
- C. The contact details of the appropriate data protection officer.
- D. The predicted consequences of the breach.
Answer: C
NEW QUESTION 52
A law enforcement subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?
- A. SCA
- B. ECPA
- C. CALEA
- D. USA Freedom Act
Answer: C
NEW QUESTION 53
SCENARIO
Please use the following to answer the next question:
WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:
"WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the data. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information.
We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."
"We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."
"We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities." What must the contract between WonderKids and the hosting service provider contain?
- A. A non-disclosure agreement.
- B. Controller-to-controller model contract clauses.
- C. Audit rights for the data subjects.
- D. The requirement to implement technical and organizational measures to protect the data.
Answer: D
NEW QUESTION 54
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
- A. Data inventory or data mapping exercises that have been conducted.
- B. Retention periods for erasure and deletion of categories of personal data.
- C. Incidents of personal data breaches, whether disclosed or not.
- D. Categories of recipients to whom the personal data have been disclosed.
Answer: B
NEW QUESTION 55
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location.
During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
In addition to notifying employees about the purpose of the monitoring, the potential uses of their data and their privacy rights, what information should Building Block have provided them before implementing the security measures?
- A. Information about how providing consent could affect them as employees.
- B. Information about what is specified in the employment contract.
- C. Information about who employees should contact with any queries.
- D. Information about how the measures are in the best interests of the company.
Answer: B
NEW QUESTION 56
If a company is planning to use closed-circuit television (CCTV) on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?
- A. Ensure that safeguards are in place to prevent unauthorized access to the footage.
- B. Perform a data protection impact assessment (DPIA).
- C. Notify the appropriate data protection authority.
- D. Create an information retention policy for those who operate the system.
Answer: D
NEW QUESTION 57
Article 5(1)(b) of the GDPR states that personal data must be "collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes." Based on Article 5(1)(b), what is the impact of a member state's interpretation of the word "incompatible"?
- A. It dictates the level of security a processor must follow when using and storing personal data for two different purposes.
- B. It sets the standard for the level of detail a controller must record when documenting the purpose for collecting personal data.
- C. It guides the courts on the severity of the consequences for those who are convicted of the intentional misuse of personal data.
- D. It indicates the degree of flexibility a controller has in using personal data in ways that may vary from its original intended purpose.
Answer: A
NEW QUESTION 58
What was the aim of the European Data Protection Directive 95/46/EC?
- A. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.
- B. To harmonize the implementation of the European Convention of Human Rights across all member states.
- C. To completely prevent the transfer of personal data out of the European Union.
- D. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.
Answer: A
NEW QUESTION 59
What term BEST describes the European model for data protection?
- A. Sectoral
- B. Comprehensive
- C. Self-regulatory
- D. Market-based
Answer: A
NEW QUESTION 60
What obligation does a data controller or processor have after appointing a data protection officer?
- A. To provide resources necessary to carry out the defined tasks of the data protection officer and to maintain his or her expert knowledge.
- B. To ensure that the data protection officer receives sufficient instructions regarding the exercise of his or her defined tasks.
- C. To submit for approval to the data protection officer a code of conduct to govern organizational practices and demonstrate compliance with data protection principles.
- D. To ensure that the data protection officer acts as the sole point of contact for individuals' Questions:
about their personal data.
Answer: C
NEW QUESTION 61
What practice does the USA FREEDOM Act NOT authorize?
- A. An extension of the expiration for roving wiretaps
- B. An increase in the maximum penalty for material support to terrorism
- C. The bulk collection of telephone data and internet metadata
- D. Emergency exceptions that allows the government to target roamers
Answer: D
NEW QUESTION 62
Which of the following is an example of direct marketing that would be subject to European data protection laws?
- A. A revision of contract terms conveyed to an individual by SMS from a marketing organization.
- B. An updated privacy notice sent to an individual's personal email address.
- C. A charity fundraising event notice sent to an individual at her business address.
- D. A service outage notification provided to an individual by recorded telephone message.
Answer: C
NEW QUESTION 63
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations.
TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?
- A. The sensitivity of the categories of data involved in the incident was not substantial enough.
- B. The resulting obligation to notify data subjects would involve disproportionate effort.
- C. The incident resulted from the actions of a third-party that were beyond their control.
- D. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
Answer: C
NEW QUESTION 64
SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years.
Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles.
Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Based on current trends in European privacy practices, which aspect of Brady Box' Online Behavioral Advertising (OBA) is most likely to be insufficient if the company becomes established in Europe?
- A. The level of security within the website.
- B. The contract with the third-party advertising network.
- C. The need to have the contents of the advertising approved.
- D. The lack of the option to opt in.
Answer: D
NEW QUESTION 65
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?
- A. If the company limits the footage to data subjects solely of legal age.
- B. If obtaining consent is deemed voluntary by local legislation.
- C. If the company's status as a documentary provider allows it to claim legitimate interest.
- D. If obtaining consent is deemed to involve disproportionate effort.
Answer: B
NEW QUESTION 66
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?
- A. The data subject already has information regarding how his data will be used
- B. Third-party data would be disclosed by providing such information to the data subject
- C. The processing of the data subject's data is protected by appropriate technical measures
- D. The provision of such information to the data subject would be too problematic
Answer: A
NEW QUESTION 67
......
Guaranteed Success with CIPP-C Dumps: https://www.testinsides.top/CIPP-C-dumps-review.html
Pass IAPP CIPP-C Exam – Experts Are Here To Help You: https://drive.google.com/open?id=1hYVIzkJHzhpFKC2YVoXM9SiRoI8uV7T5