[2024] Easy To Download CIPP-E Actual Exam Dumps Resources [Q141-Q160]

Share

[2024] Easy To Download CIPP-E Actual Exam Dumps Resources

Uplift Your CIPP-E Exam Marks With The Help of CIPP-E Dumps


What are the Problems of IAPP CIPP/E Exam

Candidates face many problems when they start preparing for the IAPP CIPP/E Exam. If a candidate wants to prepare his for the IAPP CIPP/E Exam without any problem and get good grades in the exam. Then they have to choose the best IAPP CIPP/E Exam exam dumps for real exam questions practice. There are many websites that are offering the latest IAPP CIPP/E Exam questions and answers but these questions are not verified by IAPP certified experts and that's why many are failed in their just first attempt. PrepAway is the best platform which provides the candidate with the necessary IAPP 63 questions that will help him to pass the IAPP CIPP/E Exam on the first time. The candidate will not have to take the IAPP CIPP/E Exam twice because with the help of IAPP CIPP/E Exam exam dumps the Candidate will have every valuable material required to pass the IAPP CIPP/E Exam. We are providing the latest and actual questions and that is the reason why this is the one that he needs to use and there are no chances to fail when a candidate will have valid braindumps from PrepAway. We have the guarantee that the questions that we have will be the ones that will pass candidate in the IAPP CIPP/E Exam in the very first attempt.

 

NEW QUESTION # 141
Under Article 58 of the GDPR, which of the following describes a power of supervisory authorities in European Union (EU) member states?

  • A. The ability to enact new laws by executive order.
  • B. The right to access data for investigative purposes.
  • C. The authority to select penalties when a controller is found guilty in a court of law.
  • D. The discretion to carry out goals of elected officials within the member state.

Answer: B


NEW QUESTION # 142
There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?

  • A. Consent management and withdrawal.
  • B. Preventative security.
  • C. Incident detection and response.
  • D. Remedial security.

Answer: A

Explanation:
A) Consent management and withdrawal. Comprehensive Explanation: Article 32 of the GDPR requires the controller and the processor to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of the processing. These measures should take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons. The three domains of security covered by Article 32 are:
Preventative security: This refers to the measures that aim to prevent or reduce the likelihood of security incidents, such as unauthorized or unlawful access, disclosure, alteration, loss or destruction of personal data. Examples of preventative security measures include encryption, pseudonymization, access control, firewalls, antivirus software, etc.
Incident detection and response: This refers to the measures that aim to detect, analyze, contain, eradicate and recover from security incidents, as well as to notify the relevant authorities and data subjects, and to document the facts and actions taken. Examples of incident detection and response measures include security monitoring, logging, auditing, incident response plans, breach notification procedures, etc.
Remedial security: This refers to the measures that aim to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident, as well as to mitigate the adverse effects of security incidents on the data subjects. Examples of remedial security measures include backup, disaster recovery, business continuity, compensation, etc.
Consent management and withdrawal is not a domain of security covered by Article 32, but rather a requirement for the lawfulness of processing based on consent under Article 6(1)(a) and Article 7 of the GDPR. Consent management and withdrawal involves obtaining, recording, updating and revoking the consent of data subjects for specific purposes of processing, as well as informing them of their right to withdraw their consent at any time. Reference: Free CIPP/E Study Guide, page 35; CIPP/E Certification, page 17; GDPR, Article 32, Article 6(1)(a), Article 7.


NEW QUESTION # 143
Which of the following was the first to implement national law for data protection in 1973?

  • A. Sweden
  • B. France
  • C. United Kingdom
  • D. Germany

Answer: A

Explanation:
Reference:
Sweden was the first country to enact a national data protection law in 1973, called the Data Act. It went into effect on 1 July 1974 and required licenses by the Swedish Data Protection Authority for information systems handling personal data. The law was a result of public concern about the use of computers and the potential abuse of personal data by the government and other entities. The law was later superseded by the Personal Data Act in 1998, which implemented the EU Data Protection Directive. Reference: Data Act (Sweden) - Wikipedia, Data Privacy Act: A Brief History of Modern Data Privacy Laws - eperi, Swedish Authority for Privacy Protection - Wikipedia Learn more
1en.wikipedia.org2blog.eperi.c


NEW QUESTION # 144
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?

  • A. When the controller is required to have a Data Protection Officer.
  • B. When personal data is being transferred outside of the EEA.
  • C. When personal data is being collected and combined with other personal data to profile the creditworthiness of individuals.
  • D. When the controller is collecting email addresses from individuals via an online registration form for marketing purposes.

Answer: C

Explanation:
According to the GDPR, a data protection impact assessment (DPIA) is a process to help identify and minimize the data protection risks of a project. A DPIA is required when the processing is likely to result in a high risk to the rights and freedoms of natural persons, taking into account the nature, scope, context and purposes of the processing. The GDPR provides a list of examples of processing operations that require a DPIA, such as:
Systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person.
Processing on a large scale of special categories of data or of personal data relating to criminal convictions and offences.
Systematic monitoring of a publicly accessible area on a large scale.
Therefore, an example of a scenario where a controller is most likely required to undertake a DPIA is when personal data is being collected and combined with other personal data to profile the creditworthiness of individuals, as this involves a systematic and extensive evaluation of personal aspects based on automated processing and profiling, and may have significant effects on the individuals. The other scenarios are not necessarily indicative of a high risk to the rights and freedoms of natural persons, and do not fall under the examples of processing operations that require a DPIA provided by the GDPR. Reference: Free CIPP/E Study Guide, page 37; CIPP/E Certification, page 18; GDPR, Article 35, Recital 91.
Reference:
%20the%20General,and%20freedoms%20of%20natural%20persons%27.


NEW QUESTION # 145
Which of the following is NOT an explicit right granted to data subjects under the GDPR?

  • A. The right to request the deletion of data a controller holds about them.
  • B. The right to request restriction of processing of personal data, under certain scenarios.
  • C. The right to request access to the personal data a controller holds about them.
  • D. The right to opt-out of the sale of their personal data to third parties.

Answer: C

Explanation:
Reference https://www.i-scoop.eu/gdpr/data-subject-rights-gdpr/


NEW QUESTION # 146
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
* Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
* Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
* Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees.
These records are available to former students after registering through Granchester's Alumni portal.
* Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
* Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level.
Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Anna will find that a risk analysis is NOT necessary in this situation as long as?

  • A. The processing will not negatively affect the rights of the data subjects
  • B. The data subjects gave their unambiguous consent for the original processing
  • C. The data subjects are no longer current students of Frank's
  • D. The algorithms that Frank uses for the processing are technologically sound

Answer: B


NEW QUESTION # 147
Two companies, Gellcoat and Freifish, make plans to launch a co-branded product the prototype of which is called Gellifish 9090. The companies want to organize an event to introduce the new product, so they decide to share data from their client databases and come up with a list of people to invite. They agree on the content of the invitations and together build an app to gather feedback at the event.
In this scenario, Gellcoat and Freifish are considered to be?

  • A. Separate controllers because pint controllers^ requires a written designation in a contract
  • B. Joint controllers with respect to the personal data related to the event and separate controllers for their other purposes.
  • C. Separate controllers and processors since they are each providing services to the other
  • D. Joint controllers for all purposes because they have merged their databases and their data is now jointly owned.

Answer: B


NEW QUESTION # 148
In the wake of the Schrems II ruling, which of the following actions has been recommended by the EDPB for companies transferring personal data to third countries?

  • A. Ensuring that all data transfers are encrypted with unbreakable encryption algorithms.
  • B. Obtaining explicit consent from each EU citizen for every individual data transfer.
  • C. Storing all personal data within the borders of the European Union.
  • D. Adopting a risk-based approach and implementing supplementary measures as needed.

Answer: D


NEW QUESTION # 149
An organisation receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal dat a. Under what condition can the organisation charge the data subject for processing the request?

  • A. Only where the organisation can show that it is reasonable to do so because more than one request was made.
  • B. Only to the extent this is allowed under the restrictions on data subjects' rights introduced under Art 23 of GDPR.
  • C. Only where the administrative costs of taking the action requested exceeds a certain threshold.
  • D. Only if the organisation can demonstrate that the request is clearly excessive or misguided.

Answer: D


NEW QUESTION # 150
According to Article 84 of the GDPR, the rules on penalties applicable to infringements shall be laid down by?

  • A. The local Data Protection Supervisory Authorities.
  • B. The EU Commission.
  • C. The European Data Protection Board.
  • D. The Member States.

Answer: D

Explanation:
Reference https://gdpr-text.com/read/article-84/


NEW QUESTION # 151
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze's headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
Which of the following is T-Craze's lead supervisory authority?

  • A. Germany, because that is where T-Craze is headquartered.
  • B. France, because that is where T-Craze conducts processing of personal information.
  • C. Spain, because that is T-Craze's primary market based on its marketing campaigns.
  • D. T-Craze may choose its lead supervisory authority where any of its affiliates are based, because it has presence in several European countries.

Answer: D


NEW QUESTION # 152
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?

  • A. Categories of recipients to whom the personal data have been disclosed.
  • B. Incidents of personal data breaches, whether disclosed or not.
  • C. Retention periods for erasure and deletion of categories of personal data.
  • D. Data inventory or data mapping exercises that have been conducted.

Answer: C

Explanation:
Section: (none)


NEW QUESTION # 153
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B.
Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
* Name
* Address
* Date of Birth
* Payroll number
* National Insurance number
* Sick pay entitlement
* Maternity/paternity pay entitlement
* Holiday entitlement
* Pension and benefits contributions
* Trade union contributions
Jenny is the compliance officer at Company A.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their failure to provide sufficient security safeguards to Company A's data.
  • B. Their omission of data protection provisions in their contract with Company C.
  • C. Their engagement of Company C to improve their payroll service.
  • D. Their decision to operate without a data protection officer.

Answer: C


NEW QUESTION # 154
Under the GDPR, who would be LEAST likely to be allowed to engage in the collection, use, and disclosure of a data subject's sensitive medical information without the data subject's knowledge or consent?

  • A. A journalist writing an article relating to the medical condition in question, who believes that the publication of such information is in the public interest.
  • B. A health professional involved in the medical care for the data subject, where the data subject's life hinges on the timely dissemination of such information.
  • C. A public authority responsible for public health, where the sharing of such information is considered necessary for the protection of the general populace.
  • D. A member of the judiciary involved in adjudicating a legal dispute involving the data subject and concerning the health of the data subject.

Answer: C

Explanation:
Explanation/Reference: https://www.eui.eu/Documents/ServicesAdmin/DeanOfStudies/ResearchEthics/Guide-Data- Protection-Research.pdf


NEW QUESTION # 155
In relation to third countries and international organizations, which of the following shall, along with the supervisory authorities, take appropriate steps to develop international cooperation mechanisms for the enforcement of data protection legislation?

  • A. The designated Data Protection Officers
  • B. The European Commission
  • C. The European Parliament
  • D. The Council of the European Union.

Answer: A


NEW QUESTION # 156
SCENARIO
Please use the following to answer the next question:
Jason, a long-time customer of ABC insurance, was involved in a minor car accident a few months ago.
Although no one was hurt, Jason has been plagued by texts and calls from a company called Erbium Insurance offering to help him recover compensation for personal injury. Jason has heard about insurance companies selling customers' data to third parties, and he's convinced that Erbium must have gotten his information from ABC.
Jason has also been receiving an increased amount of marketing information from ABC, trying to sell him their full range of their insurance policies.
Perturbed by this, Jason has started looking at price comparison sites on the Internet and has been shocked to find that other insurers offer much cheaper rates than ABC, even though he has been a loyal customer for many years. When his ABC policy comes up for renewal, he decides to switch to Xentron Insurance.
In order to activate his new insurance policy, Jason needs to supply Xentron with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask ABC to transfer his information directly to Xentron. He also takes this opportunity to ask ABC to stop using his personal data for marketing purposes.
ABC supplies Jason with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Jason it cannot transfer his data directly to Xentron at this is not technically feasible. ABC also explains that Jason's contract included a provision whereby Jason agreed that his data could be used for marketing purposes; according to ABC, it is too late for Jason to change his mind about this. It angers Jason when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Jason is still receiving unwanted calls from Erbium Insurance. He writes to Erbium to ask for the name of the organization that supplied his details to them. He warns Erbium that he plans to complain to the data protection authority because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Erbium's response letter confirms Jason's suspicions. Erbium is ABC's wholly owned subsidiary, and they received information about Jason's accident from ABC shortly after Jason submitted his accident claim.
Erbium assures Jason that there has been no breach of the GDPR, as Jason's contract included a provision in which he agreed to share his information with ABC's affiliates for business purposes.
Jason is disgusted by the way in which he has been treated by ABC, and writes to them insisting that all his information be erased from their computer system.
Which statement accurately summarizes ABC's obligation in regard to Jason's data portability request?

  • A. ABC does not have to transfer Jason's data to Xentron because the right to data portability does not apply where personal data are processed in order to carry out tasks in the public interest.
  • B. ABC has failed to comply with the duty to transfer Jason's data to Xentron because it has an obligation to develop commonly used, machine-readable and interoperable formats so that all customer data can be ported to other insurers on request.
  • C. ABC has failed to comply with the duty to transfer Jason's data to Xentron because the duty applies wherever personal data are processed by automated means and necessary for the performance of a contract with the customer.
  • D. ABC does not have a duty to transfer Jason's data to Xentron if doing so is legitimately not technically feasible.

Answer: A


NEW QUESTION # 157
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canad a. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
Who-R-U is NOT required to notify the local German DPA about the laptop theft because?

  • A. The company isn't a controller established in the Union.
  • B. The data isn't considered personally identifiable financial information.
  • C. There is no evidence that the thieves have accessed the data on the laptop.
  • D. The laptop belonged to a company located in Canada.

Answer: A

Explanation:
According to the GDPR, a data breach must be notified to the supervisory authority of the member state where the controller or processor is established, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons1. The GDPR defines a controller as "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data"2. The GDPR also specifies that a controller or processor is considered to be established in the Union if it has "an effective and real exercise of activity through stable arrangements" in the Union, regardless of its legal form or location of its headquarters3.
In this scenario, Who-R-U is not a controller established in the Union, because it does not have any stable arrangements in the Union that involve the processing of personal data. The company only offers its services to Canadians, and does not target or monitor individuals in the Union. The fact that it has purchased the naming rights for a building in Germany, which comes with a few offices, does not constitute an effective and real exercise of activity in the Union, as the offices do not include any technology or infrastructure for processing personal data, and are only used by executives while traveling internationally. Therefore, Who-R-U is not subject to the GDPR's data breach notification obligation, and is not required to notify the local German DPA about the laptop theft.
Reference:
Art. 33 GDPR - Notification of a personal data breach to the supervisory authority Art. 4 GDPR - Definitions Art. 3 GDPR - Territorial scope Guidelines 9/2022 on personal data breach notification under GDPR Guidelines 3/2018 on the territorial scope of the GDPR I hope this helps you understand the GDPR and data breach notification better. If you have any other questions, please feel free to ask me.


NEW QUESTION # 158
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data on the stick is unencrypted and in clear text. It is uncertain what has happened to the stick at this stage, but it likely was lost during the travel of an employee. What should the company do?

  • A. Launch an investigation and if nothing is found within one month, notify the data protection supervisory authority.
  • B. Notify as soon as possible the data protection supervisory authority that a data breach may have taken place.
  • C. Immediately notify all the customers of the company that their information has been accessed by an unauthorized person.
  • D. Invoke the "disproportionate effort" exception under Article 33 to postpone notifying data subjects until more information can be gathered.

Answer: B

Explanation:
The GDPR requires that in the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons1. A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed2. In this scenario, the company ABCD is the controller of the client data, and the loss of the memory stick containing unencrypted and clear text personal data is a personal data breach that may pose a risk to the rights and freedoms of the data subjects, such as identity theft, fraud, financial loss, or reputational damage. Therefore, the company ABCD should notify the data protection supervisory authority as soon as possible, and provide the information specified in Article 33(3) of the GDPR, such as the nature of the breach, the categories and number of data subjects and personal data records concerned, the likely consequences of the breach, and the measures taken or proposed to address the breach1. Option A is the correct answer, as it reflects the obligation of the controller under the GDPR. Options B, C and D are incorrect, as they do not comply with the GDPR requirements. Option B would delay the notification beyond the 72-hour deadline, which could result in administrative fines or other sanctions3. Option C would misuse the "disproportionate effort" exception, which only applies to the communication of the breach to the data subjects, not to the notification to the supervisory authority, and only when the controller has implemented appropriate technical and organisational protection measures, such as encryption, that render the personal data unintelligible to any person who is not authorised to access it4. Option D would prematurely notify the customers of the company without first notifying the supervisory authority, and without assessing the level of risk and the necessity of such communication, which should be done in consultation with the supervisory authority5. Reference: 1: Article 33(1) of the GDPR 2: Article 4(12) of the GDPR 3: Article 83(4)(a) of the GDPR 4: Article 34(3)(a) of the GDPR 5: Article 34(1) and (2) of the GDPR


NEW QUESTION # 159
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?

  • A. Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.
  • B. Categories of processing carried out on behalf of each controller for which the processor is acting.
  • C. Name and contact details of each controller on behalf of which the processor is acting.
  • D. Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.

Answer: D

Explanation:
Explanation/Reference: https://gdpr-info.eu/art-30-gdpr/


NEW QUESTION # 160
......

Use IAPP CIPP-E Dumps To Succeed Instantly in CIPP-E Exam: https://prepaway.testkingpdf.com/CIPP-E-testking-pdf-torrent.html