Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

IAPP CIPP-E - Certified Information Privacy Professional/Europe (CIPP/E)

Page: 1 / 9
Total 295 questions

SCENARIO

Please use the following to answer the next question:

Gentle Hedgehog Inc. is a privately owned website design agency incorporated in

Italy. The company has numerous remote workers in different EU countries. Recently,

the management of Gentle Hedgehog noticed a decrease in productivity of their sales

team, especially among remote workers. As a result, the company plans to implement

a robust but privacy-friendly remote surveillance system to prevent absenteeism,

reward top performers, and ensure the best quality of customer service when sales

people are interacting with customers.

Gentle Hedgehog eventually hires Sauron Eye Inc., a Chinese vendor of employee

surveillance software whose European headquarters is in Germany. Sauron Eye's

software provides powerful remote-monitoring capabilities, including 24/7 access to

computer cameras and microphones, screen captures, emails, website history, and

keystrokes. Any device can be remotely monitored from a central server that is

securely installed at Gentle Hedgehog headquarters. The monitoring is invisible by

default; however, a so-called Transparent Mode, which regularly and conspicuously

notifies all users about the monitoring and its precise scope, also exists. Additionally,

the monitored employees are required to use a built-in verification technology

involving facial recognition each time they log in.

All monitoring data, including the facial recognition data, is securely stored in Microsoft Azure cloud servers operated by Sauron Eye, which are physically located in France.

Under what condition could the surveillance system be used on the personal devices

of employees?

A.

Only if the monitoring system is manufactured by a European vendor storing the monitoring data within the EU.

B.

Only if the employees give valid consent and the monitoring is narrowly limited to their professional tasks.

C.

Only if the cloud that stores the monitoring data is certified by the EDPB as GDPR compliant.

D.

Only if the employer offers an adequate compensation for using the employee's devices.

Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?

A.

The right to privacy is an absolute right

B.

The right to privacy has to be balanced against other rights under the ECHR

C.

The right to freedom of expression under Article 10 of the ECHR will always override the right to privacy

D.

The right to privacy protects the right to hold opinions and to receive and impart ideas without interference

In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?

A.

Approved data controllers.

B.

The Council of the European Union.

C.

National data protection authorities.

D.

The European Data Protection Supervisor.

Pursuant to Article 4(5) of the GDPR, data is considered “pseudonymized” if?

A.

It cannot be attributed to a data subject without the use of additional information.

B.

It cannot be attributed to a person under any circumstances.

C.

It can only be attributed to a person by the controller.

D.

It can only be attributed to a person by a third party.

SCENARIO

Please use the following to answer the next question:

Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in

Greece (5), Italy (15) and Spain (1), have registered their most profitable results

ever. To celebrate this achievement, ARRA Hotels' Human Resources office, based

in ARRA's main Italian establishment, has organized a team event for its 420

employees and their families at its hotel in Spain.

Upon arrival at the hotel, each employee and family member is given an electronic

wristband at the reception desk. The wristband serves a number of functions:

. Allows access to the "party zone" of the hotel, and emits a buzz if the user

approaches any unauthorized areas

. Allows up to three free drinks for each person of legal age, and emits a

buzz once this limit has been reached

. Grants a unique ID number for participating in the games and contests that

have been planned.

Along with the wristband, each guest receives a QR code that leads to the online

privacy notice describing the use of the wristband. The page also contains an

unchecked consent checkbox. In the case of employee family members under the

age of 16, consent must be given by a parent.

Among the various activities planned for the event, ARRA Hotels' HR office has

autonomously set up a photocall area, separate from the main event venue, where

employees can come and have their pictures taken in traditional carnival costume.

The photos will be posted on ARRA Hotels' main website for general marketing

purposes.

On the night of the event, an employee from one of ARRA's Greek hotels is

displeased with the results of the photos in which he appears. He intends to file a

complaint with the relevant supervisory authority in regard to the following:

. The lack of any privacy notice in the separate photocall area

The unlawful cross-border processing of his personal data

. The unacceptable aesthetic outcome of his photos

Why would consent NOT be considered an adequate legal basis for accessing the

party zone?

A.

The consent is not completely unambiguous.

B.

The consent is not sufficiently informed.

C.

The consent is not freely given.

D.

The consent is not in writing.

In which of the following situations would an individual most likely to be able to withdraw her consent for processing?

A.

When she is leaving her bank and moving to another bank.

B.

When she has recently changed jobs and no longer works for the same company.

C.

When she disagrees with a diagnosis her doctor has recorded on her records.

D.

When she no longer wishes to be sent marketing materials from an organization.

A private company has establishments in France, Poland, the United Kingdom, and most prominently, Germany, where its headquarters is established. The company offers its services worldwide. Most of the services are designed in Germany and supported in the other establishments. However, one of the services, a Software as a Service (SaaS) application, was defined and implemented by the Polish establishment. It is also supported by the other establishments.

What is the lead supervisory authority for the SaaS service?

A.

The supervisory authority of Germany at the federal level.

B.

The supervisory authority of Germany at the regional level.

C.

The supervisory authority of the Republic of Poland.

D.

The supervisory authority of the European Union.

Under what circumstances might the “soft opt-in” rule apply in relation to direct marketing?

A.

When an individual has not consented to the marketing.

B.

When an individual’s details are obtained from their inquiries about buying a product.

C.

Where an individual’s details have been obtained from a bought-in marketing list.

D.

Where an individual is given the ability to unsubscribe from marketing emails sent to him.

What obligation does a data controller or processor have after appointing a data protection officer?

A.

To ensure that the data protection officer receives sufficient instructions regarding the exercise of his or her defined tasks.

B.

To provide resources necessary to carry out the defined tasks of the data protection officer and to maintain his or her expert knowledge.

C.

To ensure that the data protection officer acts as the sole point of contact for individuals’ Questions: about their personal data.

D.

To submit for approval to the data protection officer a code of conduct to govern organizational practices and demonstrate compliance with data protection principles.

Which of the following is an example of direct marketing that would be subject to European data protection laws?

A.

An updated privacy notice sent to an individual’s personal email address.

B.

A charity fundraising event notice sent to an individual at her business address.

C.

A service outage notification provided to an individual by recorded telephone message.

D.

A revision of contract terms conveyed to an individual by SMS from a marketing organization.