Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 14 pages
Exam (elaborations)

CIPP/E Exam Questions and Answers | Detailed Explanations and Full Rationales | Grade A+

Document preview thumbnail
Preview 2 out of 14 pages

CIPP/E Exam Questions and Answers | Detailed Explanations and Full Rationales | Grade A+

Content preview

CIPP/E Exam Questions and Answers | Detailed
Explanations and Full Rationales | Grade A+
• What is the one major goal that the OECD Guidelinges, Convention 108, and the
Directive all had in common but largely failed to achieve in Europe? -✓✓The
restriction of cross-border data flow

• Which EU institution is vested with the competence to propose new data
protection legislation on its own initiative? -✓✓Commission

• Which institution has the power to adopt findings that confirm the adequacy of
the data protection level in a non-EU country? -✓✓European Commission

• What type of data lies beyond the scope of the GDPR? -✓✓Anonymised

• What is the consequence if a processor makes an independent decision regarding
the purposes and means of processing it carries out on behalf of a controller? -
✓✓The processor will be considered to be a controller

• With the issue of consent, the GDPR allows member states some choice
regarding what? -✓✓The age which children must be required to obtain parental
consent

• Which sentence BEST summarizes the concepts of Fairness, lawfullness, and
transparency, as expressly required by Article 5 of the GDPR? -✓✓Fairness and
transparency refer to the communication of key information before collecting data;
lawfulness refers to compliance with government regulations

• Assuming that the "without undue delay" provison is followed, what is the time
limit for complying with a data access request? -✓✓1 month + additional 2 months

• Company X has entrusted the processing of their payroll data provider to Y.
Provider Y stores this encrypted data on its server. The IT department of Provider
Y finds out that someone managed to hack into the system and take a copy of the
data from its server. In this scenario, whom does Provider Y have the obligation to
notify? -✓✓Company X

, • Which of the following would require designationg a data protection officer? -
✓✓The core activites of the controller or processor consist of processing
operations that require systematic monitoring of data subjects on a large scale.
(public authority or large scal sensitive data would apply as well)

• When is a data sharing agreement MOST likely to be needed? -✓✓When
personal data is being shared between commercial orgs acting as joint data
controllers

• An employee of company X has just noticed a memory stick containing records
of client data, including their names, addresses and full contact details has
disappeared. The data on the stick is unencrypted and in clear text. It is uncertain
what has happened to the stick as this stage, but it likely was lost during the travel
of an employee. What should the company do? -✓✓Notify as soon as possible the
data protection supervisory authority that a data breach may have taken place

• The GDPR specifies fines that may be levied against data controllers for certain
infringements. Which of the following infringements would be subject to the less
severe administrative fine of up to 10 million Euros? -✓✓Failure to implement
technical and organisational measures to ensure data protection is enshrined by
design and default

• Why is it advisable to avoid consent as a legal basis for an employer to process
employee data? -✓✓Consent may not be valid if the employee feels compelled to
provide it

• What is true about an employee who makes an access request to his employer for
any personal data held about him? -✓✓The employer must supply all the
information held about the employee unless there is an exemption

• Discover which employees are accessing cloud services and from which devices
and apps
Lock down the data in those apps and devices
Monitor and analyse the apps and devices for compliance
Manage application life cycles
Monitor data sharing

An organisation should perform these steps to do which of the following? -
✓✓Maintain a secure BYOD program

Document information

Uploaded on
April 27, 2026
Number of pages
14
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$12.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PACKPASS
3.5
(6)
Sold
50
Followers
1
Items
7271
Last sold
6 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions