Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 53 pages
Exam (elaborations)

FULL CIPP-E EXAM 2026 -LATEST QUESTIONS WITH VERIFIED SOLUTIONS

Document preview thumbnail
Preview 4 out of 53 pages

FULL CIPP-E EXAM 2026 -LATEST QUESTIONS WITH VERIFIED SOLUTIONS

Content preview

1|Page



FULL CIPP/E EXAM 2026-COMPLETE
EXAM SET WITH QUESTIONS AND
VERIFIED ANSWERS


Biometrics - correct-answer -Data concerning the *intrinsic physical or behavioral
characteristics* of an individual. Examples include *DNA, fingerprints, retina and
iris patterns, voice, face, handwriting, keystroke technique* and *gait*. The GDPR,
in Article 9, lists these for the purpose of uniquely identifying a natural person as a
special category of data for which processing is not allowed other than in specific
circumstances.




Bodily Privacy - correct-answer -One of the four classes of privacy, along with
information privacy, territorial privacy and communications privacy. It focuses on a
person's physical being and any invasion thereof. Such an invasion can take the
form of *genetic testing, drug testing* or *body cavity searches*.




Breach Disclosure (EU specific) - correct-answer -The requirement that a data
controller *notify regulators*, potentially within *72 hours* of discovery, and/or
victims, of incidents affecting the confidentiality and security of personal data,
depending on the assessed risks to the rights and freedoms of affected data
subjects.

,2|Page




Bundesdatenschutzgesetz-neu - correct-answer -*Germany's federal data
protection act*, implementing the GDPR. With the passage of the GDPR, it
replaced a previous law with the same name and enhanced a series of other acts
mainly in areas of law enforcement and intelligence services. Furthermore, the
*new version suggests a procedure* for national data protection authorities *to
challenge adequacy decisions* of the EU Commission.




CCTV - correct-answer -Has come to be shorthand for any video surveillance
system. *Originally*, such systems relied on coaxial cable and was truly *only
accessible on premise*. *Today*, most surveillance systems are *hosted via
TCP/IP networks* and can be *accessed remotely*, and the footage much more
*easily shared*, eliciting new and different privacy concerns.




Certification Mechanisms - correct-answer -Introduced by the GDPR, a *new valid
adequacy mechanism for* the *transfer* of personal data outside of the
European Union *in* the *absence of an adequacy decision* and instead of other
mechanisms such as binding corporate rules or contractual clauses. These *must
be developed by certifying bodies*, *approved by data protection authorities or
the EDPB* (European Data Protection Board), *and* have *a methodology for
auditing* compliance. Similar to binding corporate rules, they compel
organizations to be able to demonstrate their compliance with all aspects of
applicable data protection legislation.

,3|Page


Charter of Fundamental Rights - correct-answer -A treaty that consolidates human
rights within the EU. The treaty states that *everyone has a right to protect their
personal data*, that *data must be processed for legitimate and specified
purposes* and that *compliance is subject to control by an authority*.




Choice - correct-answer -In the context of consent, this refers to the idea that
consent must be freely given and that data subjects must have a *genuine
____________* as to whether to provide personal data or not. If this is not truly
given it is unlikely the consent will be deemed valid under the GDPR.




Cloud Computing - correct-answer -The provision of information technology
services over the Internet. These services may be provided by a company for its
internal users in private or by third-party suppliers. The *services can include
software, infrastructure (i.e., servers), hosting and platforms (i.e., operating
systems)*. Has numerous applications, from personal webmail to corporate data
storage, and can be subdivided into different types of service models.




Codes of Conduct - correct-answer -Introduced by the GDPR, these are a new
valid adequacy mechanism for the transfer of personal data outside of the
European Union in the absence of an adequacy decision and instead of other
mechanisms such as binding corporate rules or contractual clauses. these must be
*developed by industry trade groups, associations or other bodies* representing
categories of controllers or processors. They *must be approved by supervisory
authorities or the European Data Protection Board*, and have a methodology for
auditing compliance. Similar to binding corporate rules, they compel organizations

, 4|Page


to be able to demonstrate their compliance with all aspects of applicable data
protection legislation.




Collection Limitation - correct-answer -A *fair information practices* principle, it
is the principle stating *there should be limits to* the *collection* of personal
data, that any such *data should be obtained by lawful and fair means and*,
where appropriate, *with* the knowledge or consent* of the data subject.




Communications Privacy - correct-answer -One of the four classes of privacy,
along with information privacy, bodily privacy and territorial privacy. It
encompasses protection of the means of correspondence, including *postal mail,
telephone conversations, electronic e-mail* and *other forms of communicative
behavior and apparatus*.




Confidentiality - correct-answer -Data is this if it is *protected against
unauthorised or unlawful* processing. The GDPR requires that an organization be
able to ensure the ongoing confidentiality, integrity, availability and resilience of
processing systems and services as part of its requirements for appropriate
security. In addition, the GDPR requires that *persons authorised to process* the
personal data *have committed* themselves *to confidentiality* or are under an
appropriate statutory obligation of this.




Consent (EU specific) - correct-answer -This privacy requirement is one of the
*fair information practices*. In the GDPR, however, it is specifically one of the

Document information

Uploaded on
May 12, 2026
Number of pages
53
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
DRVERITY
3.8
(13)
Sold
112
Followers
0
Items
8721
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions