• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 20 pages
Exam (elaborations)

CIPP-E EXAM LATEST EXAM QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIFIED ANSWERS) |ALREADY GRADED A+

Document preview thumbnail
Preview 3 out of 20 pages

CIPP-E EXAM LATEST EXAM QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIFIED ANSWERS) |ALREADY GRADED A+ Accountability - Answer -A fair information practices principle, it is the idea that when personal information is to be transferred to another person or organization, the personal information controller should obtain the consent of the individual or exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with other fair use principles. Adequate Level of Protection - Answer -A label that the EU may apply to third-party countries who have committed to protect data through domestic law making or international commitments. Conferring of the label requires a proposal by the European Commission, an Article 29 Working Group Opinion, an opinion of the article 31 Management Committee, a right of scrutiny by the European Parliament and adoption by the European Commission. Adverse Action - Answer -Under the Fair Credit Reporting Act, the term "adverse action" is defined very broadly to include all business, credit and employment actions affecting consumers that can be considered to have a negative impact, such as denying or canceling credit or insurance, or denying employment or promotion. No adverse action occurs in a credit transaction where the creditor makes a counteroffer that is accepted by the consumer. Such an action requires that the decision maker furnish the recipient of the adverse action with a copy of the credit report leading to the adverse action. Annual Reports - Answer -The requirement under the European Data Protection Directive that member state data protection authorities report on their activities at regular intervals. Antidiscrimination Laws - Answer -Refers to the right of people to be treated equally. Article 29 Working Party - Answer -A European Union organization that functions as an independent advisory body on data protection and privacy. While EU data protection laws are actually enforced by the national Data Protection Authorities of EU member states. Authentication - Answer -The process by which an entity (such as a person or computer system) determines whether another entity is who it claims to be. Authentication identified as an individual based on some credential; i.e. a password, biometrics, etc. Authentication is different from authorization. Proper authentication ensures that a person is who he or she claims to be, but it says nothing about the access rights of the individual. Background Screening/Checks - Answer -Verifying an applicant's ability to function in the working environment as well as assuring the safety and security of existing workers. Background checks range from checking a person's educational background to checking on past criminal activity. Behavioral Advertising - Answer -The act of tracking users' online activities and then delivering ads or recommendations based upon the tracked activities. The most comprehensive form of targeted advertising. By building a profile on a user through their browsing habits such as sites they visit, articles read, searches made, ads previously clicked on, etc., advertising companies place ads pertaining to the known information about the user across all websites visited. Behavioral Advertising also uses data aggregation to place ads on websites that a user may not have shown interest in, but similar individuals had shown interest in. Binding Corporate Rules - Answer -Legally binding internal corporate privacy rules for transferring personal information within a corporate group. BCRs are typically used by corporations that operate in multiple jurisdictions, and they are alternatives to the EU-U.S. Privacy Shield and Model Contract Clauses. BCRs must be approved by the EU data protection authorities of the member states in which the corporation operates. Binding Safe Processor Rules - Answer -Self-regulatory principles (similar to Binding Corporate Rules) for processors that are applicable to customer personal data. Once a supplier's BSPR are approved, a supplier gains "safe processor" status and its customers would be able to meet the EU Data Protection Directive's requirements for international transfers in a similar manner as BCR allow. BSPR are currently being considered as a concept by the Article 29 Working Party and national authorities. Biometrics - Answer -Data concerning the intrinsic physical or behavioral characteristics of an individual. Examples include DNA, fingerprints, retina and iris patterns, voice, face, handwriting, keystroke technique and gait. Bodily Privacy - Answer -One of the four classes of privacy, along with information privacy, territorial privacy and communications privacy. It focuses on a person's physical being and any invasion thereof. Such an invasion can take the form of genetic testing, drug testing or body cavity searches. Breach Disclosure - Answer -The requirement that a data controller notify regulators and victims of incidents affecting the confidentiality and security of personal data. It is a transparency mechanism highlights operational failures, this helps mitigate damage and aids in the understanding of causes of failure.

Content preview

CIPP-E EXAM LATEST EXAM QUESTIONS AND
CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+
Accountability - Answer -A fair information practices principle, it is the idea that when
personal information is to be transferred to another person or organization, the personal
information controller should obtain the consent of the individual or exercise due
diligence and take reasonable steps to ensure that the recipient person or organization
will protect the information consistently with other fair use principles.

Adequate Level of Protection - Answer -A label that the EU may apply to third-party
countries who have committed to protect data through domestic law making or
international commitments. Conferring of the label requires a proposal by the European
Commission, an Article 29 Working Group Opinion, an opinion of the article 31
Management Committee, a right of scrutiny by the European Parliament and adoption
by the European Commission.

Adverse Action - Answer -Under the Fair Credit Reporting Act, the term "adverse action"
is defined very broadly to include all business, credit and employment actions affecting
consumers that can be considered to have a negative impact, such as denying or
canceling credit or insurance, or denying employment or promotion. No adverse action
occurs in a credit transaction where the creditor makes a counteroffer that is accepted
by the consumer. Such an action requires that the decision maker furnish the recipient
of the adverse action with a copy of the credit report leading to the adverse action.

Annual Reports - Answer -The requirement under the European Data Protection
Directive that member state data protection authorities report on their activities at
regular intervals.

Antidiscrimination Laws - Answer -Refers to the right of people to be treated equally.

Article 29 Working Party - Answer -A European Union organization that functions as an
independent advisory body on data protection and privacy. While EU data protection
laws are actually enforced by the national Data Protection Authorities of EU member
states.

Authentication - Answer -The process by which an entity (such as a person or computer
system) determines whether another entity is who it claims to be. Authentication
identified as an individual based on some credential; i.e. a password, biometrics, etc.
Authentication is different from authorization. Proper authentication ensures that a
person is who he or she claims to be, but it says nothing about the access rights of the
individual.

,Background Screening/Checks - Answer -Verifying an applicant's ability to function in
the working environment as well as assuring the safety and security of existing workers.
Background checks range from checking a person's educational background to
checking on past criminal activity.

Behavioral Advertising - Answer -The act of tracking users' online activities and then
delivering ads or recommendations based upon the tracked activities. The most
comprehensive form of targeted advertising. By building a profile on a user through their
browsing habits such as sites they visit, articles read, searches made, ads previously
clicked on, etc., advertising companies place ads pertaining to the known information
about the user across all websites visited. Behavioral Advertising also uses data
aggregation to place ads on websites that a user may not have shown interest in, but
similar individuals had shown interest in.

Binding Corporate Rules - Answer -Legally binding internal corporate privacy rules for
transferring personal information within a corporate group. BCRs are typically used by
corporations that operate in multiple jurisdictions, and they are alternatives to the EU-
U.S. Privacy Shield and Model Contract Clauses. BCRs must be approved by the EU
data protection authorities of the member states in which the corporation operates.

Binding Safe Processor Rules - Answer -Self-regulatory principles (similar to Binding
Corporate Rules) for processors that are applicable to customer personal data. Once a
supplier's BSPR are approved, a supplier gains "safe processor" status and its
customers would be able to meet the EU Data Protection Directive's requirements for
international transfers in a similar manner as BCR allow. BSPR are currently being
considered as a concept by the Article 29 Working Party and national authorities.

Biometrics - Answer -Data concerning the intrinsic physical or behavioral characteristics
of an individual. Examples include DNA, fingerprints, retina and iris patterns, voice,
face, handwriting, keystroke technique and gait.

Bodily Privacy - Answer -One of the four classes of privacy, along with information
privacy, territorial privacy and communications privacy. It focuses on a person's physical
being and any invasion thereof. Such an invasion can take the form of genetic testing,
drug testing or body cavity searches.

Breach Disclosure - Answer -The requirement that a data controller notify regulators
and victims of incidents affecting the confidentiality and security of personal data. It is a
transparency mechanism highlights operational failures, this helps mitigate damage and
aids in the understanding of causes of failure.

Bundesdatenschutzgesetz - Answer -A German national data protection law that
including specific requirements for data services outsourcing agreements. The
legislation contains ten specific requirements for outsourcing agreements: (1) Subject
and duration of work; (2) the extent, type and purpose of data processing; (3) technical
and organizational measures to be taken under section 9; (4) the rectification, erasure

, and blocking of data; (5) the processor's section 4 obligations, particularly with regard to
monitoring; (6) rights regarding subcontracting; (7) the controller's monitoring rights; (8)
the subcontractor's notification obligations; (9) the extent of the controller's authority to
issue instructions to the processor; (10) the return and/or erasure of data by the
processor at the conclusion of the work.

Charter of Fundamental Rights - Answer -A treaty that consolidates human rights within
the EU. The treaty states that everyone has a right to protect their personal data, that
data must be processed for legitimate and specified purposes and that compliance is
subject to control by an authority.

Children's Online Privacy Protection Act (COPPA) of 1998 - Answer -A U.S. federal law
that applies to the operators of commercial websites and online services that are
directed to children under the age of 13. It also applies to general audience websites
and online services that have actual knowledge that they are collecting personal
information from children under the age of 13. COPPA requires these website
operators: to post a privacy notice on the homepage of the website; provide notice
about collection practices to parents; obtain verifiable parental consent before collecting
personal information from children; give parents a choice as to whether their child's
personal information will be disclosed to third parties; provide parents access and the
opportunity to delete the child's personal information and opt out of future collection or
use of the information, and maintain the confidentiality, security and integrity of personal
information collected from children.

Choice - Answer -An individual's ability to determine whether or how their personal
information may be used or disclosed by the entity that collected the information. Also,
the ability of an individual to limit certain uses of their personal information. For
example; an individual may have choice about whether to permit a company to contact
them or share their data with third parties. Can be express or implied.

Closed Circuit Television - Answer -Systems of cameras, monitors and recording
equipment that are not used for broadcasting but are connected to a closed network by
cables. CCTV is used primarily for video surveillance of premises.

Cloud Computing - Answer -The storage of information on the Internet. Although it is an
evolving concept, definitions typically include on-demand accessibility, scalability, and
secure access from almost any location. Cloud storage presents unique security risks.

Collection Limitation - Answer -A fair information practices principle, it is the principle
stating there should be limits to the collection of personal data, that any such data
should be obtained by lawful and fair means and, where appropriate, with the
knowledge or consent of the data subject.

Commercial Activity - Answer -Under PIPEDA, "commercial activity" means any
particular transaction, act or conduct, or any regular course of conduct, that is of a
commercial character, including the selling, bartering or leasing of donor, membership

Document information

Uploaded on
January 10, 2025
Number of pages
20
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.29

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BrightByte
3.0
(3)
Sold
51
Followers
12
Items
3176
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions