Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

CIPP-C Free Certification Exam Material from BraindumpsIT with 180 Questions [Q26-Q50]

Share

CIPP-C Free Certification Exam Material from BraindumpsIT with 180 Questions

Use Real CIPP-C - 100% Cover Real Exam Questions 

NEW QUESTION 26
What is the function of the privacy operational life cycle?

  • A. It allows the organization to respond to ever-changing privacy demands
  • B. It ensures that outdated privacy policies are retired on a set schedule
  • C. It allows privacy policies to mature to a fixed form
  • D. It establishes initial plans for privacy protection and implementation

Answer: D

 

NEW QUESTION 27
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?

  • A. The Canadian Council
  • B. The Canadian Commission
  • C. The Canadian Parliament
  • D. Office of the Privacy Commissioner of Canada

Answer: D

 

NEW QUESTION 28
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?

  • A. A company wants to use location data to infer information on a person's clothes purchasing habits.
  • B. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
  • C. A company wants to combine location data with other data in order to offer more personalized service for the customer.
  • D. A company wants to use location data to track delivery trucks in order to make the routes more efficient.

Answer: B

 

NEW QUESTION 29
Why is advisable to avoid consent as a legal basis for an employer to process employee data?

  • A. Data protection laws do not apply to processing of employee data.
  • B. Employee data can only be processed if there is an approval from the data protection officer.
  • C. An employer might have difficulty obtaining consent from every employee.
  • D. Consent may not be valid if the employee feels compelled to provide it.

Answer: B

 

NEW QUESTION 30
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Under the GDPR, Liem and EcoMick's contract with MarketIQ must include all of the following provisions EXCEPT?

  • A. Assistance to Liem and EcoMick in their compliance with data protection impact assessments.
  • B. Returning or deleting personal data after the end of the provision of the services.
  • C. Processing the personal data upon documented instructions regarding data transfers outside of the EEA.
  • D. Notification regarding third party requests for access to Liem and EcoMick's personal data.

Answer: A

 

NEW QUESTION 31
SCENARIO
Please use the following to answer the next QUESTION:
Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has become a grand event. It fills one of the large downtown conference hotels and overflows into the others, with several thousand attendees enjoying three days of presentations, panel discussions and networking. The convention is the centerpiece of the company's product rollout schedule and a great training opportunity for current users. The sales force also encourages prospective clients to attend to get a better sense of the ways in which the system can be customized to meet diverse needs and understand that when they buy into this system, they are joining a community that feels like family.
This year's conference is only three weeks away, and you have just heard news of a new initiative supporting it: a smartphone app for attendees. The app will support late registration, highlight the featured presentations and provide a mobile version of the conference program. It also links to a restaurant reservation system with the best cuisine in the areas featured. "It's going to be great," the developer, Deidre Hoffman, tells you, "if, that is, we actually get it working!" She laughs nervously but explains that because of the tight time frame she'd been given to build the app, she outsourced the job to a local firm. "It's just three young people," she says, "but they do great work." She describes some of the other apps they have built. When asked how they were selected for this job, Deidre shrugs. "They do good work, so I chose them." Deidre is a terrific employee with a strong track record. That's why she's been charged to deliver this rushed project. You're sure she has the best interests of the company at heart, and you don't doubt that she's under pressure to meet a deadline that cannot be pushed back. However, you have concerns about the app's handling of personal data and its security safeguards. Over lunch in the break room, you start to talk to her about it, but she quickly tries to reassure you, "I'm sure with your help we can fix any security issues if we have to, but I doubt there'll be any. These people build apps for a living, and they know what they're doing. You worry too much, but that's why you're so good at your job!" You want to point out that normal protocols have not been followed in this matter. Which process in particular has been neglected?

  • A. Vendor due diligence or vetting
  • B. Privacy breach prevention
  • C. Forensic inquiry
  • D. Data mapping

Answer: A

 

NEW QUESTION 32
An organization is establishing a mission statement for its privacy program. Which of the following statements would be the best to use?

  • A. The goal of the privacy program is to protect the privacy of all individuals who support our organization. To meet this goal, we must work to comply with all applicable privacy laws.
  • B. Our organization was founded in 2054 to reduce the chance of a future disaster like the one that occurred ten years ago. All individuals from our area of the country should be concerned about a future disaster. However, with our privacy program, they should not be concerned about the misuse of their information.
  • C. In the next 20 years, our privacy program should be able to eliminate 80% of our current breaches. To do this, everyone in our organization must complete our annual privacy training course and all personally identifiable information must be inventoried.
  • D. This privacy program encourages cross-organizational collaboration which will stop all data breaches

Answer: A

 

NEW QUESTION 33
SCENARIO
Please use the following to answer the next question:
Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Javier lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Javier was photographed while working out at a branch of EVERFIT in Frankfurt, Germany. At the time, Javier gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club's U.K.
brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Javier no longer feels comfortable with his photograph being publicly associated with the fitness club.
After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Javier sends a letter to EVETFIT requesting that his image be removed from the website and all promotional materials. Months pass and Javier, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact EVETFIT through alternate channels, he decides to take action against the company.
Javier contacts the U.K. Information Commissioner's Office ('ICO' - the U.K.'s supervisory authority) to lodge a complaint about this matter. The ICO, pursuant to Article 56 (3) of the GDPR, informs the CNIL (i.e.
the supervisory authority of EVERFIT's main establishment) about this matter. Despite the fact that EVERFIT has an establishment in the U.K., the CNIL decides to handle the case in accordance with Article 60 of the GDPR. The CNIL liaises with the ICO, as relevant under the cooperation procedure. In light of issues amongst the supervisory authorities to reach a decision, the European Data Protection Board becomes involved and, pursuant to the consistency mechanism, issues a binding decision.
Additionally, Javier sues EVERFIT for the damages caused as a result of its failure to honor his request to have his photograph removed from the brochure and website.
Assuming that multiple EVETFIT branches across several EU countries are acting as separate data controllers, and that each of those branches were responsible for mishandling Javier's request, how may Javier proceed in order to seek compensation?

  • A. He will be able to apply to the European Data Protection Board in order to determine which particular EVETFIT branch is liable for damages, based on the decision that was made by the board.
  • B. He will be able to sue any one of the relevant EVETFIT branches, as each one may be held liable for the entire damage.
  • C. He will have to sue each EVETFIT branch so that each branch provides proportionate compensation commensurate with its contribution to the damage or distress suffered by Javier.
  • D. He will have to sue the EVETFIT's head office in France, where EVETFIT has its main establishment.

Answer: D

 

NEW QUESTION 34
A U.S.-based online shop uses sophisticated software to track the browsing behavior of its European customers and predict future purchases. It also shares this information with third parties. Under the GDPR, what is the online shop's PRIMARY obligation while engaging in this kind of profiling?

  • A. It must prove that it uses sufficient security safeguards to protect customer data
  • B. It must seek authorization from the European supervisory authorities
  • C. It must solicit informed consent through a notice on its website
  • D. It must be able to demonstrate a prior business relationship with the customers

Answer: C

 

NEW QUESTION 35
In which of the following cases, cited as an example by a WP29 guidance, would conducting a single data protection impact assessment to address multiple processing operations be allowed?

  • A. A data controller who plans to use a new technology product that has already undergone a DPIA by the product's provider.
  • B. A marketing team that wants to collect mailing addresses of customers for whom they already have email addresses.
  • C. A medical organization that wants to begin genetic testing to support earlier research for which they have performed a DPIA.
  • D. A railway operator who plans to evaluate the same video surveillance in all the train stations of his company.

Answer: D

 

NEW QUESTION 36
SCENARIO
Please use the following to answer the next question:
WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:
"WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the data. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information.
We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."
"We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."
"We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities." What must the contract between WonderKids and the hosting service provider contain?

  • A. A non-disclosure agreement.
  • B. Controller-to-controller model contract clauses.
  • C. Audit rights for the data subjects.
  • D. The requirement to implement technical and organizational measures to protect the data.

Answer: D

 

NEW QUESTION 37
SCENARIO
Please use the following to answer the next question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago.
Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible.
Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
Based on the GDPR's position on the use of personal data for direct marketing purposes, which of the following is true about Louis's rights as a data subject?

  • A. Louis does not have the right to object to the use of his data because he previously consented to it.
  • B. Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.
  • C. Louis does not have the right to object to the use of his data if Bedrock can demonstrate compelling legitimate grounds for the processing.
  • D. Louis has the right to object to the use of his data, unless his data is required by Bedrock for the purpose of exercising a legal claim.

Answer: B

 

NEW QUESTION 38
What was the aim of the European Data Protection Directive 95/46/EC?

  • A. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.
  • B. To harmonize the implementation of the European Convention of Human Rights across all member states.
  • C. To completely prevent the transfer of personal data out of the European Union.
  • D. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.

Answer: A

 

NEW QUESTION 39
Which is the best way to view an organization's privacy framework?

  • A. As a living structure that aligns to changes in the organization
  • B. As an industry benchmark that can apply to many organizations
  • C. As an aspirational goal that improves the organization
  • D. As a fixed structure that directs changes in the organization

Answer: D

 

NEW QUESTION 40
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?

  • A. The behavior of suspected terrorists being monitored by EU law enforcement bodies.
  • B. The behavior of EU citizens outside the EU being monitored by non-EU law enforcement bodies.
  • C. Personal data of EU citizens being processed by a controller or processor based outside the EU.
  • D. Personal data of EU residents being processed by a non-EU business that targets EU customers.

Answer: C

 

NEW QUESTION 41
Which of the following is NOT recognized as being a common characteristic of cloud-computing services?

  • A. The supplier determines the location, security measures, and service standards applicable to the processing.
  • B. The supplier assumes the vendor's business risk associated with data processed by the supplier.
  • C. The service's infrastructure is shared among the supplier's customers and can be located in a number of countries.
  • D. The supplier allows customer data to be transferred around the infrastructure according to capacity.

Answer: B

 

NEW QUESTION 42
According to the GDPR, what is the main task of a Data Protection Officer (DPO)?

  • A. To create and maintain records of processing activities.
  • B. To create procedures for notification of personal data breaches to competent supervisory authorities.
  • C. To conduct Privacy Impact Assessments on behalf of the controller or processor.
  • D. To monitor compliance with other local or European data protection provisions.

Answer: C

 

NEW QUESTION 43
SCENARIO
Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.
You also recall a recent visit to the Records Storage Section, often termed "The Dungeon" in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage.
Which data lifecycle phase needs the most attention at this Ontario medical center?

  • A. Disclosure
  • B. Use
  • C. Retention
  • D. Collection

Answer: C

 

NEW QUESTION 44
Under the GDPR, which essential pieces of information must be provided to data subjects before collecting their personal data?

  • A. The authority by which the controller is collecting the data and the third parties to whom the data will be sent.
  • B. The name/s of relevant government agencies involved and the steps needed for revising the data.
  • C. The contact information of the controller and a description of the retention policy.
  • D. The identity and contact details of the controller and the reasons the data is being collected.

Answer: D

 

NEW QUESTION 45
As a result of the European Court of Justice's ruling in the case of Google v. Spain, search engines outside the EEA are also likely to be subject to the Regulation's right to be forgotten. This holds true if the activities of an EU subsidiary and its U.S. parent are what?

  • A. Bound by a standard contractual clause.
  • B. Consistent with Privacy Shield requirements
  • C. Inextricably linked in their businesses.
  • D. Supervised by the same Data Protection Officer.

Answer: C

 

NEW QUESTION 46
What type of data lies beyond the scope of the General Data Protection Regulation?

  • A. Pseudonymized
  • B. Masked
  • C. Anonymized
  • D. Encrypted

Answer: C

 

NEW QUESTION 47
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What would MOST effectively assist Zandelay in conducting their data protection impact assessment?

  • A. Existing DPIA guides published by local supervisory authorities.
  • B. Data breach documentation that data controllers are required to maintain.
  • C. Information about DPIAs found in Articles 38 through 40 of the GDPR.
  • D. Records of processing activities that data controllers are required to maintain.

Answer: C

 

NEW QUESTION 48
A law enforcement subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?

  • A. SCA
  • B. ECPA
  • C. CALEA
  • D. USA Freedom Act

Answer: C

 

NEW QUESTION 49
SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years.
Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles.
Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Under the General Data Protection Regulation (GDPR), what is the most likely reason Serge may have grounds to object to the use of his quotation?

  • A. Because of the misrepresentation of personal data as an endorsement.
  • B. Because of the juxtaposition of the quotation with others' quotations.
  • C. Because of the use of personal data outside of the social networking service (SNS).
  • D. Because of the misapplication of the household exception in relation to a social networking service (SNS).

Answer: D

 

NEW QUESTION 50
......

Dumps Brief Outline Of The CIPP-C Exam: https://www.braindumpsit.com/CIPP-C_real-exam.html

CIPP-C Training & Certification Get Latest Certified Information Privacy Professional : https://drive.google.com/open?id=1iQ71C1mEyW6mqi5n0Zxl1iMlwZNLHuM6