
Grab latest IAPP CIPP-C Dumps as PDF Updated on 2022
Newly Released CIPP-C Dumps for Certified Information Privacy Professional Certified
NEW QUESTION 25
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B.
Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
* Name
* Address
* Date of Birth
* Payroll number
* National Insurance number
* Sick pay entitlement
* Maternity/paternity pay entitlement
* Holiday entitlement
* Pension and benefits contributions
* Trade union contributions
Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
The GDPR requires sufficient guarantees of a company's ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?
- A. Avoiding the use of another company's data to improve their own services.
- B. Vetting companies' measures with the appropriate supervisory authority.
- C. Hiring companies whose measures are consistent with recommendations of accrediting bodies.
- D. Requesting advice and technical support from Company A's IT team.
Answer: C
NEW QUESTION 26
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What must Zandelay provide to the supervisory authority during the prior consultation?
- A. An evaluation of the complexity of the intended processing.
- B. An explanation of the purposes and means of the intended processing.
- C. Records showing that customers have explicitly consented to the intended profiling activities.
- D. Certificates that prove Martin's professional qualities and expert knowledge of data protection law.
Answer: B
NEW QUESTION 27
Which GDPR principle would a Spanish employer most likely depend upon to annually send the personal data of its employees to the national tax authority?
- A. The protection of the vital interest of the employees.
- B. The legal obligation of the employer.
- C. The consent of the employees.
- D. The legitimate interest of the public administration.
Answer: B
NEW QUESTION 28
In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?
- A. When paying a search engine company to give prominence to certain products and services within specific search results.
- B. When emailing a customer to announce that his recent order should arrive earlier than expected.
- C. When creating an untargeted pop-up ad on a website.
- D. When calling a potential customer to notify her of an upcoming product sale.
Answer: C
NEW QUESTION 29
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations.
TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?
- A. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
- B. The resulting obligation to notify data subjects would involve disproportionate effort.
- C. The incident resulted from the actions of a third-party that were beyond their control.
- D. The sensitivity of the categories of data involved in the incident was not substantial enough.
Answer: C
NEW QUESTION 30
With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?
- A. When it has been determined that adequate protection can be performed.
- B. If the data controller has received preapproval from a Data Protection Authority (DPA), after submitting the appropriate documents.
- C. Only as a last resort and when interpreted restrictively.
- D. Only if the Data Protection Impact Assessment (DPIA) shows low risk.
Answer: A
NEW QUESTION 31
When may a financial institution share consumer information with non-affiliated third parties for marketing purposes?
- A. After disclosing marketing practices to customers and after giving them an opportunity to opt in.
- B. After disclosing marketing practices to customers and after giving them an opportunity to opt out.
- C. After disclosing information-sharing practices to customers and after giving them an opportunity to opt in.
- D. After disclosing information-sharing practices to customers and after giving them an opportunity to opt out.
Answer: D
NEW QUESTION 32
Which of the following is an example of direct marketing that would be subject to European data protection laws?
- A. A charity fundraising event notice sent to an individual at her business address.
- B. An updated privacy notice sent to an individual's personal email address.
- C. A service outage notification provided to an individual by recorded telephone message.
- D. A revision of contract terms conveyed to an individual by SMS from a marketing organization.
Answer: A
NEW QUESTION 33
How is the GDPR's position on consent MOST likely to affect future app design and implementation?
- A. Users will see fewer advertisements when using apps.
- B. App developers' responsibilities as data controllers will increase.
- C. Users will be given granular types of consent for particular types of processing.
- D. App developers will expand the amount of data necessary to collect for an app's functionality.
Answer: C
NEW QUESTION 34
A company is hesitating between Binding Corporate Rules and Standard Contractual Clauses as a global data transfer solution. Which of the following statements would help the company make an effective decision?
- A. The data exporter does not need to be located in the EU for the standard Contractual Clauses.
- B. The company will need the prior authorization of all EU data protection authorities for concluding Standard Contractual Clauses.
- C. Binding Corporate Rules are especially recommended for small and medium companies.
- D. Binding Corporate Rules provide a global solution for all the entities of a company that are bound by the intra-group agreement.
Answer: D
NEW QUESTION 35
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
- A. A company wants to combine location data with other data in order to offer more personalized service for the customer.
- B. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- C. A company wants to use location data to infer information on a person's clothes purchasing habits.
- D. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
Answer: B
NEW QUESTION 36
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location.
During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
In addition to notifying employees about the purpose of the monitoring, the potential uses of their data and their privacy rights, what information should Building Block have provided them before implementing the security measures?
- A. Information about how providing consent could affect them as employees.
- B. Information about what is specified in the employment contract.
- C. Information about how the measures are in the best interests of the company.
- D. Information about who employees should contact with any queries.
Answer: B
NEW QUESTION 37
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What would MOST effectively assist Zandelay in conducting their data protection impact assessment?
- A. Information about DPIAs found in Articles 38 through 40 of the GDPR.
- B. Records of processing activities that data controllers are required to maintain.
- C. Existing DPIA guides published by local supervisory authorities.
- D. Data breach documentation that data controllers are required to maintain.
Answer: A
NEW QUESTION 38
Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. Which of the following is NOT one of these exceptions?
- A. The processing is done by a non-profit organization and the results are disclosed outside the organization.
- B. The processing is necessary to protect the vital interests of the data subject when he or she is incapable of giving consent.
- C. The processing is explicitly consented to by the data subject and he or she is allowed by Union or Member State law to lift the prohibition.
- D. The processing is necessary for the establishment, exercise or defense of legal claims when courts are acting in a judicial capacity.
Answer: A
NEW QUESTION 39
SCENARIO
Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.
You also recall a recent visit to the Records Storage Section, often termed "The Dungeon" in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage.
Which regulation most likely applies to the data stored by Berry Country Regional Medical Center?
- A. The Health Records Act 2001
- B. The European Union Directive 95/46/EC
- C. Health Insurance Portability and Accountability Act
- D. Personal Information Protection and Electronic Documents Act
Answer: D
NEW QUESTION 40
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018 guidance, company Z should do which of the following?
- A. Notify the supervisory authority about the loss of availability
- B. Conduct a thorough audit of all security systems
- C. Notify affected individuals that their data was unavailable for a period of time.
- D. Document the loss of availability to demonstrate accountability
Answer: A
NEW QUESTION 41
What is the MAIN reason GDPR Article 4(22) establishes the concept of the "concerned supervisory authority"?
- A. To ensure that the interests of individuals residing outside the lead authority's jurisdiction are represented.
- B. To encourage the consistency of local data processing activity.
- C. To give corporations a choice about who their supervisory authority will be.
- D. To ensure the GDPR covers controllers that do not have an establishment in the EU but have a representative in a member state.
Answer: B
NEW QUESTION 42
......
Latest CIPP-C Exam Dumps IAPP Exam from Training: https://www.prepawaytest.com/IAPP/CIPP-C-practice-exam-dumps.html
Updated Verified CIPP-C dumps Q&As - 100% Pass: https://drive.google.com/open?id=1IvlJDj6M3KWLblIlzqetFoZqePuCY4z4