Home
View All Exams
Request Exam
Oracle
Fortinet
Juniper
Microsoft
Cisco
Citrix
CompTIA
VMware
SAP
EMC
PMI
View All
Menu
Oracle
Fortinet
Juniper
Microsoft
Cisco
Citrix
CompTIA
VMware
SAP
EMC
PMI
Home
IAPP Certification
CIPP-E Exam
IAPP.CIPP-E.v2022-05-14.q101 Practice Test
««
«
…
4
5
6
7
8
9
10
11
12
13
…
»
»»
Question
36
What is a reason the European Court of Justice declared the Data Retention Directive invalid in 2014?
A.
The requirements affected individuals without exception.
B.
The requirements were financially burdensome to EU businesses.
C.
The requirements specified that data must be held within the EU.
D.
The requirements had limitations on how national authorities could use data.
Correct Answer:
D
Reference:
%20the%20Grand,proportionality%20in%20forging%20the%20Directive.
Comment:
*
Name:
*
Email:
*
Verification:
*
Question
37
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?
A.
Within 40 days of receipt
B.
Within 40 days of receipt, which may be extended by up to 40 additional days
C.
Within one month of receipt, which may be extended by up to an additional month
D.
Within one month of receipt, which may be extended by an additional two months
Correct Answer:
C
Explanation/Reference: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection- regulation-gdpr/individual-rights/right-of-access/
Comment:
*
Name:
*
Email:
*
Verification:
*
Question
38
A.
Their decision to operate without a data protection officer.
B.
Their engagement of Company C to improve their payroll service.
C.
Their failure to provide sufficient security safeguards to Company A's data.
D.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?
E.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company
F.
Their omission of data protection provisions in their contract with Company C.
Correct Answer:
B
Comment:
*
Name:
*
Email:
*
Verification:
*
Question
39
The European Parliament jointly exercises legislative and budgetary functions with which of the following?
A.
The Article 29 Working Party.
B.
The European Data Protection Board.
C.
The European Commission.
D.
The Council of the European Union.
Correct Answer:
D
Comment:
*
Name:
*
Email:
*
Verification:
*
Question
40
After leaving the EU under the terms of Brexit, the United Kingdom will seek an adequacy determination. What is the reason for this?
A.
Adequacy determinations automatically lapse when a Member State leaves the EU.
B.
The UK is less trustworthy now that its not part of the Union.
C.
The Insurance Commissioner determined that an adequacy determination is required by the Data Protection Act.
D.
The UK is now a third country because it's no longer subject to the GDPR.
Correct Answer:
D
Comment:
*
Name:
*
Email:
*
Verification:
*
««
«
…
4
5
6
7
8
9
10
11
12
13
…
»
»»
Other Version
980
IAPP.CIPP-E.v2025-08-02.q177
1379
IAPP.CIPP-E.v2023-08-14.q153
1565
IAPP.CIPP-E.v2022-11-25.q113
2364
IAPP.CIPP-E.v2022-07-03.q102
57
IAPP.Trainingdump.CIPP-E.v2021-11-07.by.june.59q.pdf
Latest Upload
102
Huawei.H35-210_V2.5.v2025-09-18.q127
103
NBMTM.BCMTMS.v2025-09-18.q34
102
Microsoft.PL-500.v2025-09-18.q152
110
GAQM.CDCS-001.v2025-09-17.q15
116
Huawei.H19-301_V4.0.v2025-09-17.q37
105
VMware.5V0-33.23.v2025-09-17.q24
115
Oracle.1Z0-1078-23.v2025-09-17.q30
152
IAPP.CIPP-US.v2025-09-17.q217
158
Salesforce.ADM-201.v2025-09-16.q192
139
SAP.C-HRHPC-2505.v2025-09-15.q26
[×]
Download PDF File
Enter your email address to download
IAPP.CIPP-E.v2022-05-14.q101 Practice Test
Email:
Download