Latest Nov 15, 2021 Real CIPP-C Exam Dumps Questions Valid CIPP-C Dumps PDF [Q42-Q61]

Share

Latest Nov 15, 2021 Real CIPP-C Exam Dumps Questions Valid CIPP-C Dumps PDF

IAPP CIPP-C Exam Dumps - PDF Questions and Testing Engine

NEW QUESTION 42
What type of data lies beyond the scope of the General Data Protection Regulation?

  • A. Masked
  • B. Encrypted
  • C. Pseudonymized
  • D. Anonymized

Answer: D

 

NEW QUESTION 43
Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. Which of the following is NOT one of these exceptions?

  • A. The processing is necessary to protect the vital interests of the data subject when he or she is incapable of giving consent.
  • B. The processing is explicitly consented to by the data subject and he or she is allowed by Union or Member State law to lift the prohibition.
  • C. The processing is done by a non-profit organization and the results are disclosed outside the organization.
  • D. The processing is necessary for the establishment, exercise or defense of legal claims when courts are acting in a judicial capacity.

Answer: C

 

NEW QUESTION 44
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?

  • A. The behavior of suspected terrorists being monitored by EU law enforcement bodies.
  • B. Personal data of EU residents being processed by a non-EU business that targets EU customers.
  • C. The behavior of EU citizens outside the EU being monitored by non-EU law enforcement bodies.
  • D. Personal data of EU citizens being processed by a controller or processor based outside the EU.

Answer: D

 

NEW QUESTION 45
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?

  • A. Data inventory or data mapping exercises that have been conducted.
  • B. Categories of recipients to whom the personal data have been disclosed.
  • C. Incidents of personal data breaches, whether disclosed or not.
  • D. Retention periods for erasure and deletion of categories of personal data.

Answer: D

 

NEW QUESTION 46
SCENARIO
Please use the following to answer the next QUESTION:
Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has become a grand event. It fills one of the large downtown conference hotels and overflows into the others, with several thousand attendees enjoying three days of presentations, panel discussions and networking. The convention is the centerpiece of the company's product rollout schedule and a great training opportunity for current users. The sales force also encourages prospective clients to attend to get a better sense of the ways in which the system can be customized to meet diverse needs and understand that when they buy into this system, they are joining a community that feels like family.
This year's conference is only three weeks away, and you have just heard news of a new initiative supporting it: a smartphone app for attendees. The app will support late registration, highlight the featured presentations and provide a mobile version of the conference program. It also links to a restaurant reservation system with the best cuisine in the areas featured. "It's going to be great," the developer, Deidre Hoffman, tells you, "if, that is, we actually get it working!" She laughs nervously but explains that because of the tight time frame she'd been given to build the app, she outsourced the job to a local firm. "It's just three young people," she says, "but they do great work." She describes some of the other apps they have built. When asked how they were selected for this job, Deidre shrugs. "They do good work, so I chose them." Deidre is a terrific employee with a strong track record. That's why she's been charged to deliver this rushed project. You're sure she has the best interests of the company at heart, and you don't doubt that she's under pressure to meet a deadline that cannot be pushed back. However, you have concerns about the app's handling of personal data and its security safeguards. Over lunch in the break room, you start to talk to her about it, but she quickly tries to reassure you, "I'm sure with your help we can fix any security issues if we have to, but I doubt there'll be any. These people build apps for a living, and they know what they're doing.
You worry too much, but that's why you're so good at your job!"
Which is the best first step in understanding the data security practices of a potential vendor?

  • A. Examining investigation records of any breaches the vendor has experienced.
  • B. Conducting a physical audit of the vendor's facilities.
  • C. Requiring the vendor to complete a questionaire assessing International Organization for Standardization (ISO) 27001 compliance.
  • D. Conducting a penetration test of the vendor's data security structure.

Answer: A

 

NEW QUESTION 47
SCENARIO
WebTracker Limited is a cloud-based online marketing service located in London. Last year, WebTracker migrated its IT infrastructure to the cloud provider AmaZure, which provides SQL Databases and Artificial Intelligence services to WebTracker. The roles and responsibilities between the two companies have been formalized in a standard contract, which includes allocating the role of data controller to WebTracker.
The CEO of WebTracker, Mr. Bond, would like to assess the effectiveness of AmaZure's privacy controls, and he recently decided to hire you as an independent auditor. The scope of the engagement is limited only to the marketing services provided by WebTracker, you will not be evaluating any internal data processing activity, such as HR or Payroll.
This ad-hoc audit was triggered due to a future partnership between WebTracker and SmartHome - a partnership that will not require any data sharing. SmartHome is based in the USA, and most recently has dedicated substantial resources to developing smart refrigerators that can suggest the recommended daily calorie intake based on DNA information. This and other personal data is collected by WebTracker.
To get an idea of the scope of work involved, you have decided to start reviewing the company's documentation and interviewing key staff to understand potential privacy risks.
The results of this initial work include the following notes:
* There are several typos in the current privacy notice of WebTracker, and you were not able to find the privacy notice for SmartHome.
* You were unable to identify all the sub-processors working for SmartHome. No subcontractor is indicated in the cloud agreement with AmaZure, which is responsible for the support and maintenance of the cloud infrastructure.
* There are data flows representing personal data being collected from the internal employees of WebTracker, including an interface from the HR system.
* Part of the DNA data collected by WebTracker was from employees, as this was a prototype approved by the CEO of WebTracker.
* All the WebTracker and SmartHome customers are based in USA and Canada.
Which of the following issues is most likely to require an investigation by the Chief Privacy Officer (CPO) of WebTracker?

  • A. AmaZure sends newsletter to WebTracker customers, as approved by the Marketing Manager.
  • B. Data flows use encryption for data at rest, as defined by the IT manager.
  • C. Employees' personal data are being stored in a cloud HR system, as approved by the HR Manager.
  • D. File Integrity Monitoring is being deployed in SQL servers, as indicated by the IT Architect Manager.

Answer: A

 

NEW QUESTION 48
Which statement is correct when considering the right to privacy under Section 7 of the Canadian Charter of Rights and Freedoms?

  • A. The right to privacy is an absolute right
  • B. The right to freedom of expression under section 10 will always override the right to privacy
  • C. The right to privacy protects the right to hold opinions and to receive and impart ideas without interference
  • D. The Supreme Court of Canada has stated that the Privacy Act has "quasi-constitutional status", and that the values and rights set out in the Act are closely linked to those set out in the Constitution as being necessary to a free and democratic society.

Answer: D

Explanation:
Explanation
https://www.priv.gc.ca/en/about-the-opc/publications/guide_ind/

 

NEW QUESTION 49
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?

  • A. Only where the personal data is to be subjected to specific computerized processing, such as image scanning or optical character recognition.
  • B. Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.
  • C. Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.
  • D. Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.

Answer: D

 

NEW QUESTION 50
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Which of the following BEST describes the relationship between Liem, EcoMick and JaphSoft?

  • A. Liem and EcoMick are joint controllers because they carry out joint marketing activities.
  • B. Liem is a controller and EcoMick is a processor because Liem provides specific instructions regarding how the marketing campaigns should be rolled out.
  • C. EcoMick and JaphSoft are is a controller and Liem is a processor because EcoMick is sharing its marketing data with Liem for contacts in Europe.
  • D. JaphSoft is the sole processor because it processes personal data on behalf of its clients.

Answer: C

 

NEW QUESTION 51
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
If Who-R-U decides to track locations using its app, what must it do to comply with the GDPR?

  • A. Anonymize the data and add latency so it avoids disclosing real time locations.
  • B. Get consent from the app users.
  • C. Obtain a court order because location data is a special category of personal data.
  • D. Provide a transparent notice to users.

Answer: B

 

NEW QUESTION 52
SCENARIO
Please use the following to answer the next question:
WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:
"WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the data. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information.
We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."
"We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."
"We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities." What additional information must Wonderkids provide in their Privacy Statement?

  • A. Technical and organizational measures to protect data.
  • B. How often promotional emails will be sent.
  • C. Contact information of the hosting company.
  • D. The categories of recipients with whom data will be shared.

Answer: C

 

NEW QUESTION 53
SCENARIO
Please use the following to answer the next QUESTION:
Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has become a grand event. It fills one of the large downtown conference hotels and overflows into the others, with several thousand attendees enjoying three days of presentations, panel discussions and networking. The convention is the centerpiece of the company's product rollout schedule and a great training opportunity for current users. The sales force also encourages prospective clients to attend to get a better sense of the ways in which the system can be customized to meet diverse needs and understand that when they buy into this system, they are joining a community that feels like family.
This year's conference is only three weeks away, and you have just heard news of a new initiative supporting it: a smartphone app for attendees. The app will support late registration, highlight the featured presentations and provide a mobile version of the conference program. It also links to a restaurant reservation system with the best cuisine in the areas featured. "It's going to be great," the developer, Deidre Hoffman, tells you, "if, that is, we actually get it working!" She laughs nervously but explains that because of the tight time frame she'd been given to build the app, she outsourced the job to a local firm. "It's just three young people," she says, "but they do great work." She describes some of the other apps they have built. When asked how they were selected for this job, Deidre shrugs. "They do good work, so I chose them." Deidre is a terrific employee with a strong track record. That's why she's been charged to deliver this rushed project. You're sure she has the best interests of the company at heart, and you don't doubt that she's under pressure to meet a deadline that cannot be pushed back. However, you have concerns about the app's handling of personal data and its security safeguards. Over lunch in the break room, you start to talk to her about it, but she quickly tries to reassure you, "I'm sure with your help we can fix any security issues if we have to, but I doubt there'll be any. These people build apps for a living, and they know what they're doing. You worry too much, but that's why you're so good at your job!" You see evidence that company employees routinely circumvent the privacy officer in developing new initiatives. How can you best draw attention to the scope of this problem?

  • A. Insist upon one-on-one consultation with each person who works around the privacy officer.
  • B. Hold discussions with the department head of anyone who fails to consult with the privacy officer.
  • C. Take your concerns straight to the Chief Executive Officer.
  • D. Develop a metric showing the number of initiatives launched without consultation and include it in reports, presentations, and consultation.

Answer: B

 

NEW QUESTION 54
Which of the following is NOT recognized as being a common characteristic of cloud-computing services?

  • A. The supplier allows customer data to be transferred around the infrastructure according to capacity.
  • B. The supplier determines the location, security measures, and service standards applicable to the processing.
  • C. The service's infrastructure is shared among the supplier's customers and can be located in a number of countries.
  • D. The supplier assumes the vendor's business risk associated with data processed by the supplier.

Answer: D

 

NEW QUESTION 55
With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?

  • A. Only as a last resort and when interpreted restrictively.
  • B. When it has been determined that adequate protection can be performed.
  • C. Only if the Data Protection Impact Assessment (DPIA) shows low risk.
  • D. If the data controller has received preapproval from a Data Protection Authority (DPA), after submitting the appropriate documents.

Answer: B

 

NEW QUESTION 56
What was the aim of the European Data Protection Directive 95/46/EC?

  • A. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.
  • B. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.
  • C. To completely prevent the transfer of personal data out of the European Union.
  • D. To harmonize the implementation of the European Convention of Human Rights across all member states.

Answer: B

 

NEW QUESTION 57
What should a controller do after a data subject opts out of a direct marketing activity?

  • A. Without undue delay, provide information to the data subject on the action that will be taken.
  • B. Refrain from processing personal data relating to the data subject for the relevant type of communication.
  • C. Take reasonable steps to inform third-party recipients that the data subject's personal data should be deleted and no longer processed.
  • D. Without exception, securely delete all personal data relating to the data subject.

Answer: B

 

NEW QUESTION 58
What is the MAIN reason GDPR Article 4(22) establishes the concept of the "concerned supervisory authority"?

  • A. To ensure that the interests of individuals residing outside the lead authority's jurisdiction are represented.
  • B. To encourage the consistency of local data processing activity.
  • C. To give corporations a choice about who their supervisory authority will be.
  • D. To ensure the GDPR covers controllers that do not have an establishment in the EU but have a representative in a member state.

Answer: B

 

NEW QUESTION 59
To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client.
Regarding the domain of the controller-processor relationships, how is this situation considered?

  • A. Not applicable, because the data base is password protected, and therefore is not at risk of identifying any data subject.
  • B. Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the controller.
  • C. Compliant with the security principle, because the data base is password-protected.
  • D. Compliant with the storage limitation principle, so long as the internal auditor permanently deletes the data base.

Answer: B

 

NEW QUESTION 60
Which is TRUE about the scope and authority of data protection oversight authorities?

  • A. All authority in the European Union rests with the Data Protection Commission (DPC)
  • B. No one agency officially oversees the enforcement of privacy regulations in the United States
  • C. The Asia-Pacific Economic Cooperation (APEC) Privacy Frameworks require all member nations to designate a national data protection authority
  • D. The Office of the Privacy Commissioner (OPC) of Canada has the right to impose financial sanctions on violators

Answer: D

 

NEW QUESTION 61
......

Reliable Certified Information Privacy Professional CIPP-C Dumps PDF Nov 15, 2021 Recently Updated Questions: https://www.prep4away.com/IAPP-certification/braindumps.CIPP-C.ete.file.html

Latest CIPP-C Exam Dumps for Pass Guaranteed: https://drive.google.com/open?id=1lroXjdpAL1pk9pEUrpLI-_FjVBdLfZE3