最新の[2025年04月17日]CIPP-E試験問題集で有効で更新された問題集 [Q175-Q193]

Share

最新の[2025年04月17日]CIPP-E試験問題集で有効で更新された問題集

無料お試しまもなく終了!100%有効なCIPP-E試験問題集には294問があります

質問 # 175
What is the main task of the European Data Protection Board?

  • A. To assess adequacy of data protection in third countries
  • B. To publish guidelines tor data subjects on how to property enforce their rights
  • C. To ensure consistent application of the GDPR.
  • D. To proactively prevent disputes between national supervisory authorities.

正解:C


質問 # 176
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

  • A. The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved
  • B. The processor will be considered to be a controller in respect of the processing concerned
  • C. The controller will be liable to pay an administrative fine
  • D. The processor will be liable to pay compensation to affected data subjects

正解:D

解説:
Reference https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection- regulation-gdpr/key-definitions/controllers-and-processors/


質問 # 177
The EDPB's Guidelines 8/2020 on the targeting of social media users stipulates that in order to rely on legitimate interest as a legal basis to process personal data, three tests must be passed. Which of the following is NOT one of the three tests?

  • A. Adequacy test.
  • B. Purpose test.
  • C. Necessity test.
  • D. Balancing test.

正解:A

解説:
The EDPB's Guidelines 8/2020 on the targeting of social media users explain that the legitimate interest legal basis requires passing three cumulative tests: the purpose test, the necessity test, and the balancing test. The purpose test checks whether there is a legitimate interest pursued by the data controller or a third party. The necessity test checks whether the processing is necessary for the purpose identified. The balancing test checks whether the legitimate interest is not overridden by the interests or rights and freedoms of the data subject. The adequacy test is not one of the three tests required by the legitimate interest legal basis. The adequacy test is relevant for data transfers to third countries, not for data processing within the EU.
Reference:
EDPB Guidelines 8/2020 on the targeting of social media users, Section 3.2.11 GDPR Article 6(1)(f)2 GDPR Recital 472 IAPP CIPP/E Study Guide, Chapter 3, Section 3.2.23


質問 # 178
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What must Zandelay provide to the supervisory authority during the prior consultation?

  • A. An evaluation of the complexity of the intended processing.
  • B. An of the purposes and means of the intended processing.
  • C. Records showing that customers have explicitly consented to the intended profiling activities.
  • D. Certificates that prove Martin's professional qualities and expert knowledge of data protection law.

正解:B


質問 # 179
A news website based m (he United Slates reports primarily on North American events The website is accessible to any user regardless of location, as the website operator does not block connections from outside of the U.S. The website offers a pad subscription that requires the creation of a user account; this subscription can only be paid in U.S. dollars.
Which of the following explains why the website operator, who is the responsible for all processing related to account creation and subscriptions, is NOT required to comply with the GDPR?

  • A. The website is not available in several official languages of European Un on Member States
  • B. The website cannot block connections from outside the U.S. that use a Virtual Private Network (VPN) to simulate a US location.
  • C. Payments cannot be made in a European Union currency.
  • D. The controller does not have an establishment in the European Union.

正解:D


質問 # 180
Which of the following is NOT an explicit right granted to data subjects under the GDPR?

  • A. The right to opt-out of the sale of their personal data to third parties.
  • B. The right to request the deletion of data a controller holds about them.
  • C. The right to request access to the personal data a controller holds about them.
  • D. The right to request restriction of processing of personal data, under certain scenarios.

正解:A

解説:
This is not an explicit right granted to data subjects under the GDPR, as the GDPR does not specifically address the sale of personal data. However, the GDPR does require that data subjects give their consent to any processing of their personal data that is not based on another legal basis, such as a contract or a legal obligation1. Therefore, data subjects have the right to withdraw their consent at any time, and the controller must inform them of this right before obtaining their consent2. The other options are explicit rights granted to data subjects under the GDPR, as they are listed in Chapter 3 of the regulation3. Reference:
Free CIPP/E Study Guide, page 23, section 3.1
CIPP/E Certification, page 18, section 3.1
The Ultimate CIPP/E Study Guide for 2023, page 16, section 3.1
GDPR data subject rights - 8 fundamental & additional rights, paragraph 4 Rights of the data subject - General Data Protection Regulation (GDPR), Article 7 Rights of the data subject - General Data Protection Regulation (GDPR), Chapter 3


質問 # 181
Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?

  • A. The right to privacy is an absolute right
  • B. The right to freedom of expression under Article 10 of the ECHR will always override the right to privacy
  • C. The right to privacy has to be balanced against other rights under the ECHR
  • D. The right to privacy protects the right to hold opinions and to receive and impart ideas without interference

正解:C

解説:
Article 8 of the ECHR protects the right to respect for private and family life, home and correspondence. However, this right is not absolute and can be subject to limitations by a public authority in accordance with the law and for a legitimate aim. The European Court of Human Rights (ECtHR) has developed a two-stage test to determine whether such limitations are justified. First, the court must examine whether there is a legitimate aim pursued by the public authority, such as national security, public safety or the prevention of crime. Second, the court must assess whether the means used by the public authority are appropriate and necessary to achieve that aim, taking into account all relevant factors such as proportionality, necessity and less restrictive alternatives12. Therefore, the right to privacy is not an absolute right but a qualified one that has to be balanced against other rights under the ECHR. Reference:
Article 8 - Protection of personal data
Your right to respect for private and family life
Right to respect for private and family life
Guide on Article 8 of the European Convention on Human Rights
European Convention on Human Rights - Article 8


質問 # 182
Which judicial body makes decisions on actions taken by individuals wishing to enforce their rights under EU law?

  • A. Court of Justice of European Union
  • B. European Data Protection Board
  • C. Court of Auditors
  • D. European Court of Human Rights

正解:A

解説:
Reference https://europa.eu/european-union/about-eu/institutions-bodies/court-justice_en


質問 # 183
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA.
Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
As a result of Sam's actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?

  • A. Notify its Data Protection Authority about the data breach.
  • B. Notify all of its customers that reside in the European Union.
  • C. Analyze and evaluate all of its breach notification obligations.
  • D. Analyze and evaluate the liability for customers in Ireland.

正解:A


質問 # 184
SCENARIO
Please use the following to answer the next question:
WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:
"WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the dat a. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information. We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."
"We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."
"We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities." What additional information must Wonderkids provide in their Privacy Statement?

  • A. The categories of recipients with whom data will be shared.
  • B. Contact information of the hosting company.
  • C. Technical and organizational measures to protect data.
  • D. How often promotional emails will be sent.

正解:A


質問 # 185
According to the GDPR, what is the main task of a Data Protection Officer (DPO)?

  • A. To create procedures for notification of personal data breaches to competent supervisory authorities.
  • B. To conduct Privacy Impact Assessments on behalf of the controller or processor.
  • C. To create and maintain records of processing activities.
  • D. To monitor compliance with other local or European data protection provisions.

正解:D

解説:
Reference https://digitalguardian.com/blog/what-data-protection-officer-dpo-learn-about-new-role-required- gdpr-compliance


質問 # 186
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?

  • A. Conducting regular audits of the data protection program.
  • B. Encrypting data in transit and at rest using strong encryption algorithms.
  • C. Anonymizing special categories of data.
  • D. Getting consent from the data subject for a cross border data transfer.

正解:A

解説:
The accountability principle found in Article 5, Section 2 of the GDPR requires data controllers to take responsibility for complying with the GDPR and to be able to demonstrate their compliance1. This means that data controllers must implement appropriate technical and organisational measures to ensure and show that they process personal data in accordance with the GDPR2. One of the measures that can demonstrate compliance with the accountability principle is conducting regular audits of the data protection program. Audits are systematic and independent assessments of the data processing activities and the data protection policies and procedures of an organisation3. They can help to identify and address any gaps or risks in the data protection program, as well as to verify the effectiveness and efficiency of the data protection measures3. Audits can also provide evidence of compliance to the supervisory authorities and the data subjects, as well as to enhance the trust and reputation of the organisation3. Therefore, conducting regular audits of the data protection program is a way to demonstrate compliance with the accountability principle. Reference: 1: CIPP/E study guide, page 15; Art. 5 GDPR; Accountability principle | ICO2: CIPP/E study guide, page 16; Art. 24 GDPR; [Guide to accountability and governance | ICO]3: CIPP/E study guide, page 91; [Auditing | ICO]; [GDPR Audits: What You Need to Know - IT Governance Blog].


質問 # 187
What was the aim of the European Data Protection Directive 95/46/EC?

  • A. To completely prevent the transfer of personal data out of the European Union.
  • B. To further reconcile the protection of the fundamental rights of individuals with the free flow of data from one member state to another.
  • C. To implement the OECD Guidelines on the Protection of Privacy and trans-border flows of Personal Data.
  • D. To harmonize the implementation of the European Convention of Human Rights across all member states.

正解:B

解説:
The aim of the European Data Protection Directive 95/46/EC was to establish a common legal framework for the protection of personal data within the European Union, and to ensure the free movement of such data within the internal market. The Directive was based on the recognition that the processing of personal data affects the fundamental rights and freedoms of individuals, especially their right to privacy, and that these rights need to be respected and safeguarded. At the same time, the Directive acknowledged that the free flow of personal data is essential for the economic and social development of the EU, and that the harmonization of data protection laws would facilitate the exchange of information and the provision of services across the member states. Therefore, the Directive aimed to strike a balance between the protection of individuals' rights and the promotion of the internal market, by laying down the key principles, obligations and rights for the processing of personal data, and by providing mechanisms for cooperation and coordination among the national data protection authorities. Reference: Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, Data Protection Directive - Wikipedia


質問 # 188
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?

  • A. Approved data controllers.
  • B. National data protection authorities.
  • C. The European Data Protection Supervisor.
  • D. The Council of the European Union.

正解:A


質問 # 189
SCENARIO
Please use the following to answer the next Question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
Based on the GDPR's position on the use of personal data for direct marketing purposes, which of the following is true about Louis's rights as a data subject?

  • A. Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.
  • B. Louis does not have the right to object to the use of his data if Bedrock can demonstrate compelling legitimate grounds for the processing.
  • C. Louis has the right to object to the use of his data, unless his data is required by Bedrock for the purpose of exercising a legal claim.
  • D. Louis does not have the right to object to the use of his data because he previously consented to it.

正解:A


質問 # 190
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?

  • A. A voluntary notification for personal data breaches applicable to all data controllers.
  • B. A mandatory notification for personal data breaches applicable to all data controllers.
  • C. A voluntary notification for personal data breaches applicable to electronic communication providers.
  • D. A mandatory notification for personal data breaches applicable to electronic communication providers.

正解:D


質問 # 191
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately
650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What would MOST effectively assist Zandelay in conducting their data protection impact assessment?

  • A. Records of processing activities that data controllers are required to maintain.
  • B. Data breach documentation that data controllers are required to maintain.
  • C. Information about DPIAs found in Articles 38 through 40 of the GDPR.
  • D. Existing DPIA guides published by local supervisory authorities.

正解:C


質問 # 192
When is data sharing agreement MOST likely to be needed?

  • A. When personal data is being shared between commercial organizations acting as joint data controllers.
  • B. When anonymized data is being shared.
  • C. When personal data is being proactively shared by a controller to support a police investigation.
  • D. When personal data is being shared with a public authority with powers to require the personal data to be disclosed.

正解:A


質問 # 193
......

CIPP-E試験問題集で100%高得点させるCIPP-E試験解答がこちら:https://www.passtest.jp/IAPP/CIPP-E-shiken.html

検証済みのCIPP-E試験問題成功確定させます:https://drive.google.com/open?id=1p9wgubSiKhx9K1qNg4YnJE87gpbq-CIA