
無料提供されるCIPP-E問題集とCIPP-Eリアル試験問題
IAPP CIPP-E実際の問題とブレーン問題集
質問 119
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees. These records are available to former students after registering through Granchester's Alumni portal. Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Which of the University's records does Anna NOT have to include in her record of processing activities?
- A. Department for Education records
- B. Staff and alumni records
- C. Student records
- D. Frank's performance database
正解: D
質問 120
After leaving the EU under the terms of Brexit, the United Kingdom will seek an adequacy determination. What is the reason for this?
- A. The UK is less trustworthy now that its not part of the Union.
- B. The Insurance Commissioner determined that an adequacy determination is required by the Data Protection Act.
- C. Adequacy determinations automatically lapse when a Member State leaves the EU.
- D. The UK is now a third country because it's no longer subject to the GDPR.
正解: D
質問 121
If a multi-national company wanted to conduct background checks on all current and potential employees, including those based in Europe, what key provision would the company have to follow?
- A. Background checks on employees could be performed only under prior notice to all employees.
- B. Background checks are only authorized with prior notice and express consent from all employees including those based in Europe.
- C. Background checks may not be allowed on European employees, but the company can create lists based on its legitimate interests, identifying individuals who are ineligible for employment.
- D. Background checks on European employees will stem from data protection and employment law, which can vary between member states.
正解: D
質問 122
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
- A. Retention periods for erasure and deletion of categories of personal data.
Section: (none)
Explanation - B. Data inventory or data mapping exercises that have been conducted.
- C. Categories of recipients to whom the personal data have been disclosed.
- D. Incidents of personal data breaches, whether disclosed or not.
正解: A
質問 123
What must a data controller do in order to make personal data pseudonymous?
- A. Use the data only in aggregated form for research purposes.
- B. Encrypt the data in order to prevent any unauthorized access or modification.
- C. Separately hold any information that would allow linking the data to the data subject.
- D. Remove all indirect data identifiers and dispose of them securely.
正解: C
質問 124
In which situation would a data controller most likely be able to justify the processing of the data of a child without parental consent?
- A. When a legitimate business interest makes obtaining consent impractical.
- B. When providing preventive or counselling services to the child.
- C. When the data is to be processed for market research.
- D. When providing the child with materials purely for educational use.
正解: B
質問 125
SCENARIO
Please use the following to answer the next question:
The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its website as a free download. Vigotron's marketing manager asks his assistant Emily to create a webpage that describes the app and specifies the terms of use. Emily, who is new at Vigotron, is excited about this task. At her previous job she took a data protection class, and though the details are a little hazy, she recognizes that Vigotron is going to need to obtain user consent for use of the app in some cases. Emily sketches out the following draft, trying to cover as much as possible before sending it to Vigotron's legal department.
Registration Form
Vigotron's new M-Health app makes it easy for you to monitor a variety of health-related activities, including diet, exercise, and sleep patterns. M-Health relies on your smartphone settings (along with other third-party apps you may already have) to collect data about all of these important lifestyle elements, and provide the information necessary for you to enrich your quality of life. (Please click here to read a full description of the services that M-Health provides.) Vigotron values your privacy. The M-Heaith app allows you to decide which information is stored in it, and which apps can access your dat a. When your device is locked with a passcode, all of your health and fitness data is encrypted with your passcode. You can back up data stored in the Health app to Vigotron's cloud provider, Stratculous. (Read more about Stratculous here.) Vigotron will never trade, rent or sell personal information gathered from the M-Health app. Furthermore, we will not provide a customer's name, email address or any other information gathered from the app to any third- party without a customer's consent, unless ordered by a court, directed by a subpoena, or to enforce the manufacturer's legal rights or protect its business or property.
We are happy to offer the M-Health app free of charge. If you want to download and use it, we ask that you first complete this registration form. (Please note that use of the M-Health app is restricted to adults aged 16 or older, unless parental consent has been given to minors intending to use it.) First name:
Surname:
Year of birth:
Email:
Physical Address (optional*):
Health status:
*If you are interested in receiving newsletters about our products and services that we think may be of interest to you, please include your physical address. If you decide later that you do not wish to receive these newsletters, you can unsubscribe by sending an email to [email protected] or send a letter with your request to the address listed at the bottom of this page.
Terms and Conditions
1. Jurisdiction. [...]
2. Applicable law. [...]
3. Limitation of liability. [...]
Consent
By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of any advertising or marketing, you agree that Vigotron may contact you or provide you with any required notices, agreements, or other information concerning the services by email or other electronic means. You also agree that the Company may send automated emails with alerts regarding any problems with the M-Health app that may affect your well being.
Emily sends the draft to Sam for review. Which of the following is Sam most likely to point out as the biggest problem with Emily's consent provision?
- A. Processing health data requires explicit consent, but the form does not ask for explicit consent.
- B. The provision of the fitness app should be made conditional on the consent to the data processing for direct marketing.
- C. Direct marketing requires explicit consent, whereas the registration form only provides for a right to object
- D. It is not legal to include fields requiring information regarding health status without consent.
正解: C
質問 126
When may browser settings be relied upon for the lawful application of cookies?
- A. When a user rejects cookies that are strictly necessary.
- B. When users are provided with information about which cookies have been set.
- C. When it is impossible to bypass the choices made by users in their browser settings.
- D. When users are aware of the ability to adjust their settings.
正解: D
質問 127
What is a reason the European Court of Justice declared the Data Retention Directive invalid in 2014?
- A. The requirements specified that data must be held within the EU.
- B. The requirements were financially burdensome to EU businesses.
- C. The requirements affected individuals without exception.
- D. The requirements had limitations on how national authorities could use data.
正解: D
解説:
Reference:
%20the%20Grand,proportionality%20in%20forging%20the%20Directive.
質問 128
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
- A. A company wants to use location data to infer information on a person's clothes purchasing habits.
- B. A company wants to combine location data with other data in order to offer more personalized service for the customer.
- C. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- D. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
正解: C
質問 129
SCENARIO
Please use the following to answer the next question:
ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
What is the time period in which Mike should receive a response to his request?
- A. When all the information about Mike has been collected.
- B. Not more than one month of receipt of Mike's request.
- C. Not more than two months after verifying Mike's identity.
- D. Not more than thirty days after submission of Mike's request.
正解: D
質問 130
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Why would the consent provided by Ms. Iman NOT be considered valid in regard to JaphSoft?
- A. She was not told which controller would be processing her personal data.
- B. She did not read the privacy notice stating that her personal data would be shared.
- C. She has never made any purchases from JaphSoft and has no relationship with the company.
- D. She only viewed the visual representations of the privacy notice Liem provided.
正解: B
質問 131
According to the E-Commerce Directive 2000/31/EC, where is the place of "establishment" for a company providing services via an Internet website confirmed by the GDPR?
- A. Where the website is accessed
- B. Where the technology supporting the website is located
- C. Where the decisions about processing are made
- D. Where the customer's Internet service provider is located
正解: D
解説:
Explanation/Reference: https://www.ohiobar.org/member-tools-benefits/publications/Ohio-Lawyer/the-european-general- data-protection-regulation-gdpr/
質問 132
A Spanish electricity customer calls her local supplier with questions about the company's upcoming merger. Specifically, the customer wants to know the recipients to whom her personal data will be disclosed once the merger is final. According to Article 13 of the GDPR, what must the company do before providing the customer with the requested information?
- A. Verify that the identity of the customer can be proven by other means.
- B. Verify that the purpose of the request from the customer is in line with the GDPR.
- C. Verify that the request is applicable to the data collected before the GDPR entered into force.
- D. Verify that the personal data has not already been sent to the customer.
正解: C
質問 133
SCENARIO
Please use the following to answer the next question:
Sandy recently joined Market4U, an advertising technology company founded in 2016, as their VP of Privacy and Data Governance. Through her first initiative in conducting a data inventory, Sandy learned that Market4U maintains a list of 19 million global contacts that were collected throughout the course of Market4U's existence. Knowing the risk of having such a large amount of data, Sandy wanted to purge all contacts that were entered into Market4U's systems prior to May 2018, unless such contacts had a more recent interaction with Market4U content. However, Dan, the VP of Sales, informed Sandy that all of the contacts provide useful information regarding successful marketing campaigns and trends in industry verticals for Market4U's clients.
Dan also informed Sandy that he had wanted to focus on gaining more customers within the sports and entertainment industry. To assist with this behavior, Market4U's marketing team decided to add several new fields to Market4U's website forms, including forms for downloading white papers, creating accounts to participate in Market4U's forum, and attending events. Such fields include birth date and salary.
What should Sandy give as feedback to Dan and the marketing team regarding the new fields Dan wants to add to Market4U's forms?
- A. Make all the fields optional.
- B. Eliminate the fields as they are not necessary for the purposes of providing white papers or registration for events.
- C. Eliminate the fields, as they are not proportional to the services being offered.
- D. Only request the information in brackets (i.e., age group and salary range).
正解: B
質問 134
What is an important difference between the European Court of Human Rights (ECHR) and the Court of Justice of the European Union (CJEU) in relation to their roles and functions?
- A. CJEU can hear appeals on human rights decisions made by national courts, while the ECHR cannot.
- B. CJEU can force national governments to implement and honor EU law, while the ECHR cannot.
- C. ECHR can enforce human rights laws against governments that fail to implement them, while the CJEU cannot.
- D. ECHR can rule on issues concerning privacy as a fundamental right, while the CJEU cannot.
正解: B
質問 135
Under the GDPR, which of the following is true in regard to adequacy decisions involving cross-border transfers?
- A. EU member states are vested with the power to accept or reject a European Commission adequacy decision.
- B. To be considered as adequate, third countries must implement the EU General Data Protection Regulation into their national legislation.
- C. The European Commission can adopt an adequacy decision for individual companies.
- D. The European Commission can adopt, repeal or amend an existing adequacy decision.
正解: C
解説:
Explanation/Reference: https://www.futurelearn.com/courses/general-data-protection-regulation/0/steps/32449
質問 136
SCENARIO
Please use the following to answer the next question:
Jason, a long-time customer of ABC insurance, was involved in a minor car accident a few months ago.
Although no one was hurt, Jason has been plagued by texts and calls from a company called Erbium Insurance offering to help him recover compensation for personal injury. Jason has heard about insurance companies selling customers' data to third parties, and he's convinced that Erbium must have gotten his information from ABC.
Jason has also been receiving an increased amount of marketing information from ABC, trying to sell him their full range of their insurance policies.
Perturbed by this, Jason has started looking at price comparison sites on the Internet and has been shocked to find that other insurers offer much cheaper rates than ABC, even though he has been a loyal customer for many years. When his ABC policy comes up for renewal, he decides to switch to Xentron Insurance.
In order to activate his new insurance policy, Jason needs to supply Xentron with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask ABC to transfer his information directly to Xentron. He also takes this opportunity to ask ABC to stop using his personal data for marketing purposes.
ABC supplies Jason with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Jason it cannot transfer his data directly to Xentron at this is not technically feasible. ABC also explains that Jason's contract included a provision whereby Jason agreed that his data could be used for marketing purposes; according to ABC, it is too late for Jason to change his mind about this. It angers Jason when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Jason is still receiving unwanted calls from Erbium Insurance. He writes to Erbium to ask for the name of the organization that supplied his details to them. He warns Erbium that he plans to complain to the data protection authority because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Erbium's response letter confirms Jason's suspicions. Erbium is ABC's wholly owned subsidiary, and they received information about Jason's accident from ABC shortly after Jason submitted his accident claim.
Erbium assures Jason that there has been no breach of the GDPR, as Jason's contract included a provision in which he agreed to share his information with ABC's affiliates for business purposes.
Jason is disgusted by the way in which he has been treated by ABC, and writes to them insisting that all his information be erased from their computer system.
Which statement accurately summarizes ABC's obligation in regard to Jason's data portability request?
- A. ABC has failed to comply with the duty to transfer Jason's data to Xentron because the duty applies wherever personal data are processed by automated means and necessary for the performance of a contract with the customer.
- B. ABC does not have to transfer Jason's data to Xentron because the right to data portability does not apply where personal data are processed in order to carry out tasks in the public interest.
- C. ABC has failed to comply with the duty to transfer Jason's data to Xentron because it has an obligation to develop commonly used, machine-readable and interoperable formats so that all customer data can be ported to other insurers on request.
- D. ABC does not have a duty to transfer Jason's data to Xentron if doing so is legitimately not technically feasible.
正解: B
質問 137
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
- A. When the controller is collecting email addresses from individuals via an online registration form for marketing purposes.
- B. When personal data is being collected and combined with other personal data to profile the creditworthiness of individuals.
- C. When personal data is being transferred outside of the EEA.
- D. When the controller is required to have a Data Protection Officer.
正解: D
解説:
Reference:
%20the%20General,and%20freedoms%20of%20natural%20persons%27.
質問 138
Data retention in the EU was underpinned by a legal framework established by the Data Retention Directive (2006/24/EC). Why is the Directive no longer part of EU law?
- A. The Directive was superseded by the EU Directive on Privacy and Electronic Communications.
- B. The Directive was annulled by the European Court of Human Rights.
- C. The Directive was superseded by the General Data Protection Regulation.
- D. The Directive was annulled by the Court of Justice of the European Union.
正解: D
質問 139
An organisation receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal dat a. Under what condition can the organisation charge the data subject for processing the request?
- A. Only if the organisation can demonstrate that the request is clearly excessive or misguided.
- B. Only where the administrative costs of taking the action requested exceeds a certain threshold.
- C. Only to the extent this is allowed under the restrictions on data subjects' rights introduced under Art 23 of GDPR.
- D. Only where the organisation can show that it is reasonable to do so because more than one request was made.
正解: A
質問 140
Under the GDPR, which essential pieces of information must be provided to data subjects before collecting their personal data?
- A. The name/s of relevant government agencies involved and the steps needed for revising the data.
- B. The contact information of the controller and a description of the retention policy.
- C. The authority by which the controller is collecting the data and the third parties to whom the data will be sent.
- D. The identity and contact details of the controller and the reasons the data is being collected.
正解: D
解説:
Explanation/Reference: https://gdpr-info.eu/art-13-gdpr/
質問 141
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location.
During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization.
The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
To comply with the GDPR, what should Building Block have done as a first step before implementing the SecurityScan measure?
- A. Consulted with the relevant data protection authority about potential privacy violations.
- B. Assessed potential privacy risks by conducting a data protection impact assessment.
- C. Consulted with the Information Security team to weigh security measures against possible server impacts.
- D. Distributed a more comprehensive notice to employees and received their express consent.
正解: D
質問 142
In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?
- A. When emailing a customer to announce that his recent order should arrive earlier than expected.
- B. When paying a search engine company to give prominence to certain products and services within specific search results.
- C. When calling a potential customer to notify her of an upcoming product sale.
- D. When creating an untargeted pop-up ad on a website.
正解: D
質問 143
......
CIPP-E合格させる問題集でIAPP24時間で試験合格できます:https://www.passtest.jp/IAPP/CIPP-E-shiken.html
最新問題を使おうCIPP-E試験問題と解答PDFで一年間無料更新:https://drive.google.com/open?id=1Cq2Wkp21WKw3IGaVfVEv54hxVjcUH68_