New DumpsReview CIPP-C Exam Questions Real CIPP-C Dumps Updated on Mar 17, 2022 [Q101-Q125]

Share

New DumpsReview CIPP-C Exam Questions| Real CIPP-C Dumps Updated on Mar 17, 2022

CIPP-C Braindumps – CIPP-C Questions to Get Better Grades


How to prepare for the IAPP CIPP-C Certification Exam

Preparation Guide for the IAPP CIPP-C Certification Exam

IAPP CIPP-C: Tips to solve the CIPP-C exam If you don't have time to read all the pages of the syllabus

The IAPP CIPP-C certification exam is an important exam for those wanting to become a qualified Privacy Professional. This certification is the most popular of all IAPP certifications, with great demand worldwide. This blog is going to cover in brief how to prepare for the CIPP-C exam and some pointers on information to expect when meeting with a Financial Learning Company representative. IAPP CIPP-C exam dumps are available online which can be used to assist you in preparing for this exam.

 

NEW QUESTION 101
What should a controller do after a data subject opts out of a direct marketing activity?

  • A. Take reasonable steps to inform third-party recipients that the data subject's personal data should be deleted and no longer processed.
  • B. Refrain from processing personal data relating to the data subject for the relevant type of communication.
  • C. Without exception, securely delete all personal data relating to the data subject.
  • D. Without undue delay, provide information to the data subject on the action that will be taken.

Answer: B

 

NEW QUESTION 102
A mobile device application that uses cookies will be subject to the consent requirement of which of the following?

  • A. The E-Commerce Directive
  • B. The ePrivacy Directive
  • C. The EU Cybersecurity Directive
  • D. The Data Retention Directive

Answer: B

 

NEW QUESTION 103
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?

  • A. Within one month of receipt, which may be extended by up to an additional month
  • B. Within 40 days of receipt
  • C. Within one month of receipt, which may be extended by an additional two months
  • D. Within 40 days of receipt, which may be extended by up to 40 additional days

Answer: A

 

NEW QUESTION 104
SCENARIO
Please use the following to answer the next question:
The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its website as a free download. Vigotron's marketing manager asks his assistant Emily to create a webpage that describes the app and specifies the terms of use. Emily, who is new at Vigotron, is excited about this task.
At her previous job she took a data protection class, and though the details are a little hazy, she recognizes that Vigotron is going to need to obtain user consent for use of the app in some cases. Emily sketches out the following draft, trying to cover as much as possible before sending it to Vigotron's legal department.
Registration Form
Vigotron's new M-Health app makes it easy for you to monitor a variety of health-related activities, including diet, exercise, and sleep patterns. M-Health relies on your smartphone settings (along with other third-party apps you may already have) to collect data about all of these important lifestyle elements, and provide the information necessary for you to enrich your quality of life. (Please click here to read a full description of the services that M-Health provides.) Vigotron values your privacy. The M-Heaith app allows you to decide which information is stored in it, and which apps can access your data. When your device is locked with a passcode, all of your health and fitness data is encrypted with your passcode. You can back up data stored in the Health app to Vigotron's cloud provider, Stratculous. (Read more about Stratculous here.) Vigotron will never trade, rent or sell personal information gathered from the M-Health app. Furthermore, we will not provide a customer's name, email address or any other information gathered from the app to any third- party without a customer's consent, unless ordered by a court, directed by a subpoena, or to enforce the manufacturer's legal rights or protect its business or property.
We are happy to offer the M-Health app free of charge. If you want to download and use it, we ask that you first complete this registration form. (Please note that use of the M-Health app is restricted to adults aged 16 or older, unless parental consent has been given to minors intending to use it.)
* First name:
* Surname:
* Year of birth:
* Email:
* Physical Address (optional*):
* Health status:
*If you are interested in receiving newsletters about our products and services that we think may be of interest to you, please include your physical address. If you decide later that you do not wish to receive these newsletters, you can unsubscribe by sending an email to [email protected] or send a letter with your request to the address listed at the bottom of this page.
Terms and Conditions
1.Jurisdiction. [...]
2.Applicable law. [...]
3.Limitation of liability. [...]
Consent
By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of any advertising or marketing, you agree that Vigotron may contact you or provide you with any required notices, agreements, or other information concerning the services by email or other electronic means. You also agree that the Company may send automated emails with alerts regarding any problems with the M-Health app that may affect your well being.
Emily sends the draft to Sam for review. Which of the following is Sam most likely to point out as the biggest problem with Emily's consent provision?

  • A. It is not legal to include fields requiring information regarding health status without consent.
  • B. Direct marketing requires explicit consent, whereas the registration form only provides for a right to object
  • C. Processing health data requires explicit consent, but the form does not ask for explicit consent.
  • D. The provision of the fitness app should be made conditional on the consent to the data processing for direct marketing.

Answer: B

 

NEW QUESTION 105
What is the key difference between the European Council and the Council of the European Union?

  • A. The Council of the European Union has a degree of legislative power.
  • B. The European Council is comprised of the heads of each EU member state.
  • C. The European Council focuses primarily on issues involving human rights.
  • D. The Council of the European Union is helmed by a president.

Answer: B

 

NEW QUESTION 106
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?

  • A. If the company's status as a documentary provider allows it to claim legitimate interest.
  • B. If the company limits the footage to data subjects solely of legal age.
  • C. If obtaining consent is deemed voluntary by local legislation.
  • D. If obtaining consent is deemed to involve disproportionate effort.

Answer: C

 

NEW QUESTION 107
Which is the best way to view an organization's privacy framework?

  • A. As an industry benchmark that can apply to many organizations
  • B. As a fixed structure that directs changes in the organization
  • C. As an aspirational goal that improves the organization
  • D. As a living structure that aligns to changes in the organization

Answer: B

 

NEW QUESTION 108
Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002/58/EC)?

  • A. An email from a retail outlet promoting a sale to one of their previous customer.
  • B. Advertisements passively displayed on a website.
  • C. The use of cookies to collect data about an individual.
  • D. A text message to individuals from a company offering concert tickets for sale.

Answer: B

 

NEW QUESTION 109
A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, the company decides on a CCTV system to monitor for future incidents. Company technicians install cameras in the entrance of the building, hallways and offices. Footage is recorded continuously, and is monitored by the home office in the United States. What is the most realistic step the company could take to address their security concerns and comply with the personal data processing principles set out in Article 5 of the GDPR?

  • A. Have cameras recording during work hours only.
  • B. Retain captured footage for no more than 30 days.
  • C. Seek informed consent from company employees.
  • D. Restrict camera placement to building entrances only.

Answer: C

 

NEW QUESTION 110
What is true if an employee makes an access request to his employer for any personal data held about him?

  • A. The employer must supply any information held about an employee unless an exemption applies.
  • B. The employer must supply all the information held about the employee.
  • C. The employer can automatically decline the request if it contains personal data about a third person.
  • D. The employer can decline the request if the information is only held electronically.

Answer: A

 

NEW QUESTION 111
SCENARIO
Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.
You also recall a recent visit to the Records Storage Section, often termed "The Dungeon" in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage.
Which regulation most likely applies to the data stored by Berry Country Regional Medical Center?

  • A. The European Union Directive 95/46/EC
  • B. The Health Records Act 2001
  • C. Personal Information Protection and Electronic Documents Act
  • D. Health Insurance Portability and Accountability Act

Answer: C

 

NEW QUESTION 112
SCENARIO
Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.
You also recall a recent visit to the Records Storage Section, often termed "The Dungeon" in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage.
Which data lifecycle phase needs the most attention at this Ontario medical center?

  • A. Use
  • B. Retention
  • C. Disclosure
  • D. Collection

Answer: B

 

NEW QUESTION 113
Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?

  • A. Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.
  • B. Categories of processing carried out on behalf of each controller for which the processor is acting.
  • C. Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.
  • D. Name and contact details of each controller on behalf of which the processor is acting.

Answer: A

 

NEW QUESTION 114
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
Who-R-U is NOT required to notify the local German DPA about the laptop theft because?

  • A. There is no evidence that the thieves have accessed the data on the laptop.
  • B. The company isn't a controller established in the Union.
  • C. The laptop belonged to a company located in Canada.
  • D. The data isn't considered personally identifiable financial information.

Answer: B

 

NEW QUESTION 115
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?

  • A. Special categories of data
  • B. Cross-border processing
  • C. Data subject rights
  • D. Data access disputes

Answer: B

 

NEW QUESTION 116
Read the following steps:
* Discover which employees are accessing cloud services and from which devices and apps Lock down the data in those apps and devices
* Monitor and analyze the apps and devices for compliance
* Manage application life cycles
* Monitor data sharing
An organization should perform these steps to do which of the following?

  • A. Institute a GDPR-compliant employee monitoring process.
  • B. Ensure cloud vendors are complying with internal data use policies.
  • C. Maintain a secure Bring Your Own Device (BYOD) program.
  • D. Pursue a GDPR-compliant Privacy by Design process.

Answer: C

 

NEW QUESTION 117
SCENARIO
Please use the following to answer the next QUESTION:
Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has become a grand event. It fills one of the large downtown conference hotels and overflows into the others, with several thousand attendees enjoying three days of presentations, panel discussions and networking. The convention is the centerpiece of the company's product rollout schedule and a great training opportunity for current users. The sales force also encourages prospective clients to attend to get a better sense of the ways in which the system can be customized to meet diverse needs and understand that when they buy into this system, they are joining a community that feels like family.
This year's conference is only three weeks away, and you have just heard news of a new initiative supporting it: a smartphone app for attendees. The app will support late registration, highlight the featured presentations and provide a mobile version of the conference program. It also links to a restaurant reservation system with the best cuisine in the areas featured. "It's going to be great," the developer, Deidre Hoffman, tells you, "if, that is, we actually get it working!" She laughs nervously but explains that because of the tight time frame she'd been given to build the app, she outsourced the job to a local firm. "It's just three young people," she says, "but they do great work." She describes some of the other apps they have built. When asked how they were selected for this job, Deidre shrugs. "They do good work, so I chose them." Deidre is a terrific employee with a strong track record. That's why she's been charged to deliver this rushed project. You're sure she has the best interests of the company at heart, and you don't doubt that she's under pressure to meet a deadline that cannot be pushed back. However, you have concerns about the app's handling of personal data and its security safeguards. Over lunch in the break room, you start to talk to her about it, but she quickly tries to reassure you, "I'm sure with your help we can fix any security issues if we have to, but I doubt there'll be any. These people build apps for a living, and they know what they're doing. You worry too much, but that's why you're so good at your job!" Since it is too late to restructure the contract with the vendor or prevent the app from being deployed, what is the best step for you to take next?

  • A. Implement a more comprehensive suite of information security controls than the one used by the vendor
  • B. Develop security protocols for the vendor and mandate that they be deployed
  • C. Ask the vendor for verifiable information about their privacy protections so weaknesses can be identified
  • D. Insist on an audit of the vendor's privacy procedures and safeguards

Answer: C

 

NEW QUESTION 118
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
The Customer for Life plan may conflict with which GDPR provision?

  • A. Article 16, which provides data subjects with a rights to rectification.
  • B. Article 7, which requires consent to be as easy to withdraw as it is to give.
  • C. Article 6, which requires processing to be lawful.
  • D. Article 20, which gives data subjects a right to data portability.

Answer: B

 

NEW QUESTION 119
In 2016's Guidance, the United Kingdom's Information Commissioner's Office (ICO) reaffirmed the importance of using a "layered notice" to provide data subjects with what?

  • A. A privacy notice containing brief information whilst offering access to further detail.
  • B. A privacy notice explaining the consequences for opting out of the use of cookies on a website.
  • C. An efficient means of providing written consent in member states where they are required to do so.
  • D. An explanation of the security measures used when personal data is transferred to a third party.

Answer: A

 

NEW QUESTION 120
What obligation does a data controller or processor have after appointing a data protection officer?

  • A. To submit for approval to the data protection officer a code of conduct to govern organizational practices and demonstrate compliance with data protection principles.
  • B. To ensure that the data protection officer acts as the sole point of contact for individuals' Questions:
    about their personal data.
  • C. To provide resources necessary to carry out the defined tasks of the data protection officer and to maintain his or her expert knowledge.
  • D. To ensure that the data protection officer receives sufficient instructions regarding the exercise of his or her defined tasks.

Answer: A

 

NEW QUESTION 121
What is the function of the privacy operational life cycle?

  • A. It establishes initial plans for privacy protection and implementation
  • B. It allows the organization to respond to ever-changing privacy demands
  • C. It ensures that outdated privacy policies are retired on a set schedule
  • D. It allows privacy policies to mature to a fixed form

Answer: A

 

NEW QUESTION 122
Which of the following is an example of direct marketing that would be subject to European data protection laws?

  • A. A revision of contract terms conveyed to an individual by SMS from a marketing organization.
  • B. A charity fundraising event notice sent to an individual at her business address.
  • C. A service outage notification provided to an individual by recorded telephone message.
  • D. An updated privacy notice sent to an individual's personal email address.

Answer: B

 

NEW QUESTION 123
When would a data subject NOT be able to exercise the right to portability?

  • A. When the data was supplied to the controller by the data subject.
  • B. When the processing is necessary to perform a task in the exercise of authority vested in the controller.
  • C. When the processing is based on consent.
  • D. When the processing is carried out pursuant to a contract with the data subject.

Answer: B

 

NEW QUESTION 124
SCENARIO
Please use the following to answer the next question:
Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Javier lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Javier was photographed while working out at a branch of EVERFIT in Frankfurt, Germany. At the time, Javier gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club's U.K.
brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Javier no longer feels comfortable with his photograph being publicly associated with the fitness club.
After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Javier sends a letter to EVETFIT requesting that his image be removed from the website and all promotional materials. Months pass and Javier, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact EVETFIT through alternate channels, he decides to take action against the company.
Javier contacts the U.K. Information Commissioner's Office ('ICO' - the U.K.'s supervisory authority) to lodge a complaint about this matter. The ICO, pursuant to Article 56 (3) of the GDPR, informs the CNIL (i.e.
the supervisory authority of EVERFIT's main establishment) about this matter. Despite the fact that EVERFIT has an establishment in the U.K., the CNIL decides to handle the case in accordance with Article 60 of the GDPR. The CNIL liaises with the ICO, as relevant under the cooperation procedure. In light of issues amongst the supervisory authorities to reach a decision, the European Data Protection Board becomes involved and, pursuant to the consistency mechanism, issues a binding decision.
Additionally, Javier sues EVERFIT for the damages caused as a result of its failure to honor his request to have his photograph removed from the brochure and website.
Under the cooperation mechanism, what should the lead authority (the CNIL) do after it has formed its view on the matter?

  • A. Request that the other supervisory authorities provide the lead authority with a draft decision for its consideration.
  • B. Submit a draft decision directly to the Commission to ensure the effectiveness of the consistency mechanism.
  • C. Submit a draft decision to other supervisory authorities for their opinion.
  • D. Request that members of the seconding supervisory authority and the host supervisory authority co-draft a decision.

Answer: A

 

NEW QUESTION 125
......

CIPP-C Exam Dumps - Try Best CIPP-C Exam Questions: https://www.dumpsreview.com/CIPP-C-exam-dumps-review.html

Get New CIPP-C Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1e0wFoea8FRyUGe6BncY6rrbHFwwCvvey