Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CIPT Questions Bank

Page: 2 / 16
Question 8

SCENARIO

Please use the following to answer the next question:

Jordan just joined a fitness-tracker start-up based in California, USA, as its first Information Privacy and Security Officer. The company is quickly growing its business but does not sell any of the fitness trackers itself. Instead, it relies on a distribution network of third-party retailers in all major countries. Despite not having any stores, the company has a 78% market share in the EU. It has a website presenting the company and products, and a member section where customers can access their information. Only the email address and physical address need to be provided as part of the registration process in order to customize the site to the user’s region and country. There is also a newsletter sent every month to all members featuring fitness tips, nutrition advice, product spotlights from partner companies based on user behavior and preferences.

Jordan says the General Data Protection Regulation (GDPR) does not apply to the company. He says the company is not established in the EU, nor does it have a processor in the region. Furthermore, it does not do any “offering goods or services” in the EU since it does not do any marketing there, nor sell to consumers directly. Jordan argues that it is the customers who chose to buy the products on their own initiative and there is no “offering” from the company.

The fitness trackers incorporate advanced features such as sleep tracking, GPS tracking, heart rate monitoring. wireless syncing, calorie-counting and step-tracking. The watch must be paired with either a smartphone or a computer in order to collect data on sleep levels, heart rates, etc. All information from the device must be sent to the company’s servers in order to be processed, and then the results are sent to the smartphone or computer. Jordan argues that there is no personal information involved since the company does not collect banking or social security information.

Why is Jordan’s claim that the company does not collect personal information as identified by the GDPR inaccurate?

Options:

A.

The potential customers must browse for products online.

B.

The fitness trackers capture sleep and heart rate data to monitor an individual’s behavior.

C.

The website collects the customers’ and users’ region and country information.

D.

The customers must pair their fitness trackers to either smartphones or computers.

Question 9

When analyzing user data, how is differential privacy applied?

Options:

A.

By injecting noise into aggregated datasets.

B.

By assessing differences between datasets.

C.

By applying asymmetric encryption to datasets.

D.

By removing personal identifiers from datasets.

Question 10

What is the most effective first step to take to operationalize Privacy by Design principles in new product development and projects?

Options:

A.

Implementing a mandatory privacy review and legal approval process.

B.

Obtain leadership buy-in for a mandatory privacy review and approval process.

C.

Set up an online Privacy Impact Assessment tool to facilitate Privacy by Design compliance.

D.

Conduct annual Privacy by Design training and refreshers for all impacted personnel.

Question 11

An individual drives to the grocery store for dinner. When she arrives at the store, she receives several unsolicited notifications on

her phone about discounts on items at the grocery store she is about to shop at. Which type of privacy problem does the represent?

Options:

A.

Intrusion.

B.

Surveillance.

C.

Decisional Interference.

D.

Exposure.

Page: 2 / 16
Exam Code: CIPT
Exam Name: Certified Information Privacy Technologist
Last Update: Nov 23, 2024
Questions: 220
CIPT pdf

CIPT PDF

$25.5  $84.99
CIPT Engine

CIPT Testing Engine

$28.5  $94.99
CIPT PDF + Engine

CIPT PDF + Testing Engine

$40.5  $134.99