Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

IAPP CIPP-E Based on Real Exam Environment

Page: 9 / 19
Question 36

Which of the following is one of the supervisory authority’s investigative powers?

Options:

A.

To notify the controller or the processor of an alleged infringement of the GDPR.

B.

To require that controllers or processors adopt approved data protection certification mechanisms.

C.

To determine whether a controller or processor has the right to a judicial remedy concerning a compensation decision made against them.

D.

To require data controllers to provide them with written notification of all new processing activities.

Question 37

SCENARIO

Please use the following to answer the next question:

ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.

Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain’s locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.

Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.

In which of the following situations would ABC Hotel Chain and XYZ Travel Agency NOT have to honor Mike’s data access request?

Options:

A.

The request is to obtain access and correct inaccurate personal data in his profile.

B.

The request is to obtain access and information about the purpose of processing his personal data.

C.

The request is to obtain access and erasure of his personal data while keeping his rewards membership.

D.

The request is to obtain access and the categories of recipients who have received his personal data to process his rewards membership.

Question 38

According to the GDPR, what is the main task of a Data Protection Officer (DPO)?

Options:

A.

To create and maintain records of processing activities.

B.

To conduct Privacy Impact Assessments on behalf of the controller or processor.

C.

To monitor compliance with other local or European data protection provisions.

D.

To create procedures for notification of personal data breaches to competent supervisory authorities.

Question 39

Sanctions for non-compliance with the EU Artificial Intelligence Act (Al Act) could result in a maximum fine of?

Options:

A.

The higher of up to 10 million Euro or up to 2% of the entity's total worldwide turnover for the preceding financial year.

B.

The higher of up to 40 million Euro or up to 8% of the entity's total worldwide turnover for the preceding financial year.

C.

The higher of up to 20 million Euro or up to 4% of the entity's total worldwide turnover for the preceding financial year.

D.

The higher of up to 30 million Euro or up to 6% of the entity's total worldwide turnover for the preceding financial year.

Page: 9 / 19
Exam Code: CIPP-E
Exam Name: Certified Information Privacy Professional/Europe (CIPP/E)
Last Update: Nov 21, 2024
Questions: 268
CIPP-E pdf

CIPP-E PDF

$28  $80
CIPP-E Engine

CIPP-E Testing Engine

$33.25  $95
CIPP-E PDF + Engine

CIPP-E PDF + Testing Engine

$45.5  $130