Official Bank 0/292

Certified Information Privacy Professional/Europe (CIPP/E) Exam (CIPP) - IAPP Actual Exam Questions

Last updated on May 02, 2026

97% Exam Compliance
292 Total Questions
1
Question

Company X has entrusted the processing of their payroll data to Provider

Options
A

The public

B

Company X

C

Law enforcement

D

The supervisory authority

E

Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server. In this scenario, whom does Provider Y have the obligation to notify?

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

Which kind of privacy notice, originally advocated by the Article 29 Working Party, is commonly recommended tor Al-based technologies because of the way it provides processing information at specific points of data collection?

Options
A

Privacy dashboard notice

B

Visualization notice.

C

Just-in-lime notice.

D

Layered notice.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

In 2016’s Guidance, the United Kingdom’s Information Commissioner’s Office (ICO) reaffirmed the importance of using a “layered notice” to provide data subjects with what?

Options
A

A privacy notice containing brief information whilst offering access to further detail.

B

A privacy notice explaining the consequences for opting out of the use of cookies on a website.

C

An explanation of the security measures used when personal data is transferred to a third party.

D

An efficient means of providing written consent in member states where they are required to do so.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?

Options
A

When creating an untargeted pop-up ad on a website.

B

When calling a potential customer to notify her of an upcoming product sale.

C

When emailing a customer to announce that his recent order should arrive earlier than expected.

D

When paying a search engine company to give prominence to certain products and services within specific search results.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

According to the GDPR, when should the processing of photographs be considered processing of special categories of personal data?

Options
A

When processed with the intent to publish information regarding a natural person on publicly accessible media.

B

When processed with the intent to proceed to scientific or historical research projects.

C

When processed with the intent to uniquely identify or authenticate a natural person.

D

When processed with the intent to comply with a law.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.