Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

CIPPE 2

This multiple choice assessment focuses on the new General Data Protection Regulation (GDPR).
The purpose of the assessment is to enable you to assess the extent and depth of your knowledge of the Data Protection Law in preparation for the CIPP-E.
Format: Multiple Choice
Time: 90 minutes
The result will be provided immediately, with details on all questions.

1) While implementing certain data subject rights the controller is obliged by Article 19 to inform each third party recipient of the personal data. For which of the following rights does this apply?

2) Why is it advisable to avoid consent as a legal basis for an employer to process employee data?

3) Which of the following is NOT categorically one of the types of Privacy?

4) Which of the following would require designating a data protection officer?

5) Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?

6) Which of the following controller/processing scenarios in principle CAN use the Public Interest legal basis?

7) Which of the following BEST described the EU Data Protection Model?

8) Which area of privacy is a lead supervisory authority's (SA) MAIN concern?

9) Where the data subject is a child, what steps must controllers take in respect of consent, within the constraints of available technology?

10) What permissions are required for a marketer to send an email marketing message to a consumer in the EU?

11) What is true of both the General Data Protection Regulation (GDPR) and the Council of Europe Convention 108?

12) What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

13) Under the GDPR, who would be LEAST likely to be allowed to engage in the collection, use, and disclosure of a data subject's sensitive medical information without the data subject's knowledge or consent?

14) What is the MAIN reason GDPR Article 4(22) establishes the concept of the concerned supervisory authority'?

15) Under the GDPR, which of the following is true in regard to adequacy decisions involving cross-border transfers?

16) Under the GDPR in which of the following situations are there derogations, where each member state can make adjustment to their national laws.

17) How does the GDPR now define processing'?

18) Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?

19) A mobile device application that uses cookies will be subject to the consent requirement of which of the following?

20) If a multi-national company wanted to conduct background checks on all current and potential employees, including those based in Europe, what key provision would the company have to follow?

21) Assuming that the without undue delay' provision is followed, what is the time limit for complying with a data access request?

22) If a company is planning to use closed-circuit television (CCTV') on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?

23) Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?

24) In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.