Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

CIPPE 1

This multiple choice assessment focuses on the new General Data Protection Regulation (GDPR).
The purpose of the assessment is to enable you to assess the extent and depth of your knowledge of the Data Protection Law in preparation for the CIPP-E.
Format: Multiple Choice
Time: 90 minutes
The result will be provided immediately, with details on all questions.

1) According to the General Data Protection Regulation (GDPR), when does an organisation need to take action to legitimise cross-border data transfers of personal data?

2) The GDPR and its predecessor, the Data Protection Directive 95/46/EC, were allowed to be set up as a harmonisation measure for European member states by which?

3) Which is an example of direct marketing?

4) The e-Privacy Directive 2002/58/EC contains which provision?

5) Which statement describes a European best practices approach to the protection of employment data held by an organisation?

6) When should a controller notify the supervisory authority of a loss of personal information which is likely to result in harm to an individual?

7) Under what condition may the processing ‘sensitive employee data’ be acceptable?

8) Why do Binding Corporate Rules (BCRs) prohibit the transfer of employee names to telecom providers within the same country in order to provide them with mobile phone services?

9) Along with the name and contact details of the data controller processing the personal data, what other information must be included in the records of processing to be maintained by the data controller under the GDPR?

10) Which statement is correct concerning the information to be provided when collecting personal data directly from the data subject?

11) Under the GDPR, would a European company be allowed to use video surveillance to monitor employee access to inventory?

12) Which institution is responsible for ensuring that directives are implemented properly by the member states?

13) What is true for a contract based on European Commission (EC) Standard Contractual Clauses with a processor outside the European Economic Area?

14) Which type of data subject is NOT covered by the GDPR?

15) Which of the following is not covered in the 3-part test of the Legitimate Interest Assessment?

16) How is an employer obliged to proceed before engaging in the general monitoring of email traffic and internet use of all of its employees?

17) Which is NOT a compatible purpose for processing data beyond the purpose originally specified at the time of collection?

18) Along with legitimacy, what is another condition that must be met when carrying out employee monitoring?

19) Which is an example of cloud computing?

20) According to the GDPR, the right to data portability applies:

21) The collection is part of a historical research initiative. Which is the most accurate statement concerning the obligations imposed by the GDPR?

22) Messages sent to individuals to inform them about something such as the order they have placed.

23) Which, according to the GDPR, is NOT one of the considerations that should be taken into account to determine the appropriate technical and organisational measures to ensure a level of data security appropriate to the risk?

24) Which is NOT a special category of data?

25) Which institution has the power to adopt adequacy findings for the European Union?

26) Which exemption to the e-Privacy Directive 2002/58/EC allows the data controller to send electronic marketing information?

27) Which of the following is NOT one of the cases where Processors and Controllers must appoint a DPO?

28) According to the Treaty of Lisbon, the majority of EU legislation cannot be adopted without the approval of which two European Institutions?

29) When would a data subject have the right to require the erasure of his or her data without undue delay?

30) In which case should a data subject’s consent be regarded as freely given under the GDPR?

31) Which of the following lists the attribute of security controls?

32) Which of the following is a responsibility of the European Data Protection Board?

33) Which of the following is not part of the responsibilities of a Local Data Protection Supervisory Authority?

34) Which of the following controller/processing scenarios in principle CAN use the Public Interest legal basis?

35) Where the data subject is a child, what steps must controllers take in respect of consent, within the constraints of available technology?

36) Under the GDPR in which of the following situations are there derogations, where each member state can make adjustment to their national laws.

37) Which of the following is NOT categorically one of the types of Privacy?

38) While implementing certain data subject rights the controller is obliged by Article 19 to inform each third party recipient of the personal data. For which of the following rights does this apply?

39) Which is an example of cloud computing?

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.