IAPP CIPP-E Cert Guide PDF 100% Cover Real Exam Questions [Q106-Q129]

Share

IAPP CIPP-E Cert Guide PDF 100% Cover Real Exam Questions

Pass CIPP-E Exam - Real Questions and Answers


The CIPP-E exam covers the European legal framework for data protection, including the General Data Protection Regulation (GDPR) and the ePrivacy Directive. It also covers the principles and practices of data protection, such as data processing, data breaches, and data subject rights. Professionals who pass the exam are recognized as experts in the field of European data protection and are highly sought after by organizations that operate in the European Union.

 

NEW QUESTION # 106
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?

  • A. The school gets explicit consent from the students.
  • B. A state law requires facial recognition to verify attendance.
  • C. The school places a notice near each camera.
  • D. Processing is necessary for the legitimate interests pursed by the school.

Answer: A

Explanation:
Reference https://www.jdsupra.com/legalnews/let-s-face-it-facial-recognition-1134180/


NEW QUESTION # 107
A company plans to transfer employee health information between two of its entities in France. To maintain the security of the processing, what would be the most important security measure to apply to the health data transmission?

  • A. Ensure that the receiving entity has signed a data processing agreement.
  • B. Inform the data subject of the security measures in place.
  • C. Encrypt the transferred data in transit and at rest.
  • D. Conduct a data protection impact assessment.

Answer: B


NEW QUESTION # 108
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?

  • A. Personal data of EU citizens being processed by a controller or processor based outside the EU.
  • B. The behavior of EU citizens outside the EU being monitored by non-EU law enforcement bodies.
  • C. Personal data of EU residents being processed by a non-EU business that targets EU customers.
  • D. The behavior of suspected terrorists being monitored by EU law enforcement bodies.

Answer: A


NEW QUESTION # 109
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?

  • A. Greece
  • B. Australia
  • C. Switzerland
  • D. Norway

Answer: C


NEW QUESTION # 110
What is a reason the European Court of Justice declared the Data Retention Directive invalid in 2014?

  • A. The requirements affected individuals without exception.
  • B. The requirements were financially burdensome to EU businesses.
  • C. The requirements specified that data must be held within the EU.
  • D. The requirements had limitations on how national authorities could use data.

Answer: A

Explanation:
The Data Retention Directive was a EU law that required providers of electronic communications services to retain certain data, such as traffic and location data, for a period of between six months and two years, for the purpose of preventing, investigating, detecting and prosecuting serious crime1. However, in 2014, the Court of Justice of the European Union declared the Directive invalid, because it violated the fundamental rights to respect for private life and to the protection of personal data, as enshrined in the Charter of Fundamental Rights of the EU2. The Court found that the Directive entailed a wide-ranging and particularly serious interference with those rights, without being limited to what is strictly necessary3. One of the reasons for this finding was that the Directive applied to all individuals, all means of electronic communication and all traffic data without any differentiation, limitation or exception, thus affecting the entire population of the EU4. The Court also noted that the Directive did not provide sufficient safeguards to ensure effective protection of the data against the risk of abuse and unlawful access, and did not require the data to be retained within the EU5. Reference: 1 Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending Directive 2002/58/EC2 Charter of Fundamental Rights of the European Union3 Press release No 54/14 - Judgment in Joined Cases C-293/12 and C-594/12 Digital Rights Ireland and Seitlinger and Others4 Judgment of the Court (Grand Chamber) of 8 April 2014. Digital Rights Ireland Ltd v Minister for Communications, Marine and Natural Resources and Others and Karntner Landesregierung and Others. Requests for a preliminary ruling from the High Court (Ireland) and the Verfassungsgerichtshof (Austria). Joined cases C-293/12 and C-594/125 Ibid.
Reference:
%20the%20Grand,proportionality%20in%20forging%20the%20Directive.


NEW QUESTION # 111
What is true of both the General Data Protection Regulation (GDPR) and the Council of Europe Convention
108?

  • A. Both require notification of processing activities to a supervisory authority
  • B. Both govern international transfers of personal data
  • C. Both govern the manual processing of personal data
  • D. Both only apply to European Union countries

Answer: A


NEW QUESTION # 112
If a company is planning to use closed-circuit television (CCTV) on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?

  • A. Create an information retention policy for those who operate the system.
  • B. Perform a data protection impact assessment (DPIA).
  • C. Notify the appropriate data protection authority.
  • D. Ensure that safeguards are in place to prevent unauthorized access to the footage.

Answer: C

Explanation:
Under the GDPR, using CCTV on business premises involves the processing of personal data, which requires compliance with the data protection principles and obligations. However, notifying the appropriate data protection authority (DPA) is not one of the steps that a company should take before using CCTV, unless the DPA has specifically requested it or the CCTV involves high-risk processing that requires prior consultation. The other steps are necessary to ensure GDPR compliance, as explained below:
Performing a data protection impact assessment (DPIA) is a mandatory requirement for any type of processing that is likely to result in a high risk to the rights and freedoms of individuals, such as large-scale or systematic monitoring of public areas. A DPIA is a process that helps identify and mitigate the potential privacy risks of using CCTV, and document the measures taken to address them. A DPIA should include a description of the processing, its purpose and necessity, its risks and benefits, the safeguards and security measures, and the consultation with stakeholders. A DPIA should be carried out before the CCTV system is installed or upgraded, and reviewed regularly or whenever there is a significant change in the processing.
Creating an information retention policy for those who operate the system is a good practice to ensure that the personal data collected by CCTV is not kept longer than necessary for the purpose for which it was collected, and that it is securely deleted or anonymised when no longer needed. The retention period should be determined by the specific purpose and context of using CCTV, and take into account any legal or contractual obligations, as well as the expectations and rights of the data subjects. The retention policy should also specify who is responsible for managing and deleting the CCTV footage, and how the deletion process is verified and documented.
Ensuring that safeguards are in place to prevent unauthorized access to the footage is an essential requirement to comply with the GDPR principle of integrity and confidentiality, which states that personal data must be processed in a manner that ensures appropriate security of the data, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage. The safeguards may include technical and organisational measures, such as encryption, access control, logging, audit, training, policies and procedures, that aim to protect the CCTV footage from unauthorized or unlawful access, disclosure, alteration, or destruction, both during transmission and storage. Reference: GDPR Article 35, GDPR Article 36, GDPR Article 5, CCTV and video surveillance | ICO, 5 Step Guide to Check if Your CCTV is GDPR Compliant


NEW QUESTION # 113
What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?

  • A. The synchronization of approaches to data protection
  • B. The establishment of a list of legitimate data processing criteria
  • C. The restriction of cross-border data flow
  • D. The creation of legally binding data protection principles

Answer: A

Explanation:
The OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all aimed to harmonize the national data protection laws of the member states of the European Economic Community (EEC) and to establish a common framework for the protection of personal data. However, they largely failed to achieve this goal due to several reasons, such as:
The lack of political will and commitment from the member states to implement the directives fully and consistently12.
The divergent interpretations and applications of the directives by different national authorities, courts and regulators12.
The emergence of new technologies and challenges that required new or updated legal solutions, such as electronic communications, cookies, biometrics, cloud computing, etc12.
The influence of other regional or international initiatives that addressed some aspects of data protection differently or in conflict with the directives, such as the US Privacy Shield Framework3.


NEW QUESTION # 114
What is an important difference between the European Court of Human Rights (ECHR) and the Court of Justice of the European Union (CJEU) in relation to their roles and functions?

  • A. CJEU can hear appeals on human rights decisions made by national courts, while the ECHR cannot.
  • B. ECHR can rule on issues concerning privacy as a fundamental right, while the CJEU cannot.
  • C. ECHR can enforce human rights laws against governments that fail to implement them, while the CJEU cannot.
  • D. CJEU can force national governments to implement and honor EU law, while the ECHR cannot.

Answer: D

Explanation:
The ECHR and the CJEU are part of two different legal systems: the Council of Europe and the European Union, respectively. The ECHR is a treaty that guarantees human rights and fundamental freedoms to individuals within the jurisdiction of its 47 member states. The CJEU is the judicial branch of the EU that ensures the uniform interpretation and application of EU law within its 27 member states. The ECHR can only hear complaints from individuals or states alleging violations of the rights enshrined in the convention, and it can only issue judgments that are binding on the respondent state. The CJEU, on the other hand, can hear cases from individuals, states, EU institutions, or national courts on any matter of EU law, and it can issue rulings that are binding on all EU member states and institutions. The CJEU can also impose sanctions or penalties on states that fail to comply with its judgments or EU law in general. Therefore, the CJEU has more power and authority to enforce EU law than the ECHR has to enforce human rights law. Reference: CIPP/E Certification, ECHR and the CJEU, The UK, the EU and a British Bill of Rights


NEW QUESTION # 115
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA.
Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
The data transfer mechanism that Alice drafted violates the GDPR because the company did not first get approval from?

  • A. The Data Protection Authority.
  • B. The Court of Justice of the European Union.
  • C. The European Data Protection Board.
  • D. The European Commission.

Answer: A


NEW QUESTION # 116
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?

  • A. The European Parliament
  • B. The European Commission
  • C. The European Council
  • D. The Council of the European Union

Answer: D


NEW QUESTION # 117
SCENARIO
Please use the following to answer the next question:
BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information - name, location, and prior purchase history - with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.
Prior to sharing its customer list, BHealthy conducted a review of Natural Insight's security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy's data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight's machine learning algorithms.
In which case would Natural Insight's use of BHealthy's data for improvement of its algorithms be considered data processor activity?

  • A. If Natural Insight uses BHealthy's data for improving price point predictions only for BHealthy.
  • B. If Natural Insight agrees to be fully liable for its use of BHealthy's customer information in its product improvement activities.
  • C. If Natural Insight satisfies the transparency requirement by notifying BHealthy's customers of its plans to use their information for its product improvement activities.
  • D. If Natural Insight receives express contractual instructions from BHealthy to use its data for improving its algorithms.

Answer: A


NEW QUESTION # 118
Articles 13 and 14 of the GDPR provide details on the obligation of data controllers to inform data subjects when collecting personal dat a. However, both articles specify an exemption for situations in which the data subject already has the information.
Which other situation would also exempt the data controller from this obligation under Article 14?

  • A. When providing the information would go against a police order.
  • B. When the personal data was obtained 5 years before the entry into force of the GDPR
  • C. When the personal data was obtained through multiple source in the public domain
  • D. When providing the information would involve a disproportionate effort

Answer: D


NEW QUESTION # 119
SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles. Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Based on current trends in European privacy practices, which aspect of Brady Box' Online Behavioral Advertising (OBA) is most likely to be insufficient if the company becomes established in Europe?

  • A. The lack of the option to opt in.
  • B. The contract with the third-party advertising network.
  • C. The need to have the contents of the advertising approved.
  • D. The level of security within the website.

Answer: A

Explanation:
Section: (none)
Explanation
Online Behavioural Advertising (OBA) means the collection of data from a particular computer or device regarding web viewing behaviours over time and across multiple web domains not under Common Control for the purpose of using such data to predict web user preferences or interests to deliver online advertising to that particular computer or device based on the preferences or interests inferred from such web viewing behaviours1. OBA is subject to the EU law on consent to the processing of personal data, which requires a clear affirmative action by the data subject indicating his or her agreement to the processing2. The consent must be freely given, specific, informed and unambiguous, and it can be withdrawn at any time2. The consent must also be obtained prior to the collection and use of data for OBA purposes3. Therefore, Brady Box's OBA practice is most likely to be


NEW QUESTION # 120
WP29's "Guidelines on Personal data breach notification under Regulation 2016/679'' provides examples of ways to communicate data breaches transparently. Which of the following was listed as a method that would NOT be effective for communicating a breach to data subjects?

  • A. A direct electronic message
  • B. A notice on a corporate blog
  • C. A prominent advertisement in print media
  • D. A postal notification

Answer: B


NEW QUESTION # 121
In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?

  • A. When paying a search engine company to give prominence to certain products and services within specific search results.
  • B. When emailing a customer to announce that his recent order should arrive earlier than expected.
  • C. When creating an untargeted pop-up ad on a website.
  • D. When calling a potential customer to notify her of an upcoming product sale.

Answer: B

Explanation:
Reference https://www.privacytrust.com/guidance/gdpr-vs-eprivacy-regulation.html


NEW QUESTION # 122
A news website based m (he United Slates reports primarily on North American events The website is accessible to any user regardless of location, as the website operator does not block connections from outside of the U.S. The website offers a pad subscription that requires the creation of a user account; this subscription can only be paid in U.S. dollars.
Which of the following explains why the website operator, who is the responsible for all processing related to account creation and subscriptions, is NOT required to comply with the GDPR?

  • A. The website cannot block connections from outside the U.S. that use a Virtual Private Network (VPN) to simulate a US location.
  • B. The controller does not have an establishment in the European Union.
  • C. Payments cannot be made in a European Union currency.
  • D. The website is not available in several official languages of European Un on Member States

Answer: B


NEW QUESTION # 123
SCENARIO
Please use the following to answer the next question:
ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
What are ABC Hotel Chain and XYZ Travel Agency's roles in this relationship?

  • A. XYZ Travel Agency is the controller and ABC Hotel Chain is the processor.
  • B. ABC Hotel Chain is the controller and XYZ Travel Agency is the processor.
  • C. ABC Hotel Chain and XYZ Travel Agency are joint controllers.
  • D. ABC Hotel Chain and XYZ Travel Agency are independent controllers.

Answer: C

Explanation:
ABC Hotel Chain and XYZ Travel Agency are joint controllers in this relationship, because they jointly determine the purposes and means of the processing of personal data of their customers. According to Article 26 of the GDPR, joint controllers are two or more controllers who jointly participate in the decision-making process regarding the processing of personal data 1. In this scenario, ABC Hotel Chain and XYZ Travel Agency use a common platform for collecting and sharing customer data, and they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data. Therefore, they have a common influence on the processing of personal data and share a common objective of integrating their marketing efforts. Moreover, they offer a rewards program that allows customers to sign up to accumulate points that can be redeemed for free travel, which implies a joint benefit from the processing of personal data.
The other options are not correct because they do not reflect the actual roles of ABC Hotel Chain and XYZ Travel Agency in this relationship. A controller is a natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data 2. A processor is a natural or legal person who processes personal data on behalf of the controller 3. In this scenario, neither ABC Hotel Chain nor XYZ Travel Agency act solely or on behalf of the other in processing the personal data of their customers. Rather, they act together in a collaborative manner and share the responsibility and accountability for the processing of personal data. Therefore, they are joint controllers, not independent controllers or controller and processor. Reference: 1: Article 26 of the GDPR 2: Article 4(7) of the GDPR 3: Article 4(8) of the GDPR


NEW QUESTION # 124
Which of the following was the first legally binding international instrument in the area of data protection?

  • A. Universal Declaration of Human Rights.
  • B. Convention 108.
  • C. General Data Protection Regulation.
  • D. EU Directive on Privacy and Electronic Communications.

Answer: B


NEW QUESTION # 125
In the wake of the Schrems II ruling, which of the following actions has been recommended by the EDPB for companies transferring personal data to third countries?

  • A. Adopting a risk-based approach and implementing supplementary measures as needed.
  • B. Ensuring that all data transfers are encrypted with unbreakable encryption algorithms.
  • C. Storing all personal data within the borders of the European Union.
  • D. Obtaining explicit consent from each EU citizen for every individual data transfer.

Answer: A


NEW QUESTION # 126
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?

  • A. The school gets explicit consent from the students.
  • B. A state law requires facial recognition to verify attendance.
  • C. The school places a notice near each camera.
  • D. Processing is necessary for the legitimate interests pursed by the school.

Answer: A

Explanation:
Reference:
The use of facial recognition technology to track student attendance involves the processing of biometric data, which is a special category of personal data under the GDPR. Such data can only be processed under certain conditions, one of which is the explicit consent of the data subject1. Therefore, the school may provide a lawful basis for this processing if it obtains the explicit consent of the students (or their legal guardians, if the students are minors). The consent must be freely given, specific, informed and unambiguous, and the students must have the right to withdraw their consent at any time2. The other options do not provide a lawful basis for this processing, as they do not meet the requirements for processing special categories of data. Placing a notice near each camera does not constitute consent, nor does it comply with the transparency principle3. Processing for the legitimate interests of the school may be a valid basis for processing personal data in general, but not for processing biometric data, unless it is authorised by a specific law that provides suitable safeguards4. A state law that requires facial recognition to verify attendance may also be a valid basis for processing personal data in general, but not for processing biometric data, unless it is necessary for reasons of substantial public interest and provides suitable safeguards5. Reference:
Free CIPP/E Study Guide, page 24, section 3.2
CIPP/E Certification, page 19, section 3.2
Cipp-e Study guides, Class notes & Summaries, page 17, section 3.2
Special categories of personal data - General Data Protection Regulation (GDPR), Article 9 Consent - General Data Protection Regulation (GDPR), Article 7 Principles - General Data Protection Regulation (GDPR), Article 5 Lawfulness of processing - General Data Protection Regulation (GDPR), Article 6 Special categories of personal data - General Data Protection Regulation (GDPR), Article 9


NEW QUESTION # 127
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?

  • A. The data subject already has information regarding how his data will be used
  • B. Third-party data would be disclosed by providing such information to the data subject
  • C. The provision of such information to the data subject would be too problematic
  • D. The processing of the data subject's data is protected by appropriate technical measures

Answer: A


NEW QUESTION # 128
Which of the following is the weakest lawful basis for processing employee personal data?

  • A. Processing based on fulfilling an employment contract.
  • B. Processing based on employee consent.
  • C. Processing based on legal obligation.
  • D. Processing based on legitimate interests.

Answer: B

Explanation:
Reference:
According to the GDPR, consent is one of the six lawful bases for processing personal data, but it is not always the most appropriate one. Consent must be freely given, specific, informed and unambiguous, and the data subject must have the right to withdraw it at any time1. In the context of employment, consent is often not a valid lawful basis, because there is a clear imbalance of power between the employer and the employee, which means that the consent is not freely given2. Moreover, consent can be difficult to manage and document, and it can pose practical problems if the employee withdraws it. Therefore, consent is the weakest lawful basis for processing employee personal data, and employers should rely on other lawful bases, such as contract, legal obligation, vital interests, public task or legitimate interests, depending on the purpose and necessity of the processing3. Reference: 1: Article 4(11) and Article 7 of the GDPR; 2: [EDPB Guidelines], page 6; 3: A Guide to Lawful Basis for Processing Employee Personal Data.


NEW QUESTION # 129
......

100% Free CIPP-E Daily Practice Exam With 270 Questions: https://www.testpdf.com/CIPP-E-exam-braindumps.html

Pass CIPP-E Review Guide, Reliable CIPP-E Test Engine: https://drive.google.com/open?id=1vRtHUzgozJDFZmLRkoE4Ssgm51sebz4K