To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client.
Regarding the domain of the controller-processor relationships, how is this situation considered?
A. Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the controller.
B. Not applicable, because the data base is password protected, and therefore is not at risk of identifying any data subject.
C. Compliant with the storage limitation principle, so long as the internal auditor permanently deletes the data base.
D. Compliant with the security principle, because the data base is password-protected.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. Which GDPR principle is she following?
A. Integrity and confidentiality
B. Accuracy
C. Lawfulness, fairness and transparency
D. Storage Limitation
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?
A. The processor will be liable to pay compensation to affected data subjects
B. The controller will be liable to pay an administrative fine
C. The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved
D. The processor will be considered to be a controller in respect of the processing concerned
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
A private company has establishments in France, Poland, the United Kingdom, and most prominently, Germany, where its headquarters is established. The company offers its services worldwide. Most of the services are designed in Germany and supported in the other establishments. However, one of the services, a Software as a Service (SaaS) application, was defined and implemented by the Polish establishment. It is also supported by the other establishments.
What is the lead supervisory authority for the SaaS service?
A. The supervisory authority of Germany at the regional level.
B. The supervisory authority of the European Union.
C. The supervisory authority of Germany at the federal level.
D. The supervisory authority of the Republic of Poland.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
After leaving the EU under the terms of Brexit, the United Kingdom will seek an adequacy determination.
What is the reason for this?
A. The UK is now a third country because it's no longer subject to the GDPR.
B. The UK is less trustworthy now that its not part of the Union.
C. The Insurance Commissioner determined that an adequacy determination is required by the Data Protection Act.
D. Adequacy determinations automatically lapse when a Member State leaves the EU.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
SCENARIO
Please use the following to answer the next question:
Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical company on a clinical trial related to COVID-19. As part of his onboarding process Jack received privacy training He was explicitly informed that while he would need to process confidential patient data in the course of his work, he may under no circumstances use this data for anything other than the performance of work-related (asks This was also specified in the privacy policy, which Jack signed upon conclusion of the training.
After several months of employment, Jack got into an argument with a patient over the phone. Out of anger he later posted the patient's name and hearth information, along with disparaging comments, on a social media website. When this was discovered by his Pharmacovigilance supervisors. Jack was immediately dismissed Jack's lawyer sent a letter to the company stating that dismissal was a disproportionate sanction, and that if Jack was not reinstated within 14 days his firm would have no alternative but to commence legal proceedings against the company. This letter was accompanied by a data access request from Jack requesting a copy of "all personal data, including internal emails that were sent/received by Jack or where Jack is directly or indirectly identifiable from the contents * In relation to the emails Jack listed six members of the management team whose inboxes he required access.
The company conducted an initial search of its IT systems, which returned a large amount of information They then contacted Jack, requesting that he be more specific regarding what information he required, so that they could carry out a targeted search Jack responded by stating that he would not narrow the scope of the information requester.
What would be the most appropriate response to Jacks data subject access request?
A. The company should provide all requested information except for the emails, as they are excluded from data access request requirements under the GDPR.
B. The company should not provide any information, as the company is headquartered outside of the EU.
C. The company should cite the need for an extension, and agree to provide the information requested in Jack's original DSAR within a period of 3 months.
D. The company should decline to provide any information, as the amount of information requested is too excessive to provide in one month.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
A worker in a European Union (EU) member state has ceased his employment with a company. What should the employer most likely do in regard to the worker's personal data?
A. Store all of the data in case the departing worker makes a subject access request.
B. Provide the employee the reasons for retaining the data.
C. Securely store the data that is required to be kept under local law.
D. Destroy sensitive information and store the rest per applicable data protection rules.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
The European Parliament jointly exercises legislative and budgetary functions with which of the following?
A. The European Commission.
B. The Council of the European Union.
C. The European Data Protection Board.
D. The Article 29 Working Party.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
979 お客様のコメント




Odajima -
Pass4Testは試験出題見直に対応しているCIPP-E問題集が素晴らしい
大学生ですが、このCIPP-E参考書を利用して一ヶ月で合格することができました。