{"id":63886,"date":"2023-09-04T03:19:03","date_gmt":"2023-09-04T03:19:03","guid":{"rendered":"https:\/\/www.dumpsbase.com\/freedumps\/?p=63886"},"modified":"2023-09-04T03:19:08","modified_gmt":"2023-09-04T03:19:08","slug":"be-prepared-for-certified-information-privacy-professional-europe-cipp-e-exam-with-updated-cipp-e-dumps-v12-02","status":"publish","type":"post","link":"https:\/\/www.dumpsbase.com\/freedumps\/be-prepared-for-certified-information-privacy-professional-europe-cipp-e-exam-with-updated-cipp-e-dumps-v12-02.html","title":{"rendered":"Be Prepared for Certified Information Privacy Professional\/Europe (CIPP\/E) Exam with Updated CIPP-E Dumps V12.02"},"content":{"rendered":"\n<p>As the world becomes increasingly digital, privacy concerns are at an all-time high. Organizations are looking to hire professionals with Certified Information Privacy Professional\/Europe (CIPP\/E) credentials to ensure that their data is handled in compliance with pan-European and national data protection laws. The CIPP\/E exam is a challenging one, but with the latest CIPP-E dumps V12.02 by DumpsBase, you can be confident of passing the exam with flying colors. DumpsBase is a leading platform that offers valid, updated, and real CIPP-E exam dumps that are particularly designed for quick and complete CIPP-E exam preparation. The updated CIPP-E dumps V12.02 have 250 practice exam questions and answers for learning. By downloading the CIPP-E dumps V12.02 from DumpsBase, you can be assured of passing the exam successfully.<\/p>\n<h2>Certified Information Privacy Professional\/Europe (CIPP\/E) <em><span style=\"background-color: #ffff00;\">Free Dumps\u00a0Demo<\/span><\/em><\/h2>\n<script>\n\t  window.fbAsyncInit = function() {\n\t    FB.init({\n\t      appId            : '622169541470367',\n\t      autoLogAppEvents : true,\n\t      xfbml            : true,\n\t      version          : 'v3.1'\n\t    });\n\t  };\n\t\n\t  (function(d, s, id){\n\t     var js, fjs = d.getElementsByTagName(s)[0];\n\t     if (d.getElementById(id)) {return;}\n\t     js = d.createElement(s); js.id = id;\n\t     js.src = \"https:\/\/connect.facebook.net\/en_US\/sdk.js\";\n\t     fjs.parentNode.insertBefore(js, fjs);\n\t   }(document, 'script', 'facebook-jssdk'));\n\t<\/script><script type=\"text\/javascript\" >\ndocument.addEventListener(\"DOMContentLoaded\", function(event) { \nif(!window.jQuery) alert(\"The important jQuery library is not properly loaded in your site. Your WordPress theme is probably missing the essential wp_head() call. You can switch to another theme and you will see that the plugin works fine and this notice disappears. If you are still not sure what to do you can contact us for help.\");\n});\n<\/script>  \n  \n<div  id=\"watupro_quiz\" class=\"quiz-area single-page-quiz\">\n<p id=\"submittingExam7735\" style=\"display:none;text-align:center;\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.dumpsbase.com\/freedumps\/wp-content\/plugins\/watupro\/img\/loading.gif\" width=\"16\" height=\"16\"><\/p>\n\n<div class=\"watupro-exam-description\" id=\"description-quiz-7735\"><\/div>\n\n<form action=\"\" method=\"post\" class=\"quiz-form\" id=\"quiz-7735\"  enctype=\"multipart\/form-data\" >\n<div class='watu-question ' id='question-1' style=';'><div id='questionWrap-1'  class='   watupro-question-id-286630'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>1. <\/span>Read the following steps: <br \/>\r<br>&#10001; Discover which employees are accessing cloud services and from which devices and apps Lock down the data in those apps and devices <br \/>\r<br>&#10001; Monitor and analyze the apps and devices for compliance <br \/>\r<br>&#10001; Manage application life cycles <br \/>\r<br>&#10001; Monitor data sharing <br \/>\r<br>An organization should perform these steps to do which of the following?<\/div><input type='hidden' name='question_id[]' id='qID_1' value='286630' \/><input type='hidden' id='answerType286630' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286630[]' id='answer-id-1126628' class='answer   answerof-286630 ' value='1126628'   \/><label for='answer-id-1126628' id='answer-label-1126628' class=' answer'><span>Pursue a GDPR-compliant Privacy by Design process.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286630[]' id='answer-id-1126629' class='answer   answerof-286630 ' value='1126629'   \/><label for='answer-id-1126629' id='answer-label-1126629' class=' answer'><span>Institute a GDPR-compliant employee monitoring process.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286630[]' id='answer-id-1126630' class='answer   answerof-286630 ' value='1126630'   \/><label for='answer-id-1126630' id='answer-label-1126630' class=' answer'><span>Maintain a secure Bring Your Own Device (BYOD) program.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286630[]' id='answer-id-1126631' class='answer   answerof-286630 ' value='1126631'   \/><label for='answer-id-1126631' id='answer-label-1126631' class=' answer'><span>Ensure cloud vendors are complying with internal data use policies.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-2' style=';'><div id='questionWrap-2'  class='   watupro-question-id-286631'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>2. <\/span>What is a reason the European Court of Justice declared the Data Retention Directive invalid in 2014?<\/div><input type='hidden' name='question_id[]' id='qID_2' value='286631' \/><input type='hidden' id='answerType286631' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286631[]' id='answer-id-1126632' class='answer   answerof-286631 ' value='1126632'   \/><label for='answer-id-1126632' id='answer-label-1126632' class=' answer'><span>The requirements affected individuals without exception.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286631[]' id='answer-id-1126633' class='answer   answerof-286631 ' value='1126633'   \/><label for='answer-id-1126633' id='answer-label-1126633' class=' answer'><span>The requirements were financially burdensome to EU businesses.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286631[]' id='answer-id-1126634' class='answer   answerof-286631 ' value='1126634'   \/><label for='answer-id-1126634' id='answer-label-1126634' class=' answer'><span>The requirements specified that data must be held within the E<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286631[]' id='answer-id-1126635' class='answer   answerof-286631 ' value='1126635'   \/><label for='answer-id-1126635' id='answer-label-1126635' class=' answer'><span>The requirements had limitations on how national authorities could use data.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-3' style=';'><div id='questionWrap-3'  class='   watupro-question-id-286632'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>3. <\/span>Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?<\/div><input type='hidden' name='question_id[]' id='qID_3' value='286632' \/><input type='hidden' id='answerType286632' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286632[]' id='answer-id-1126636' class='answer   answerof-286632 ' value='1126636'   \/><label for='answer-id-1126636' id='answer-label-1126636' class=' answer'><span>Greece<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286632[]' id='answer-id-1126637' class='answer   answerof-286632 ' value='1126637'   \/><label for='answer-id-1126637' id='answer-label-1126637' class=' answer'><span>Norway<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286632[]' id='answer-id-1126638' class='answer   answerof-286632 ' value='1126638'   \/><label for='answer-id-1126638' id='answer-label-1126638' class=' answer'><span>Australia<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286632[]' id='answer-id-1126639' class='answer   answerof-286632 ' value='1126639'   \/><label for='answer-id-1126639' id='answer-label-1126639' class=' answer'><span>Switzerland<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-4' style=';'><div id='questionWrap-4'  class='   watupro-question-id-286633'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>4. <\/span>Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?<\/div><input type='hidden' name='question_id[]' id='qID_4' value='286633' \/><input type='hidden' id='answerType286633' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286633[]' id='answer-id-1126640' class='answer   answerof-286633 ' value='1126640'   \/><label for='answer-id-1126640' id='answer-label-1126640' class=' answer'><span>The group of undertakings must obtain approval from a supervisory authority.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286633[]' id='answer-id-1126641' class='answer   answerof-286633 ' value='1126641'   \/><label for='answer-id-1126641' id='answer-label-1126641' class=' answer'><span>The group of undertakings must be comprised of organizations of similar sizes and functions.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286633[]' id='answer-id-1126642' class='answer   answerof-286633 ' value='1126642'   \/><label for='answer-id-1126642' id='answer-label-1126642' class=' answer'><span>The data protection officer must be located in the country where the data controller has its main establishment.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286633[]' id='answer-id-1126643' class='answer   answerof-286633 ' value='1126643'   \/><label for='answer-id-1126643' id='answer-label-1126643' class=' answer'><span>The data protection officer must be easily accessible from each establishment where the undertakings are located.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-5' style=';'><div id='questionWrap-5'  class='   watupro-question-id-286634'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>5. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company\u2019s IT <br \/>\r<br>servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father\u2019s company, but is also secretly working on launching a new global online dating website company called Ben Knows Best. <br \/>\r<br>Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company\u2019s online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers\u2019 philosophical beliefs, political opinions and marital status. <br \/>\r<br>If a customer identifies as single, Ben then copies all of that customer\u2019s personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out. <br \/>\r<br>Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland. <br \/>\r<br>Joe also hires his best friend\u2019s daughter, Alice, who just graduated from law school in the U.S., to be the company\u2019s new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company\u2019s operations in the European Union to the U.S. <br \/>\r<br>Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company\u2019s IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone\u2019s information. Alice believes that Joe will be happy that she did the first levelreview, as it will save the company a lot of money that would otherwise be paid to its outside law firm. <br \/>\r<br>Ben\u2019s collection of additional data from customers created several potential issues for the company, which would most likely require what?<\/div><input type='hidden' name='question_id[]' id='qID_5' value='286634' \/><input type='hidden' id='answerType286634' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286634[]' id='answer-id-1126644' class='answer   answerof-286634 ' value='1126644'   \/><label for='answer-id-1126644' id='answer-label-1126644' class=' answer'><span>New corporate governance and code of conduct.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286634[]' id='answer-id-1126645' class='answer   answerof-286634 ' value='1126645'   \/><label for='answer-id-1126645' id='answer-label-1126645' class=' answer'><span>A data protection impact assessment.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286634[]' id='answer-id-1126646' class='answer   answerof-286634 ' value='1126646'   \/><label for='answer-id-1126646' id='answer-label-1126646' class=' answer'><span>A comprehensive data inventory.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286634[]' id='answer-id-1126647' class='answer   answerof-286634 ' value='1126647'   \/><label for='answer-id-1126647' id='answer-label-1126647' class=' answer'><span>Hiring a data protection officer.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-6' style=';'><div id='questionWrap-6'  class='   watupro-question-id-286635'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>6. <\/span>A U.S.-based online shop uses sophisticated software to track the browsing behavior of its European customers and predict future purchases. It also shares this information with third parties. <br \/>\r<br>Under the GDPR, what is the online shop\u2019s PRIMARY obligation while engaging in this kind of profiling?<\/div><input type='hidden' name='question_id[]' id='qID_6' value='286635' \/><input type='hidden' id='answerType286635' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286635[]' id='answer-id-1126648' class='answer   answerof-286635 ' value='1126648'   \/><label for='answer-id-1126648' id='answer-label-1126648' class=' answer'><span>It must solicit informed consent through a notice on its website<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286635[]' id='answer-id-1126649' class='answer   answerof-286635 ' value='1126649'   \/><label for='answer-id-1126649' id='answer-label-1126649' class=' answer'><span>It must seek authorization from the European supervisory authorities<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286635[]' id='answer-id-1126650' class='answer   answerof-286635 ' value='1126650'   \/><label for='answer-id-1126650' id='answer-label-1126650' class=' answer'><span>It must be able to demonstrate a prior business relationship with the customers<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286635[]' id='answer-id-1126651' class='answer   answerof-286635 ' value='1126651'   \/><label for='answer-id-1126651' id='answer-label-1126651' class=' answer'><span>It must prove that it uses sufficient security safeguards to protect customer data<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-7' style=';'><div id='questionWrap-7'  class='   watupro-question-id-286636'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>7. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Dynaroux Fashion (\u2018Dynaroux\u2019) is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company\u2019s compliance with the General Data Protection Regulation (GDPR) and other privacy legislation. <br \/>\r<br>The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers. <br \/>\r<br>In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company\u2019s customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that <br \/>\r<br>Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux mayhave to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme. <br \/>\r<br>Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux\u2019s business plan and associated processing activities. <br \/>\r<br>Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_7' value='286636' \/><input type='hidden' id='answerType286636' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286636[]' id='answer-id-1126652' class='answer   answerof-286636 ' value='1126652'   \/><label for='answer-id-1126652' id='answer-label-1126652' class=' answer'><span>The company will be undertaking processing activities involving sensitive data categories such as financial and children\u2019s data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286636[]' id='answer-id-1126653' class='answer   answerof-286636 ' value='1126653'   \/><label for='answer-id-1126653' id='answer-label-1126653' class=' answer'><span>The company employs approximately 650 people and will therefore be carrying out extensive processing activities.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286636[]' id='answer-id-1126654' class='answer   answerof-286636 ' value='1126654'   \/><label for='answer-id-1126654' id='answer-label-1126654' class=' answer'><span>The company plans to undertake profiling of its customers through analysis of their purchasing patterns.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286636[]' id='answer-id-1126655' class='answer   answerof-286636 ' value='1126655'   \/><label for='answer-id-1126655' id='answer-label-1126655' class=' answer'><span>The company intends to shift their business model to rely more heavily on online shopping.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-8' style=';'><div id='questionWrap-8'  class='   watupro-question-id-286637'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>8. <\/span>Which GDPR requirement will present the most significant challenges for organizations with Bring Your Own Device (BYOD) programs?<\/div><input type='hidden' name='question_id[]' id='qID_8' value='286637' \/><input type='hidden' id='answerType286637' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286637[]' id='answer-id-1126656' class='answer   answerof-286637 ' value='1126656'   \/><label for='answer-id-1126656' id='answer-label-1126656' class=' answer'><span>Data subjects must be sufficiently informed of the purposes for which their personal data is processed.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286637[]' id='answer-id-1126657' class='answer   answerof-286637 ' value='1126657'   \/><label for='answer-id-1126657' id='answer-label-1126657' class=' answer'><span>Processing of special categories of personal data on a large scale requires appointing a DP<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286637[]' id='answer-id-1126658' class='answer   answerof-286637 ' value='1126658'   \/><label for='answer-id-1126658' id='answer-label-1126658' class=' answer'><span>Personal data of data subjects must always be accurate and kept up to date.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286637[]' id='answer-id-1126659' class='answer   answerof-286637 ' value='1126659'   \/><label for='answer-id-1126659' id='answer-label-1126659' class=' answer'><span>Data controllers must be in control of the data they hold at all times.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-9' style=';'><div id='questionWrap-9'  class='   watupro-question-id-286638'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>9. <\/span>What are the obligations of a processor that engages a sub-processor?<\/div><input type='hidden' name='question_id[]' id='qID_9' value='286638' \/><input type='hidden' id='answerType286638' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286638[]' id='answer-id-1126660' class='answer   answerof-286638 ' value='1126660'   \/><label for='answer-id-1126660' id='answer-label-1126660' class=' answer'><span>The processor must give the controller prior written notice and perform a preliminary audit of the sub- processor.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286638[]' id='answer-id-1126661' class='answer   answerof-286638 ' value='1126661'   \/><label for='answer-id-1126661' id='answer-label-1126661' class=' answer'><span>The processor must obtain the controller\u2019s specific written authorization and provide annual reports on the sub-processor\u2019s performance.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286638[]' id='answer-id-1126662' class='answer   answerof-286638 ' value='1126662'   \/><label for='answer-id-1126662' id='answer-label-1126662' class=' answer'><span>The processor must receive a written agreement that the sub-processor will be fully liable to the controller for the performance of its obligations in relation to the personal data concerned.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286638[]' id='answer-id-1126663' class='answer   answerof-286638 ' value='1126663'   \/><label for='answer-id-1126663' id='answer-label-1126663' class=' answer'><span>The processor must obtain the consent of the controller and ensure the sub-processor complies with data processing obligations that are equivalent to those that apply to the processor.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-10' style=';'><div id='questionWrap-10'  class='   watupro-question-id-286639'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>10. <\/span>What type of data lies beyond the scope of the General Data Protection Regulation?<\/div><input type='hidden' name='question_id[]' id='qID_10' value='286639' \/><input type='hidden' id='answerType286639' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286639[]' id='answer-id-1126664' class='answer   answerof-286639 ' value='1126664'   \/><label for='answer-id-1126664' id='answer-label-1126664' class=' answer'><span>Pseudonymized<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286639[]' id='answer-id-1126665' class='answer   answerof-286639 ' value='1126665'   \/><label for='answer-id-1126665' id='answer-label-1126665' class=' answer'><span>Anonymized<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286639[]' id='answer-id-1126666' class='answer   answerof-286639 ' value='1126666'   \/><label for='answer-id-1126666' id='answer-label-1126666' class=' answer'><span>Encrypted<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286639[]' id='answer-id-1126667' class='answer   answerof-286639 ' value='1126667'   \/><label for='answer-id-1126667' id='answer-label-1126667' class=' answer'><span>Masked<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-11' style=';'><div id='questionWrap-11'  class='   watupro-question-id-286640'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>11. <\/span>Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?<\/div><input type='hidden' name='question_id[]' id='qID_11' value='286640' \/><input type='hidden' id='answerType286640' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286640[]' id='answer-id-1126668' class='answer   answerof-286640 ' value='1126668'   \/><label for='answer-id-1126668' id='answer-label-1126668' class=' answer'><span>The European Council<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286640[]' id='answer-id-1126669' class='answer   answerof-286640 ' value='1126669'   \/><label for='answer-id-1126669' id='answer-label-1126669' class=' answer'><span>The European Parliament<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286640[]' id='answer-id-1126670' class='answer   answerof-286640 ' value='1126670'   \/><label for='answer-id-1126670' id='answer-label-1126670' class=' answer'><span>The European Commission<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286640[]' id='answer-id-1126671' class='answer   answerof-286640 ' value='1126671'   \/><label for='answer-id-1126671' id='answer-label-1126671' class=' answer'><span>The Council of the European Union<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-12' style=';'><div id='questionWrap-12'  class='   watupro-question-id-286641'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>12. <\/span>What is the main task of the European Data Protection Board?<\/div><input type='hidden' name='question_id[]' id='qID_12' value='286641' \/><input type='hidden' id='answerType286641' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286641[]' id='answer-id-1126672' class='answer   answerof-286641 ' value='1126672'   \/><label for='answer-id-1126672' id='answer-label-1126672' class=' answer'><span>To assess adequacy of data protection in third countries<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286641[]' id='answer-id-1126673' class='answer   answerof-286641 ' value='1126673'   \/><label for='answer-id-1126673' id='answer-label-1126673' class=' answer'><span>To ensure consistent application of the GDP<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286641[]' id='answer-id-1126674' class='answer   answerof-286641 ' value='1126674'   \/><label for='answer-id-1126674' id='answer-label-1126674' class=' answer'><span>To proactively prevent disputes between national supervisory authorities.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286641[]' id='answer-id-1126675' class='answer   answerof-286641 ' value='1126675'   \/><label for='answer-id-1126675' id='answer-label-1126675' class=' answer'><span>To publish guidelines tor data subjects on how to property enforce their rights<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-13' style=';'><div id='questionWrap-13'  class='   watupro-question-id-286642'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>13. <\/span>An entity\u2019s website stores text files on EU users\u2019 computer and mobile device browsers. <br \/>\r<br>Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?<\/div><input type='hidden' name='question_id[]' id='qID_13' value='286642' \/><input type='hidden' id='answerType286642' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286642[]' id='answer-id-1126676' class='answer   answerof-286642 ' value='1126676'   \/><label for='answer-id-1126676' id='answer-label-1126676' class=' answer'><span>General Data Protection Regulation 2016\/679.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286642[]' id='answer-id-1126677' class='answer   answerof-286642 ' value='1126677'   \/><label for='answer-id-1126677' id='answer-label-1126677' class=' answer'><span>E-Privacy Directive 2002\/58\/E<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286642[]' id='answer-id-1126678' class='answer   answerof-286642 ' value='1126678'   \/><label for='answer-id-1126678' id='answer-label-1126678' class=' answer'><span>E-Commerce Directive 2000\/31\/E<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286642[]' id='answer-id-1126679' class='answer   answerof-286642 ' value='1126679'   \/><label for='answer-id-1126679' id='answer-label-1126679' class=' answer'><span>Data Protection Directive 95\/46\/E<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-14' style=';'><div id='questionWrap-14'  class='   watupro-question-id-286643'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>14. <\/span>Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_14' value='286643' \/><input type='hidden' id='answerType286643' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286643[]' id='answer-id-1126680' class='answer   answerof-286643 ' value='1126680'   \/><label for='answer-id-1126680' id='answer-label-1126680' class=' answer'><span>The obligation of companies to declare data breaches.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286643[]' id='answer-id-1126681' class='answer   answerof-286643 ' value='1126681'   \/><label for='answer-id-1126681' id='answer-label-1126681' class=' answer'><span>The requirement to demonstrate compliance to a supervisory authority.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286643[]' id='answer-id-1126682' class='answer   answerof-286643 ' value='1126682'   \/><label for='answer-id-1126682' id='answer-label-1126682' class=' answer'><span>The necessity of the bulk collection of personal data by the government.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-15' style=';'><div id='questionWrap-15'  class='   watupro-question-id-286644'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>15. <\/span>Which of the following was the first to implement national law for data protection in 1973?<\/div><input type='hidden' name='question_id[]' id='qID_15' value='286644' \/><input type='hidden' id='answerType286644' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286644[]' id='answer-id-1126683' class='answer   answerof-286644 ' value='1126683'   \/><label for='answer-id-1126683' id='answer-label-1126683' class=' answer'><span>France<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286644[]' id='answer-id-1126684' class='answer   answerof-286644 ' value='1126684'   \/><label for='answer-id-1126684' id='answer-label-1126684' class=' answer'><span>Sweden<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286644[]' id='answer-id-1126685' class='answer   answerof-286644 ' value='1126685'   \/><label for='answer-id-1126685' id='answer-label-1126685' class=' answer'><span>Germany<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286644[]' id='answer-id-1126686' class='answer   answerof-286644 ' value='1126686'   \/><label for='answer-id-1126686' id='answer-label-1126686' class=' answer'><span>United Kingdom<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-16' style=';'><div id='questionWrap-16'  class='   watupro-question-id-286645'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>16. <\/span>Under Article 58 of the GDPR, which of the following describes a power of supervisory authorities in European Union (EU) member states?<\/div><input type='hidden' name='question_id[]' id='qID_16' value='286645' \/><input type='hidden' id='answerType286645' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286645[]' id='answer-id-1126687' class='answer   answerof-286645 ' value='1126687'   \/><label for='answer-id-1126687' id='answer-label-1126687' class=' answer'><span>The ability to enact new laws by executive order.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286645[]' id='answer-id-1126688' class='answer   answerof-286645 ' value='1126688'   \/><label for='answer-id-1126688' id='answer-label-1126688' class=' answer'><span>The right to access data for investigative purposes.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286645[]' id='answer-id-1126689' class='answer   answerof-286645 ' value='1126689'   \/><label for='answer-id-1126689' id='answer-label-1126689' class=' answer'><span>The discretion to carry out goals of elected officials within the member state.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286645[]' id='answer-id-1126690' class='answer   answerof-286645 ' value='1126690'   \/><label for='answer-id-1126690' id='answer-label-1126690' class=' answer'><span>The authority to select penalties when a controller is found guilty in a court of law.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-17' style=';'><div id='questionWrap-17'  class='   watupro-question-id-286646'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>17. <\/span>According to the E-Commerce Directive 2000\/31\/EC, where is the place of \u201cestablishment\u201d for a company providing services via an Internet website confirmed by the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_17' value='286646' \/><input type='hidden' id='answerType286646' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286646[]' id='answer-id-1126691' class='answer   answerof-286646 ' value='1126691'   \/><label for='answer-id-1126691' id='answer-label-1126691' class=' answer'><span>Where the technology supporting the website is located<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286646[]' id='answer-id-1126692' class='answer   answerof-286646 ' value='1126692'   \/><label for='answer-id-1126692' id='answer-label-1126692' class=' answer'><span>Where the website is accessed<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286646[]' id='answer-id-1126693' class='answer   answerof-286646 ' value='1126693'   \/><label for='answer-id-1126693' id='answer-label-1126693' class=' answer'><span>Where the decisions about processing are made<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286646[]' id='answer-id-1126694' class='answer   answerof-286646 ' value='1126694'   \/><label for='answer-id-1126694' id='answer-label-1126694' class=' answer'><span>Where the customer\u2019s Internet service provider is located<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-18' style=';'><div id='questionWrap-18'  class='   watupro-question-id-286647'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>18. <\/span>Article 29 Working Party has emphasized that the GDPR forbids \u201cforum shopping\u201d, which occurs when companies do what?<\/div><input type='hidden' name='question_id[]' id='qID_18' value='286647' \/><input type='hidden' id='answerType286647' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286647[]' id='answer-id-1126695' class='answer   answerof-286647 ' value='1126695'   \/><label for='answer-id-1126695' id='answer-label-1126695' class=' answer'><span>Choose the data protection officer that is most sympathetic to their business concerns.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286647[]' id='answer-id-1126696' class='answer   answerof-286647 ' value='1126696'   \/><label for='answer-id-1126696' id='answer-label-1126696' class=' answer'><span>Designate their main establishment in member state with the most flexible practices.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286647[]' id='answer-id-1126697' class='answer   answerof-286647 ' value='1126697'   \/><label for='answer-id-1126697' id='answer-label-1126697' class=' answer'><span>File appeals of infringement judgments with more than one EU institution simultaneously.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286647[]' id='answer-id-1126698' class='answer   answerof-286647 ' value='1126698'   \/><label for='answer-id-1126698' id='answer-label-1126698' class=' answer'><span>Select third-party processors on the basis of cost rather than quality of privacy protection.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-19' style=';'><div id='questionWrap-19'  class='   watupro-question-id-286648'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>19. <\/span>When is data sharing agreement MOST likely to be needed?<\/div><input type='hidden' name='question_id[]' id='qID_19' value='286648' \/><input type='hidden' id='answerType286648' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286648[]' id='answer-id-1126699' class='answer   answerof-286648 ' value='1126699'   \/><label for='answer-id-1126699' id='answer-label-1126699' class=' answer'><span>When anonymized data is being shared.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286648[]' id='answer-id-1126700' class='answer   answerof-286648 ' value='1126700'   \/><label for='answer-id-1126700' id='answer-label-1126700' class=' answer'><span>When personal data is being shared between commercial organizations acting as joint data controllers.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286648[]' id='answer-id-1126701' class='answer   answerof-286648 ' value='1126701'   \/><label for='answer-id-1126701' id='answer-label-1126701' class=' answer'><span>When personal data is being proactively shared by a controller to support a police investigation.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286648[]' id='answer-id-1126702' class='answer   answerof-286648 ' value='1126702'   \/><label for='answer-id-1126702' id='answer-label-1126702' class=' answer'><span>When personal data is being shared with a public authority with powers to require the personal data to be disclosed.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-20' style=';'><div id='questionWrap-20'  class='   watupro-question-id-286649'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>20. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to <br \/>\r<br>Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn\u2019t prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address. <br \/>\r<br>Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base. <br \/>\r<br>The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre-registrations, it will develop EU-specific content and services. <br \/>\r<br>Another plan is called Customer for Life. The idea is to offer additional services through the company\u2019s app, like storage and sharing of DNA information with other applications and medical providers. The company\u2019s contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers\u2019 attempts to withdraw consent because the contract invalidates them. <br \/>\r<br>The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn\u2019t include any technology or infrastructure; rather, it\u2019s simply a room with a desk and some chairs. <br \/>\r<br>On a recent trip concerning the naming-rights deal, Bob\u2019s laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information. <br \/>\r<br>If Who-R-U decides to track locations using its app, what must it do to comply with the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_20' value='286649' \/><input type='hidden' id='answerType286649' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286649[]' id='answer-id-1126703' class='answer   answerof-286649 ' value='1126703'   \/><label for='answer-id-1126703' id='answer-label-1126703' class=' answer'><span>Get consent from the app users.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286649[]' id='answer-id-1126704' class='answer   answerof-286649 ' value='1126704'   \/><label for='answer-id-1126704' id='answer-label-1126704' class=' answer'><span>Provide a transparent notice to users.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286649[]' id='answer-id-1126705' class='answer   answerof-286649 ' value='1126705'   \/><label for='answer-id-1126705' id='answer-label-1126705' class=' answer'><span>Anonymize the data and add latency so it avoids disclosing real time locations.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286649[]' id='answer-id-1126706' class='answer   answerof-286649 ' value='1126706'   \/><label for='answer-id-1126706' id='answer-label-1126706' class=' answer'><span>Obtain a court order because location data is a special category of personal data.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-21' style=';'><div id='questionWrap-21'  class='   watupro-question-id-286650'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>21. <\/span>How is the retention of communications traffic data for law enforcement purposes addressed by European data protection law?<\/div><input type='hidden' name='question_id[]' id='qID_21' value='286650' \/><input type='hidden' id='answerType286650' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286650[]' id='answer-id-1126707' class='answer   answerof-286650 ' value='1126707'   \/><label for='answer-id-1126707' id='answer-label-1126707' class=' answer'><span>The ePrivacy Directive allows individual EU member states to engage in such data retention.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286650[]' id='answer-id-1126708' class='answer   answerof-286650 ' value='1126708'   \/><label for='answer-id-1126708' id='answer-label-1126708' class=' answer'><span>The ePrivacy Directive harmonizes EU member states\u2019 rules concerning such data retention.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286650[]' id='answer-id-1126709' class='answer   answerof-286650 ' value='1126709'   \/><label for='answer-id-1126709' id='answer-label-1126709' class=' answer'><span>The Data Retention Directive\u2019s annulment makes such data retention now permissible.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286650[]' id='answer-id-1126710' class='answer   answerof-286650 ' value='1126710'   \/><label for='answer-id-1126710' id='answer-label-1126710' class=' answer'><span>The GDPR allows the retention of such data for the prevention, investigation, detection or prosecution of criminal offences only.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-22' style=';'><div id='questionWrap-22'  class='   watupro-question-id-286651'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>22. <\/span>Since blockchain transactions are classified as pseudonymous, are they considered to be within the material scope of the GDPR or outside of it?<\/div><input type='hidden' name='question_id[]' id='qID_22' value='286651' \/><input type='hidden' id='answerType286651' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286651[]' id='answer-id-1126711' class='answer   answerof-286651 ' value='1126711'   \/><label for='answer-id-1126711' id='answer-label-1126711' class=' answer'><span>Outside the material scope of the GDPR, because transactions do not include personal data about data subjects m the European Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286651[]' id='answer-id-1126712' class='answer   answerof-286651 ' value='1126712'   \/><label for='answer-id-1126712' id='answer-label-1126712' class=' answer'><span>Within the material scope of the GDPR but outside of the territorial scope, because blockchains are decentralized.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286651[]' id='answer-id-1126713' class='answer   answerof-286651 ' value='1126713'   \/><label for='answer-id-1126713' id='answer-label-1126713' class=' answer'><span>Within the material scope of the GDPR to the extent that transactions include data subjects in the European Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286651[]' id='answer-id-1126714' class='answer   answerof-286651 ' value='1126714'   \/><label for='answer-id-1126714' id='answer-label-1126714' class=' answer'><span>Outside the material scope of the GDPR, because transactions are for personal or household purposes<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-23' style=';'><div id='questionWrap-23'  class='   watupro-question-id-286652'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>23. <\/span>Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002\/58\/EC?<\/div><input type='hidden' name='question_id[]' id='qID_23' value='286652' \/><input type='hidden' id='answerType286652' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286652[]' id='answer-id-1126715' class='answer   answerof-286652 ' value='1126715'   \/><label for='answer-id-1126715' id='answer-label-1126715' class=' answer'><span>A voluntary notification for personal data breaches applicable to all data controllers.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286652[]' id='answer-id-1126716' class='answer   answerof-286652 ' value='1126716'   \/><label for='answer-id-1126716' id='answer-label-1126716' class=' answer'><span>A voluntary notification for personal data breaches applicable to electronic communication providers.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286652[]' id='answer-id-1126717' class='answer   answerof-286652 ' value='1126717'   \/><label for='answer-id-1126717' id='answer-label-1126717' class=' answer'><span>A mandatory notification for personal data breaches applicable to all data controllers.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286652[]' id='answer-id-1126718' class='answer   answerof-286652 ' value='1126718'   \/><label for='answer-id-1126718' id='answer-label-1126718' class=' answer'><span>A mandatory notification for personal data breaches applicable to electronic communication providers.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-24' style=';'><div id='questionWrap-24'  class='   watupro-question-id-286653'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>24. <\/span>Bioface is a company based in the United States. It has no servers, personnel or assets in the European Union. By collecting photographs from social media and other web-based services, such as newspapers and blogs, it uses machine learning to develop a facial recognition algorithm. The algorithm identifies individuals in photographs who are not in its data set based the algorithm and its existing data. The service collects photographs of data subjects in the European Union and will identify them if presented with their photographs. Bioface offers its service to government agencies and companies in the United States and Canada, but not to those in the European Union. Bioface does not offer the service to individuals. <br \/>\r<br>Why is Bioface subject to the territorial scope of the General Data Protection Regulation?<\/div><input type='hidden' name='question_id[]' id='qID_24' value='286653' \/><input type='hidden' id='answerType286653' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286653[]' id='answer-id-1126719' class='answer   answerof-286653 ' value='1126719'   \/><label for='answer-id-1126719' id='answer-label-1126719' class=' answer'><span>It collects data from European Union websites, which constitutes an establishment in the European Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286653[]' id='answer-id-1126720' class='answer   answerof-286653 ' value='1126720'   \/><label for='answer-id-1126720' id='answer-label-1126720' class=' answer'><span>It offers services in the European Union by identifying data subjects in the European Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286653[]' id='answer-id-1126721' class='answer   answerof-286653 ' value='1126721'   \/><label for='answer-id-1126721' id='answer-label-1126721' class=' answer'><span>It collects data from subjects and uses it for automated processing.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286653[]' id='answer-id-1126722' class='answer   answerof-286653 ' value='1126722'   \/><label for='answer-id-1126722' id='answer-label-1126722' class=' answer'><span>It monitors the behavior of data subjects in the European Union.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-25' style=';'><div id='questionWrap-25'  class='   watupro-question-id-286654'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>25. <\/span>After detecting an intrusion involving the theft of unencrypted personal data, who shall the breached company notify first under GDPR requirements?<\/div><input type='hidden' name='question_id[]' id='qID_25' value='286654' \/><input type='hidden' id='answerType286654' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286654[]' id='answer-id-1126723' class='answer   answerof-286654 ' value='1126723'   \/><label for='answer-id-1126723' id='answer-label-1126723' class=' answer'><span>Any parents of children whose personal data was compromised.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286654[]' id='answer-id-1126724' class='answer   answerof-286654 ' value='1126724'   \/><label for='answer-id-1126724' id='answer-label-1126724' class=' answer'><span>Any affected customers whose data was compromised.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286654[]' id='answer-id-1126725' class='answer   answerof-286654 ' value='1126725'   \/><label for='answer-id-1126725' id='answer-label-1126725' class=' answer'><span>A competent supervisory authority.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286654[]' id='answer-id-1126726' class='answer   answerof-286654 ' value='1126726'   \/><label for='answer-id-1126726' id='answer-label-1126726' class=' answer'><span>A local law enforcement agency<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-26' style=';'><div id='questionWrap-26'  class='   watupro-question-id-286655'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>26. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Javier is a member of the fitness club EVERFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Javier lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Javier was photographed while working out at a branch of EVERFIT in Frankfurt, Germany. At the time, Javier gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club\u2019s U.K. brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Javier no longer feels comfortable with his photograph being publicly associated with the fitness club. <br \/>\r<br>After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Javier sends a letter to EVETFIT requesting that his image be removed from the website and all promotional materials. Months pass and Javier, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact EVETFIT through alternate channels, he decides to take action against the company. <br \/>\r<br>Javier contacts the U.K. Information Commissioner\u2019s Office (\u2018ICO\u2019 C the U.K.\u2019s supervisory authority) to lodge a complaint about this matter. The ICO, pursuant to Article 56 (3) of the GDPR, informs the CNIL (i.e. the supervisory authority of EVERFIT\u2019s main establishment) about this matter. Despite the fact that EVERFIT has an establishment in the U.K., the CNIL decides to handle the case in accordance with Article 60 of the GDPR. The CNIL liaises with the ICO, as relevant under the cooperation procedure. In light of issues amongst the supervisory authorities to reach a decision, the European Data Protection Board becomes involved and, pursuant to the consistency mechanism, issues a binding decision. <br \/>\r<br>Additionally, Javier sues EVERFIT for the damages caused as a result of its failure to honor his request to have his photograph removed from the brochure and website. <br \/>\r<br>Under the cooperation mechanism, what should the lead authority (the CNIL) do after it has formed its view on the matter?<\/div><input type='hidden' name='question_id[]' id='qID_26' value='286655' \/><input type='hidden' id='answerType286655' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286655[]' id='answer-id-1126727' class='answer   answerof-286655 ' value='1126727'   \/><label for='answer-id-1126727' id='answer-label-1126727' class=' answer'><span>Submit a draft decision to other supervisory authorities for their opinion.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286655[]' id='answer-id-1126728' class='answer   answerof-286655 ' value='1126728'   \/><label for='answer-id-1126728' id='answer-label-1126728' class=' answer'><span>Request that the other supervisory authorities provide the lead authority with a draft decision for its consideration.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286655[]' id='answer-id-1126729' class='answer   answerof-286655 ' value='1126729'   \/><label for='answer-id-1126729' id='answer-label-1126729' class=' answer'><span>Submit a draft decision directly to the Commission to ensure the effectiveness of the consistency mechanism.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286655[]' id='answer-id-1126730' class='answer   answerof-286655 ' value='1126730'   \/><label for='answer-id-1126730' id='answer-label-1126730' class=' answer'><span>Request that members of the seconding supervisory authority and the host supervisory authority co-draft a decision.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-27' style=';'><div id='questionWrap-27'  class='   watupro-question-id-286656'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>27. <\/span>Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002\/58\/EC)?<\/div><input type='hidden' name='question_id[]' id='qID_27' value='286656' \/><input type='hidden' id='answerType286656' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286656[]' id='answer-id-1126731' class='answer   answerof-286656 ' value='1126731'   \/><label for='answer-id-1126731' id='answer-label-1126731' class=' answer'><span>Advertisements passively displayed on a website.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286656[]' id='answer-id-1126732' class='answer   answerof-286656 ' value='1126732'   \/><label for='answer-id-1126732' id='answer-label-1126732' class=' answer'><span>The use of cookies to collect data about an individual.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286656[]' id='answer-id-1126733' class='answer   answerof-286656 ' value='1126733'   \/><label for='answer-id-1126733' id='answer-label-1126733' class=' answer'><span>A text message to individuals from a company offering concert tickets for sale.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286656[]' id='answer-id-1126734' class='answer   answerof-286656 ' value='1126734'   \/><label for='answer-id-1126734' id='answer-label-1126734' class=' answer'><span>An email from a retail outlet promoting a sale to one of their previous customer.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-28' style=';'><div id='questionWrap-28'  class='   watupro-question-id-286657'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>28. <\/span>Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?<\/div><input type='hidden' name='question_id[]' id='qID_28' value='286657' \/><input type='hidden' id='answerType286657' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286657[]' id='answer-id-1126735' class='answer   answerof-286657 ' value='1126735'   \/><label for='answer-id-1126735' id='answer-label-1126735' class=' answer'><span>When the personal data is processed only in non-electronic form<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286657[]' id='answer-id-1126736' class='answer   answerof-286657 ' value='1126736'   \/><label for='answer-id-1126736' id='answer-label-1126736' class=' answer'><span>When the personal data is collected and then pseudonymised by the controller<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286657[]' id='answer-id-1126737' class='answer   answerof-286657 ' value='1126737'   \/><label for='answer-id-1126737' id='answer-label-1126737' class=' answer'><span>When the personal data is held by the controller but not processed for further purposes<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286657[]' id='answer-id-1126738' class='answer   answerof-286657 ' value='1126738'   \/><label for='answer-id-1126738' id='answer-label-1126738' class=' answer'><span>When the personal data is processed by an individual only for their household activities<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-29' style=';'><div id='questionWrap-29'  class='   watupro-question-id-286658'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>29. <\/span>Pursuant to Article 17 and EDPB Guidelines S'2019 on RTBF criteria in search engines cases, all of the following would be valid grounds for data subject delisting requests EXCEPT?<\/div><input type='hidden' name='question_id[]' id='qID_29' value='286658' \/><input type='hidden' id='answerType286658' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286658[]' id='answer-id-1126739' class='answer   answerof-286658 ' value='1126739'   \/><label for='answer-id-1126739' id='answer-label-1126739' class=' answer'><span>The personal dale has been collected in relation to the offer of Information society services (ISS) to a child.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286658[]' id='answer-id-1126740' class='answer   answerof-286658 ' value='1126740'   \/><label for='answer-id-1126740' id='answer-label-1126740' class=' answer'><span>The data subject withdraws consent and there is no other legal basis for the processing.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286658[]' id='answer-id-1126741' class='answer   answerof-286658 ' value='1126741'   \/><label for='answer-id-1126741' id='answer-label-1126741' class=' answer'><span>The personal data is no longer necessary in relation to the search engine provider's processing<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286658[]' id='answer-id-1126742' class='answer   answerof-286658 ' value='1126742'   \/><label for='answer-id-1126742' id='answer-label-1126742' class=' answer'><span>The processing s necessary for exercising the right of freedom of expression and information<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-30' style=';'><div id='questionWrap-30'  class='   watupro-question-id-286659'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>30. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company\u2019s IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father\u2019s company, but is also secretly working on launching a new global online dating website company called Ben Knows Best. <br \/>\r<br>Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company\u2019s online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers\u2019 philosophical beliefs, political opinions and marital status. <br \/>\r<br>If a customer identifies as single, Ben then copies all of that customer\u2019s personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out. <br \/>\r<br>Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland. <br \/>\r<br>Joe also hires his best friend\u2019s daughter, Alice, who just graduated from law school in the U.S., to be the company\u2019s new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company\u2019s operations in the European Union to the U.S. <br \/>\r<br>Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company\u2019s IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone\u2019s information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm. <br \/>\r<br>As a result of Sam\u2019s actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?<\/div><input type='hidden' name='question_id[]' id='qID_30' value='286659' \/><input type='hidden' id='answerType286659' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286659[]' id='answer-id-1126743' class='answer   answerof-286659 ' value='1126743'   \/><label for='answer-id-1126743' id='answer-label-1126743' class=' answer'><span>Notify its Data Protection Authority about the data breach.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286659[]' id='answer-id-1126744' class='answer   answerof-286659 ' value='1126744'   \/><label for='answer-id-1126744' id='answer-label-1126744' class=' answer'><span>Analyze and evaluate the liability for customers in Ireland.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286659[]' id='answer-id-1126745' class='answer   answerof-286659 ' value='1126745'   \/><label for='answer-id-1126745' id='answer-label-1126745' class=' answer'><span>Analyze and evaluate all of its breach notification obligations.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286659[]' id='answer-id-1126746' class='answer   answerof-286659 ' value='1126746'   \/><label for='answer-id-1126746' id='answer-label-1126746' class=' answer'><span>Notify all of its customers that reside in the European Union.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-31' style=';'><div id='questionWrap-31'  class='   watupro-question-id-286660'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>31. <\/span>Which statement provides an accurate description of a directive?<\/div><input type='hidden' name='question_id[]' id='qID_31' value='286660' \/><input type='hidden' id='answerType286660' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286660[]' id='answer-id-1126747' class='answer   answerof-286660 ' value='1126747'   \/><label for='answer-id-1126747' id='answer-label-1126747' class=' answer'><span>A directive speo5es certain results that must be achieved, but each member state is free to decide how to turn it into a national law<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286660[]' id='answer-id-1126748' class='answer   answerof-286660 ' value='1126748'   \/><label for='answer-id-1126748' id='answer-label-1126748' class=' answer'><span>A directive has binding legal force throughout every member state and enters into force on a set date in all the member states.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286660[]' id='answer-id-1126749' class='answer   answerof-286660 ' value='1126749'   \/><label for='answer-id-1126749' id='answer-label-1126749' class=' answer'><span>A directive is a legal act relating to specific cases and directed towards member states, companies 0' private individuals.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286660[]' id='answer-id-1126750' class='answer   answerof-286660 ' value='1126750'   \/><label for='answer-id-1126750' id='answer-label-1126750' class=' answer'><span>A directive is a legal act that applies automatically and uniformly to all EU countries as soon as it enters into force.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-32' style=';'><div id='questionWrap-32'  class='   watupro-question-id-286661'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>32. <\/span>What ruling did the Planet 49 CJEU judgment make regarding the issue of pre-ticked boxes?<\/div><input type='hidden' name='question_id[]' id='qID_32' value='286661' \/><input type='hidden' id='answerType286661' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286661[]' id='answer-id-1126751' class='answer   answerof-286661 ' value='1126751'   \/><label for='answer-id-1126751' id='answer-label-1126751' class=' answer'><span>They are allowed if determined to be technically necessary.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286661[]' id='answer-id-1126752' class='answer   answerof-286661 ' value='1126752'   \/><label for='answer-id-1126752' id='answer-label-1126752' class=' answer'><span>They do not amount to valid consent under any circumstances.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286661[]' id='answer-id-1126753' class='answer   answerof-286661 ' value='1126753'   \/><label for='answer-id-1126753' id='answer-label-1126753' class=' answer'><span>They are allowed if recorded In the register of processing activities.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286661[]' id='answer-id-1126754' class='answer   answerof-286661 ' value='1126754'   \/><label for='answer-id-1126754' id='answer-label-1126754' class=' answer'><span>They constitute valid consent if the processing is necessary for purposes of legitimate interest<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-33' style=';'><div id='questionWrap-33'  class='   watupro-question-id-286662'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>33. <\/span>Which mechanism, new to the GDPR, now allows for the possibility of personal data transfers to third countries under Article 42?<\/div><input type='hidden' name='question_id[]' id='qID_33' value='286662' \/><input type='hidden' id='answerType286662' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286662[]' id='answer-id-1126755' class='answer   answerof-286662 ' value='1126755'   \/><label for='answer-id-1126755' id='answer-label-1126755' class=' answer'><span>Approved certifications.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286662[]' id='answer-id-1126756' class='answer   answerof-286662 ' value='1126756'   \/><label for='answer-id-1126756' id='answer-label-1126756' class=' answer'><span>Binding corporate rules.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286662[]' id='answer-id-1126757' class='answer   answerof-286662 ' value='1126757'   \/><label for='answer-id-1126757' id='answer-label-1126757' class=' answer'><span>Law enforcement requests.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286662[]' id='answer-id-1126758' class='answer   answerof-286662 ' value='1126758'   \/><label for='answer-id-1126758' id='answer-label-1126758' class=' answer'><span>Standard contractual clauses.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-34' style=';'><div id='questionWrap-34'  class='   watupro-question-id-286663'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>34. <\/span>What is an important difference between the European Court of Human Rights (ECHR) and the Court of Justice of the European Union (CJEU) in relation to their roles and functions?<\/div><input type='hidden' name='question_id[]' id='qID_34' value='286663' \/><input type='hidden' id='answerType286663' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286663[]' id='answer-id-1126759' class='answer   answerof-286663 ' value='1126759'   \/><label for='answer-id-1126759' id='answer-label-1126759' class=' answer'><span>ECHR can rule on issues concerning privacy as a fundamental right, while the CJEU cannot.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286663[]' id='answer-id-1126760' class='answer   answerof-286663 ' value='1126760'   \/><label for='answer-id-1126760' id='answer-label-1126760' class=' answer'><span>CJEU can force national governments to implement and honor EU law, while the ECHR cannot.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286663[]' id='answer-id-1126761' class='answer   answerof-286663 ' value='1126761'   \/><label for='answer-id-1126761' id='answer-label-1126761' class=' answer'><span>CJEU can hear appeals on human rights decisions made by national courts, while the ECHR cannot.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286663[]' id='answer-id-1126762' class='answer   answerof-286663 ' value='1126762'   \/><label for='answer-id-1126762' id='answer-label-1126762' class=' answer'><span>ECHR can enforce human rights laws against governments that fail to implement them, while the CJEU cannot.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-35' style=';'><div id='questionWrap-35'  class='   watupro-question-id-286664'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>35. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees\u2019 computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees\u2019 computers. <br \/>\r<br>Since these measures would potentially impact employees, Building Block\u2019s Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches. <br \/>\r<br>After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees\u2019 computers activity and their location. During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased. <br \/>\r<br>Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company\u2019s computers, and from working remotely without authorization. <br \/>\r<br>What would be the MOST APPROPRIATE way for Building Block to handle the situation with the employee from Italy?<\/div><input type='hidden' name='question_id[]' id='qID_35' value='286664' \/><input type='hidden' id='answerType286664' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286664[]' id='answer-id-1126763' class='answer   answerof-286664 ' value='1126763'   \/><label for='answer-id-1126763' id='answer-label-1126763' class=' answer'><span>Since the GDPR does not apply to this situation, the company would be entitled to apply any disciplinary measure authorized under Italian labor law.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286664[]' id='answer-id-1126764' class='answer   answerof-286664 ' value='1126764'   \/><label for='answer-id-1126764' id='answer-label-1126764' class=' answer'><span>Since the employee was the cause of a serious risk for the server performance and their data, the company would be entitled to apply disciplinary measures to this employee, including fair dismissal.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286664[]' id='answer-id-1126765' class='answer   answerof-286664 ' value='1126765'   \/><label for='answer-id-1126765' id='answer-label-1126765' class=' answer'><span>Since the employee was not informed that the security measures would be used for other purposes such as monitoring, the company could face difficulties in applying any disciplinary measures to this employee.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286664[]' id='answer-id-1126766' class='answer   answerof-286664 ' value='1126766'   \/><label for='answer-id-1126766' id='answer-label-1126766' class=' answer'><span>Since this was a serious infringement, but the employee was not appropriately informed about the consequences the new security measures, the company would be entitled to apply some disciplinary measures, but not dismissal.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-36' style=';'><div id='questionWrap-36'  class='   watupro-question-id-286665'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>36. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage <br \/>\r<br>What transfer mechanism did ProStorage most likely rely on to transfer Ruth's medical information to the hospital?<\/div><input type='hidden' name='question_id[]' id='qID_36' value='286665' \/><input type='hidden' id='answerType286665' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286665[]' id='answer-id-1126767' class='answer   answerof-286665 ' value='1126767'   \/><label for='answer-id-1126767' id='answer-label-1126767' class=' answer'><span>Ruth's implied consent.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286665[]' id='answer-id-1126768' class='answer   answerof-286665 ' value='1126768'   \/><label for='answer-id-1126768' id='answer-label-1126768' class=' answer'><span>Protecting the vital interest of Ruth<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286665[]' id='answer-id-1126769' class='answer   answerof-286665 ' value='1126769'   \/><label for='answer-id-1126769' id='answer-label-1126769' class=' answer'><span>Performance of a contract with Ruth.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286665[]' id='answer-id-1126770' class='answer   answerof-286665 ' value='1126770'   \/><label for='answer-id-1126770' id='answer-label-1126770' class=' answer'><span>Protecting against legal liability from Ruth.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-37' style=';'><div id='questionWrap-37'  class='   watupro-question-id-286666'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>37. <\/span>WP29\u2019s \u201cGuidelines on Personal data breach notification under Regulation 2016\/679\u2019\u2019 provides examples of ways to communicate data breaches transparently. <br \/>\r<br>Which of the following was listed as a method that would NOT be effective for communicating a breach to data subjects?<\/div><input type='hidden' name='question_id[]' id='qID_37' value='286666' \/><input type='hidden' id='answerType286666' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286666[]' id='answer-id-1126771' class='answer   answerof-286666 ' value='1126771'   \/><label for='answer-id-1126771' id='answer-label-1126771' class=' answer'><span>A postal notification<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286666[]' id='answer-id-1126772' class='answer   answerof-286666 ' value='1126772'   \/><label for='answer-id-1126772' id='answer-label-1126772' class=' answer'><span>A direct electronic message<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286666[]' id='answer-id-1126773' class='answer   answerof-286666 ' value='1126773'   \/><label for='answer-id-1126773' id='answer-label-1126773' class=' answer'><span>A notice on a corporate blog<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286666[]' id='answer-id-1126774' class='answer   answerof-286666 ' value='1126774'   \/><label for='answer-id-1126774' id='answer-label-1126774' class=' answer'><span>A prominent advertisement in print media<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-38' style=';'><div id='questionWrap-38'  class='   watupro-question-id-286667'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>38. <\/span>A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. <br \/>\r<br>What is the company first required to do?<\/div><input type='hidden' name='question_id[]' id='qID_38' value='286667' \/><input type='hidden' id='answerType286667' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286667[]' id='answer-id-1126775' class='answer   answerof-286667 ' value='1126775'   \/><label for='answer-id-1126775' id='answer-label-1126775' class=' answer'><span>Obtain specific consent for the new processing<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286667[]' id='answer-id-1126776' class='answer   answerof-286667 ' value='1126776'   \/><label for='answer-id-1126776' id='answer-label-1126776' class=' answer'><span>Only inform the data subjects of the new purpose.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286667[]' id='answer-id-1126777' class='answer   answerof-286667 ' value='1126777'   \/><label for='answer-id-1126777' id='answer-label-1126777' class=' answer'><span>Proceed no further, as such repurposing is unlawful<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286667[]' id='answer-id-1126778' class='answer   answerof-286667 ' value='1126778'   \/><label for='answer-id-1126778' id='answer-label-1126778' class=' answer'><span>Update the privacy notice upon which consent was given<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-39' style=';'><div id='questionWrap-39'  class='   watupro-question-id-286668'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>39. <\/span>In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?<\/div><input type='hidden' name='question_id[]' id='qID_39' value='286668' \/><input type='hidden' id='answerType286668' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286668[]' id='answer-id-1126779' class='answer   answerof-286668 ' value='1126779'   \/><label for='answer-id-1126779' id='answer-label-1126779' class=' answer'><span>When creating an untargeted pop-up ad on a website.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286668[]' id='answer-id-1126780' class='answer   answerof-286668 ' value='1126780'   \/><label for='answer-id-1126780' id='answer-label-1126780' class=' answer'><span>When calling a potential customer to notify her of an upcoming product sale.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286668[]' id='answer-id-1126781' class='answer   answerof-286668 ' value='1126781'   \/><label for='answer-id-1126781' id='answer-label-1126781' class=' answer'><span>When emailing a customer to announce that his recent order should arrive earlier than expected.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286668[]' id='answer-id-1126782' class='answer   answerof-286668 ' value='1126782'   \/><label for='answer-id-1126782' id='answer-label-1126782' class=' answer'><span>When paying a search engine company to give prominence to certain products and services within specific search results.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-40' style=';'><div id='questionWrap-40'  class='   watupro-question-id-286669'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>40. <\/span>In which case would a controller who has undertaken a DPIA most likely need to consult with a supervisory authority?<\/div><input type='hidden' name='question_id[]' id='qID_40' value='286669' \/><input type='hidden' id='answerType286669' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286669[]' id='answer-id-1126783' class='answer   answerof-286669 ' value='1126783'   \/><label for='answer-id-1126783' id='answer-label-1126783' class=' answer'><span>Where the DPIA identifies that personal data needs to be transferred to other countries outside of the EE<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286669[]' id='answer-id-1126784' class='answer   answerof-286669 ' value='1126784'   \/><label for='answer-id-1126784' id='answer-label-1126784' class=' answer'><span>Where the DPIA identifies high risks to individuals\u2019 rights and freedoms that the controller can take steps to reduce.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286669[]' id='answer-id-1126785' class='answer   answerof-286669 ' value='1126785'   \/><label for='answer-id-1126785' id='answer-label-1126785' class=' answer'><span>Where the DPIA identifies that the processing being proposed collects the sensitive data of EU citizens.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286669[]' id='answer-id-1126786' class='answer   answerof-286669 ' value='1126786'   \/><label for='answer-id-1126786' id='answer-label-1126786' class=' answer'><span>Where the DPIA identifies risks that will require insurance for protecting its business interests.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-41' style=';'><div id='questionWrap-41'  class='   watupro-question-id-286670'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>41. <\/span>How does the GDPR now define \u201cprocessing\u201d?<\/div><input type='hidden' name='question_id[]' id='qID_41' value='286670' \/><input type='hidden' id='answerType286670' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286670[]' id='answer-id-1126787' class='answer   answerof-286670 ' value='1126787'   \/><label for='answer-id-1126787' id='answer-label-1126787' class=' answer'><span>Any act involving the collecting and recording of personal data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286670[]' id='answer-id-1126788' class='answer   answerof-286670 ' value='1126788'   \/><label for='answer-id-1126788' id='answer-label-1126788' class=' answer'><span>Any operation or set of operations performed on personal data or on sets of personal data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286670[]' id='answer-id-1126789' class='answer   answerof-286670 ' value='1126789'   \/><label for='answer-id-1126789' id='answer-label-1126789' class=' answer'><span>Any use or disclosure of personal data compatible with the purpose for which the data was collected.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286670[]' id='answer-id-1126790' class='answer   answerof-286670 ' value='1126790'   \/><label for='answer-id-1126790' id='answer-label-1126790' class=' answer'><span>Any operation or set of operations performed by automated means on personal data or on sets of personal data.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-42' style=';'><div id='questionWrap-42'  class='   watupro-question-id-286671'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>42. <\/span>What is the MAIN reason GDPR Article 4(22) establishes the concept of the \u201cconcerned supervisory authority\u201d?<\/div><input type='hidden' name='question_id[]' id='qID_42' value='286671' \/><input type='hidden' id='answerType286671' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286671[]' id='answer-id-1126791' class='answer   answerof-286671 ' value='1126791'   \/><label for='answer-id-1126791' id='answer-label-1126791' class=' answer'><span>To encourage the consistency of local data processing activity.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286671[]' id='answer-id-1126792' class='answer   answerof-286671 ' value='1126792'   \/><label for='answer-id-1126792' id='answer-label-1126792' class=' answer'><span>To give corporations a choice about who their supervisory authority will be.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286671[]' id='answer-id-1126793' class='answer   answerof-286671 ' value='1126793'   \/><label for='answer-id-1126793' id='answer-label-1126793' class=' answer'><span>To ensure the GDPR covers controllers that do not have an establishment in the EU but have a representative in a member state.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286671[]' id='answer-id-1126794' class='answer   answerof-286671 ' value='1126794'   \/><label for='answer-id-1126794' id='answer-label-1126794' class=' answer'><span>To ensure that the interests of individuals residing outside the lead authority\u2019s jurisdiction are represented.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-43' style=';'><div id='questionWrap-43'  class='   watupro-question-id-286672'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>43. <\/span>Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?<\/div><input type='hidden' name='question_id[]' id='qID_43' value='286672' \/><input type='hidden' id='answerType286672' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286672[]' id='answer-id-1126795' class='answer   answerof-286672 ' value='1126795'   \/><label for='answer-id-1126795' id='answer-label-1126795' class=' answer'><span>The behavior of suspected terrorists being monitored by EU law enforcement bodies.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286672[]' id='answer-id-1126796' class='answer   answerof-286672 ' value='1126796'   \/><label for='answer-id-1126796' id='answer-label-1126796' class=' answer'><span>Personal data of EU citizens being processed by a controller or processor based outside the E<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286672[]' id='answer-id-1126797' class='answer   answerof-286672 ' value='1126797'   \/><label for='answer-id-1126797' id='answer-label-1126797' class=' answer'><span>The behavior of EU citizens outside the EU being monitored by non-EU law enforcement bodies.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286672[]' id='answer-id-1126798' class='answer   answerof-286672 ' value='1126798'   \/><label for='answer-id-1126798' id='answer-label-1126798' class=' answer'><span>Personal data of EU residents being processed by a non-EU business that targets EU customers.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-44' style=';'><div id='questionWrap-44'  class='   watupro-question-id-286673'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>44. <\/span>It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3<\/div><input type='hidden' name='question_id[]' id='qID_44' value='286673' \/><input type='hidden' id='answerType286673' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286673[]' id='answer-id-1126799' class='answer   answerof-286673 ' value='1126799'   \/><label for='answer-id-1126799' id='answer-label-1126799' class=' answer'><span>Notify the police and Tile a criminal complaint about the incident<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286673[]' id='answer-id-1126800' class='answer   answerof-286673 ' value='1126800'   \/><label for='answer-id-1126800' id='answer-label-1126800' class=' answer'><span>Start an investigation to understand the incident's possible scope, duration and nature<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286673[]' id='answer-id-1126801' class='answer   answerof-286673 ' value='1126801'   \/><label for='answer-id-1126801' id='answer-label-1126801' class=' answer'><span>Send a notification to the competent supervisory authority describing the incident.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286673[]' id='answer-id-1126802' class='answer   answerof-286673 ' value='1126802'   \/><label for='answer-id-1126802' id='answer-label-1126802' class=' answer'><span>Send an email about the incident to all clients and ask them to change their passwords<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-45' style=';'><div id='questionWrap-45'  class='   watupro-question-id-286674'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>45. <\/span>A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, the company decides on a CCTV system to monitor for future incidents. Company technicians install cameras in the entrance of the building, hallways and offices. Footage is recorded continuously, and is monitored by the home office in the United States. <br \/>\r<br>What is the most realistic step the company could take to address their security concerns and comply with the personal data processing principles set out in Article 5 of the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_45' value='286674' \/><input type='hidden' id='answerType286674' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286674[]' id='answer-id-1126803' class='answer   answerof-286674 ' value='1126803'   \/><label for='answer-id-1126803' id='answer-label-1126803' class=' answer'><span>Seek informed consent from company employees.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286674[]' id='answer-id-1126804' class='answer   answerof-286674 ' value='1126804'   \/><label for='answer-id-1126804' id='answer-label-1126804' class=' answer'><span>Have cameras recording during work hours only.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286674[]' id='answer-id-1126805' class='answer   answerof-286674 ' value='1126805'   \/><label for='answer-id-1126805' id='answer-label-1126805' class=' answer'><span>Retain captured footage for no more than 30 days.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286674[]' id='answer-id-1126806' class='answer   answerof-286674 ' value='1126806'   \/><label for='answer-id-1126806' id='answer-label-1126806' class=' answer'><span>Restrict camera placement to building entrances only.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-46' style=';'><div id='questionWrap-46'  class='   watupro-question-id-286675'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>46. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies. <br \/>\r<br>T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze\u2019s headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success. <br \/>\r<br>The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze. <br \/>\r<br>Why does the Spanish supervisory authority notify the French supervisory authority when it opens an investigation into T-Craze based on Sofia\u2019s complaint?<\/div><input type='hidden' name='question_id[]' id='qID_46' value='286675' \/><input type='hidden' id='answerType286675' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286675[]' id='answer-id-1126807' class='answer   answerof-286675 ' value='1126807'   \/><label for='answer-id-1126807' id='answer-label-1126807' class=' answer'><span>T-Craze has a French affiliate.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286675[]' id='answer-id-1126808' class='answer   answerof-286675 ' value='1126808'   \/><label for='answer-id-1126808' id='answer-label-1126808' class=' answer'><span>The French affiliate procured the services of Right Target.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286675[]' id='answer-id-1126809' class='answer   answerof-286675 ' value='1126809'   \/><label for='answer-id-1126809' id='answer-label-1126809' class=' answer'><span>T-Craze conducts its marketing and sales activities in France.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286675[]' id='answer-id-1126810' class='answer   answerof-286675 ' value='1126810'   \/><label for='answer-id-1126810' id='answer-label-1126810' class=' answer'><span>The Spanish supervisory authority is providing a courtesy notification not required under the GDP<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-47' style=';'><div id='questionWrap-47'  class='   watupro-question-id-286676'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>47. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Zandelay Fashion (\u2018Zandelay\u2019) is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company\u2019s compliance with the General Data Protection Regulation (GDPR) and other privacy legislation. <br \/>\r<br>The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers. <br \/>\r<br>In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company\u2019s customers by analyzing their purchases. <br \/>\r<br>Martin tells the CEO that: <br \/>\r<br>(a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and <br \/>\r<br>(b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish <br \/>\r<br>Data Protection Commissioner before implementing the app and loyalty scheme. <br \/>\r<br>Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay\u2019s business plan and associated processing activities. <br \/>\r<br>What would MOST effectively assist Zandelay in conducting their data protection impact assessment?<\/div><input type='hidden' name='question_id[]' id='qID_47' value='286676' \/><input type='hidden' id='answerType286676' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286676[]' id='answer-id-1126811' class='answer   answerof-286676 ' value='1126811'   \/><label for='answer-id-1126811' id='answer-label-1126811' class=' answer'><span>Information about DPIAs found in Articles 38 through 40 of the GDP<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286676[]' id='answer-id-1126812' class='answer   answerof-286676 ' value='1126812'   \/><label for='answer-id-1126812' id='answer-label-1126812' class=' answer'><span>Data breach documentation that data controllers are required to maintain.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286676[]' id='answer-id-1126813' class='answer   answerof-286676 ' value='1126813'   \/><label for='answer-id-1126813' id='answer-label-1126813' class=' answer'><span>Existing DPIA guides published by local supervisory authorities.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286676[]' id='answer-id-1126814' class='answer   answerof-286676 ' value='1126814'   \/><label for='answer-id-1126814' id='answer-label-1126814' class=' answer'><span>Records of processing activities that data controllers are required to maintain.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-48' style=';'><div id='questionWrap-48'  class='   watupro-question-id-286677'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>48. <\/span>What is true if an employee makes an access request to his employer for any personal data held about him?<\/div><input type='hidden' name='question_id[]' id='qID_48' value='286677' \/><input type='hidden' id='answerType286677' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286677[]' id='answer-id-1126815' class='answer   answerof-286677 ' value='1126815'   \/><label for='answer-id-1126815' id='answer-label-1126815' class=' answer'><span>The employer can automatically decline the request if it contains personal data about a third person.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286677[]' id='answer-id-1126816' class='answer   answerof-286677 ' value='1126816'   \/><label for='answer-id-1126816' id='answer-label-1126816' class=' answer'><span>The employer can decline the request if the information is only held electronically.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286677[]' id='answer-id-1126817' class='answer   answerof-286677 ' value='1126817'   \/><label for='answer-id-1126817' id='answer-label-1126817' class=' answer'><span>The employer must supply all the information held about the employee.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286677[]' id='answer-id-1126818' class='answer   answerof-286677 ' value='1126818'   \/><label for='answer-id-1126818' id='answer-label-1126818' class=' answer'><span>The employer must supply any information held about an employee unless an exemption applies.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-49' style=';'><div id='questionWrap-49'  class='   watupro-question-id-286678'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>49. <\/span>Which of the following is the weakest lawful basis for processing employee personal data?<\/div><input type='hidden' name='question_id[]' id='qID_49' value='286678' \/><input type='hidden' id='answerType286678' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286678[]' id='answer-id-1126819' class='answer   answerof-286678 ' value='1126819'   \/><label for='answer-id-1126819' id='answer-label-1126819' class=' answer'><span>Processing based on fulfilling an employment contract.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286678[]' id='answer-id-1126820' class='answer   answerof-286678 ' value='1126820'   \/><label for='answer-id-1126820' id='answer-label-1126820' class=' answer'><span>Processing based on employee consent.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286678[]' id='answer-id-1126821' class='answer   answerof-286678 ' value='1126821'   \/><label for='answer-id-1126821' id='answer-label-1126821' class=' answer'><span>Processing based on legitimate interests.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286678[]' id='answer-id-1126822' class='answer   answerof-286678 ' value='1126822'   \/><label for='answer-id-1126822' id='answer-label-1126822' class=' answer'><span>Processing based on legal obligation.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-50' style=';'><div id='questionWrap-50'  class='   watupro-question-id-286679'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>50. <\/span>Which of the following regulates the use of electronic communications services within the European Union?<\/div><input type='hidden' name='question_id[]' id='qID_50' value='286679' \/><input type='hidden' id='answerType286679' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286679[]' id='answer-id-1126823' class='answer   answerof-286679 ' value='1126823'   \/><label for='answer-id-1126823' id='answer-label-1126823' class=' answer'><span>Regulator (EU) 2015\/2120 of the European Parliament and of the Council of 25 November 2015.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286679[]' id='answer-id-1126824' class='answer   answerof-286679 ' value='1126824'   \/><label for='answer-id-1126824' id='answer-label-1126824' class=' answer'><span>Regulation (EU) 2017\/1953 of the European Parliament and of the Council of 25 October 2017.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286679[]' id='answer-id-1126825' class='answer   answerof-286679 ' value='1126825'   \/><label for='answer-id-1126825' id='answer-label-1126825' class=' answer'><span>Directive 2002\/58'EC of the European Parliament and of the Council of 12 July 2002.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286679[]' id='answer-id-1126826' class='answer   answerof-286679 ' value='1126826'   \/><label for='answer-id-1126826' id='answer-label-1126826' class=' answer'><span>Directive (EU) 2019.789 of the European Parliament and of the Council of 17 April 2019.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-51' style=';'><div id='questionWrap-51'  class='   watupro-question-id-286680'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>51. <\/span>Which of the following is NOT an explicit right granted to data subjects under the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_51' value='286680' \/><input type='hidden' id='answerType286680' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286680[]' id='answer-id-1126827' class='answer   answerof-286680 ' value='1126827'   \/><label for='answer-id-1126827' id='answer-label-1126827' class=' answer'><span>The right to request access to the personal data a controller holds about them.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286680[]' id='answer-id-1126828' class='answer   answerof-286680 ' value='1126828'   \/><label for='answer-id-1126828' id='answer-label-1126828' class=' answer'><span>The right to request the deletion of data a controller holds about them.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286680[]' id='answer-id-1126829' class='answer   answerof-286680 ' value='1126829'   \/><label for='answer-id-1126829' id='answer-label-1126829' class=' answer'><span>The right to opt-out of the sale of their personal data to third parties.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286680[]' id='answer-id-1126830' class='answer   answerof-286680 ' value='1126830'   \/><label for='answer-id-1126830' id='answer-label-1126830' class=' answer'><span>The right to request restriction of processing of personal data, under certain scenarios.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-52' style=';'><div id='questionWrap-52'  class='   watupro-question-id-286681'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>52. <\/span>A U.S. company\u2019s website sells widgets. <br \/>\r<br>Which of the following factors would NOT in itself subject the company to the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_52' value='286681' \/><input type='hidden' id='answerType286681' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286681[]' id='answer-id-1126831' class='answer   answerof-286681 ' value='1126831'   \/><label for='answer-id-1126831' id='answer-label-1126831' class=' answer'><span>The widgets are offered in EU and priced in euro.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286681[]' id='answer-id-1126832' class='answer   answerof-286681 ' value='1126832'   \/><label for='answer-id-1126832' id='answer-label-1126832' class=' answer'><span>The website is in English and French, and is accessible in France.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286681[]' id='answer-id-1126833' class='answer   answerof-286681 ' value='1126833'   \/><label for='answer-id-1126833' id='answer-label-1126833' class=' answer'><span>An affiliate office is located in France but the processing is in the<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286681[]' id='answer-id-1126834' class='answer   answerof-286681 ' value='1126834'   \/><label for='answer-id-1126834' id='answer-label-1126834' class=' answer'><span>The website places cookies to monitor the EU website user behavior.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-53' style=';'><div id='questionWrap-53'  class='   watupro-question-id-286682'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>53. <\/span>Under the GDPR, which of the following is true in regard to adequacy decisions involving cross-border transfers?<\/div><input type='hidden' name='question_id[]' id='qID_53' value='286682' \/><input type='hidden' id='answerType286682' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286682[]' id='answer-id-1126835' class='answer   answerof-286682 ' value='1126835'   \/><label for='answer-id-1126835' id='answer-label-1126835' class=' answer'><span>The European Commission can adopt an adequacy decision for individual companies.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286682[]' id='answer-id-1126836' class='answer   answerof-286682 ' value='1126836'   \/><label for='answer-id-1126836' id='answer-label-1126836' class=' answer'><span>The European Commission can adopt, repeal or amend an existing adequacy decision.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286682[]' id='answer-id-1126837' class='answer   answerof-286682 ' value='1126837'   \/><label for='answer-id-1126837' id='answer-label-1126837' class=' answer'><span>EU member states are vested with the power to accept or reject a European Commission adequacy decision.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286682[]' id='answer-id-1126838' class='answer   answerof-286682 ' value='1126838'   \/><label for='answer-id-1126838' id='answer-label-1126838' class=' answer'><span>To be considered as adequate, third countries must implement the EU General Data Protection Regulation into their national legislation.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-54' style=';'><div id='questionWrap-54'  class='   watupro-question-id-286683'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>54. <\/span>For which of the following operations would an employer most likely be justified in requesting the data subject\u2019s consent?<\/div><input type='hidden' name='question_id[]' id='qID_54' value='286683' \/><input type='hidden' id='answerType286683' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286683[]' id='answer-id-1126839' class='answer   answerof-286683 ' value='1126839'   \/><label for='answer-id-1126839' id='answer-label-1126839' class=' answer'><span>Posting an employee\u2019s bicycle race photo on the company\u2019s social media.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286683[]' id='answer-id-1126840' class='answer   answerof-286683 ' value='1126840'   \/><label for='answer-id-1126840' id='answer-label-1126840' class=' answer'><span>Processing an employee\u2019s health certificate in order to provide sick leave.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286683[]' id='answer-id-1126841' class='answer   answerof-286683 ' value='1126841'   \/><label for='answer-id-1126841' id='answer-label-1126841' class=' answer'><span>Operating a CCTV system on company premises.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286683[]' id='answer-id-1126842' class='answer   answerof-286683 ' value='1126842'   \/><label for='answer-id-1126842' id='answer-label-1126842' class=' answer'><span>Assessing a potential employee\u2019s job application.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-55' style=';'><div id='questionWrap-55'  class='   watupro-question-id-286684'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>55. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU). <br \/>\r<br>People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations. <br \/>\r<br>The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform. <br \/>\r<br>The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''<\/div><input type='hidden' name='question_id[]' id='qID_55' value='286684' \/><input type='hidden' id='answerType286684' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286684[]' id='answer-id-1126843' class='answer   answerof-286684 ' value='1126843'   \/><label for='answer-id-1126843' id='answer-label-1126843' class=' answer'><span>No, the assessors do not quality as data processors as they only have access to encrypted data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286684[]' id='answer-id-1126844' class='answer   answerof-286684 ' value='1126844'   \/><label for='answer-id-1126844' id='answer-label-1126844' class=' answer'><span>No. the assessors do not quality as data processors as they do not copy the data to their facilities.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286684[]' id='answer-id-1126845' class='answer   answerof-286684 ' value='1126845'   \/><label for='answer-id-1126845' id='answer-label-1126845' class=' answer'><span>Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286684[]' id='answer-id-1126846' class='answer   answerof-286684 ' value='1126846'   \/><label for='answer-id-1126846' id='answer-label-1126846' class=' answer'><span>Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-56' style=';'><div id='questionWrap-56'  class='   watupro-question-id-286685'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>56. <\/span>Which of the following is NOT considered a fair processing practice in relation to the transparency principle?<\/div><input type='hidden' name='question_id[]' id='qID_56' value='286685' \/><input type='hidden' id='answerType286685' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286685[]' id='answer-id-1126847' class='answer   answerof-286685 ' value='1126847'   \/><label for='answer-id-1126847' id='answer-label-1126847' class=' answer'><span>Providing a multi-layered privacy notice, in a website environment.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286685[]' id='answer-id-1126848' class='answer   answerof-286685 ' value='1126848'   \/><label for='answer-id-1126848' id='answer-label-1126848' class=' answer'><span>Providing a QR code linking to more detailed privacy notice, in a CCTV sign.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286685[]' id='answer-id-1126849' class='answer   answerof-286685 ' value='1126849'   \/><label for='answer-id-1126849' id='answer-label-1126849' class=' answer'><span>Providing a hyperlink to the organization\u2019s home page, in a hard copy application form.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286685[]' id='answer-id-1126850' class='answer   answerof-286685 ' value='1126850'   \/><label for='answer-id-1126850' id='answer-label-1126850' class=' answer'><span>Providing a \u201cjust-in-time\u201d contextual pop-up privacy notice, in an online application from field.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-57' style=';'><div id='questionWrap-57'  class='   watupro-question-id-286686'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>57. <\/span>In the Planet 49 case, what was the man judgement of the Coon of Justice of the European Union (CJEU) regarding the issue of cookies?<\/div><input type='hidden' name='question_id[]' id='qID_57' value='286686' \/><input type='hidden' id='answerType286686' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286686[]' id='answer-id-1126851' class='answer   answerof-286686 ' value='1126851'   \/><label for='answer-id-1126851' id='answer-label-1126851' class=' answer'><span>If the cookies do not track personal data, then pre-checked boxes are acceptable.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286686[]' id='answer-id-1126852' class='answer   answerof-286686 ' value='1126852'   \/><label for='answer-id-1126852' id='answer-label-1126852' class=' answer'><span>If the ePrivacy Directive requires consent for cookies, then the GDPR's consent requirements apply.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286686[]' id='answer-id-1126853' class='answer   answerof-286686 ' value='1126853'   \/><label for='answer-id-1126853' id='answer-label-1126853' class=' answer'><span>If a website's cookie notice makes clear the information gathered and the lifespan of the cookie, then pre-checked boxes are acceptable.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286686[]' id='answer-id-1126854' class='answer   answerof-286686 ' value='1126854'   \/><label for='answer-id-1126854' id='answer-label-1126854' class=' answer'><span>If a data subject continues to scroll through a website after reading a cookie banner, this activity constitutes valid consent for the tracking described in the cookie banner.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-58' style=';'><div id='questionWrap-58'  class='   watupro-question-id-286687'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>58. <\/span>Limitation of liability. [\u2026] <br \/>\r<br>Consent <br \/>\r<br>By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of any advertising or marketing, you agree that Vigotron may contact you or provide you with any required notices, agreements, or other information concerning the services by email or other electronic means. You also agree that the Company may send automated emails with alerts regarding any problems with the M-Health app that may affect your well being. <br \/>\r<br>What is one potential problem Vigotron\u2019s age policy might encounter under the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_58' value='286687' \/><input type='hidden' id='answerType286687' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286687[]' id='answer-id-1126855' class='answer   answerof-286687 ' value='1126855'   \/><label for='answer-id-1126855' id='answer-label-1126855' class=' answer'><span>Age restrictions are more stringent when health data is involved.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286687[]' id='answer-id-1126856' class='answer   answerof-286687 ' value='1126856'   \/><label for='answer-id-1126856' id='answer-label-1126856' class=' answer'><span>Users are only required to be aged 13 or over to be considered adults.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286687[]' id='answer-id-1126857' class='answer   answerof-286687 ' value='1126857'   \/><label for='answer-id-1126857' id='answer-label-1126857' class=' answer'><span>Organizations must make reasonable efforts to verify parental consent.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286687[]' id='answer-id-1126858' class='answer   answerof-286687 ' value='1126858'   \/><label for='answer-id-1126858' id='answer-label-1126858' class=' answer'><span>Organizations that tie a service to marketing must seek consent for each purpose.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-59' style=';'><div id='questionWrap-59'  class='   watupro-question-id-286688'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>59. <\/span>Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?<\/div><input type='hidden' name='question_id[]' id='qID_59' value='286688' \/><input type='hidden' id='answerType286688' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286688[]' id='answer-id-1126859' class='answer   answerof-286688 ' value='1126859'   \/><label for='answer-id-1126859' id='answer-label-1126859' class=' answer'><span>A company wants to combine location data with other data in order to offer more personalized service for the customer.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286688[]' id='answer-id-1126860' class='answer   answerof-286688 ' value='1126860'   \/><label for='answer-id-1126860' id='answer-label-1126860' class=' answer'><span>A company wants to use location data to infer information on a person\u2019s clothes purchasing habits.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286688[]' id='answer-id-1126861' class='answer   answerof-286688 ' value='1126861'   \/><label for='answer-id-1126861' id='answer-label-1126861' class=' answer'><span>A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286688[]' id='answer-id-1126862' class='answer   answerof-286688 ' value='1126862'   \/><label for='answer-id-1126862' id='answer-label-1126862' class=' answer'><span>A company wants to use location data to track delivery trucks in order to make the routes more efficient.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-60' style=';'><div id='questionWrap-60'  class='   watupro-question-id-286689'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>60. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady\u2019s business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady\u2019s company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores. <br \/>\r<br>Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box\u2019s chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable. <br \/>\r<br>Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated <br \/>\r<br>Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers. <br \/>\r<br>Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box\u2019s home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box\u2019s Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy. <br \/>\r<br>Despite some customer complaints, Brady\u2019s business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles. Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services. <br \/>\r<br>Based on current trends in European privacy practices, which aspect of Brady Box\u2019 Online Behavioral Advertising (OBA) is most likely to be insufficient if the company becomes established in Europe?<\/div><input type='hidden' name='question_id[]' id='qID_60' value='286689' \/><input type='hidden' id='answerType286689' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286689[]' id='answer-id-1126863' class='answer   answerof-286689 ' value='1126863'   \/><label for='answer-id-1126863' id='answer-label-1126863' class=' answer'><span>The lack of the option to opt in.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286689[]' id='answer-id-1126864' class='answer   answerof-286689 ' value='1126864'   \/><label for='answer-id-1126864' id='answer-label-1126864' class=' answer'><span>The level of security within the website.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286689[]' id='answer-id-1126865' class='answer   answerof-286689 ' value='1126865'   \/><label for='answer-id-1126865' id='answer-label-1126865' class=' answer'><span>The contract with the third-party advertising network.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286689[]' id='answer-id-1126866' class='answer   answerof-286689 ' value='1126866'   \/><label for='answer-id-1126866' id='answer-label-1126866' class=' answer'><span>The need to have the contents of the advertising approved.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-61' style=';'><div id='questionWrap-61'  class='   watupro-question-id-286690'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>61. <\/span>Which of the following is NOT recognized as being a common characteristic of cloud-computing services?<\/div><input type='hidden' name='question_id[]' id='qID_61' value='286690' \/><input type='hidden' id='answerType286690' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286690[]' id='answer-id-1126867' class='answer   answerof-286690 ' value='1126867'   \/><label for='answer-id-1126867' id='answer-label-1126867' class=' answer'><span>The service\u2019s infrastructure is shared among the supplier\u2019s customers and can be located in a number of countries.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286690[]' id='answer-id-1126868' class='answer   answerof-286690 ' value='1126868'   \/><label for='answer-id-1126868' id='answer-label-1126868' class=' answer'><span>The supplier determines the location, security measures, and service standards applicable to the processing.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286690[]' id='answer-id-1126869' class='answer   answerof-286690 ' value='1126869'   \/><label for='answer-id-1126869' id='answer-label-1126869' class=' answer'><span>The supplier allows customer data to be transferred around the infrastructure according to capacity.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286690[]' id='answer-id-1126870' class='answer   answerof-286690 ' value='1126870'   \/><label for='answer-id-1126870' id='answer-label-1126870' class=' answer'><span>The supplier assumes the vendor\u2019s business risk associated with data processed by the supplier.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-62' style=';'><div id='questionWrap-62'  class='   watupro-question-id-286691'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>62. <\/span>There are three domains of security covered by Article 32 of the GDPR that apply to both the controller and the processor. These include all of the following EXCEPT?<\/div><input type='hidden' name='question_id[]' id='qID_62' value='286691' \/><input type='hidden' id='answerType286691' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286691[]' id='answer-id-1126871' class='answer   answerof-286691 ' value='1126871'   \/><label for='answer-id-1126871' id='answer-label-1126871' class=' answer'><span>Consent management and withdrawal.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286691[]' id='answer-id-1126872' class='answer   answerof-286691 ' value='1126872'   \/><label for='answer-id-1126872' id='answer-label-1126872' class=' answer'><span>Incident detection and response.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286691[]' id='answer-id-1126873' class='answer   answerof-286691 ' value='1126873'   \/><label for='answer-id-1126873' id='answer-label-1126873' class=' answer'><span>Preventative security.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286691[]' id='answer-id-1126874' class='answer   answerof-286691 ' value='1126874'   \/><label for='answer-id-1126874' id='answer-label-1126874' class=' answer'><span>Remedial security.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-63' style=';'><div id='questionWrap-63'  class='   watupro-question-id-286692'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>63. <\/span>A company wishes to transfer personal data to a country outside of the European Union\/EEA In order to do so, they are planning an assessment of the country's laws and practices, knowing that these may impinge upon the transfer safeguards they intend to use All of the following factors would be relevant for the company to consider EXCEPT'?<\/div><input type='hidden' name='question_id[]' id='qID_63' value='286692' \/><input type='hidden' id='answerType286692' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286692[]' id='answer-id-1126875' class='answer   answerof-286692 ' value='1126875'   \/><label for='answer-id-1126875' id='answer-label-1126875' class=' answer'><span>Any onward transfers, such as transfers of personal data to a sub-processor in the same or another third country.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286692[]' id='answer-id-1126876' class='answer   answerof-286692 ' value='1126876'   \/><label for='answer-id-1126876' id='answer-label-1126876' class=' answer'><span>The process of modernization in the third country concerned and their access to emerging technologies that rely on international transfers of personal data<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286692[]' id='answer-id-1126877' class='answer   answerof-286692 ' value='1126877'   \/><label for='answer-id-1126877' id='answer-label-1126877' class=' answer'><span>The technical, financial, and staff resources available to an authority m the third country concerned that may access the personal data to be transferred<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286692[]' id='answer-id-1126878' class='answer   answerof-286692 ' value='1126878'   \/><label for='answer-id-1126878' id='answer-label-1126878' class=' answer'><span>The contractual clauses between the data controller or processor established in the European Union\/EEA and the recipient of the transfer established in the third country concerned<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-64' style=';'><div id='questionWrap-64'  class='   watupro-question-id-286693'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>64. <\/span>Which of the following would NOT be relevant when determining if a processing activity would be considered profiling?<\/div><input type='hidden' name='question_id[]' id='qID_64' value='286693' \/><input type='hidden' id='answerType286693' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286693[]' id='answer-id-1126879' class='answer   answerof-286693 ' value='1126879'   \/><label for='answer-id-1126879' id='answer-label-1126879' class=' answer'><span>If the processing is to be performed by a third-party vendor<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286693[]' id='answer-id-1126880' class='answer   answerof-286693 ' value='1126880'   \/><label for='answer-id-1126880' id='answer-label-1126880' class=' answer'><span>If the processing involves data that is considered personal data<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286693[]' id='answer-id-1126881' class='answer   answerof-286693 ' value='1126881'   \/><label for='answer-id-1126881' id='answer-label-1126881' class=' answer'><span>If the processing of the data is done through automated means<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286693[]' id='answer-id-1126882' class='answer   answerof-286693 ' value='1126882'   \/><label for='answer-id-1126882' id='answer-label-1126882' class=' answer'><span>If the processing is used to predict the behavior of data subjects<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-65' style=';'><div id='questionWrap-65'  class='   watupro-question-id-286694'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>65. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company\u2019s revenue is due to international sales. <br \/>\r<br>The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children\u2019s Questions: on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well. The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience. <br \/>\r<br>When a child asks the toy a QUESTION, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure\u2019s integrated speakers, making it appear as though that the toy is actually responding to the child\u2019s QUESTION. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this. <br \/>\r<br>In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures\u2019 abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character\u2019s abilities remain intact. <br \/>\r<br>In light of the requirements of Article 32 of the GDPR (related to the Security of Processing), which practice should the company institute?<\/div><input type='hidden' name='question_id[]' id='qID_65' value='286694' \/><input type='hidden' id='answerType286694' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286694[]' id='answer-id-1126883' class='answer   answerof-286694 ' value='1126883'   \/><label for='answer-id-1126883' id='answer-label-1126883' class=' answer'><span>Encrypt the data in transit over the wireless Bluetooth connection.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286694[]' id='answer-id-1126884' class='answer   answerof-286694 ' value='1126884'   \/><label for='answer-id-1126884' id='answer-label-1126884' class=' answer'><span>Include dual-factor authentication before each use by a child in order to ensure a minimum amount of security.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286694[]' id='answer-id-1126885' class='answer   answerof-286694 ' value='1126885'   \/><label for='answer-id-1126885' id='answer-label-1126885' class=' answer'><span>Include three-factor authentication before each use by a child in order to ensure the best level of security possible.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286694[]' id='answer-id-1126886' class='answer   answerof-286694 ' value='1126886'   \/><label for='answer-id-1126886' id='answer-label-1126886' class=' answer'><span>Insert contractual clauses into the contract between the toy manufacturer and the cloud service provider, since South Africa is outside the European Union.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-66' style=';'><div id='questionWrap-66'  class='   watupro-question-id-286695'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>66. <\/span>When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?<\/div><input type='hidden' name='question_id[]' id='qID_66' value='286695' \/><input type='hidden' id='answerType286695' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286695[]' id='answer-id-1126887' class='answer   answerof-286695 ' value='1126887'   \/><label for='answer-id-1126887' id='answer-label-1126887' class=' answer'><span>Documenting due diligence steps taken in the pre-contractual stage.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286695[]' id='answer-id-1126888' class='answer   answerof-286695 ' value='1126888'   \/><label for='answer-id-1126888' id='answer-label-1126888' class=' answer'><span>Conducting a risk assessment to analyze possible outsourcing threats.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286695[]' id='answer-id-1126889' class='answer   answerof-286695 ' value='1126889'   \/><label for='answer-id-1126889' id='answer-label-1126889' class=' answer'><span>Requiring that the processor directly notify the appropriate supervisory authority.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286695[]' id='answer-id-1126890' class='answer   answerof-286695 ' value='1126890'   \/><label for='answer-id-1126890' id='answer-label-1126890' class=' answer'><span>Maintaining evidence that the processor was the best possible market choice available.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-67' style=';'><div id='questionWrap-67'  class='   watupro-question-id-286696'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>67. <\/span>Data retention in the EU was underpinned by a legal framework established by the Data Retention Directive (2006\/24\/EC). <br \/>\r<br>Why is the Directive no longer part of EU law?<\/div><input type='hidden' name='question_id[]' id='qID_67' value='286696' \/><input type='hidden' id='answerType286696' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286696[]' id='answer-id-1126891' class='answer   answerof-286696 ' value='1126891'   \/><label for='answer-id-1126891' id='answer-label-1126891' class=' answer'><span>The Directive was superseded by the EU Directive on Privacy and Electronic Communications.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286696[]' id='answer-id-1126892' class='answer   answerof-286696 ' value='1126892'   \/><label for='answer-id-1126892' id='answer-label-1126892' class=' answer'><span>The Directive was superseded by the General Data Protection Regulation.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286696[]' id='answer-id-1126893' class='answer   answerof-286696 ' value='1126893'   \/><label for='answer-id-1126893' id='answer-label-1126893' class=' answer'><span>The Directive was annulled by the Court of Justice of the European Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286696[]' id='answer-id-1126894' class='answer   answerof-286696 ' value='1126894'   \/><label for='answer-id-1126894' id='answer-label-1126894' class=' answer'><span>The Directive was annulled by the European Court of Human Rights.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-68' style=';'><div id='questionWrap-68'  class='   watupro-question-id-286697'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>68. <\/span>In which situation would a data controller most likely be able to justify the processing of the data of a child without parental consent?<\/div><input type='hidden' name='question_id[]' id='qID_68' value='286697' \/><input type='hidden' id='answerType286697' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286697[]' id='answer-id-1126895' class='answer   answerof-286697 ' value='1126895'   \/><label for='answer-id-1126895' id='answer-label-1126895' class=' answer'><span>When the data is to be processed for market research.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286697[]' id='answer-id-1126896' class='answer   answerof-286697 ' value='1126896'   \/><label for='answer-id-1126896' id='answer-label-1126896' class=' answer'><span>When providing preventive or counselling services to the child.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286697[]' id='answer-id-1126897' class='answer   answerof-286697 ' value='1126897'   \/><label for='answer-id-1126897' id='answer-label-1126897' class=' answer'><span>When providing the child with materials purely for educational use.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286697[]' id='answer-id-1126898' class='answer   answerof-286697 ' value='1126898'   \/><label for='answer-id-1126898' id='answer-label-1126898' class=' answer'><span>When a legitimate business interest makes obtaining consent impractical.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-69' style=';'><div id='questionWrap-69'  class='   watupro-question-id-286698'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>69. <\/span>A news website based m (he United Slates reports primarily on North American events The website is accessible to any user regardless of location, as the website operator does not block connections from outside of the U.S. The website offers a pad subscription that requires the creation of a user account; this subscription can only be paid in U.S. dollars. <br \/>\r<br>Which of the following explains why the website operator, who is the responsible for all processing related to account creation and subscriptions, is NOT required to comply with the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_69' value='286698' \/><input type='hidden' id='answerType286698' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286698[]' id='answer-id-1126899' class='answer   answerof-286698 ' value='1126899'   \/><label for='answer-id-1126899' id='answer-label-1126899' class=' answer'><span>Payments cannot be made in a European Union currency.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286698[]' id='answer-id-1126900' class='answer   answerof-286698 ' value='1126900'   \/><label for='answer-id-1126900' id='answer-label-1126900' class=' answer'><span>The controller does not have an establishment in the European Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286698[]' id='answer-id-1126901' class='answer   answerof-286698 ' value='1126901'   \/><label for='answer-id-1126901' id='answer-label-1126901' class=' answer'><span>The website is not available in several official languages of European Un on Member States<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286698[]' id='answer-id-1126902' class='answer   answerof-286698 ' value='1126902'   \/><label for='answer-id-1126902' id='answer-label-1126902' class=' answer'><span>The website cannot block connections from outside the<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286698[]' id='answer-id-1126903' class='answer   answerof-286698 ' value='1126903'   \/><label for='answer-id-1126903' id='answer-label-1126903' class=' answer'><span>that use a Virtual Private Network (VPN) to simulate a US location.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-70' style=';'><div id='questionWrap-70'  class='   watupro-question-id-286699'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>70. <\/span>A homeowner has installed a motion-detecting surveillance system that films his front doc <br \/>\r<br>and entryway. The camera does not film any public areas only areas that are the property of the homeowner. The system has seen declared to the authorities per the homeowner's country law, and a placard indicating the area is being video monitored is visible when entering the property <br \/>\r<br>Why can the homeowner NOT depend on the household exemption with regards to the processing of the video images recorded by the surveillance camera system?<\/div><input type='hidden' name='question_id[]' id='qID_70' value='286699' \/><input type='hidden' id='answerType286699' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286699[]' id='answer-id-1126904' class='answer   answerof-286699 ' value='1126904'   \/><label for='answer-id-1126904' id='answer-label-1126904' class=' answer'><span>The surveillance camera system can potentially capture biometric information of the homeowner's family, which would be considered a processing of special categories of personal data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286699[]' id='answer-id-1126905' class='answer   answerof-286699 ' value='1126905'   \/><label for='answer-id-1126905' id='answer-label-1126905' class=' answer'><span>The homeowner has not specified which security measures ore in place as part of the surveillance camera system<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286699[]' id='answer-id-1126906' class='answer   answerof-286699 ' value='1126906'   \/><label for='answer-id-1126906' id='answer-label-1126906' class=' answer'><span>The GDPR specifically excludes surveillance camera images from the household exemption<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286699[]' id='answer-id-1126907' class='answer   answerof-286699 ' value='1126907'   \/><label for='answer-id-1126907' id='answer-label-1126907' class=' answer'><span>The surveillance camera system can potentially film individuals who enter its filming perimeter<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-71' style=';'><div id='questionWrap-71'  class='   watupro-question-id-286700'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>71. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn\u2019t prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address. <br \/>\r<br>Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base. <br \/>\r<br>The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services. <br \/>\r<br>Another plan is called Customer for Life. The idea is to offer additional services through the company\u2019s app, like storage and sharing of DNA information with other applications and medical providers. The company\u2019s contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketingdirector, suggests that the company should fully exploit these provisions, and that it can work around customers\u2019 attempts to withdraw consent because the contract invalidates them. <br \/>\r<br>The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn\u2019t include any technology or infrastructure; rather, it\u2019s simply a room with a desk and some chairs. <br \/>\r<br>On a recent trip concerning the naming-rights deal, Bob\u2019s laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information. <br \/>\r<br>If Who-R-U adopts the We-Track-U pilot plan, why is it likely to be subject to the territorial scope of the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_71' value='286700' \/><input type='hidden' id='answerType286700' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286700[]' id='answer-id-1126908' class='answer   answerof-286700 ' value='1126908'   \/><label for='answer-id-1126908' id='answer-label-1126908' class=' answer'><span>Its plan would be in the context of the establishment of a controller in the Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286700[]' id='answer-id-1126909' class='answer   answerof-286700 ' value='1126909'   \/><label for='answer-id-1126909' id='answer-label-1126909' class=' answer'><span>It would be offering goods or services to data subjects in the Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286700[]' id='answer-id-1126910' class='answer   answerof-286700 ' value='1126910'   \/><label for='answer-id-1126910' id='answer-label-1126910' class=' answer'><span>It is engaging in commercial activities conducted in the Union.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286700[]' id='answer-id-1126911' class='answer   answerof-286700 ' value='1126911'   \/><label for='answer-id-1126911' id='answer-label-1126911' class=' answer'><span>It is monitoring the behavior of data subjects in the Union.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-72' style=';'><div id='questionWrap-72'  class='   watupro-question-id-286701'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>72. <\/span>When does the GDPR provide more latitude for a company to process data beyond its original collection purpose?<\/div><input type='hidden' name='question_id[]' id='qID_72' value='286701' \/><input type='hidden' id='answerType286701' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286701[]' id='answer-id-1126912' class='answer   answerof-286701 ' value='1126912'   \/><label for='answer-id-1126912' id='answer-label-1126912' class=' answer'><span>When the data has been pseudonymized.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286701[]' id='answer-id-1126913' class='answer   answerof-286701 ' value='1126913'   \/><label for='answer-id-1126913' id='answer-label-1126913' class=' answer'><span>When the data is protected by technological safeguards.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286701[]' id='answer-id-1126914' class='answer   answerof-286701 ' value='1126914'   \/><label for='answer-id-1126914' id='answer-label-1126914' class=' answer'><span>When the data serves legitimate interest of third parties.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286701[]' id='answer-id-1126915' class='answer   answerof-286701 ' value='1126915'   \/><label for='answer-id-1126915' id='answer-label-1126915' class=' answer'><span>When the data subject has failed to use a provided opt-out mechanism.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-73' style=';'><div id='questionWrap-73'  class='   watupro-question-id-286702'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>73. <\/span>Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?<\/div><input type='hidden' name='question_id[]' id='qID_73' value='286702' \/><input type='hidden' id='answerType286702' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286702[]' id='answer-id-1126916' class='answer   answerof-286702 ' value='1126916'   \/><label for='answer-id-1126916' id='answer-label-1126916' class=' answer'><span>The data subject already has information regarding how his data will be used<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286702[]' id='answer-id-1126917' class='answer   answerof-286702 ' value='1126917'   \/><label for='answer-id-1126917' id='answer-label-1126917' class=' answer'><span>The provision of such information to the data subject would be too problematic<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286702[]' id='answer-id-1126918' class='answer   answerof-286702 ' value='1126918'   \/><label for='answer-id-1126918' id='answer-label-1126918' class=' answer'><span>Third-party data would be disclosed by providing such information to the data subject<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286702[]' id='answer-id-1126919' class='answer   answerof-286702 ' value='1126919'   \/><label for='answer-id-1126919' id='answer-label-1126919' class=' answer'><span>The processing of the data subject\u2019s data is protected by appropriate technical measures<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-74' style=';'><div id='questionWrap-74'  class='   watupro-question-id-286703'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>74. <\/span>The origin of privacy as a fundamental human right can be found in which document?<\/div><input type='hidden' name='question_id[]' id='qID_74' value='286703' \/><input type='hidden' id='answerType286703' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286703[]' id='answer-id-1126920' class='answer   answerof-286703 ' value='1126920'   \/><label for='answer-id-1126920' id='answer-label-1126920' class=' answer'><span>Universal Declaration of Human Rights 1948.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286703[]' id='answer-id-1126921' class='answer   answerof-286703 ' value='1126921'   \/><label for='answer-id-1126921' id='answer-label-1126921' class=' answer'><span>European Convention of Human Rights 1953.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286703[]' id='answer-id-1126922' class='answer   answerof-286703 ' value='1126922'   \/><label for='answer-id-1126922' id='answer-label-1126922' class=' answer'><span>OECD Guidelines on the Protection of Privacy 1980.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286703[]' id='answer-id-1126923' class='answer   answerof-286703 ' value='1126923'   \/><label for='answer-id-1126923' id='answer-label-1126923' class=' answer'><span>Charier of Fundamental Rights of the European Union 2000.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-75' style=';'><div id='questionWrap-75'  class='   watupro-question-id-286704'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>75. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees\u2019 computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees\u2019 computers. <br \/>\r<br>Since these measures would potentially impact employees, Building Block\u2019s Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches. <br \/>\r<br>After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees\u2019 computers activity and their location. During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased. <br \/>\r<br>Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company\u2019s computers, and from working remotely without authorization. <br \/>\r<br>In addition to notifying employees about the purpose of the monitoring, the potential uses of their data and their privacy rights, what information should Building Block have provided them before implementing the security measures?<\/div><input type='hidden' name='question_id[]' id='qID_75' value='286704' \/><input type='hidden' id='answerType286704' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286704[]' id='answer-id-1126924' class='answer   answerof-286704 ' value='1126924'   \/><label for='answer-id-1126924' id='answer-label-1126924' class=' answer'><span>Information about what is specified in the employment contract.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286704[]' id='answer-id-1126925' class='answer   answerof-286704 ' value='1126925'   \/><label for='answer-id-1126925' id='answer-label-1126925' class=' answer'><span>Information about who employees should contact with any queries.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286704[]' id='answer-id-1126926' class='answer   answerof-286704 ' value='1126926'   \/><label for='answer-id-1126926' id='answer-label-1126926' class=' answer'><span>Information about how providing consent could affect them as employees.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286704[]' id='answer-id-1126927' class='answer   answerof-286704 ' value='1126927'   \/><label for='answer-id-1126927' id='answer-label-1126927' class=' answer'><span>Information about how the measures are in the best interests of the company.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-76' style=';'><div id='questionWrap-76'  class='   watupro-question-id-286705'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>76. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn\u2019t prevent all non-Canadian traffic). Italso declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address. <br \/>\r<br>Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base. <br \/>\r<br>The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre-registrations, it will develop EU-specific content and services. <br \/>\r<br>Another plan is called Customer for Life. The idea is to offer additional services through the company\u2019s app, like storage and sharing of DNA information with other applications and medical providers. The company\u2019s contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers\u2019 attempts to withdraw consent because the contract invalidates them. <br \/>\r<br>The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, <br \/>\r<br>which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn\u2019t include any technology or infrastructure; rather, it\u2019s simply a room with a desk and some chairs. <br \/>\r<br>On a recent trip concerning the naming-rights deal, Bob\u2019s laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information. <br \/>\r<br>The Customer for Life plan may conflict with which GDPR provision?<\/div><input type='hidden' name='question_id[]' id='qID_76' value='286705' \/><input type='hidden' id='answerType286705' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286705[]' id='answer-id-1126928' class='answer   answerof-286705 ' value='1126928'   \/><label for='answer-id-1126928' id='answer-label-1126928' class=' answer'><span>Article 6, which requires processing to be lawful.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286705[]' id='answer-id-1126929' class='answer   answerof-286705 ' value='1126929'   \/><label for='answer-id-1126929' id='answer-label-1126929' class=' answer'><span>Article 7, which requires consent to be as easy to withdraw as it is to give.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286705[]' id='answer-id-1126930' class='answer   answerof-286705 ' value='1126930'   \/><label for='answer-id-1126930' id='answer-label-1126930' class=' answer'><span>Article 16, which provides data subjects with a rights to rectification.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286705[]' id='answer-id-1126931' class='answer   answerof-286705 ' value='1126931'   \/><label for='answer-id-1126931' id='answer-label-1126931' class=' answer'><span>Article 20, which gives data subjects a right to data portability.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-77' style=';'><div id='questionWrap-77'  class='   watupro-question-id-286706'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>77. <\/span>What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?<\/div><input type='hidden' name='question_id[]' id='qID_77' value='286706' \/><input type='hidden' id='answerType286706' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286706[]' id='answer-id-1126932' class='answer   answerof-286706 ' value='1126932'   \/><label for='answer-id-1126932' id='answer-label-1126932' class=' answer'><span>The controller will be liable to pay an administrative fine<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286706[]' id='answer-id-1126933' class='answer   answerof-286706 ' value='1126933'   \/><label for='answer-id-1126933' id='answer-label-1126933' class=' answer'><span>The processor will be liable to pay compensation to affected data subjects<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286706[]' id='answer-id-1126934' class='answer   answerof-286706 ' value='1126934'   \/><label for='answer-id-1126934' id='answer-label-1126934' class=' answer'><span>The processor will be considered to be a controller in respect of the processing concerned<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286706[]' id='answer-id-1126935' class='answer   answerof-286706 ' value='1126935'   \/><label for='answer-id-1126935' id='answer-label-1126935' class=' answer'><span>The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-78' style=';'><div id='questionWrap-78'  class='   watupro-question-id-286707'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>78. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts. <br \/>\r<br>Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick\u2019s instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations. <br \/>\r<br>Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients\u2019 data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft\u2019s engineers, however, maintain all contact information in the same database as the identifying information. <br \/>\r<br>Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies\u2019 websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem\u2019s as well as EcoMick\u2019s latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem\u2019s products, she has never shopped EcoMick, nor provided her personal data to that company. <br \/>\r<br>JaphSoft\u2019s use of pseudonymization is NOT in compliance with the CDPR because?<\/div><input type='hidden' name='question_id[]' id='qID_78' value='286707' \/><input type='hidden' id='answerType286707' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286707[]' id='answer-id-1126936' class='answer   answerof-286707 ' value='1126936'   \/><label for='answer-id-1126936' id='answer-label-1126936' class=' answer'><span>JaphSoft failed to first anonymize the personal data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286707[]' id='answer-id-1126937' class='answer   answerof-286707 ' value='1126937'   \/><label for='answer-id-1126937' id='answer-label-1126937' class=' answer'><span>JaphSoft pseudonymized all the data instead of deleting what it no longer needed.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286707[]' id='answer-id-1126938' class='answer   answerof-286707 ' value='1126938'   \/><label for='answer-id-1126938' id='answer-label-1126938' class=' answer'><span>JaphSoft was in possession of information that could be used to identify data subjects.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286707[]' id='answer-id-1126939' class='answer   answerof-286707 ' value='1126939'   \/><label for='answer-id-1126939' id='answer-label-1126939' class=' answer'><span>JaphSoft failed to keep personally identifiable information in a separate database.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-79' style=';'><div id='questionWrap-79'  class='   watupro-question-id-286708'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>79. <\/span>Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit organizations in a privacy group litigation or class action. <br \/>\r<br>These organizations are commonly known as?<\/div><input type='hidden' name='question_id[]' id='qID_79' value='286708' \/><input type='hidden' id='answerType286708' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286708[]' id='answer-id-1126940' class='answer   answerof-286708 ' value='1126940'   \/><label for='answer-id-1126940' id='answer-label-1126940' class=' answer'><span>Law firm organizations.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286708[]' id='answer-id-1126941' class='answer   answerof-286708 ' value='1126941'   \/><label for='answer-id-1126941' id='answer-label-1126941' class=' answer'><span>Civil society organizations.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286708[]' id='answer-id-1126942' class='answer   answerof-286708 ' value='1126942'   \/><label for='answer-id-1126942' id='answer-label-1126942' class=' answer'><span>Human rights organizations.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286708[]' id='answer-id-1126943' class='answer   answerof-286708 ' value='1126943'   \/><label for='answer-id-1126943' id='answer-label-1126943' class=' answer'><span>Constitutional rights organizations.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-80' style=';'><div id='questionWrap-80'  class='   watupro-question-id-286709'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>80. <\/span>According to the GDPR, how is pseudonymous personal data defined?<\/div><input type='hidden' name='question_id[]' id='qID_80' value='286709' \/><input type='hidden' id='answerType286709' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286709[]' id='answer-id-1126944' class='answer   answerof-286709 ' value='1126944'   \/><label for='answer-id-1126944' id='answer-label-1126944' class=' answer'><span>Data that can no longer be attributed to a specific data subject without the use of additional information kept separately.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286709[]' id='answer-id-1126945' class='answer   answerof-286709 ' value='1126945'   \/><label for='answer-id-1126945' id='answer-label-1126945' class=' answer'><span>Data that can no longer be attributed to a specific data subject, with no possibility of re-identifying the data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286709[]' id='answer-id-1126946' class='answer   answerof-286709 ' value='1126946'   \/><label for='answer-id-1126946' id='answer-label-1126946' class=' answer'><span>Data that has been rendered anonymous in such a manner that the data subject is no longer identifiable.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286709[]' id='answer-id-1126947' class='answer   answerof-286709 ' value='1126947'   \/><label for='answer-id-1126947' id='answer-label-1126947' class=' answer'><span>Data that has been encrypted or is subject to other technical safeguards.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-81' style=';'><div id='questionWrap-81'  class='   watupro-question-id-286710'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>81. <\/span>When would a data subject NOT be able to exercise the right to portability?<\/div><input type='hidden' name='question_id[]' id='qID_81' value='286710' \/><input type='hidden' id='answerType286710' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286710[]' id='answer-id-1126948' class='answer   answerof-286710 ' value='1126948'   \/><label for='answer-id-1126948' id='answer-label-1126948' class=' answer'><span>When the processing is necessary to perform a task in the exercise of authority vested in the controller.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286710[]' id='answer-id-1126949' class='answer   answerof-286710 ' value='1126949'   \/><label for='answer-id-1126949' id='answer-label-1126949' class=' answer'><span>When the processing is carried out pursuant to a contract with the data subject.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286710[]' id='answer-id-1126950' class='answer   answerof-286710 ' value='1126950'   \/><label for='answer-id-1126950' id='answer-label-1126950' class=' answer'><span>When the data was supplied to the controller by the data subject.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286710[]' id='answer-id-1126951' class='answer   answerof-286710 ' value='1126951'   \/><label for='answer-id-1126951' id='answer-label-1126951' class=' answer'><span>When the processing is based on consent.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-82' style=';'><div id='questionWrap-82'  class='   watupro-question-id-286711'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>82. <\/span>A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?<\/div><input type='hidden' name='question_id[]' id='qID_82' value='286711' \/><input type='hidden' id='answerType286711' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286711[]' id='answer-id-1126952' class='answer   answerof-286711 ' value='1126952'   \/><label for='answer-id-1126952' id='answer-label-1126952' class=' answer'><span>If obtaining consent is deemed to involve disproportionate effort.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286711[]' id='answer-id-1126953' class='answer   answerof-286711 ' value='1126953'   \/><label for='answer-id-1126953' id='answer-label-1126953' class=' answer'><span>If obtaining consent is deemed voluntary by local legislation.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286711[]' id='answer-id-1126954' class='answer   answerof-286711 ' value='1126954'   \/><label for='answer-id-1126954' id='answer-label-1126954' class=' answer'><span>If the company limits the footage to data subjects solely of legal age.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286711[]' id='answer-id-1126955' class='answer   answerof-286711 ' value='1126955'   \/><label for='answer-id-1126955' id='answer-label-1126955' class=' answer'><span>If the company\u2019s status as a documentary provider allows it to claim legitimate interest.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-83' style=';'><div id='questionWrap-83'  class='   watupro-question-id-286712'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>83. <\/span>As per the GDPR, which legal basis would be the most appropriate for an online shop that wishes to process personal data for the purpose of fraud prevention?<\/div><input type='hidden' name='question_id[]' id='qID_83' value='286712' \/><input type='hidden' id='answerType286712' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286712[]' id='answer-id-1126956' class='answer   answerof-286712 ' value='1126956'   \/><label for='answer-id-1126956' id='answer-label-1126956' class=' answer'><span>Protection of the interests of the data subjects.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286712[]' id='answer-id-1126957' class='answer   answerof-286712 ' value='1126957'   \/><label for='answer-id-1126957' id='answer-label-1126957' class=' answer'><span>Performance of a contact<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286712[]' id='answer-id-1126958' class='answer   answerof-286712 ' value='1126958'   \/><label for='answer-id-1126958' id='answer-label-1126958' class=' answer'><span>Legitimate interest<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286712[]' id='answer-id-1126959' class='answer   answerof-286712 ' value='1126959'   \/><label for='answer-id-1126959' id='answer-label-1126959' class=' answer'><span>Consent<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-84' style=';'><div id='questionWrap-84'  class='   watupro-question-id-286713'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>84. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts. <br \/>\r<br>Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick\u2019s instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations. <br \/>\r<br>Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients\u2019 data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft\u2019s engineers, however, maintain all contact information in the same database as the identifying information. <br \/>\r<br>Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which <br \/>\r<br>included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies\u2019 websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem\u2019s as well as EcoMick\u2019s latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem\u2019s products, she has never shopped EcoMick, nor provided her personal data to that company. <br \/>\r<br>For what reason would JaphSoft be considered a controller under the GDPR?<\/div><input type='hidden' name='question_id[]' id='qID_84' value='286713' \/><input type='hidden' id='answerType286713' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286713[]' id='answer-id-1126960' class='answer   answerof-286713 ' value='1126960'   \/><label for='answer-id-1126960' id='answer-label-1126960' class=' answer'><span>It determines how long to retain the personal data collected.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286713[]' id='answer-id-1126961' class='answer   answerof-286713 ' value='1126961'   \/><label for='answer-id-1126961' id='answer-label-1126961' class=' answer'><span>It has been provided access to personal data in the MarketIQ database.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286713[]' id='answer-id-1126962' class='answer   answerof-286713 ' value='1126962'   \/><label for='answer-id-1126962' id='answer-label-1126962' class=' answer'><span>It uses personal data to improve its products and services for its client-base through machine learning.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286713[]' id='answer-id-1126963' class='answer   answerof-286713 ' value='1126963'   \/><label for='answer-id-1126963' id='answer-label-1126963' class=' answer'><span>It makes decisions regarding the technical and organizational measures necessary to protect the personal data.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-85' style=';'><div id='questionWrap-85'  class='   watupro-question-id-286714'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>85. <\/span>Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. <br \/>\r<br>Which of the following is NOT one of these exceptions?<\/div><input type='hidden' name='question_id[]' id='qID_85' value='286714' \/><input type='hidden' id='answerType286714' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286714[]' id='answer-id-1126964' class='answer   answerof-286714 ' value='1126964'   \/><label for='answer-id-1126964' id='answer-label-1126964' class=' answer'><span>The processing is done by a non-profit organization and the results are disclosed outside the organization.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286714[]' id='answer-id-1126965' class='answer   answerof-286714 ' value='1126965'   \/><label for='answer-id-1126965' id='answer-label-1126965' class=' answer'><span>The processing is necessary to protect the vital interests of the data subject when he or she is incapable of giving consent.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286714[]' id='answer-id-1126966' class='answer   answerof-286714 ' value='1126966'   \/><label for='answer-id-1126966' id='answer-label-1126966' class=' answer'><span>The processing is necessary for the establishment, exercise or defense of legal claims when courts are acting in a judicial capacity.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286714[]' id='answer-id-1126967' class='answer   answerof-286714 ' value='1126967'   \/><label for='answer-id-1126967' id='answer-label-1126967' class=' answer'><span>The processing is explicitly consented to by the data subject and he or she is allowed by Union or Member State law to lift the prohibition.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-86' style=';'><div id='questionWrap-86'  class='   watupro-question-id-286715'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>86. <\/span>Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?<\/div><input type='hidden' name='question_id[]' id='qID_86' value='286715' \/><input type='hidden' id='answerType286715' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286715[]' id='answer-id-1126968' class='answer   answerof-286715 ' value='1126968'   \/><label for='answer-id-1126968' id='answer-label-1126968' class=' answer'><span>Employees must sign an ad hoc contractual agreement each time personal data is exported.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286715[]' id='answer-id-1126969' class='answer   answerof-286715 ' value='1126969'   \/><label for='answer-id-1126969' id='answer-label-1126969' class=' answer'><span>All employees are subject to the rules in their entirety, regardless of where the work is taking place.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286715[]' id='answer-id-1126970' class='answer   answerof-286715 ' value='1126970'   \/><label for='answer-id-1126970' id='answer-label-1126970' class=' answer'><span>All employees must follow the privacy regulations of the jurisdictions where the current scope of their work is established.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286715[]' id='answer-id-1126971' class='answer   answerof-286715 ' value='1126971'   \/><label for='answer-id-1126971' id='answer-label-1126971' class=' answer'><span>Employees who control personal data must complete a rigorous certification procedure, as they are exempt from legal enforcement.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-87' style=';'><div id='questionWrap-87'  class='   watupro-question-id-286716'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>87. <\/span>If a French controller has a car-sharing app available only in Morocco, Algeria and Tunisia, but the data processing activities are carried out by the appointed processor in Spain, the GDPR will apply to the processing of the personal data so long as?<\/div><input type='hidden' name='question_id[]' id='qID_87' value='286716' \/><input type='hidden' id='answerType286716' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286716[]' id='answer-id-1126972' class='answer   answerof-286716 ' value='1126972'   \/><label for='answer-id-1126972' id='answer-label-1126972' class=' answer'><span>The individuals are European citizens or residents.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286716[]' id='answer-id-1126973' class='answer   answerof-286716 ' value='1126973'   \/><label for='answer-id-1126973' id='answer-label-1126973' class=' answer'><span>The data processing activities are in Spain.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286716[]' id='answer-id-1126974' class='answer   answerof-286716 ' value='1126974'   \/><label for='answer-id-1126974' id='answer-label-1126974' class=' answer'><span>The data controller is in France.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286716[]' id='answer-id-1126975' class='answer   answerof-286716 ' value='1126975'   \/><label for='answer-id-1126975' id='answer-label-1126975' class=' answer'><span>The EU individuals are targeted.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-88' style=';'><div id='questionWrap-88'  class='   watupro-question-id-286717'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>88. <\/span>A worker in a European Union (EU) member state has ceased his employment with a company. <br \/>\r<br>What should the employer most likely do in regard to the worker\u2019s personal data?<\/div><input type='hidden' name='question_id[]' id='qID_88' value='286717' \/><input type='hidden' id='answerType286717' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286717[]' id='answer-id-1126976' class='answer   answerof-286717 ' value='1126976'   \/><label for='answer-id-1126976' id='answer-label-1126976' class=' answer'><span>Destroy sensitive information and store the rest per applicable data protection rules.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286717[]' id='answer-id-1126977' class='answer   answerof-286717 ' value='1126977'   \/><label for='answer-id-1126977' id='answer-label-1126977' class=' answer'><span>Store all of the data in case the departing worker makes a subject access request.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286717[]' id='answer-id-1126978' class='answer   answerof-286717 ' value='1126978'   \/><label for='answer-id-1126978' id='answer-label-1126978' class=' answer'><span>Securely store the data that is required to be kept under local law.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286717[]' id='answer-id-1126979' class='answer   answerof-286717 ' value='1126979'   \/><label for='answer-id-1126979' id='answer-label-1126979' class=' answer'><span>Provide the employee the reasons for retaining the data.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-89' style=';'><div id='questionWrap-89'  class='   watupro-question-id-286718'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>89. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company <br \/>\r<br>B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry. <br \/>\r<br>Company B\u2019s payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A\u2019s factories. Company B won\u2019t hold any biometric data itself, but the related data will be uploaded to Company B\u2019s UK servers and used to provide the payroll service. <br \/>\r<br>Company B\u2019s live systems will contain the following information for each of Company A\u2019s employees: <br \/>\r<br>&#10001; Name <br \/>\r<br>&#10001; Address <br \/>\r<br>&#10001; Date of Birth <br \/>\r<br>&#10001; Payroll number <br \/>\r<br>&#10001; National Insurance number <br \/>\r<br>&#10001; Sick pay entitlement <br \/>\r<br>&#10001; Maternity\/paternity pay entitlement <br \/>\r<br>&#10001; Holiday entitlement <br \/>\r<br>&#10001; Pension and benefits contributions <br \/>\r<br>&#10001; Trade union contributions <br \/>\r<br>Jenny is the compliance officer at Company <br \/>\r<br>A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn\u2019t sure whether or not this is required. <br \/>\r<br>Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn\u2019t have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract. <br \/>\r<br>Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B\u2019s live systems in order to create a new database for Company B. <br \/>\r<br>This database will be stored in a test environment hosted on Company C\u2019s U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes. <br \/>\r<br>Unfortunately, Company C\u2019s U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A\u2019s employees is visible to anyone visiting Company C\u2019s website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees. <br \/>\r<br>The GDPR requires sufficient guarantees of a company\u2019s ability to implement adequate technical and organizational measures. <br \/>\r<br>What would be the most realistic way that Company B could have fulfilled this requirement? <br \/>\r<br>A. Hiring companies whose measures are consistent with recommendations of accrediting bodies. <br \/>\r<br>B. Requesting advice and technical support from Company A\u2019s IT team. <br \/>\r<br>C. Avoiding the use of another company\u2019s data to improve their own services. <br \/>\r<br>D. Vetting companies\u2019 measures with the appropriate supervisory authority.<\/div><input type='hidden' name='question_id[]' id='qID_89' value='286718' \/><input type='hidden' id='answerType286718' value='textarea'><!-- end question-content--><\/div><div class='question-choices '><p><textarea name='answer-286718[]' id='textarea_q_286718' class='watupro-textarea-medium' rows='5' cols='80'><\/textarea>\n<\/p><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-90' style=';'><div id='questionWrap-90'  class='   watupro-question-id-286719'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>90. <\/span>Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?<\/div><input type='hidden' name='question_id[]' id='qID_90' value='286719' \/><input type='hidden' id='answerType286719' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286719[]' id='answer-id-1126981' class='answer   answerof-286719 ' value='1126981'   \/><label for='answer-id-1126981' id='answer-label-1126981' class=' answer'><span>Name and contact details of each controller on behalf of which the processor is acting.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286719[]' id='answer-id-1126982' class='answer   answerof-286719 ' value='1126982'   \/><label for='answer-id-1126982' id='answer-label-1126982' class=' answer'><span>Categories of processing carried out on behalf of each controller for which the processor is acting.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286719[]' id='answer-id-1126983' class='answer   answerof-286719 ' value='1126983'   \/><label for='answer-id-1126983' id='answer-label-1126983' class=' answer'><span>Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286719[]' id='answer-id-1126984' class='answer   answerof-286719 ' value='1126984'   \/><label for='answer-id-1126984' id='answer-label-1126984' class=' answer'><span>Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-91' style=';'><div id='questionWrap-91'  class='   watupro-question-id-286720'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>91. <\/span>What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95\/46\/EC) all had in common but largely failed to achieve in Europe?<\/div><input type='hidden' name='question_id[]' id='qID_91' value='286720' \/><input type='hidden' id='answerType286720' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286720[]' id='answer-id-1126985' class='answer   answerof-286720 ' value='1126985'   \/><label for='answer-id-1126985' id='answer-label-1126985' class=' answer'><span>The establishment of a list of legitimate data processing criteria<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286720[]' id='answer-id-1126986' class='answer   answerof-286720 ' value='1126986'   \/><label for='answer-id-1126986' id='answer-label-1126986' class=' answer'><span>The creation of legally binding data protection principles<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286720[]' id='answer-id-1126987' class='answer   answerof-286720 ' value='1126987'   \/><label for='answer-id-1126987' id='answer-label-1126987' class=' answer'><span>The synchronization of approaches to data protection<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286720[]' id='answer-id-1126988' class='answer   answerof-286720 ' value='1126988'   \/><label for='answer-id-1126988' id='answer-label-1126988' class=' answer'><span>The restriction of cross-border data flow<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-92' style=';'><div id='questionWrap-92'  class='   watupro-question-id-286721'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>92. <\/span>What obligation does a data controller or processor have after appointing a data protection officer?<\/div><input type='hidden' name='question_id[]' id='qID_92' value='286721' \/><input type='hidden' id='answerType286721' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286721[]' id='answer-id-1126989' class='answer   answerof-286721 ' value='1126989'   \/><label for='answer-id-1126989' id='answer-label-1126989' class=' answer'><span>To ensure that the data protection officer receives sufficient instructions regarding the exercise of his or her defined tasks.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286721[]' id='answer-id-1126990' class='answer   answerof-286721 ' value='1126990'   \/><label for='answer-id-1126990' id='answer-label-1126990' class=' answer'><span>To provide resources necessary to carry out the defined tasks of the data protection officer and to maintain his or her expert knowledge.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286721[]' id='answer-id-1126991' class='answer   answerof-286721 ' value='1126991'   \/><label for='answer-id-1126991' id='answer-label-1126991' class=' answer'><span>To ensure that the data protection officer acts as the sole point of contact for individuals\u2019 Questions: about their personal data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286721[]' id='answer-id-1126992' class='answer   answerof-286721 ' value='1126992'   \/><label for='answer-id-1126992' id='answer-label-1126992' class=' answer'><span>To submit for approval to the data protection officer a code of conduct to govern organizational practices and demonstrate compliance with data protection principles.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-93' style=';'><div id='questionWrap-93'  class='   watupro-question-id-286722'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>93. <\/span>SCENARIO <br \/>\r<br>Please use the following to answer the next question: <br \/>\r<br>Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical company on a clinical trial related to COVID-19. As part of his onboarding process Jack received privacy training He was explicitly informed that while he would need to process confidential patient data in the course of his work, he may under no circumstances use this data for anything other than the performance of work-related (asks This was also specified in the privacy policy, which Jack signed upon conclusion of the training. <br \/>\r<br>After several months of employment, Jack got into an argument with a patient over the phone. Out of anger he later posted the patient's name and hearth information, along with disparaging comments, on a social media website. When this was discovered by his Pharmacovigilance supervisors. Jack was immediately dismissed <br \/>\r<br>Jack's lawyer sent a letter to the company stating that dismissal was a disproportionate sanction, and that if Jack was not reinstated within 14 days his firm would have no alternative but to commence legal proceedings against the company. This letter was accompanied by a data access request from Jack requesting a copy of &quot;all personal data, including internal emails that were sent\/received by Jack or where Jack is directly or indirectly identifiable from the contents In relation to the emails Jack listed six members of the management team whose inboxes he required access. <br \/>\r<br>The company conducted an initial search of its IT systems, which returned a large amount of information They then contacted Jack, requesting that he be more specific regarding what information he required, so that they could carry out a targeted search Jack responded by stating that he would not narrow the scope of the information requester. <br \/>\r<br>Under Article 82 of the GDPR (&quot;Right to compensation and liability-), which party is liable for the damage caused by the data breach?<\/div><input type='hidden' name='question_id[]' id='qID_93' value='286722' \/><input type='hidden' id='answerType286722' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286722[]' id='answer-id-1126993' class='answer   answerof-286722 ' value='1126993'   \/><label for='answer-id-1126993' id='answer-label-1126993' class=' answer'><span>Both parties are exempt, as the company is involved in human health research<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286722[]' id='answer-id-1126994' class='answer   answerof-286722 ' value='1126994'   \/><label for='answer-id-1126994' id='answer-label-1126994' class=' answer'><span>Jack and the pharmaceutical company are jointly liable.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286722[]' id='answer-id-1126995' class='answer   answerof-286722 ' value='1126995'   \/><label for='answer-id-1126995' id='answer-label-1126995' class=' answer'><span>The pharmaceutical company is liable.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286722[]' id='answer-id-1126996' class='answer   answerof-286722 ' value='1126996'   \/><label for='answer-id-1126996' id='answer-label-1126996' class=' answer'><span>Jack is liable<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-94' style=';'><div id='questionWrap-94'  class='   watupro-question-id-286723'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>94. <\/span>According to Art 23 GDPR, which of the following data subject rights can NOT be restricted?<\/div><input type='hidden' name='question_id[]' id='qID_94' value='286723' \/><input type='hidden' id='answerType286723' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286723[]' id='answer-id-1126997' class='answer   answerof-286723 ' value='1126997'   \/><label for='answer-id-1126997' id='answer-label-1126997' class=' answer'><span>Right to restriction of processing.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286723[]' id='answer-id-1126998' class='answer   answerof-286723 ' value='1126998'   \/><label for='answer-id-1126998' id='answer-label-1126998' class=' answer'><span>Right to erasure (&quot;Right to be forgotten&quot;).<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286723[]' id='answer-id-1126999' class='answer   answerof-286723 ' value='1126999'   \/><label for='answer-id-1126999' id='answer-label-1126999' class=' answer'><span>Right to lodge a complaint with a supervisory authority.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286723[]' id='answer-id-1127000' class='answer   answerof-286723 ' value='1127000'   \/><label for='answer-id-1127000' id='answer-label-1127000' class=' answer'><span>Right not to be subject to automated individual decision-making<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-95' style=';'><div id='questionWrap-95'  class='   watupro-question-id-286724'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>95. <\/span>According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject\u2019s personal data has been obtained from other sources?<\/div><input type='hidden' name='question_id[]' id='qID_95' value='286724' \/><input type='hidden' id='answerType286724' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286724[]' id='answer-id-1127001' class='answer   answerof-286724 ' value='1127001'   \/><label for='answer-id-1127001' id='answer-label-1127001' class=' answer'><span>As soon as possible after obtaining the personal data.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286724[]' id='answer-id-1127002' class='answer   answerof-286724 ' value='1127002'   \/><label for='answer-id-1127002' id='answer-label-1127002' class=' answer'><span>As soon as possible after the first communication with the data subject.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286724[]' id='answer-id-1127003' class='answer   answerof-286724 ' value='1127003'   \/><label for='answer-id-1127003' id='answer-label-1127003' class=' answer'><span>Within a reasonable period after obtaining the personal data, but no later than one month.<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286724[]' id='answer-id-1127004' class='answer   answerof-286724 ' value='1127004'   \/><label for='answer-id-1127004' id='answer-label-1127004' class=' answer'><span>Within a reasonable period after obtaining the personal data, but no later than eight weeks.<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-96' style=';'><div id='questionWrap-96'  class='   watupro-question-id-286725'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>96. <\/span>Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. <br \/>\r<br>Which GDPR principle is she following?<\/div><input type='hidden' name='question_id[]' id='qID_96' value='286725' \/><input type='hidden' id='answerType286725' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286725[]' id='answer-id-1127005' class='answer   answerof-286725 ' value='1127005'   \/><label for='answer-id-1127005' id='answer-label-1127005' class=' answer'><span>Accuracy<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286725[]' id='answer-id-1127006' class='answer   answerof-286725 ' value='1127006'   \/><label for='answer-id-1127006' id='answer-label-1127006' class=' answer'><span>Storage Limitation<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286725[]' id='answer-id-1127007' class='answer   answerof-286725 ' value='1127007'   \/><label for='answer-id-1127007' id='answer-label-1127007' class=' answer'><span>Integrity and confidentiality<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286725[]' id='answer-id-1127008' class='answer   answerof-286725 ' value='1127008'   \/><label for='answer-id-1127008' id='answer-label-1127008' class=' answer'><span>Lawfulness, fairness and transparency<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div class='watu-question ' id='question-97' style=';'><div id='questionWrap-97'  class='   watupro-question-id-286726'>\n\t\t\t<div class='question-content'><div><span class='watupro_num'>97. <\/span>Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?<\/div><input type='hidden' name='question_id[]' id='qID_97' value='286726' \/><input type='hidden' id='answerType286726' value='radio'><!-- end question-content--><\/div><div class='question-choices watupro-choices-columns '><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286726[]' id='answer-id-1127009' class='answer   answerof-286726 ' value='1127009'   \/><label for='answer-id-1127009' id='answer-label-1127009' class=' answer'><span>The right to privacy is an absolute right<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286726[]' id='answer-id-1127010' class='answer   answerof-286726 ' value='1127010'   \/><label for='answer-id-1127010' id='answer-label-1127010' class=' answer'><span>The right to privacy has to be balanced against other rights under the ECHR<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286726[]' id='answer-id-1127011' class='answer   answerof-286726 ' value='1127011'   \/><label for='answer-id-1127011' id='answer-label-1127011' class=' answer'><span>The right to freedom of expression under Article 10 of the ECHR will always override the right to privacy<\/span><\/label><\/div><div class='watupro-question-choice  ' dir='auto' ><input type='radio' name='answer-286726[]' id='answer-id-1127012' class='answer   answerof-286726 ' value='1127012'   \/><label for='answer-id-1127012' id='answer-label-1127012' class=' answer'><span>The right to privacy protects the right to hold opinions and to receive and impart ideas without interference<\/span><\/label><\/div><!-- end question-choices--><\/div><!-- end questionWrap--><\/div><\/div><div style='display:none' id='question-98'>\n\t<div class='question-content'>\n\t\t<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.dumpsbase.com\/freedumps\/wp-content\/plugins\/watupro\/img\/loading.gif\" width=\"16\" height=\"16\" alt=\"Loading...\" title=\"Loading...\" \/>&nbsp;Loading...\t<\/div>\n<\/div>\n\n<br \/>\n\t\n\t\t\t<div class=\"watupro_buttons flex \" id=\"watuPROButtons7735\" >\n\t\t  <div id=\"prev-question\" style=\"display:none;\"><input type=\"button\" value=\"&lt; Previous\" onclick=\"WatuPRO.nextQuestion(event, 'previous');\"\/><\/div>\t\t  \t\t  \t\t   \n\t\t   \t  \t\t<div><input type=\"button\" name=\"action\" class=\"watupro-submit-button\" onclick=\"WatuPRO.submitResult(event)\" id=\"action-button\" value=\"View Results\"  \/>\n\t\t<\/div>\n\t\t<\/div>\n\t\t\n\t<input type=\"hidden\" name=\"quiz_id\" value=\"7735\" id=\"watuPROExamID\"\/>\n\t<input type=\"hidden\" name=\"start_time\" id=\"startTime\" value=\"2026-04-15 10:22:52\" \/>\n\t<input type=\"hidden\" name=\"start_timestamp\" id=\"startTimeStamp\" value=\"1776248572\" \/>\n\t<input type=\"hidden\" name=\"question_ids\" value=\"\" \/>\n\t<input type=\"hidden\" name=\"watupro_questions\" value=\"286630:1126628,1126629,1126630,1126631 | 286631:1126632,1126633,1126634,1126635 | 286632:1126636,1126637,1126638,1126639 | 286633:1126640,1126641,1126642,1126643 | 286634:1126644,1126645,1126646,1126647 | 286635:1126648,1126649,1126650,1126651 | 286636:1126652,1126653,1126654,1126655 | 286637:1126656,1126657,1126658,1126659 | 286638:1126660,1126661,1126662,1126663 | 286639:1126664,1126665,1126666,1126667 | 286640:1126668,1126669,1126670,1126671 | 286641:1126672,1126673,1126674,1126675 | 286642:1126676,1126677,1126678,1126679 | 286643:1126680,1126681,1126682 | 286644:1126683,1126684,1126685,1126686 | 286645:1126687,1126688,1126689,1126690 | 286646:1126691,1126692,1126693,1126694 | 286647:1126695,1126696,1126697,1126698 | 286648:1126699,1126700,1126701,1126702 | 286649:1126703,1126704,1126705,1126706 | 286650:1126707,1126708,1126709,1126710 | 286651:1126711,1126712,1126713,1126714 | 286652:1126715,1126716,1126717,1126718 | 286653:1126719,1126720,1126721,1126722 | 286654:1126723,1126724,1126725,1126726 | 286655:1126727,1126728,1126729,1126730 | 286656:1126731,1126732,1126733,1126734 | 286657:1126735,1126736,1126737,1126738 | 286658:1126739,1126740,1126741,1126742 | 286659:1126743,1126744,1126745,1126746 | 286660:1126747,1126748,1126749,1126750 | 286661:1126751,1126752,1126753,1126754 | 286662:1126755,1126756,1126757,1126758 | 286663:1126759,1126760,1126761,1126762 | 286664:1126763,1126764,1126765,1126766 | 286665:1126767,1126768,1126769,1126770 | 286666:1126771,1126772,1126773,1126774 | 286667:1126775,1126776,1126777,1126778 | 286668:1126779,1126780,1126781,1126782 | 286669:1126783,1126784,1126785,1126786 | 286670:1126787,1126788,1126789,1126790 | 286671:1126791,1126792,1126793,1126794 | 286672:1126795,1126796,1126797,1126798 | 286673:1126799,1126800,1126801,1126802 | 286674:1126803,1126804,1126805,1126806 | 286675:1126807,1126808,1126809,1126810 | 286676:1126811,1126812,1126813,1126814 | 286677:1126815,1126816,1126817,1126818 | 286678:1126819,1126820,1126821,1126822 | 286679:1126823,1126824,1126825,1126826 | 286680:1126827,1126828,1126829,1126830 | 286681:1126831,1126832,1126833,1126834 | 286682:1126835,1126836,1126837,1126838 | 286683:1126839,1126840,1126841,1126842 | 286684:1126843,1126844,1126845,1126846 | 286685:1126847,1126848,1126849,1126850 | 286686:1126851,1126852,1126853,1126854 | 286687:1126855,1126856,1126857,1126858 | 286688:1126859,1126860,1126861,1126862 | 286689:1126863,1126864,1126865,1126866 | 286690:1126867,1126868,1126869,1126870 | 286691:1126871,1126872,1126873,1126874 | 286692:1126875,1126876,1126877,1126878 | 286693:1126879,1126880,1126881,1126882 | 286694:1126883,1126884,1126885,1126886 | 286695:1126887,1126888,1126889,1126890 | 286696:1126891,1126892,1126893,1126894 | 286697:1126895,1126896,1126897,1126898 | 286698:1126899,1126900,1126901,1126902,1126903 | 286699:1126904,1126905,1126906,1126907 | 286700:1126908,1126909,1126910,1126911 | 286701:1126912,1126913,1126914,1126915 | 286702:1126916,1126917,1126918,1126919 | 286703:1126920,1126921,1126922,1126923 | 286704:1126924,1126925,1126926,1126927 | 286705:1126928,1126929,1126930,1126931 | 286706:1126932,1126933,1126934,1126935 | 286707:1126936,1126937,1126938,1126939 | 286708:1126940,1126941,1126942,1126943 | 286709:1126944,1126945,1126946,1126947 | 286710:1126948,1126949,1126950,1126951 | 286711:1126952,1126953,1126954,1126955 | 286712:1126956,1126957,1126958,1126959 | 286713:1126960,1126961,1126962,1126963 | 286714:1126964,1126965,1126966,1126967 | 286715:1126968,1126969,1126970,1126971 | 286716:1126972,1126973,1126974,1126975 | 286717:1126976,1126977,1126978,1126979 | 286718:1126980 | 286719:1126981,1126982,1126983,1126984 | 286720:1126985,1126986,1126987,1126988 | 286721:1126989,1126990,1126991,1126992 | 286722:1126993,1126994,1126995,1126996 | 286723:1126997,1126998,1126999,1127000 | 286724:1127001,1127002,1127003,1127004 | 286725:1127005,1127006,1127007,1127008 | 286726:1127009,1127010,1127011,1127012\" \/>\n\t<input type=\"hidden\" name=\"no_ajax\" value=\"0\">\t\t\t<\/form>\n\t<p>&nbsp;<\/p>\n<\/div>\n\n<script type=\"text\/javascript\">\n\/\/jQuery(document).ready(function(){\ndocument.addEventListener(\"DOMContentLoaded\", function(event) { \t\nvar question_ids = \"286630,286631,286632,286633,286634,286635,286636,286637,286638,286639,286640,286641,286642,286643,286644,286645,286646,286647,286648,286649,286650,286651,286652,286653,286654,286655,286656,286657,286658,286659,286660,286661,286662,286663,286664,286665,286666,286667,286668,286669,286670,286671,286672,286673,286674,286675,286676,286677,286678,286679,286680,286681,286682,286683,286684,286685,286686,286687,286688,286689,286690,286691,286692,286693,286694,286695,286696,286697,286698,286699,286700,286701,286702,286703,286704,286705,286706,286707,286708,286709,286710,286711,286712,286713,286714,286715,286716,286717,286718,286719,286720,286721,286722,286723,286724,286725,286726\";\nWatuPROSettings[7735] = {};\nWatuPRO.qArr = question_ids.split(',');\nWatuPRO.exam_id = 7735;\t    \nWatuPRO.post_id = 63886;\nWatuPRO.store_progress = 0;\nWatuPRO.curCatPage = 1;\nWatuPRO.requiredIDs=\"0\".split(\",\");\nWatuPRO.hAppID = \"0.11836300 1776248572\";\nvar url = \"https:\/\/www.dumpsbase.com\/freedumps\/wp-content\/plugins\/watupro\/show_exam.php\";\nWatuPRO.examMode = 1;\nWatuPRO.siteURL=\"https:\/\/www.dumpsbase.com\/freedumps\/wp-admin\/admin-ajax.php\";\nWatuPRO.emailIsNotRequired = 0;\nWatuPROIntel.init(7735);\nWatuPRO.inCategoryPages=1;});    \t \n<\/script>\n<p>\u00a0<\/p>\n\n\n\n\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9860,8844],"tags":[16214],"class_list":["post-63886","post","type-post","status-publish","format-standard","hentry","category-cipp-e-certification","category-iapp","tag-cipp-e-updated-dumps"],"_links":{"self":[{"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/posts\/63886","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/comments?post=63886"}],"version-history":[{"count":1,"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/posts\/63886\/revisions"}],"predecessor-version":[{"id":63887,"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/posts\/63886\/revisions\/63887"}],"wp:attachment":[{"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/media?parent=63886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/categories?post=63886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dumpsbase.com\/freedumps\/wp-json\/wp\/v2\/tags?post=63886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}