Aug 30, 2026 Reliable Study Materials for CIPP-E Exam Success For Sure [Q80-Q96]

Share

Aug 30, 2026 Reliable Study Materials for CIPP-E Exam Success For Sure

100% Latest Most updated CIPP-E Questions and Answers


The CIPP/E certification is ideal for individuals who work in privacy roles, including data protection officers, privacy consultants, privacy lawyers, and privacy auditors. Certified Information Privacy Professional/Europe (CIPP/E) certification is also suitable for individuals who are responsible for managing and implementing data protection policies and procedures in their organizations. The CIPP/E certification provides the necessary knowledge and skills to ensure that organizations comply with European data protection laws and regulations.

 

NEW QUESTION # 80
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What must Zandelay provide to the supervisory authority during the prior consultation?

  • A. Certificates that prove Martin's professional qualities and expert knowledge of data protection law.
  • B. An explanation of the purposes and means of the intended processing.
  • C. An evaluation of the complexity of the intended processing.
  • D. Records showing that customers have explicitly consented to the intended profiling activities.

Answer: B

Explanation:
According to Article 36 of the GDPR, when a controller intends to process personal data that would result in a high risk to the rights and freedoms of data subjects, and a data protection impact assessment under Article 35 indicates that the risk cannot be mitigated by the controller, the controller must consult the supervisory authority before processing. The purpose of this prior consultation is to seek the advice of the supervisory authority on whether the processing complies with the GDPR and what measures can be taken to ensure compliance. During the prior consultation, the controller must provide the supervisory authority with the following information:
* the respective responsibilities of the controller, joint controllers and processors involved in the processing, in particular for processing within a group of undertakings;
* the purposes and means of the intended processing;
* the measures and safeguards provided to protect the rights and freedoms of data subjects pursuant to the GDPR;
* the contact details of the data protection officer, if any;
* the data protection impact assessment provided for in Article 35; and
* any other information requested by the supervisory authority.
Therefore, the correct answer is B. An explanation of the purposes and means of the intended processing. This information is essential for the supervisory authority to understand the nature and scope of the processing and to assess its compliance with the GDPR. The other options are not required by Article 36, although they may be relevant for other aspects of the GDPR, such as the data protection by design and by default principle (A), the lawfulness of processing , or the designation of the data protection officer (D). References:
* Article 36 of the GDPR, which regulates the prior consultation with the supervisory authority.
* ICO guidance, which explains the process and requirements of the prior consultation.
* EDPB guidelines, which provide further guidance on the criteria and procedure of the prior consultation.


NEW QUESTION # 81
Which of the following would require designating a data protection officer?

  • A. The core activities of the controller or processor consist of processing operations of financial information or information relating to children.
  • B. The core activities of the controller or processor consist of processing operations that require systematic monitoring of data subjects on a large scale.
  • C. Processing is carried out by an organization employing 250 persons or more.
  • D. Processing is carried out for the purpose of providing for-profit goods or services to individuals in the EU.

Answer: B

Explanation:
According to Article 37 of the GDPR, the designation of a data protection officer (DPO) is mandatory for controllers and processors in three cases1:
When the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; When the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or When the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.
The GDPR does not define what constitutes "regular and systematic monitoring" or "large scale", but the Article 29 Working Party (now replaced by the European Data Protection Board) has provided some guidance on these concepts2. According to the guidance, "regular and systematic monitoring" includes all forms of tracking and profiling on the internet, including for the purposes of behavioural advertising, but also offline activities such as CCTV or health data monitoring. The guidance also suggests some criteria to assess whether the processing is carried out on a large scale, such as the number of data subjects concerned, the volume of data or the range of data items processed, the duration or permanence of the processing activity, and the geographical extent of the processing.
In the given scenario, option D is the only one that clearly falls under the second case of mandatory DPO designation, as it implies that the controller or processor is engaged in regular and systematic monitoring of data subjects on a large scale as part of their core activities. This could include, for example, online behavioural advertising, location tracking, loyalty programs, or health data analytics. The other options are not sufficient to trigger the obligation to appoint a DPO, unless they are combined with other factors that indicate a large scale or a high risk of the processing. For instance, option A is not relevant, as the GDPR does not set a threshold based on the size or number of employees of the organisation. Option B is also not decisive, as the GDPR does not distinguish between for-profit or non-profit purposes of the processing. Option C may require a DPO if the processing of financial information or information relating to children is done on a large scale and involves special categories of data, but it is not a general rule. Reference:
1: Article 37 of the GDPR
2: Guidelines on Data Protection Officers ('DPOs')
3: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
4: https://edpb.europa.eu/sites/edpb/files/files/file1/wp243rev01_en.pdf
5: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
6: [https://edpb.europa.eu/sites/edpb/files/files/file1/wp243rev01_en.pdf]
7: [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679]


NEW QUESTION # 82
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data on the stick is unencrypted and in clear text. It is uncertain what has happened to the stick at this stage, but it likely was lost during the travel of an employee. What should the company do?

  • A. Launch an investigation and if nothing is found within one month, notify the data protection supervisory authority.
  • B. Invoke the "disproportionate effort" exception under Article 33 to postpone notifying data subjects until more information can be gathered.
  • C. Immediately notify all the customers of the company that their information has been accessed by an unauthorized person.
  • D. Notify as soon as possible the data protection supervisory authority that a data breach may have taken place.

Answer: D

Explanation:
The GDPR requires that in the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons1. A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed2. In this scenario, the company ABCD is the controller of the client data, and the loss of the memory stick containing unencrypted and clear text personal data is a personal data breach that may pose a risk to the rights and freedoms of the data subjects, such as identity theft, fraud, financial loss, or reputational damage. Therefore, the company ABCD should notify the data protection supervisory authority as soon as possible, and provide the information specified in Article 33(3) of the GDPR, such as the nature of the breach, the categories and number of data subjects and personal data records concerned, the likely consequences of the breach, and the measures taken or proposed to address the breach1. Option A is the correct answer, as it reflects the obligation of the controller under the GDPR. Options B, C and D are incorrect, as they do not comply with the GDPR requirements. Option B would delay the notification beyond the 72-hour deadline, which could result in administrative fines or other sanctions3. Option C would misuse the "disproportionate effort" exception, which only applies to the communication of the breach to the data subjects, not to the notification to the supervisory authority, and only when the controller has implemented appropriate technical and organisational protection measures, such as encryption, that render the personal data unintelligible to any person who is not authorised to access it4. Option D would prematurely notify the customers of the company without first notifying the supervisory authority, and without assessing the level of risk and the necessity of such communication, which should be done in consultation with the supervisory authority5. Reference: 1: Article 33(1) of the GDPR 2: Article 4(12) of the GDPR 3: Article 83(4)(a) of the GDPR 4: Article 34(3)(a) of the GDPR 5: Article 34(1) and (2) of the GDPR


NEW QUESTION # 83
To comply with the GDPR and the EU Court of Justice's decision in Schrems II, the European Commission issued what are commonly referred to as the new standard contractual clauses (SCCs). As a result, businesses must do all of the following EXCEPT?

  • A. Consider the new optional docking clause, which expressly permits adding new parties to the SCCs.
  • B. Implement the new SCCs in the U.K. following Brexit, as the U.K. Information Commissioner's Office does not have the authority to publish its own set of SCCs.
  • C. Take steps to flow down the new SCCs to relevant parts of their supply chain using the new SCCs as of September 27, 2021, if the business is a data importer.
  • D. Migrate all contracts entered into before September 27, 2021, that use the old SCCs to the new SCCs by December 27, 2022.

Answer: B

Explanation:
The General Data Protection Regulation (GDPR) introduces a mechanism for personal data transfers to third countries or international organisations that do not ensure an adequate level of data protection, based on approved certifications. According to Article 46 of the GDPR, contractual clauses ensuring appropriate data protection safeguards can be used as a ground for data transfers from the EU to third countries. This includes model contract clauses - so-called standard contractual clauses (SCCs) - that have been "pre-approved" by the European Commission.
On 4 June 2021, the Commission issued modernised standard contractual clauses under the GDPR for data transfers from controllers or processors in the EU/EEA (or otherwise subject to the GDPR) to controllers or processors established outside the EU/EEA (and not subject to the GDPR). These modernised SCCs replace the three sets of SCCs that were adopted under the previous Data Protection Directive 95/46. The Commission developed Questions and Answers (Q&As) to provide practical guidance on the use of the SCCs and assist stakeholders in their compliance efforts under the GDPR.
The Q&As state that businesses must do all of the following:
Consider the new optional docking clause, which expressly permits adding new parties to the SCCs.
According to the Q&As, the docking clause allows controllers and processors that are not part of the original contract to accede to the SCCs at a later stage, either as data exporters or importers. This clause is intended to facilitate the use of the SCCs in complex processing chains and to avoid the need to enter into multiple contracts.
Migrate all contracts entered into before September 27, 2021, that use the old SCCs to the new SCCs by December 27, 2022. According to the Q&As, the old SCCs will be repealed on September 27, 2021.
However, contracts concluded before that date on the basis of the old SCCs will remain valid until December
27, 2022, provided that the processing operations that are the subject matter of the contract remain unchanged and that reliance on those clauses ensures that the transfer of personal data is subject to appropriate safeguards within the meaning of Article 46(1) of the GDPR. After December 27, 2022, the old SCCs will no longer provide a valid legal basis for data transfers to third countries, and the new SCCs will have to be used instead.
Take steps to flow down the new SCCs to relevant parts of their supply chain using the new SCCs as of September 27, 2021, if the business is a data importer. According to the Q&As, the new SCCs require data importers to enter into contracts with any subprocessors that process the personal data transferred under the SCCs, and to include in those contracts the same data protection obligations as those imposed on the data importer under the SCCs. This means that data importers must ensure that the new SCCs are flowed down to their subprocessors as of September 27, 2021, and that any changes in the subprocessors are notified to the data exporter, who has the right to object.
The Q&As do not state that businesses must do the following:
Implement the new SCCs in the U.K. following Brexit, as the U.K. Information Commissioner's Office does not have the authority to publish its own set of SCCs. This is not a valid statement, as the U.K. has its own data protection regime after leaving the EU, and the U.K. Information Commissioner's Office (ICO) has the power to issue its own SCCs for data transfers from the U.K. to third countries. According to the ICO website, the ICO is currently developing bespoke U.K. SCCs, which will be subject to a public consultation and an opinion from the European Data Protection Board (EDPB). Until the U.K. SCCs are finalised, the ICO advises businesses to continue to use the EU SCCs for new contracts, as these clauses have been recognised as a valid transfer mechanism under the U.K. data protection law. However, the ICO also warns businesses that they may need to amend the EU SCCs to reflect that the U.K. is no longer an EU member state, and that they will need to update their contracts to the U.K. SCCs once they are available.
References:
GDPR, Articles 3, 4, 28, 29, 32, 44, 45, 46, 47, 48 and 49.
New Standard Contractual Clauses - Questions and Answers overview, paragraphs 1, 2, 3, 4, 5, 6, 7, 8, 9, 10 and 11.
Standard Contractual Clauses (SCC), paragraphs 1, 2, 3, 4, 5, 6, 7 and 8.
[Using international data transfers], paragraphs 1, 2, 3, 4, 5, 6, 7, 8, 9 and 10.


NEW QUESTION # 84
Under Article 58 of the GDPR, which of the following describes a power of supervisory authorities in European Union (EU) member states?

  • A. The authority to select penalties when a controller is found guilty in a court of law.
  • B. The ability to enact new laws by executive order.
  • C. The right to access data for investigative purposes.
  • D. The discretion to carry out goals of elected officials within the member state.

Answer: C


NEW QUESTION # 85
To which of the following parties does the territorial scope of the GDPR NOT apply?

  • A. All member countries party to the Treaty of Lisbon.
  • B. All member countries of the European Economic Area.
  • C. All member countries of the European Union.
  • D. All member countries party to the Paris Agreement.

Answer: B

Explanation:
Reference https://www.complianceweek.com/understanding-the-territorial-scope-of-the-gdpr/24693.article


NEW QUESTION # 86
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?

  • A. The European Council
  • B. The Council of the European Union
  • C. The European Commission
  • D. The European Parliament

Answer: C

Explanation:
Reference https://www.tandfonline.com/doi/full/10.1080/13600834.2019.1573501


NEW QUESTION # 87
If a data subject puts a complaint before a DPA and receives no information about its progress or outcome, how long does the data subject have to wait before taking action in the courts?

  • A. 12 months.
  • B. 1 month.
  • C. 3 months.
  • D. 5 months.

Answer: C


NEW QUESTION # 88
In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?

  • A. When emailing a customer to announce that his recent order should arrive earlier than expected.
  • B. When creating an untargeted pop-up ad on a website.
  • C. When calling a potential customer to notify her of an upcoming product sale.
  • D. When paying a search engine company to give prominence to certain products and services within specific search results.

Answer: A

Explanation:
Reference https://www.privacytrust.com/guidance/gdpr-vs-eprivacy-regulation.html


NEW QUESTION # 89
SCENARIO
Please use the following to answer the next question:
Outliers Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Jonathan, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company ZenFiTech, hoping that they can design a new, cutting-edge website for Outliers Inc.'s foundering business.
During negotiations, a ZenFiTech representative describes a plan for gathering more customer information through detailed questionnaires, which could be used to tailor their preferences to specific travel destinations. Outliers Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Jonathan loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the questionnaires will require customers to provide explicit consent to having their data collected. The ZenFiTech representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the Outliers Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which ZenFiTech will analyze by means of a special program. Outliers Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Jonathan enthusiastically engages ZenFiTech for these services.
With regard to Outliers Inc.'s use of website cookies, which of the following statements is correct?

  • A. Because not all of the cookies are strictly necessary to enable the use of a service requested from Outliers Inc., consent requirements apply to their use of cookies.
  • B. Because ZenFiTech will receive only aggregate statistics of data collected from the cookies, no additional consent is necessary.
  • C. Because the use of cookies involves the potential for location tracking, explicit consent must be obtained from customers.
  • D. Because of the categories of data involved, explicit consent for the use of cookies must be obtained separately from customers.

Answer: D


NEW QUESTION # 90
Which of the following is an example of direct marketing that would be subject to European data protection laws?

  • A. An updated privacy notice sent to an individual's personal email address.
  • B. A service outage notification provided to an individual by recorded telephone message.
  • C. A charity fundraising event notice sent to an individual at her business address.
  • D. A revision of contract terms conveyed to an individual by SMS from a marketing organization.

Answer: D

Explanation:
According to the definition of direct marketing in the context of data protection law, it is personal data processed to communicate a marketing or advertising message. This includes messages from commercial organisations, as well as from charities and political organisations. Therefore, option D is an example of direct marketing that would be subject to European data protection laws, as it involves sending a marketing message by SMS to an individual. The other options are not examples of direct marketing, as they do not involve marketing or advertising messages, but rather information or service messages that are not intended to promote any product or service. Reference:
[IAPP article on direct marketing (EU specific)]
Lexology article on direct marketing requirements under the GDPR


NEW QUESTION # 91
SCENARIO
Please use the following to answer the next Question: 01
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
Based on the GDPR's position on the use of personal data for direct marketing purposes, which of the following is true about Louis's rights as a data subject?

  • A. Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.
  • B. Louis does not have the right to object to the use of his data if Bedrock can demonstrate compelling legitimate grounds for the processing.
  • C. Louis does not have the right to object to the use of his data because he previously consented to it.
  • D. Louis has the right to object to the use of his data, unless his data is required by Bedrock for the purpose of exercising a legal claim.

Answer: A


NEW QUESTION # 92
According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject's personal data has been obtained from other sources?

  • A. Within a reasonable period after obtaining the personal data, but no later than one month.
  • B. As soon as possible after the first communication with the data subject.
  • C. As soon as possible after obtaining the personal data.
  • D. Within a reasonable period after obtaining the personal data, but no later than eight weeks.

Answer: A

Explanation:
Reference https://dataprivacymanager.net/gdpr-exemptions-from-the-obligation-to-provide-information-to-the- individual-data-subject/


NEW QUESTION # 93
Which of the following would most likely NOT be covered by the definition of "personal data" under the GDPR?

  • A. The unlinked aggregated data used for statistical purposes by an Italian company
  • B. The identification number of a German candidate for a professional examination in Germany
  • C. The payment card number of a Dutch citizen
  • D. The U.S. social security number of an American citizen living in France

Answer: A

Explanation:
The definition of personal data under the GDPR is broad and covers any information that relates to an identified or identifiable natural person. This means that personal data can include information such as name, email, phone number, address, date of birth, race, gender, political opinions and more. The GDPR protects personal data on all levels, platforms and technologies, and requires organizations to process it only for a specific purpose and keep it for a limited time.
The unlinked aggregated data used for statistical purposes by an Italian company would most likely NOT be covered by the definition of personal data under the GDPR. Aggregated data is data that has been processed in such a way that individual records are no longer identifiable. For example, if a company collects the names and email addresses of its customers and then calculates the average age of its customers, the resulting data is aggregated and not personal. Therefore, this type of data would not be subject to the GDPR.
However, this does not mean that the Italian company can use this type of data without any restrictions or obligations. The GDPR still applies to any processing activity that involves personal data in any form or manner. For example, if the Italian company uses this type of data to create a profile or a segment of its customers based on their characteristics or preferences, it may still need to comply with certain principles and conditions under the GDPR. For instance, it may need to obtain consent from its customers before using their aggregated data for marketing purposes; it may need to ensure that its aggregated data is accurate and up-to-date; it may need to limit the retention period of its aggregated data; and it may need to respect the rights of its customers regarding their personal data.
Reference:
What is personal data? | ICO
What is considered personal data under the EU GDPR?
[GDPR personal data - what information does this cover?]


NEW QUESTION # 94
Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?

  • A. Investigatory powers.
  • B. Corrective powers.
  • C. Legislative powers.
  • D. Authorization and advisory powers.

Answer: C

Explanation:
Reference:
Article 58 of the GDPR lists the powers of supervisory authorities, which include investigative, corrective, and authorization and advisory powers. However, legislative powers are not among those granted to supervisory authorities, as they belong to the EU and the member states. Therefore, option A is the correct answer. Reference: Art. 58 GDPR - Powers, Article 58 Powers - GDPR, Article 58 GDPR - GDPRhub


NEW QUESTION # 95
A news website based m (he United Slates reports primarily on North American events The website is accessible to any user regardless of location, as the website operator does not block connections from outside of the U.S. The website offers a pad subscription that requires the creation of a user account; this subscription can only be paid in U.S. dollars.
Which of the following explains why the website operator, who is the responsible for all processing related to account creation and subscriptions, is NOT required to comply with the GDPR?

  • A. The website cannot block connections from outside the U.S. that use a Virtual Private Network (VPN) to simulate a US location.
  • B. The website is not available in several official languages of European Un on Member States
  • C. The controller does not have an establishment in the European Union.
  • D. Payments cannot be made in a European Union currency.

Answer: D

Explanation:
The GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not1. This means that the GDPR applies to any controller or processor that has a branch, office, subsidiary, or other stable arrangement in the EU, even if the data processing occurs outside the EU. However, the GDPR also applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union1. This means that the GDPR applies to any controller or processor that targets or tracks EU data subjects, even if they do not have a presence in the EU. In this case, the website operator is not required to comply with the GDPR because it does not have an establishment in the EU (option B), and it does not offer goods or services or monitor the behaviour of EU data subjects. The website operator reports primarily on North American events, does not block connections from outside the U.S., and only accepts payments in U.S. dollars, which indicate that it does not intend to target or track EU data subjects. Therefore, option B is the correct answer. Reference: Art. 3 GDPR - Territorial scope, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), [What does territorial scope mean under the GDPR?]


NEW QUESTION # 96
......


The CIPP-E certification is suitable for professionals working in various fields such as privacy, compliance, legal, and IT. It is also useful for data protection officers, data privacy consultants, and professionals who are responsible for ensuring compliance with data protection laws and regulations. Certified Information Privacy Professional/Europe (CIPP/E) certification demonstrates the candidate's commitment to data protection and their ability to handle complex data protection issues. Overall, the IAPP CIPP-E certification is a valuable credential for professionals who want to enhance their knowledge and skills in the field of privacy and data protection.

 

New IAPP CIPP-E Dumps & Questions: https://actual4test.torrentvce.com/CIPP-E-valid-vce-collection.html