- | P a g e
CIPP/E Actual Exam Version 2 Newest 2025/2026 Complete 200 Questions And Correct Detailed Answers (Verified Answers) |Already Graded A+||Brand New Version!!
The requirement that a data controller notify regulators, potentially within *72 hours* of discovery, and/or victims, of incidents affecting the confidentiality and security of personal data, depending on the assessed risks to the rights and freedoms of affected data subjects. - ANSWER-Data Breach Notification (EU specific)
A *unit of data* that cannot be broken down further or has a distinct meaning. This may be a *date of birth, a numerical identifier, or location coordinates*. In the context of data protection, it is important to understand that these in isolation *may* not be personal data but, *when combined, become personally identifiable* and therefore personal data. - ANSWER-Data Elements
The natural or legal person, public authority, agency or any other body which alone or jointly with others *determines the purposes and means* of the processing of personal data. Where the purposes and means of such processing are determined by 1 / 4
- | P a g e
EU or member state law, this or the specific criteria for its nomination may be provided for by EU or member state law. - ANSWER-Data Controller
In certain circumstances, generally where data processing is done on the basis of consent or a contract, data subjects have the right to receive their personal data, which they have provided to a controller, in a *structured, commonly used and machine- readable format* and have the right to transmit that data to another controller without hindrance from the controller to which the personal data has been provided. - ANSWER-Data Portability
A natural or legal person (*other than an employee* of the controller), public authority, agency or other body which *processes personal data on behalf of the controller*. An organization can be both a controller and a processor at the same time, depending on the function the organization is performing. - ANSWER-Data Processor
A term often used to refer to a *supervisory authority* - ANSWER-Data Protection Authority (EU specific)
- / 4
- | P a g e
The implementation of appropriate *technical and organisational* measures for ensuring *that, by default, only* personal *data* which are *necessary for each specific purpose* of the processing *are processed*. That obligation *applies to* the *amount* of personal data collected, the *extent* of their processing, the *period* of their storage and their *accessibility*. In particular, such measures shall ensure that by default personal data are *not made accessible* without the individual's intervention *to an indefinite number* of natural persons. Such organizational *measures could consist*, inter alia, *of minimising* the processing of personal data, *pseudonymising* personal data as soon as possible, *transparency* with regard to the functions and processing of personal data, *and enabling the data subject to monitor* the data processing. - ANSWER-Data Protection by Default
When developing, designing, selecting and using applications, services and products that are based on the processing of personal data or process personal data to fulfil their task, producers of the products, services and applications should be encouraged to *take into account the right to data protection when developing and designing* such *products, services and applications* and, *with due regard to* the *state of the art*, to make sure that controllers and processors are able to fulfil their data protection obligations. - ANSWER-Data Protection by Design 3 / 4
- | P a g e
The *title* given in *some member states* to the *supervisory authority* - ANSWER-Data Protection Commissioner
Was replaced by the GDPR in 2018. The Directive was adopted in 1995, became effective in 1998 and was the *first EU-wide legislation that protected individuals' privacy* and personal data use. - ANSWER-EU Data Protection Directive (*95/46/EC*)
The process by which companies can *systematically assess and identify* the *privacy* and data protection *impacts of* any *products* they offer *and services* they provide. It enables them to *identify the impact* and *take* the *appropriate actions* to prevent or, at the very least, *minimise the risk* of those impacts. *are required* by the General Data Protection Regulation in some instances, particularly *where a* new *product or service is likely to result in a high risk* to the rights and freedoms of natural persons. - ANSWER-Data Protection Impact Assessment
While the title has long been in use, particularly in Germany and France, the GDPR introduced a *new legal definition of this with specific tasks*. Certain *organizations*, particularly those *that process personal data as part of their business model or*
- / 4