IAPP CIPP-E Exam Prep
Certified Information Privacy Professional/Europe (CIPP/E) (Page 28 )

Updated On: 7-Sep-2026

SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick’s instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients’ data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft’s engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies’ websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem’s as well as EcoMick’s latest products.
While Ms. Iman recalls checking a box to receive information in the future regarding Liem’s products, she has never shopped EcoMick, nor provided her personal data to that company.
Which of the following BEST describes the relationship between Liem, EcoMick and JaphSoft?

  1. Liem is a controller and EcoMick is a processor because Liem provides specific instructions regarding how the marketing campaigns should be rolled out.
  2. EcoMick and JaphSoft are is a controller and Liem is a processor because EcoMick is sharing its marketing data with Liem for contacts in Europe.
  3. JaphSoft is the sole processor because it processes personal data on behalf of its clients.
  4. Liem and EcoMick are joint controllers because they carry out joint marketing activities.

Answer(s): D


Reference:

https://gdpr-info.eu/art-26-gdpr/



SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick’s instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients’ data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft’s engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies’ websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem’s as well as EcoMick’s latest products.
While Ms. Iman recalls checking a box to receive information in the future regarding Liem’s products, she has never shopped EcoMick, nor provided her personal data to that company.
Under the GDPR, Liem and EcoMick’s contract with MarketIQ must include all of the following provisions EXCEPT?

  1. Processing the personal data upon documented instructions regarding data transfers outside of the EE
  2. Notification regarding third party requests for access to Liem and EcoMick’s personal data.
  3. Assistance to Liem and EcoMick in their compliance with data protection impact assessments.
  4. Returning or deleting personal data after the end of the provision of the services.

Answer(s): D


Reference:

https://gdpr-info.eu/art-28-gdpr/



When is data sharing agreement MOST likely to be needed?

  1. When anonymized data is being shared.
  2. When personal data is being shared between commercial organizations acting as joint data controllers.
  3. When personal data is being proactively shared by a controller to support a police investigation.
  4. When personal data is being shared with a public authority with powers to require the personal data to be disclosed.

Answer(s): B


Reference:

https://gdpr-info.eu/art-26-gdpr/



An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data on the stick is unencrypted and in clear text. It is uncertain what has happened to the stick at this stage, but it likely was lost during the travel of an employee.
What should the company do?

  1. Notify as soon as possible the data protection supervisory authority that a data breach may have taken place.
  2. Launch an investigation and if nothing is found within one month, notify the data protection supervisory authority.
  3. Invoke the “disproportionate effort” exception under Article 33 to postpone notifying data subjects until more information can be gathered.
  4. Immediately notify all the customers of the company that their information has been accessed by an unauthorized person.

Answer(s): A


Reference:

https://gdpr-info.eu/art-34-gdpr/



Which of the following does NOT have to be included in the records most processors must maintain in relation to their data processing activities?

  1. Name and contact details of each controller on behalf of which the processor is acting.
  2. Categories of processing carried out on behalf of each controller for which the processor is acting.
  3. Details of transfers of personal data to a third country carried out on behalf of each controller for which the processor is acting.
  4. Details of any data protection impact assessment conducted in relation to any processing activities carried out by the processor on behalf of each controller for which the processor is acting.

Answer(s): D


Reference:

https://gdpr-info.eu/art-28-gdpr/



Viewing page 28 of 65
Viewing questions 136 - 140 out of 319 questions


Post your Comments and Discuss IAPP CIPP-E exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!