Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP-E Exam - Topic 7 Question 20 Discussion

In which of the following cases, cited as an example by a WP29 guidance, would conducting a single data protection impact assessment to address multiple processing operations be allowed?
D) A railway operator who plans to evaluate the same video surveillance in all the train stations of his company.
A) A medical organization that wants to begin genetic testing to support earlier research for which they have performed a DPIA.
B) A data controller who plans to use a new technology product that has already undergone a DPIA by the product's provider.
C) A marketing team that wants to collect mailing addresses of customers for whom they already have email addresses.

IAPP CIPP-E Exam - Topic 7 Question 20 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 20
Topic #: 7
[All CIPP-E Questions]

In which of the following cases, cited as an example by a WP29 guidance, would conducting a single data protection impact assessment to address multiple processing operations be allowed?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Rueben
11 months ago
I’m leaning towards C being a no-go, that’s a bit sketchy.
upvoted 0 times
...
Goldie
11 months ago
A and D could also be valid, depending on context.
upvoted 0 times
...
Buck
11 months ago
Wait, can you really do that for multiple operations? Seems risky.
upvoted 0 times
...
Quiana
11 months ago
Totally agree, B is the way to go!
upvoted 0 times
...
Sage
11 months ago
I think option B makes sense since the product already had a DPIA.
upvoted 0 times
...
Regenia
11 months ago
I thought option C was a bit tricky since it involves collecting more data, but I can't recall if that would allow for a single DPIA.
upvoted 0 times
...
Geraldo
11 months ago
I'm leaning towards A, but I feel like it might depend on how closely related the genetic testing is to the previous DPIA.
upvoted 0 times
...
Sang
11 months ago
I remember discussing something similar in class about how multiple operations could be assessed together if they are related. Maybe D is a good choice?
upvoted 0 times
...
Felix
11 months ago
I think option B makes sense because if the technology already had a DPIA, it might cover the new use case. But I'm not entirely sure.
upvoted 0 times
...
Flo
12 months ago
I'm a bit confused by this one. There are a lot of moving parts in the prompt, and I'm not sure which solution is the best fit. I might need to re-read it a few times to really understand what they're looking for. Any tips on how to approach this type of question?
upvoted 0 times
...
Leanora
12 months ago
Okay, let's think this through. We want to break down the User Story into smaller, more focused pieces. Splitting it into CRUD operations seems like a good approach to me. I'm going to go with option C.
upvoted 0 times
...
Luis
12 months ago
Hmm, I'm a bit unsure about the difference between "important risks" and "business risk." I'll need to review my notes on the evolution of the internal audit function to answer this confidently.
upvoted 0 times
...

Save Cancel