[May-2026] The IAPP CIPT Exam Test For Brief Preparation
Revolutionary Guide To Exam IAPP Dumps
IAPP CIPT Certification Exam is designed to test individuals' knowledge of privacy and data protection concepts as they relate to technology. Certified Information Privacy Technologist (CIPT) certification is intended for professionals who work in fields such as information technology, data analytics, cybersecurity, and software development, among others. CIPT exam covers topics such as privacy laws and regulations, data security, data governance, and privacy by design principles.
NEW QUESTION # 16
SCENARIO
Please use the following to answer the next questions:
Your company is launching a new track and trace health app during the outbreak of a virus pandemic in the US. The developers claim the app is based on privacy by design because personal data collected was considered to ensure only necessary data is captured, users are presented with a privacy notice, and they are asked to give consent before data is shared. Users can update their consent after logging into an account, through a dedicated privacy and consent hub. This is accessible through the 'Settings' icon from any app page, then clicking 'My Preferences', and selecting 'Information Sharing and Consent' where the following choices are displayed:
* "I consent to receive notifications and infection alerts";
* "I consent to receive information on additional features or services, and new products";
* "I consent to sharing only my risk result and location information, for exposure and contact tracing purposes";
* "I consent to share my data for medical research purposes"; and
* "I consent to share my data with healthcare providers affiliated to the company".
For each choice, an ON* or OFF tab is available The default setting is ON for all Users purchase a virus screening service for USS29 99 for themselves or others using the app The virus screening service works as follows:
* Step 1 A photo of the user's face is taken.
* Step 2 The user measures their temperature and adds the reading in the app
* Step 3 The user is asked to read sentences so that a voice analysis can detect symptoms
* Step 4 The user is asked to answer questions on known symptoms
* Step 5 The user can input information on family members (name date of birth, citizenship, home address, phone number, email and relationship).) The results are displayed as one of the following risk status "Low. "Medium" or "High" if the user is deemed at "Medium " or "High" risk an alert may be sent to other users and the user is Invited to seek a medical consultation and diagnostic from a healthcare provider.
A user's risk status also feeds a world map for contact tracing purposes, where users are able to check if they have been or are in dose proximity of an infected person If a user has come in contact with another individual classified as "medium' or 'high' risk an instant notification also alerts the user of this. The app collects location trails of every user to monitor locations visited by an infected individual Location is collected using the phone's GPS functionary, whether the app is in use or not however, the exact location of the user is "blurred' for privacy reasons Users can only see on the map circles What is likely to be the biggest privacy concern with the current 'Information Sharing and Consent' page?
- A. The information sharing with healthcare providers affiliated with the company.
- B. The option to consent to receive potential marketing information.
- C. The navigation needed in the app to get to the consent page.
- D. The ON or OFF default setting for each item.
Answer: D
Explanation:
Having default settings for information sharing and consent can be problematic because it may not accurately reflect a user's preferences. Users may not be aware of these default settings or may not understand their implications. This could result in personal information being shared without the user's explicit consent.
NEW QUESTION # 17
SCENARIO
Wesley Energy has finally made its move, acquiring the venerable oil and gas exploration firm Lancelot from its long-time owner David Wilson. As a member of the transition team, you have come to realize that Wilson's quirky nature affected even Lancelot's data practices, which are maddeningly inconsistent. "The old man hired and fired IT people like he was changing his necktie," one of Wilson's seasoned lieutenants tells you, as you identify the traces of initiatives left half complete.
For instance, while some proprietary data and personal information on clients and employees is encrypted, other sensitive information, including health information from surveillance testing of employees for toxic exposures, remains unencrypted, particularly when included within longer records with less-sensitive data. You also find that data is scattered across applications, servers and facilities in a manner that at first glance seems almost random.
Among your preliminary findings of the condition of data at Lancelot are the following:
* Cloud technology is supplied by vendors around the world, including firms that you have not heard of. You are told by a former Lancelot employee that these vendors operate with divergent security requirements and protocols.
* The company's proprietary recovery process for shale oil is stored on servers among a variety of less- sensitive information that can be accessed not only by scientists, but by personnel of all types at most company locations.
* DES is the strongest encryption algorithm currently used for any file.
* Several company facilities lack physical security controls, beyond visitor check-in, which familiar vendors often bypass.
* Fixing all of this will take work, but first you need to grasp the scope of the mess and formulate a plan of action to address it.
Which is true regarding the type of encryption Lancelot uses?
- A. It is a data masking methodology.
- B. It employs the data scrambling technique known as obfuscation.
- C. It uses a single key for encryption and decryption.
- D. Its decryption key is derived from its encryption key.
Answer: C
NEW QUESTION # 18
A key principle of an effective privacy policy is that it should be?
- A. Presented with external parties as the intended audience.
- B. Designed primarily by the organization's lawyers.
- C. Written in enough detail to cover the majority of likely scenarios.
- D. Made general enough to maximize flexibility in its application.
Answer: A
Explanation:
A key principle of an effective privacy policy is that it should be presented with external parties as the intended audience1. This means that the privacy policy should be clear, easily understandable, and accessible to anyone who interacts with the organization or its services. The privacy policy should also inform external parties about how their personal data is collected, processed, stored, shared, and protected by the organization2. The other options are not principles of an effective privacy policy, but rather potential pitfalls or limitations.
NEW QUESTION # 19
Which of the following would be the best method of ensuring that Information Technology projects follow Privacy by Design (PbD) principles?
- A. Develop training programs that aid the developers in understanding how to turn privacy requirements into actionable code and design level specifications.
- B. Develop a technical privacy framework that integrates with the development lifecycle.
- C. Identify the privacy requirements as a part of the Privacy Impact Assessment (PIA) process during development and evaluation stages.
- D. Utilize Privacy Enhancing Technologies (PETs) as a part of product risk assessment and management.
Answer: A
NEW QUESTION # 20
Which of the following is the best method to minimize tracking through the use of cookies?
- A. Manage settings in the browser to limit the use of cookies and remove them once the session completes.
- B. Install a commercially available third-party application on top of the browser that is already installed.
- C. Use 'private browsing' mode and delete checked files, clear cookies and cache once a day.
- D. Install and use a web browser that is advertised as 'built specifically to safeguard user privacy'.
Answer: A
Explanation:
Use 'private browsing' mode and delete checked files, clear cookies and cache once a day (A): While this can reduce tracking, it is not the most effective method for minimizing cookie tracking. Reference: IAPP CIPT Body of Knowledge.
Install a commercially available third-party application on top of the browser (B): This method may introduce additional risks and is not the most direct approach to managing cookies. Reference: IAPP CIPT Body of Knowledge.
Install and use a web browser that is advertised as 'built specifically to safeguard user privacy' (C):
This can be effective, but it depends on the browser's capabilities and user settings. Reference: IAPP CIPT Body of Knowledge.
Manage settings in the browser to limit the use of cookies and remove them once the session completes (D): This is the most proactive and direct method to minimize tracking via cookies. Reference: IAPP CIPT Body of Knowledge.
NEW QUESTION # 21
Between November 30th and December 2nd, 2013, cybercriminals successfully infected the credit card payment systems and bypassed security controls of a United States-based retailer with malware that exfiltrated 40 million credit card numbers. Six months prior, the retailer had malware detection software installed to prevent against such an attack.
Which of the following would best explain why the retailer's consumer data was still exfiltrated?
- A. The IT systems and security measures utilized by the retailer's third-party vendors were in compliance with industry standards, but their credentials were stolen by black hat hackers who then entered the retailer's system.
- B. The detection software alerted the retailer's security operations center per protocol, but the information security personnel failed to act upon the alerts.
- C. The U.S Department of Justice informed the retailer of the security breach on Dec. 12th, but the retailer took three days to confirm the breach and eradicate the malware.
- D. The retailer's network that transferred personal data and customer payments was separate from the rest of the corporate network, but the malware code was disguised with the name of software that is supposed to protect this information.
Answer: B
Explanation:
* Option A: This option explains that the detection software worked as intended and alerted the security team, but the failure occurred due to human error - the security personnel did not act on the alerts. This is a common issue where the technology functions correctly, but the human response is lacking.
* Option B: This explains a delay in action post-notification from the Department of Justice, but it doesn' t fully account for how the breach was successful initially despite having detection software.
* Option C: This option shifts the blame to third-party vendors, which may not directly explain the effectiveness of the malware detection.
* Option D: This points to the malware disguising itself, which could bypass some detection, but the crucial factor was the human oversight in not responding to alerts.
:
IAPP CIPT Study Guide
Case studies on data breaches and human error in cybersecurity responses
NEW QUESTION # 22
Which of the following statements is true regarding software notifications and agreements?
- A. Software agreements are designed to be brief, while notifications provide more details.
- B. "Just in time" software agreement notifications provide users with a final opportunity to modify the agreement.
- C. It is a good practice to provide users with information about privacy prior to software installation.
- D. Website visitors must view the site's privacy statement before downloading software.
Answer: C
NEW QUESTION # 23
SCENARIO
Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.
As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!" But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.
At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say.
"Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should." Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase." Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"
'I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy." Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out!
And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand." When initially collecting personal information from customers, what should Jane be guided by?
- A. Digital rights management.
- B. Vendor management principles
- C. Data minimization principles.
- D. Onward transfer rules.
Answer: C
Explanation:
When collecting personal information from customers, Jane should be guided by data minimization principles.
These principles emphasize that only the minimum necessary amount of personal data should be collected for any given purpose. This aligns with best practices in data management to ensure that organizations do not hold more personal data than necessary, thus reducing the risk of data breaches and enhancing privacy protection.
According to the IAPP, data minimization is a foundational principle that helps mitigate privacy risks by limiting the amount and types of data collected, processed, and stored.
NEW QUESTION # 24
SCENARIO
Clean-Q is a company that offers house-hold and office cleaning services. The company receives requests from consumers via their website and telephone, to book cleaning services. Based on the type and size of service, Clean-Q then contracts individuals that are registered on its resource database - currently managed in-house by Clean-Q IT Support. Because of Clean-Q's business model, resources are contracted as needed instead of permanently employed.
The table below indicates some of the personal information Clean-Q requires as part of its business operations:
Clean-Q has an internal employee base of about 30 people. A recent privacy compliance exercise has been conducted to align employee data management and human resource functions with applicable data protection regulation. Therefore, the Clean-Q permanent employee base is not included as part of this scenario.
With an increase in construction work and housing developments, Clean-Q has had an influx of requests for cleaning services. The demand has overwhelmed Clean-Q's traditional supply and demand system that has caused some overlapping bookings.
Ina business strategy session held by senior management recently, Clear-Q invited vendors to present potential solutions to their current operational issues. These vendors included Application developers and Cloud-Q's solution providers, presenting their proposed solutions and platforms.
The Managing Director opted to initiate the process to integrate Clean-Q's operations with a cloud solution (LeadOps) that will provide the following solution one single online platform: A web interface that Clean-Q accesses for the purposes of resource and customer management. This would entail uploading resource and customer information.
* A customer facing web interface that enables customers to register, manage and submit cleaning service requests online.
* A resource facing web interface that enables resources to apply and manage their assigned jobs.
* An online payment facility for customers to pay for services.
Considering that LeadOps will host/process personal information on behalf of Clean-Q remotely, what is an appropriate next step for Clean-Q senior management to assess LeadOps' appropriateness?
- A. Nothing at this stage as the Managing Director has made a decision.
- B. Obtain a legal opinion from an external law firm on contracts management.
- C. Involve the Information Security team to understand in more detail the types of services and solutions LeadOps is proposing.
- D. Determine if any Clean-Q competitors currently use LeadOps as a solution.
Answer: C
Explanation:
Given that LeadOps will host/process personal information on behalf of Clean-Q remotely, it is crucial to involve the Information Security team to understand in more detail the types of services and solutions LeadOps is proposing.
* Explanation:
* Security Assessment: The Information Security team should evaluate LeadOps' security measures, data protection practices, and compliance with relevant regulations. This assessment ensures that the service provider has adequate safeguards to protect personal information.
* Risk Management: Understanding the security environment helps identify potential risks associated with outsourcing data processing. This includes assessing encryption practices, data storage policies, and incident response plans.
* Vendor Due Diligence: Conducting thorough due diligence on LeadOps helps determine their capability to handle sensitive data securely. This can involve reviewing their security certifications, audits, and compliance with industry standards like ISO 27001.
* Legal and Compliance Considerations: Involving the Information Security team ensures that Clean-Q adheres to data protection regulations such as GDPR or CCPA, which require businesses to ensure their processors provide adequate data protection.
References:
* IAPP Privacy Management, Information Privacy Technologist Certification Textbooks
* ISO/IEC 27001 - Information Security Management Systems
* GDPR Articles 28 and 32
NEW QUESTION # 25
Value sensitive design focuses on which of the following?
- A. Confidentiality and integrity.
- B. Consent and human rights.
- C. Ethics and morality.
- D. Quality and benefit.
Answer: C
Explanation:
* Option A: Quality and benefit are important in design but do not specifically capture the essence of value sensitive design, which is more about ethical considerations.
* Option B: Value sensitive design integrates considerations of ethics and morality into the technology design process, ensuring that the resulting systems align with human values.
* Option C: Confidentiality and integrity are key aspects of information security but are not the primary focus of value sensitive design.
* Option D: Consent and human rights are related to privacy and data protection but are narrower than the broader focus of ethics and morality in value sensitive design.
:
IAPP CIPT Study Guide
Literature on Value Sensitive Design (VSD) principles and methodologies
NEW QUESTION # 26
What has been found to undermine the public key infrastructure system?
- A. Disreputable certificate authorities.
- B. Inability to track abandoned keys.
- C. Browsers missing a copy of the certificate authority's public key.
- D. Man-in-the-middle attacks.
Answer: A
Explanation:
Public key infrastructure (PKI) relies heavily on the trustworthiness of certificate authorities (CAs). These CAs are responsible for issuing and verifying digital certificates. If a CA is compromised or disreputable, the entire PKI system's integrity can be undermined because the certificates it issues can no longer be trusted.
This can lead to a range of security issues, including the potential for man-in-the-middle attacks, as malicious actors could exploit compromised certificates to impersonate legitimate entities. Thus, maintaining reputable and secure CAs is critical to the PKI system's effectiveness.
Reference: IAPP CIPT Certification Textbook, Chapter on Cryptography and PKI, emphasizing the role and importance of CAs in PKI systems.
NEW QUESTION # 27
In order to prevent others from identifying an individual within a data set, privacy engineers use a cryptographically-secure hashing algorithm. Use of hashes in this way illustrates the privacy tactic known as what?
- A. Stripping.
- B. Obfuscation.
- C. Perturbation.
- D. Isolation.
Answer: B
Explanation:
The use of a cryptographically-secure hashing algorithm is a method of transforming data into a different format through a process that makes it challenging to reverse-engineer or decode without a key. This technique is a form of obfuscation, which aims to make data less identifiable or understandable to unauthorized users. By applying obfuscation, the privacy engineer ensures that even if the hashed data is exposed, it does not reveal the actual personal data, thus protecting individuals' identities. This concept is supported by various privacy engineering practices that emphasize the importance of data transformation to protect privacy, as outlined in the IAPP Information Privacy Technologist documents.
NEW QUESTION # 28
Which of the following most embodies the principle of Data Protection by Default?
- A. An electronic teddy bear with built-in voice recognition that only responds to its owner's voice.
- B. An internet forum for victims of domestic violence that allows anonymous posts without registration.
- C. A website that has an opt-in form for marketing emails when registering to download a whitepaper.
- D. A messaging app for high school students that uses HTTPS to communicate with the server.
Answer: C
Explanation:
Explanation
NEW QUESTION # 29
SCENARIO
Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.
As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!" But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.
At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say.
"Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should." Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase." Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"
'I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy." Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out!
And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand." Which regulator has jurisdiction over the shop's data management practices?
- A. The Data Protection Authority.
- B. The Federal Trade Commission.
- C. The Federal Communications Commission.
- D. The Department of Commerce.
Answer: B
Explanation:
The Federal Trade Commission (FTC) is responsible for protecting consumers in the U.S. by preventing fraudulent, deceptive, and unfair business practices. It has jurisdiction over commercial data privacy and security practices, including those of Carol's shop. The FTC enforces data protection and privacy standards to ensure consumer information is handled appropriately.
References:
* IAPP CIPT Study Guide: Regulatory Environment.
* IAPP Certified Information Privacy Technologist (CIPT) Handbook: Section on U.S. Privacy Laws and Regulations.
NEW QUESTION # 30
Which Organization for Economic Co-operation and Development (OECD) privacy protection principle encourages an organization to obtain an individual s consent before transferring personal information?
- A. Individual participation.
- B. Purpose specification.
- C. Collection limitation.
- D. Accountability.
Answer: C
NEW QUESTION # 31
SCENARIO - Please use the following to answer the next question:
Wesley Energy has finally made its move, acquiring the venerable oil and gas exploration firm Lancelot from its long-time owner David Wilson. As a member of the transition team, you have come to realize that Wilson s quirky nature affected even Lancelot s data practices, which are maddeningly inconsistent. "The old man hired and fired IT people like he was changing his necktie,'1 one of Wilson s seasoned lieutenants tells you, as you identify the traces of initiatives left half complete.
For instance, while some proprietary data and personal information on clients and employees is encrypted, other sensitive^ information, including health information from surveillance testing of employees for toxic exposures, remains unencrypted, particularly when included within longer records with less-sensitive data.
You also find that data is scattered across applications, servers and facilities in a manner that at first glance seems almost random.
Among your preliminary findings of the condition of data at Lancelot are the following:
Cloud technology is supplied by vendors around the world, including firms that you have not heard of. You are told by a former Lancelot employee that these vendors operate with divergent security requirements and protocols.
o The company s proprietary recovery process for shale oil is stored on servers among a variety of less-sensitive information that can be accessed not only by scientists, but by personnel of all types at most company locations.
o DES is the strongest encryption algorithm currently used for any file.
o Several company facilities lack physical security controls beyond visitor check-in, which familiar vendors often bypass.
o Fixing all of this will take work, but first you need to grasp the scope of the mess and formulate a plan of action to address it.
Which procedure should be employed to identify the types and locations of data held by Wesley Energy?
- A. Data inventory.
- B. Data classification.
- C. Log collection.
- D. Privacy audit.
Answer: D
NEW QUESTION # 32
Why is first-party web tracking very difficult to prevent?
- A. Consumers enjoy the many benefits they receive from targeted advertising.
- B. The available tools to block tracking would break most sites' functionality.
- C. Most browsers do not support automatic blocking.
- D. Regulatory frameworks are not concerned with web tracking.
Answer: B
Explanation:
First-party web tracking is difficult to prevent because:
* The available tools to block tracking would break most sites' functionality (Option A): Many web applications rely on first-party cookies for essential functions like user authentication, session management, and personalization. Blocking these cookies can render websites unusable.
Option B is incorrect because consumer preference for targeted advertising does not impact the technical difficulty of blocking first-party tracking.
Option C is incorrect as regulatory frameworks are increasingly addressing web tracking.
Option D is incorrect because most browsers do offer mechanisms to block tracking, although they are more effective against third-party tracking.
References:
IAPP Information Privacy Technologist (CIPT) training materials
"Privacy Engineering: A Data Flow and Ontological Approach" by IAPP
NEW QUESTION # 33
Aadhaar is a unique-identity number of 12 digits issued to all Indian residents based on their biometric and demographic data. The data is collected by the Unique Identification Authority of India. The Aadhaar database contains the Aadhaar number, name, date of birth, gender and address of over 1 billion individuals. Which of the following datasets derived from that data would be considered the most de-identified?
- A. A count of the month of birth and hash of the person s first name.
- B. A count of the century of birth and hash of the last 3 digits of the person s Aadhaar number.
- C. A count of the day of birth and hash of the person s first initial of their first name.
- D. A count of the years of birth and hash of the person s gender.
Answer: B
NEW QUESTION # 34
SCENARIO
Please use the following to answer the next question:
Jordan just joined a fitness-tracker start-up based in California, USA, as its first Information Privacy and Security Officer. The company is quickly growing its business but does not sell any of the fitness trackers itself. Instead, it relies on a distribution network of third-party retailers in all major countries. Despite not having any stores, the company has a 78% market share in the EU. It has a website presenting the company and products, and a member section where customers can access their information. Only the email address and physical address need to be provided as part of the registration process in order to customize the site to the user's region and country. There is also a newsletter sent every month to all members featuring fitness tips, nutrition advice, product spotlights from partner companies based on user behavior and preferences.
Jordan says the General Data Protection Regulation (GDPR) does not apply to the company. He says the company is not established in the EU, nor does it have a processor in the region. Furthermore, it does not do any "offering goods or services" in the EU since it does not do any marketing there, nor sell to consumers directly. Jordan argues that it is the customers who chose to buy the products on their own initiative and there is no "offering" from the company.
The fitness trackers incorporate advanced features such as sleep tracking, GPS tracking, heart rate monitoring.
wireless syncing, calorie-counting and step-tracking. The watch must be paired with either a smartphone or a computer in order to collect data on sleep levels, heart rates, etc. All information from the device must be sent to the company's servers in order to be processed, and then the results are sent to the smartphone or computer.
Jordan argues that there is no personal information involved since the company does not collect banking or social security information.
Why is Jordan's claim that the company does not collect personal information as identified by the GDPR inaccurate?
- A. The potential customers must browse for products online.
- B. The fitness trackers capture sleep and heart rate data to monitor an individual's behavior.
- C. The customers must pair their fitness trackers to either smartphones or computers.
- D. The website collects the customers' and users' region and country information.
Answer: B
Explanation:
Under the GDPR, personal data includes any information relating to an identified or identifiable natural person. The fitness trackers collect detailed health-related data, such as sleep patterns and heart rates, which are considered sensitive personal data under the GDPR. This type of data directly relates to an individual's health and behavior, making it subject to GDPR protections regardless of whether financial information is collected. Jordan's claim that the company does not collect personal information is inaccurate because health data is a core category of personal data under the GDPR.
Reference:
GDPR Article 4, Definitions.
IAPP Certification Textbooks, particularly the sections on GDPR and the definition of personal data.
NEW QUESTION # 35
......
CIPT Free Study Guide! with New Questions: https://www.troytecdumps.com/CIPT-troytec-exam-dumps.html
Pass CIPT Exam Latest Practice Questions: https://drive.google.com/open?id=1I0jTw1z7tSVh5Lu1GVkL851mesXwWTvo