exam questions

Exam CIPM All Questions

View all questions & answers for the CIPM exam

Exam CIPM topic 1 question 130 discussion

Actual exam question from IAPP's CIPM
Question #: 130
Topic #: 1
[All CIPM Questions]

The General Data Protection Regulation (GDPR) specifies fines that may be levied against data controllers for certain infringements. Which of the following will be subject to administrative fines of up to 10 000 000 EUR, or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year?

  • A. Failure to demonstrate that consent was given by the data subject to the processing of their personal data where it is used as the basis for processing
  • B. Failure to implement technical and organizational measures to ensure data protection is enshrined by design and default
  • C. Failure to process personal information in a manner compatible with its original purpose
  • D. Failure to provide the means for a data subject to rectify inaccuracies in personal data
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Community vote distribution
B (69%)
A (23%)


Chosen Answer:
This is a voting comment. You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
7 months ago
Selected Answer: B
Given that Article 25 (data protection by design and by default) and Article 32 (security of processing) fall under Article 83(4), which covers the lower tier of fines up to €10,000,000 or 2% of total worldwide annual turnover, both are relevant here.
upvoted 2 times
9 months, 2 weeks ago
Selected Answer: D
D. Failure to provide the means for a data subject to rectify inaccuracies in personal data According to the GDPR, violations of certain obligations can result in administrative fines of up to 10,000,000 EUR or, in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher. One such obligation is the failure to provide the means for a data subject to rectify inaccuracies in personal data, as stipulated under GDPR Article 16. In contrast, the other listed failures (such as failure to demonstrate consent, failure to implement data protection by design and default, and failure to process personal information in a manner compatible with its original purpose) are subject to higher fines, up to 20,000,000 EUR or 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher.
upvoted 1 times
10 months ago
Selected Answer: A
B, B & D is gross misconduct and would result in higher fine- 4%
upvoted 1 times
1 year ago
Selected Answer: B
should be B
upvoted 2 times
1 year ago
Selected Answer: A
The less severe infringements could result in a fine of up to €10 million, or 2% of the firm’s worldwide annual revenue from the preceding financial year, whichever amount is higher. They include any violation of the articles governing: Controllers and processors (Articles 8, 11, 25-39, 42, and 43) — Organizations that collect and control data (controllers) and those that are contracted to process data (processors) must adhere to rules governing data protection, lawful basis for processing, and more. As an organization, these are the articles you need to read and adhere to. https://gdpr.eu/fines/
upvoted 2 times
1 year ago
For me A and B but - failing to demonstrate that consent was given by the data subject for processing their personal data (where consent is the basis for processing) can result in administrative fines of up to €10 million, or 2% of the total worldwide annual turnover of the preceding financial year, whichever amount is higher.
upvoted 1 times
1 year, 3 months ago
should be B
upvoted 1 times
1 year, 6 months ago
Selected Answer: B
B. Failure to implement technical and organizational measures to ensure data protection is enshrined by design and default The GDPR sets different tiers of administrative fines based on the severity of the infringement. Failing to implement data protection by design and default is subject to the lower tier of fines, which can go up to 10 million EUR or 2% of the company’s global annual revenue, whichever is higher.
upvoted 3 times
1 year, 6 months ago
Selected Answer: B
Should be B
upvoted 2 times
1 year, 7 months ago
B should be the answer, the rest result in tier 2 fines
upvoted 1 times
1 year, 9 months ago
i would suggest letter B
upvoted 1 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
Riyadh, 1 minute ago