exam questions

Exam CIPP-E All Questions

View all questions & answers for the CIPP-E exam

Exam CIPP-E topic 1 question 274 discussion

Actual exam question from IAPP's CIPP-E
Question #: 274
Topic #: 1
[All CIPP-E Questions]

According to the European Data Protection Board, controllers responding to a data subject access request can refuse to provide a copy of personal data under certain conditions. Which of the following is NOT one of these conditions?

  • A. If the data subject access request was sent to an employee that is not involved in the processing of such requests.
  • B. If there is such a large amount of data that the controller cannot identify the data subject of the request.
  • C. If the controller is unable to use end-to-end encrypted emails for responding to such requests.
  • D. If the personal data was processed in the past but is no longer at the controller’s disposal at the time of the request.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
1 month, 3 weeks ago
Selected Answer: C
Both A and C are correct. See para 40 and 55 of Guidelines 01/2022 on data subject rights - Right of access.
upvoted 1 times
6 months, 3 weeks ago
Selected Answer: D
D. the other conditions are not valid to refuse a copy of personal data
upvoted 1 times
7 months ago
Selected Answer: A
A. If a data subject is (i.e.) not informed about where he can file his request, the employee who receveid the request should send it to the relevant department to process the request according to the GDPR. It cannot be a reason for a employer to say: 'you sent yopur request to the wrong employee so we so not have to grant you your GDPR-right. That would be way to easy a way to avoid the applicability of th GDPR.
upvoted 1 times
7 months, 1 week ago
Selected Answer: C
C. If the controller is unable to use end-to-end encrypted emails for responding to such requests: This is not a valid reason to refuse a request. While security in transmission is important, alternative secure methods should be sought if end-to-end encryption is not feasible.
upvoted 1 times
10 months, 1 week ago
Shouldn't it be A?
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago