exam questions

Exam CIPP-E All Questions

View all questions & answers for the CIPP-E exam

Exam CIPP-E topic 1 question 13 discussion

Actual exam question from IAPP's CIPP-E
Question #: 13
Topic #: 1
[All CIPP-E Questions]

What type of data lies beyond the scope of the General Data Protection Regulation?

  • A. Pseudonymized
  • B. Anonymized
  • C. Encrypted
  • D. Masked
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JackDoe
Highly Voted 2 years, 2 months ago
B is the right one. It still possible to identify a data subject if you decrypt the data.
upvoted 11 times
...
Nani1982
Most Recent 5 months, 4 weeks ago
It's letter B
upvoted 1 times
...
Ssourav
6 months, 3 weeks ago
Selected Answer: B
B. Anonymized Anonymized data is data that has been processed in such a way that it can no longer be used to identify an individual, either directly or indirectly. Once data is truly anonymized, it is no longer considered personal data and falls outside the scope of the GDPR. This is because anonymized data does not pose the same privacy risks as data that can be linked to an individual. Pseudonymized, encrypted, and masked data still fall within the scope of the GDPR because they can potentially be re-identified or decrypted to reveal personal information.
upvoted 2 times
...
aliblabla
10 months, 1 week ago
It is B, not C
upvoted 1 times
...
saffron
10 months, 2 weeks ago
Selected Answer: B
B is the right answer.
upvoted 1 times
...
Snickersname
1 year, 2 months ago
B is the right one. It still possible to identify a data subject if you decrypt the data
upvoted 2 times
...
Snickersname
1 year, 2 months ago
Selected Answer: B
https://commission.europa.eu/law/law-topic/data-protection/reform/what-personal-data_en#:~:text=Different%20pieces%20of%20information%2C%20which,the%20scope%20of%20the%20GDPR. B. ANONYMIZED Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data. Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR. Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.
upvoted 3 times
...
loejee
1 year, 3 months ago
this is 100% B. Not C
upvoted 2 times
...
SecretInvasion
1 year, 3 months ago
https://commission.europa.eu/law/law-topic/data-protection/reform/what-personal-data_en#:~:text=Different%20pieces%20of%20information%2C%20which,the%20scope%20of%20the%20GDPR. B. ANONYMIZED Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data. Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR. Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.
upvoted 2 times
...
EvelynRavioli
1 year, 11 months ago
To all saying B: anonymized data have been specified as a form of data within the GDPR. Encryption has been discussed in te GDPR only as a form of additional security, not as a type of data. Thus when the question is "what type of data lies beyond the scope" it's encrypted data. Hence answer C.
upvoted 3 times
ZeroStatic
1 year, 10 months ago
Scope here should refer to what type of data falls under GDPR, not whether it is discussed or not. The GDPR specifically does not apply to data that is not considered personal data, ie.: anonymized data. Encrypted data may still be considered personal data, and as such it should be B.
upvoted 3 times
...
...
Vanda77
1 year, 12 months ago
Definitely B. Anonymized
upvoted 4 times
...
AymanOthman
2 years ago
B. Anonymized
upvoted 4 times
...
ZA2022
2 years, 1 month ago
AGREE IT SHOULD BE B
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago