CIPP-E Exam Question 56

A U.S. company's website sells widgets. Which of the following factors would NOT in itself subject the company to the GDPR?
  • CIPP-E Exam Question 57

    SCENARIO
    Please use the following to answer the next question:
    ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
    Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
    Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
    In which of the following situations would ABC Hotel Chain and XYZ Travel Agency NOT have to honor Mike's data access request?
  • CIPP-E Exam Question 58

    Under Article 21 of the GDPR, a controller must stop profiling when requested by a data subject, unless it can demonstrate compelling legitimate grounds that override the interests of the individual. In the Guidelines on Automated individual decision-making and Profiling, the WP 29 says the controller needs to do all of the following to demonstrate that it has such legitimate grounds EXCEPT?
  • CIPP-E Exam Question 59

    Under Article 9 of the GDPR, which of the following categories of data is NOT expressly prohibited from data processing?
  • CIPP-E Exam Question 60

    In which situation would a data controller most likely be able to justify the processing of the data of a child without parental consent?