exam questions

Exam CIPP-US All Questions

View all questions & answers for the CIPP-US exam

Exam CIPP-US topic 1 question 188 discussion

Actual exam question from IAPP's CIPP-US
Question #: 188
Topic #: 1
[All CIPP-US Questions]

Your company, which sells its products in the United States and the European Union, is seeking to purchase cloud storage from a multinational cloud storage provider. The engineering team at your company wants to set up cloud data centers from the storage provider in both the United States and Germany.

Which of the following contractual provisions should be included in the contract to ensure the security of the personal data being stored in both data center locations?

  • A. An audit provision that allows the cloud storage provider to restrict an independent auditor’s access to the premises, documents and personnel involved in the cloud storage provider’s processing of the data.
  • B. A general authorization provision that allows the cloud storage provider to appoint subcontractors to help provide the cloud storage services.
  • C. A purpose limitation provision that requires the data, including personal information, to only be used for the contracted purposes.
  • D. A non-solicitation provision prohibiting both companies from seeking to hire employees of the other company.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
4 months, 1 week ago
Selected Answer: A
I think A may be a better answer as restricting third party to have access to the premise can help with maintain the premise secure. In fact, most DPA would include a similar audit clause like this.
upvoted 1 times
10 months ago
Selected Answer: C
the better option - C. A purpose limitation provision that requires the data, including personal information, to only be used for the contracted purposes.
upvoted 2 times
1 year ago
Selected Answer: C
The question is built in a confusing way. Given that the other options are not applicable at all, C seems to be correct, however, I don't see how this improves security in practice.
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago