CIPP/E practice questions
IAPP · CIPP/E · 300 questions
Original practice questions for the IAPP Certified Information Privacy Professional / Europe (CIPP/E) exam, covering GDPR, European data protection law, data processing requirements, scope and accountability, and compliance obligations.
This course contains the use of artificial intelligence.
About the CIPP/E exam
- Exam fee
- $550 USD
- Time allowed
- 2 hours 30 minutes
- Questions
- 90 multiple choice (75 scored + 15 unscored pretest)
- Format
- Pearson VUE test centre or OnVUE remote proctoring; 15-minute break included. Must be sat within one year of purchase.
Exam details published by the vendor, checked 25 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Introduction to European Data Protection · 40 questions
- A city archives board asks why Europe needed special rules for personal data long before the GDPR existed. Which historical rationale best answers them?
- A municipal privacy officer cites the OECD Guidelines as if they were an EU regulation that can impose administrative fines. How should counsel correct that understanding?
- A county counsel wonders whether the Treaty of Lisbon matters for day-to-day GDPR work. Which link to the modern EU legal order is most accurate?
- A library consortium hears “Convention 108” and assumes it is identical to the GDPR. Which distinction should training emphasise?
- A regional DPO asks what a “harmonised European approach” tried to fix when Member States had divergent national data-protection laws. What problem was the drive toward consistent rules mainly addressing?
- A town hall debate treats Brexit as irrelevant to European data-protection history. Which correction best matches the BoK framing of Brexit?
- A university clinic asks whether updating Convention 108 to Convention 108+ changes only paperwork or also modernises protections. What is the sound takeaway?
- A civic tech NGO claims European data protection sprang only from consumer marketing scandals. Which historical framing is more accurate?
- A mayor’s office mixes up the European Commission and the European Council when asking who typically proposes EU legislation such as data-protection measures. Which assignment is correct?
- A city solicitor asks which body is the EU’s primary legislature that co-decides regulations such as the GDPR under the ordinary legislative procedure. Which answer is best?
- A human-rights clinic confuses the European Court of Human Rights with the Court of Justice of the European Union. Which distinction should trainers teach?
- A privacy trainee asks what the Council of Europe is if it is not an EU institution. Which explanation is accurate?
- A regional authority wants the court that interprets the GDPR as EU law and helps ensure its uniform application. Which court fills that role?
- A briefing deck labels the European Council as the day-to-day GDPR supervisor that investigates controllers. What correction is needed?
- A records manager thinks Directive 95/46/EC is still the primary EU personal-data statute for general processing. Which update should training deliver?
- A telecoms compliance lead asks why the ePrivacy Directive still matters after GDPR day one. What is the best explanation?
- A marketplace startup assumes the e-Commerce Directive alone answers all personal-data compliance questions. How should counsel respond?
- A museum digitisation project asks what the Council of Europe Convention 1981 contributed before EU directives. Which contribution is most accurate?
- A city CISO wonders whether NIS/NIS 2 belong in a European data-protection exam conversation. Which placement is correct for CIPP/E Domain I?
- An AI product owner asks how the EU AI Act relates to GDPR study for CIPP/E. What is the right framing?
- A council workshop asks for the GDPR’s main goals in one breath. Which statement captures the twin aims?
- A vendor claims the GDPR only applies to EU companies that keep servers inside the EU. Which response best corrects that myth at Domain I legislative-awareness level?
- A training deck says the ePrivacy Directive was repealed by the GDPR. What should replace that claim?
- A public body asks whether GDPR principles echo earlier Directive 95/46 themes. Which answer is most accurate?
- A logistics firm confuses the GDPR with a voluntary industry code of conduct. Which characterisation is correct?
- A civic open-data group asks why electronic commerce rules appear in a European privacy body of knowledge. Which explanation correctly places the e-Commerce Directive in the European data-protection legislative stack?
- A hospital privacy board wants the short name and official citation style for the GDPR. Which identification is correct?
- A border-town authority asks how national laws interacted with Directive 95/46/EC compared with the GDPR. Which contrast correctly describes the implementation model change?
- A smart-city vendor treats NIS 2 incident rules as identical to GDPR personal-data breach rules. Which statement correctly separates the regimes?
- A charity asks whether Convention 108 still matters after the GDPR. Which assessment is most accurate for CIPP/E framework understanding?
- A startup pitch says “GDPR equals cookie law.” Which correction should privacy counsel give?
- A regional parliament liaison asks which EU institution typically proposes updates to the European data-protection legislative stack. Which answer is correct?
- A university DPO asks what “related legislation” to the GDPR means for CIPP/E exam preparation. Which set correctly reflects BoK-named related European instruments rather than CIPP/US statutes?
- A ferry operator between Member States asks why free flow of personal data is treated as a GDPR goal. Which rationale matches the Regulation’s design?
- A municipal IT board assumes only GDPR principles matter and ignores earlier Convention language on automated processing. Which insight correctly connects that tradition to modern European data protection?
- A compliance intern asks whether the GDPR replaced the Charter right to protection of personal data. Which clarification is correct?
- A tourism board confuses “European data protection legislation principles” with ISO 27001 controls. Which response keeps the answer in the correct CIPP/E legal-principle space?
- A port authority asks why GDPR, ePrivacy, and NIS obligations can all apply to one operational incident. Which explanation is correct?
- A school district wonders whether Directive 95/46/EC case law still informs GDPR interpretation. Which statement is most accurate?
- A civic hackathon sponsor asks for the “principles and goals” headline of significant EU data-protection legislation. Which summary best captures that framework-level headline?
European Data Protection Law and Regulation · 92 questions
- A parks department spreadsheet of season-pass holders is called “just names” and therefore “not personal data.” Which GDPR assessment is correct?
- A clinic labels allergy information and genetic markers as ordinary CRM fields. Which GDPR classification should privacy counsel apply?
- An analytics team claims hashing a national ID always makes the dataset anonymous. Which distinction should the DPO enforce?
- A vendor contract calls both parties “joint owners of the data.” Which GDPR role analysis is correct?
- A call-centre staffer asks who the “data subject” is when a CRM row concerns a deceased relative. Which GDPR-focused answer is correct?
- A board slide lists “lawfulness, fairness and transparency” as optional best practices. Which correction is required under GDPR?
- A startup processes only IP addresses and argues they can never be personal data. Which GDPR position is correct?
- A municipality outsources payroll hosting and assumes the host is automatically the controller. Which analysis follows GDPR role concepts?
- A research unit replaces names with codes but keeps the key, then calls the file “anonymous open data.” Which label is correct under GDPR?
- A charity shares volunteer political opinions in a newsletter CRM. Which GDPR classification applies to those political opinions?
- A transport app stores precise disability status so staff can arrange boarding assistance. A product manager treats the field like any other preference checkbox. How should privacy counsel classify that data under the GDPR?
- A processor argues that EDPB guidance on controller and processor roles can be ignored because the written contract already looks clear. Which statement best reflects how that guidance should be used?
- A city open-data portal publishes only aggregates that, after rigorous assessment, cannot identify any resident even when combined with other reasonably available information. How should the GDPR personal-data rules apply?
- An HR system stores trade-union membership for workforce planning. Staff treat the field like a cafeteria preference. What is the correct GDPR characterisation?
- A marketing lead insists that under the GDPR, 'sensitive data' always means passwords and other secrets. Which correction best reflects EU data protection terminology?
- Two cities jointly design a shared resident portal and each decides the purposes and essential means for how resident data will be used in that portal. At a basic GDPR concepts level, how should their relationship be understood?
- A library encrypts staff laptops but leaves shared network drives open to every staff login with no further access restrictions. Leadership claims encryption alone proves GDPR security compliance. What is the best assessment?
- A hospital asks whether access controls that limit which staff can open patient records count only as organisational paperwork, or also as technical security measures under the GDPR. Which view is most accurate?
- During a ransomware tabletop exercise, citizen records are encrypted by an attacker. Leadership asks when GDPR personal-data breach notification clocks start for the controller. Which timing rule is correct?
- A SaaS vendor processing municipal customer data suffers a personal-data breach. The city asks who notifies the supervisory authority under the GDPR. Which allocation of duties is correct?
- A DPO relies on EDPB breach guidelines when deciding whether individuals must be informed after a personal-data breach. Which threshold correctly drives data-subject notification?
- Procurement skips security due diligence on a personal-data vendor because the vendor’s slide deck shows an ISO certification logo. What does responsible vendor management under GDPR security expectations require?
- A city shares resident email lists with a festival partner for joint promotions without clarifying roles or putting protective arrangements in place. What GDPR-aligned principle should guide that third-party sharing?
- An IT team configures cloud storage buckets containing personal data to be publicly readable by default 'for convenience.' How should this default be evaluated under GDPR security requirements?
- A processor subcontracts hosting of the controller’s personal data to another provider without informing the controller or obtaining the required authorisation. Which GDPR theme is primarily violated?
- A council measures ‘security’ solely by counting firewalls and ignores staff training, policies, and procedures that govern how personal data is handled. What does GDPR TOMs thinking require?
- A startup asks whether encryption is mandatory in all GDPR processing scenarios as a universal checkbox. Which framing is most accurate?
- A school discovers that an unencrypted USB stick with pupil personal data was lost three weeks earlier; staff only now become aware of the loss. How should breach-handling duties be timed?
- A vendor-management programme signs data processing agreements then never reviews security posture, access rights, or DPA performance afterward. What does responsible GDPR-aligned vendor oversight require?
- A marketing agency receives a customer list ‘to help with a campaign’ but is given no instructions on permitted purposes, retention, or deletion. Which third-party sharing requirement is most clearly missing?
- A CISO claims that GDPR security of processing is fully satisfied by completing PCI-DSS checklists alone. Which statement best corrects that claim?
- A city open Wi-Fi service logs device MAC addresses for ‘security analytics’ without discussing retention limits or other protective discipline. What GDPR security insight applies?
- A processor detects unauthorised access to personal data it processes for a controller and plans to mention it only at the next monthly quarterly business review. What timing obligation applies?
- A board asks the privacy team for ‘EDPB-aligned’ scoring when deciding whether a breach requires supervisory-authority or individual notification. How should EDPB materials factor into that assessment?
- A shared-services centre hosts multiple municipalities on one platform with no logical separation of each city’s resident data or access paths. Which security-design concern is most directly raised under GDPR TOMs?
- A municipal contractor takes printed citizen case files home overnight to finish work. Leadership calls it harmless because the files never left paper form. Which response best reflects GDPR security of personal data expectations?
- After a ransomware incident, a city restores systems from backups and leadership says there is no personal-data breach because availability was recovered. What should privacy counsel emphasize?
- A software vendor processes citizen contact data under a city contract, then quietly re-uses those contacts to train its own commercial product. What GDPR-aligned limit does this violate most directly?
- A municipality scores vendors only on lowest price and skips security questionnaires and contractual audit rights. Privacy asks for stronger vendor management. Which practice best supports responsible handling of personal data with processors?
- An employee emails a spreadsheet of welfare claimants to the wrong external address. Which characterisation best fits GDPR personal-data breach analysis?
- A cloud administrator disables multi-factor authentication on systems holding citizen personal data to 'reduce friction.' How should this change be viewed under GDPR security expectations?
- A partner hospital shares patient contact lists with another organisation for a joint health fair without assessing the recipient's safeguards. What should privacy practice require before such sharing?
- A DPO documents technical and organisational measures at system launch but never revisits them after a major architecture change that expands personal-data processing. What does GDPR-aligned security require?
- A vendor's public trust portal still lists outdated sub-processors while live support traffic already routes through new providers. Which practice best aligns with responsible processor obligations?
- After unauthorised access to citizen records, a city argues that intact backups make breach notification unnecessary. Which distinction should privacy counsel draw?
- A security policy forbids USB use with personal data, but the organisation has no monitoring, enforcement, or exception process. What lesson should CIPP/E candidates take about organisational measures?
- A processor markets 'GDPR certification' stickers but cannot show encryption, access control, or incident response capable of protecting the personal data. What should the controller prioritise?
- A cross-border vendor support team can open any EU citizen support ticket from multiple countries without role limits. Which TOMs-oriented improvement best addresses the risk?
- A council publishes a breach log that redacts names but leaves unique case IDs that readily re-identify individuals when combined with other public records. How should this disclosure be assessed?
- A vendor-management playbook relies only on a security schedule and skips data-processing agreements because 'security covers GDPR.' What correction is needed?
- An incident response plan lists technical containment steps but never assigns who assesses high risk to data subjects for notification decisions. Which organisational gap does this reveal?
- A smart-meter vendor keeps detailed household consumption profiles indefinitely 'for ML quality.' Beyond retention critiques, what security implication follows?
- A resident emails a city portal: 'Send me everything you have on me.' Which response best reflects the GDPR right of access?
- A citizen finds a wrong home address in a benefits file and demands a correction. Which data-subject right primarily applies?
- A former customer demands erasure of their account after cancelling a service. How should the controller approach the request at concept level?
- A data subject asks the controller to pause certain processing while the accuracy of records is contested. Which right is designed for that situation?
- A person objects to use of their email for direct marketing. What is the GDPR-aligned outcome?
- A signup form uses pre-ticked boxes to collect consent for optional analytics cookies and partner offers. What is wrong with this approach under GDPR consent rules?
- A bank uses purely automated scoring to deny online account applications with no meaningful human review path. Which data-subject protection theme applies?
- A user asks a streaming service to move their playlist and profile data to another provider in a structured form. Which right primarily governs this request when its conditions are met?
- A controller refuses a subject access request in full by citing a police-investigation exception, without checking whether Member State law actually authorises that restriction or whether a narrower response is possible. What is the sound GDPR approach?
- When fulfilling a subject access request, a controller ignores guidance on scope and dumps every system log, including third-party trade secrets and other people’s personal data, without any balancing. What should the controller do instead?
- A mobile app lets users consent to personalised ads with one tap at signup, but burying consent withdrawal five menus deep. What GDPR consent rule does this practice violate?
- A customer requests erasure of all personal data, including an invoice the controller must retain under tax law. How should the controller respond?
- A company uses automated profiling to screen job applicants and never explains the logic involved or available safeguards. What transparency expectation applies?
- A data subject objects to processing that the controller bases on legitimate interests. What must the controller do?
- A controller refuses a data portability request because the personal data were collected on a legal-obligation basis rather than consent or contract. Is that refusal typically aligned with GDPR portability rules?
- A city receives an access request and redacts other residents’ personal data from the response before disclosing the requester’s information. Why is that approach appropriate?
- A marketing email lacks any unsubscribe mechanism and states that GDPR consent is 'forever.' What is wrong with that approach?
- A patient asks a clinic to rectify a diagnosis code that the clinician disputes as inaccurate. While accuracy is being resolved, what GDPR tool is especially relevant?
- A social network refuses an erasure request solely because 'the post is still interesting to other users.' What is the better framing of erasure / right-to-be-forgotten analysis?
- A chatbot makes a solely automated offer decision that significantly affects whether a consumer can enter a contract. What GDPR theme is triggered?
- A controller answers a subject access request after nine months and never communicated any extension. How does that compare with GDPR timing expectations?
- A company demands a notarised passport for every trivial rectification of a typo in an email address. What principle should govern identity verification for rights requests?
- A data subject demands portability of inferred credit scores created solely by the controller’s algorithms. How does portability typically treat such inferred data?
- A child-directed online service relies on the child’s consent alone without considering age thresholds or holder-of-parental-responsibility rules. What is the compliance problem?
- A controller marks processing as restricted after a data-subject request but continues using the same personal data for marketing campaigns. What does restriction require operationally?
- An individual objects to a shop’s CCTV that captures the entrance to their home, where the shop relies on legitimate interests. Which statement best reflects the objection analysis?
- After a controller ignores a valid access request, the data subject wants to escalate. What path does GDPR expressly support?
- A signup form bundles consent for necessary contract terms together with unrelated sharing of personal data with marketing partners, making the service conditional on accepting everything. What consent problem does this create?
- A user withdraws consent for analytics cookies, but the analytics scripts keep firing unchanged. What requirement is failing?
- A company claims the right to rectification never applies to any recorded opinion about a person. How should that claim be assessed?
- A public profiling system decides welfare eligibility through solely automated means and offers no channel for human intervention. What safeguard expectation is missing?
- A data subject requests erasure of personal data that the controller also needs to establish or defend a legal claim. How may the controller respond?
- A controller’s access-request response discloses the personal data but omits recipients or categories of recipients. What Article 15 element is missing?
- A controller publishes a policy stating that every data-subject rights request costs €200 with no exceptions. How should that fee policy be assessed under the GDPR?
- A data subject asks a controller to restrict processing while the controller verifies whether legitimate interests override the objection. What is the appropriate treatment of restriction in this situation?
- A controller answers a data-portability request by sending only an unreadable screenshot PDF of a GUI. What format expectation does that response fail when portability applies?
- After a customer withdraws marketing consent, a preference centre silently re-checks the consent box on the next login without a clear new affirmative action. How should that practice be treated?
- A controller cites ‘trade secrets’ as a reason to refuse an entire access request without any balancing analysis. What is the correct approach?
- A data subject objects to processing for scientific research carried out as a task in the public interest. How does GDPR objection handling in that setting typically differ from a simple marketing opt-out?
- A DPO designs workflows for search-index-style delisting and erasure (RTBF) requests. What role should EDPB guidelines and opinions play in that design?
European Data Processing · 68 questions
- A city collected festival ticket emails solely for entry control, then reuses them to build a political-donation lookalike model without a compatible further-processing analysis. Which processing principle is primarily at risk?
- A CRM retains every inactive resident record ‘forever just in case,’ with no retention rationale tied to the original purposes. Which principle does that practice primarily undermine?
- A benefits office knows its decision dataset is outdated, yet staff continue to rely on it without reasonable update steps. Which principle is primarily breached?
- A processing activity cites a valid Article 6 basis on paper, but the user experience hides the real use of the data behind deceptive interface patterns. What principle pairing does this scenario highlight?
- A survey collects exact GPS coordinates every second when approximate neighbourhood location would meet the stated research need. Which principle is primarily engaged?
- A hospital configures clinical notes so every intern account can edit any record without need-to-know controls. Which processing principle is most directly undermined?
- A leaflet claims processing is ‘transparent,’ yet the privacy notice is dense, unreadable legalese that individuals cannot reasonably understand. How should transparency be assessed?
- A retention schedule deletes live CRM records on time, but backup tapes indefinitely retain the same personal data with no workable purge path. What does storage limitation require in this situation?
- A team skips a further-processing compatibility assessment because the new use sits in the ‘same database’ as the original collection. Is that reasoning sound under purpose limitation?
- A city publishes incorrect parking-fine personal data online and delays correcting it after the error is known. Which assessment best captures the principle failure?
- A controller instructs a processor to collect forty optional fields ‘for future unknown projects’ with no current necessity. What principle does that instruction primarily conflict with?
- A security incident investigation shows personal data processing lacked basic integrity controls and access discipline. How does that finding map to GDPR processing principles?
- A swimming-pool membership contract needs the member’s contact details to deliver pool access and billing for that service. Which Article 6 lawful basis most directly fits that processing?
- A tax authority processes personal data in tax returns because a statute requires that processing. Which Article 6 lawful basis primarily applies?
- Paramedics process an unconscious patient’s personal data to provide emergency care when the patient cannot consent. Which Article 6 basis is most appropriately considered in that narrow emergency setting?
- A municipal public-health team processes personal data to carry out an official task in the public interest grounded in Member State law. Which Article 6 basis primarily fits?
- A retailer relies on legitimate interests for fraud-prevention analytics and documents a balancing test weighing its interests against data subjects’ rights. What does valid use of Article 6(1)(f) require?
- A health clinic processes genetic data for diagnosis. Beyond identifying an Article 6 lawful basis, what additional GDPR condition is typically required?
- A retail website wants to drop non-essential analytics cookies for EU visitors. Which Art. 6 lawful basis is the controller relying on when it obtains valid consent before setting those cookies?
- An employer requires staff to accept workplace CCTV monitoring as a take-it-or-leave-it condition of keeping their jobs and treats that acceptance as GDPR consent. Why is that approach typically problematic?
- A charity collected donor emails on consent for a fundraising campaign, then silently switched to legitimate interests after many donors withdrew consent. What is the main GDPR concern with that mid-campaign basis swap?
- A product team claims "legitimate interest" for a new profiling feature but has no documented balancing assessment. What should a CIPP/E-minded reviewer expect before relying on Article 6(1)(f)?
- A factory rolls out fingerprint scanners so each worker's attendance is uniquely identified. Beyond an Article 6 basis, what additional GDPR pathway does this biometric processing generally require?
- A controller justifies collecting detailed customer browsing histories solely because "everyone else in our industry does it." How should that justification be treated under Article 6?
- A marketing team proposes using "vital interests" under Article 6(1)(d) to email discount offers because customers "might need deals." Why does that fail GDPR analysis?
- A municipal licensing office must maintain a statutory public register of license holders. Staff suggest relying on consent so individuals can "opt out" of the register. What is the better GDPR approach?
- An employer collects racial-origin data solely for a genuine equality-monitoring programme authorised by applicable Union or Member State law. Which statement best reflects the special-category pathway?
- Before launching a new processing activity on legitimate interests, a privacy counsel reviews current EDPB materials on Article 6(1)(f). What is the sound reason for that step?
- A mobile app starts collecting precise location as soon as it installs, with no explanation of why until weeks later in a buried settings screen. Which transparency failure is most clearly illustrated?
- A company's privacy notice describes purposes and rights but never names the controller or provides required DPO contact details where a DPO is designated. What Art. 13/14 gap does that create?
- A controller publishes a short first-layer privacy summary with clear links to deeper detail on purposes, rights, and transfers. How does GDPR practice generally view that design?
- A retailer buys prospect lists from a data broker and plans to delay any privacy information to those individuals indefinitely. Which statement best reflects Articles 12 and 14?
- A privacy notice describes purposes only as "improving experience and other business purposes." What transparency problem does that wording create?
- A SaaS privacy notice lists EU processors but is silent about recipients in third countries and related transfer safeguards. What notice deficiency is most relevant?
- A notice states retention only as "we keep personal data as long as needed" with no period or determination criteria. What should be corrected?
- A controller omits data-subject rights from its privacy notice because "those rights are already written in the GDPR." Why is that insufficient?
- Before a mobile feature activates the camera in a sensitive context, the app shows a brief contextual explanation of what will be captured and why. What transparency technique does that illustrate?
- A service aimed at children presents its privacy information only in dense adult legalese. What GDPR transparency expectation is most clearly missed?
- A controller materially expands processing from account administration into behavioural advertising but never updates the privacy notice or otherwise informs data subjects. What ongoing transparency duty is breached?
- A privacy notice explains categories of data and retention but never states the lawful basis for each processing purpose. Which required element is missing?
- A building posts CCTV signs with essential facts and a QR code linking to a full camera privacy notice. How is that approach generally characterised under transparency good practice?
- A lender uses solely automated decision-making that produces legal effects for credit applicants, but its privacy notice is silent on that practice. What information is missing?
- For processing on a public marketing website, the only privacy notice is a PDF placed behind an account login wall. What accessibility problem does that create under Article 12?
- A controller’s privacy notice lists an email and phone number, but both bounce and the DPO mailbox is a dead shared inbox. What transparency practice is missing?
- A retailer builds profiles from purchased marketing lists and never tells customers which categories of data came from those third parties. What indirect-collection rule is it missing?
- A startup claims it only needs a privacy notice when consent is the lawful basis and skips notices for contract and legitimate-interest processing. What is wrong with that view?
- A municipal portal serves multilingual residents and adds standardised icons plus short summaries above the full privacy notice. How do these aids relate to transparency?
- A company’s public privacy notice names its cloud processor as if that vendor were the controller deciding purposes and means. What identification error must be fixed?
- An EU employer plans to email employee HR files to a US parent company with no adequacy decision, SCCs, BCRs, or valid derogation in place. What transfer rule applies?
- Counsel confirms the European Commission has adopted an adequacy decision for the destination country where a SaaS vendor stores EU customer data. What does that adequacy finding primarily mean for the transfer?
- Outside counsel drafts a 2026 transfer clause that still relies on the US–EU Safe Harbor framework as the transfer mechanism. What historical point should the privacy team raise?
- A 2026 vendor contract proposes Privacy Shield certification as the sole basis for transferring EU personal data to the United States. What should the controller conclude?
- A project team proposes Commission Standard Contractual Clauses for a processor in a non-adequate third country and asks whether signing SCCs ends all transfer analysis. What is the sound position?
- A multinational wants a reusable mechanism for routine intra-group transfers of HR and customer data among EEA and non-adequate affiliates. Which Chapter V tool fits that group scenario at concept level?
- A startup relies on explicit consent under Article 49 as the standing basis for systematic daily bulk transfers of all EU user records to a non-adequate region. What is the main problem?
- After signing SCCs with a non-adequate vendor, a controller skips any transfer impact assessment because “the clauses are Commission-approved.” What step is still expected?
- Counsel explores an approved code of conduct or certification mechanism, paired with binding enforceable commitments, to support transfers to a non-adequate recipient. How should that option be characterised?
- A team uses SCCs to send personal data to a jurisdiction known for extensive government surveillance but performs no analysis of local access laws or supplementary measures. Which Schrems II theme is being ignored?
- Customer data remain stored in an EU cloud region, yet a third-country support team remotely reads personal data to resolve tickets. How should the privacy team treat that access?
- Engineers ask whether encrypting personal data before it leaves the EEA can help address transfer risks to a challenging third country. Which authority’s transfer guidance is commonly used to frame that supplementary-measures analysis?
- A tourism app stores EU travellers’ photos only on servers in a country covered by a Commission adequacy decision. How does that destination choice affect the transfer analysis?
- A travel platform uses an Article 49 contractual-necessity derogation for occasional transfers needed to complete a guest’s hotel booking abroad, then proposes the same derogation to justify building a permanent offshore analytics data lake. What distinction should counsel draw?
- A colleague calls the company’s ordinary processor Data Processing Agreement its “BCRs” for US transfers. What correction is needed?
- A controller plans to transfer EU customer data to a US vendor “because they are on the Data Privacy Framework,” but nobody verifies the vendor’s active participation status. What verification step is required?
- A DPIA for a new analytics platform leaves the international-transfer section blank even though EU personal data will be hosted and accessed from outside the EEA. What accountability expectation is unmet?
- A signup form includes a single pre-ticked box labelled “I agree to all processing and international transfers” with no destination, risks, or purpose detail. If the company wants to rely on consent as an Article 49 transfer derogation, what is wrong?
- During training, staff ask why the GDPR restricts unrestricted transfers of personal data to third countries. What protective rationale best answers them?
- A vendor markets a “GDPR transfer certification” but offers no binding, enforceable commitments toward data subjects or exporters. Can that certification alone serve as a Chapter V transfer tool?
European Data Protection: Scope and Accountability · 52 questions
- A US online retailer has no office or staff in the EU, but it runs German-language ads, shows prices in euros, and ships to German addresses. How should territorial scope under the GDPR be analysed?
- An online retailer is established in France and processes customer personal data for its EU shop. Processing equipment is hosted in a non-EU data centre. Which territorial-scope conclusion is correct?
- A non-EU analytics vendor has no EU office but deploys tracking cookies and behavioural profiles on visitors who are in the Union. Which Article 3 analysis is most accurate?
- A multi-country EU controller must identify its lead supervisory authority for one-stop-shop purposes. Which concept, as developed under Article 4(16) and EDPB Opinion 04/2024 themes, should guide that choice?
- A private individual keeps a Christmas card address list for family and friends with no connection to a trade or profession. A colleague claims this list is GDPR-covered business processing. Which material-scope view is correct?
- A Member State police authority processes personal data solely for the prevention, investigation, detection, or prosecution of criminal offences. Which material-scope statement best reflects the GDPR’s design?
- A cloud processor established in Ireland processes personal data only for non-EU controllers about individuals who are not in the Union. How should Article 3 be approached?
- A non-EU controller targets EU users and has no establishment in the Union. Subject to applicable exceptions, which obligation is characteristically linked to that territorial-scope situation?
- An English-language blog hosted outside the EU is merely accessible to occasional EU readers and shows no EU language versions, EU currency, EU shipping, or EU-focused ads. Counsel claims accessibility alone equals GDPR targeting. Which analysis is sound?
- A non-EU parent company operates an EU branch that processes employee personal data for local HR. Which territorial-scope statement is correct?
- A research institute publishes aggregate statistics that are truly anonymous, with no residual identifiers and no reasonable means of re-identification. How does GDPR material scope treat that output?
- A joint venture has establishments in several Member States and decision-making on purposes and means of a processing operation is split across sites. Which approach aligns with main-establishment guidance themes?
- Two separate apps jointly decide the purposes and means of processing for a shared login identity service. Which accountability step is required under GDPR joint-controller rules?
- A controller’s web form, by default, displays and invites completion of thirty optional special-category health fields that are unnecessary for the stated signup purpose. Which accountability principle is most directly engaged?
- A supervisory authority asks a non-exempt controller for its records of processing activities and learns that none exist. Which accountability conclusion follows?
- A school plans a new lobby system that uses facial recognition to log visitor entry on an ongoing basis. Which accountability action is most clearly indicated before go-live?
- A hospital’s core activities consist of processing health data on a large scale as part of care delivery. Which DPO conclusion aligns with GDPR mandatory-appointment criteria?
- A privacy programme documents policies but never tests whether controls operate in practice. Which accountability improvement is most on-point?
- A controller engages a cloud vendor that processes personal data solely on oral instructions with no written contract containing GDPR processor terms. What is the accountability problem?
- A product team launches a personal-data feature and only afterward adds a privacy banner, calling that ‘data protection by design.’ Which correction is required?
- A social platform’s default privacy settings make new user profiles publicly visible worldwide without any affirmative user choice. Which GDPR default-protection critique is strongest?
- A controller plans black-box profiling of vulnerable individuals yet completes only a one-page form ticking ‘low risk’ with no analysis of impacts or mitigations. How should that DPIA practice be judged?
- During a lawful investigation, a supervisory authority requests information from a controller, and the controller refuses all cooperation without a recognised legal ground. Which accountability rule is breached?
- A municipal public authority processes personal data in carrying out its tasks (not as a court acting in its judicial capacity). Which DPO rule applies?
- A controller maintains polished privacy policies that staff never follow, and cannot show how processing complies in practice. Which accountability diagnosis is correct?
- A controller appoints a Data Protection Officer but also makes that person Head of Marketing with conversion-rate KPIs that conflict with privacy advice. What requirement is most clearly breached?
- A DPIA concludes that residual risk to data subjects remains high after all planned measures. The controller wants to start processing immediately. What must the controller do first under GDPR?
- Two companies act as joint controllers but never tell data subjects which party handles access requests or how responsibilities are split. What transparency duty are they most clearly missing?
- A SaaS vendor argues it is 'only hosting' and therefore need not help the controller with data-subject requests or security incidents. Under GDPR processor duties, what is the better view?
- A privacy team builds a shortlist of processing that likely needs a DPIA, including systematic monitoring and large-scale special-category processing. What does that shortlist correctly reflect?
- An organisation's records of processing activities list purposes and data categories but omit categories of recipients and international transfers. What Art. 30 expectation is most clearly unmet?
- Security controls exist in production, but nothing is written down, so the team cannot show a supervisory authority what technical and organisational measures apply. Which accountability gap is this?
- A small enterprise may fall under a records-of-processing exemption for certain activities, yet it still runs large-scale health-data analytics with high residual risk and no risk analysis. What is the sound accountability approach?
- Before coding a new customer portal, the team decides data fields to collect, default encryption, and role-based access as design choices—not afterthoughts. Which GDPR concept do these choices best illustrate?
- An annual privacy audit finds that data-subject request workflows are broken. Leadership files the report for marketing and takes no corrective action. What does accountability most clearly require instead?
- A controller instructs its processor to keep processing in a way the processor reasonably believes infringes the GDPR. What should the processor do?
- A complaint concerns cross-border processing by a pan-EU SaaS whose main establishment is in one Member State. How should supervisory competence typically be approached under the one-stop-shop model?
- A trainee asks whether the EDPB and the EDPS play the same role in issuing binding guidance to all national supervisory authorities. What distinction is most accurate?
- A national supervisory authority opens an investigation into a local bakery that only serves domestic customers in that Member State. What does this scenario best illustrate?
- Cooperation on a cross-border case stalls and parties look to EDPB mechanisms to restore consistency. What EDPB role is most relevant?
- A complainant asks the EDPS to impose an administrative fine on a private German GmbH for GDPR infringements. Why is that request misdirected?
- A controller tries to designate the 'friendliest' supervisory authority as lead while ignoring where its main establishment actually exercises central administration. What is the correct approach?
- In a cross-border GDPR case, authorities other than the lead SA still have a structured role. What concept does that reflect?
- Which statement best surveys supervisory authority corrective powers under the GDPR at concept level?
- At Body of Knowledge depth, how are the GDPR's two administrative-fine tiers commonly described?
- After a personal-data breach linked to a GDPR infringement, a data subject seeks compensation for anxiety and distress without proving financial loss. Which statement best matches GDPR compensation rights?
- A consumer association brings a representative action concerning GDPR infringements affecting multiple individuals. What does this scenario primarily illustrate?
- When calculating an administrative fine, which approach aligns with Article 83?
- A controller asserts that only processors can receive administrative fines under the GDPR. What is the correct position?
- Besides GDPR administrative fines, what is accurate about additional consequences in the European framework?
- A data subject whose personal data was mishandled wants to lodge a complaint with a supervisory authority and also seek compensation in court. Which statement best reflects GDPR remedies?
- When calculating a GDPR fine capped as a percentage of annual turnover, which high-level concept should privacy counsel treat as the relevant turnover base?
Compliance with European Data Protection Law and Regulation · 48 questions
- An employer relies solely on employee consent for continuous badge-based location tracking across the workplace. What is the strongest privacy-compliance concern?
- Personnel files containing disciplinary notes are stored on a shared drive with no role-based access limits and no retention schedule. Which remediation best addresses the core GDPR risks?
- Management secretly introduces full workplace email monitoring solely to measure “productivity.” What GDPR-aligned critique is most accurate?
- A DLP tool scans all outbound email, including messages that appear to be privileged HR complaints to external counsel. How should the employer approach design of the control?
- A BYOD programme syncs employees’ personal photo libraries into corporate MDM without clear separation of work and private data. What is the primary privacy risk?
- Before deploying invasive employee monitoring, HR skips Works Council consultation in a Member State that requires it. Why does that matter for CIPP/E-level compliance judgment?
- A whistleblowing hotline processes personal data of persons accused in reports. Which design principle is most aligned with GDPR expectations?
- HR proposes relying on employee consent as the primary lawful basis for ordinary payroll processing. What is the better GDPR-aligned approach?
- A company keeps all former employees’ complete personnel files indefinitely “for references.” Which storage-limitation response is most appropriate?
- Occupational health records sit in the same shared drive folder as ordinary manager KPI spreadsheets. What is the key compliance failure?
- Security proposes a covert camera in the employee break room, justified only as “theft prevention,” without assessing less intrusive options. What is the strongest GDPR critique?
- A BYOD policy authorises wiping an employee’s entire personal phone when employment ends. Which control design better respects privacy?
- HR uses a SaaS whistleblowing platform and is unsure who is controller. The vendor hosts the tool and acts only on documented instructions. How should roles typically be characterised?
- IT enables continuous keystroke logging for every remote worker without a DPIA. Which statement best reflects GDPR accountability expectations?
- A Works Council agreement sets specific conditions for CCTV in warehouses. How should privacy counsel treat that agreement?
- Legal pulls an employee’s personal email from a BYOD device into eDiscovery without a protocol separating work from private messages. What risk does this highlight?
- A city installs CCTV in a busy public square with no signage or other transparency measures. Which compliance theme is most directly engaged?
- Police ask a provider for bulk interception of communications without discussing lawful authority or safeguards. At concept level, what should a privacy professional emphasise?
- A retail shop uses facial recognition to match customers against a shoplifter watchlist. Which characterisation best captures the GDPR risk level?
- A public authority runs citywide ANPR that stores all vehicle movements indefinitely. What compliance theme is most important?
- A consultant treats marketing wristbands that track shopper movement the same as court-ordered geolocation bracelets for parolees. What mistake is being made?
- A private detective uses a drone to film neighbours’ gardens systematically for a client investigation. Which GDPR-oriented statement is most accurate?
- A gym considers fingerprint door entry and asks how EDPB materials should factor into the assessment. What is the best practice answer?
- A telecom operator stores communications metadata for years to support 'any future investigation that might arise,' with no defined statutory purpose, retention limit, or case linkage. Which assessment best reflects European data-protection principles?
- A B2C newsletter publisher buys a cold email list from a broker and begins promotional campaigns to EU recipients with whom it has no prior relationship and no recorded consent. What is the soundest compliance conclusion?
- A retailer's marketing platform sends weekly promotional emails but provides no working unsubscribe or opt-out mechanism in those messages. Which GDPR/ePrivacy-aligned statement is correct?
- An adtech vendor builds cross-site behavioural profiles of EU users by dropping trackers that follow browsing across unrelated publishers. Which compliance theme should the privacy lead prioritise?
- A marketer argues that GDPR legitimate interests alone justify unsolicited promotional emails to cold EU consumer addresses, ignoring ePrivacy consent overlays. What is the better CIPP/E-aligned view?
- A loyalty app shares detailed purchase profiles of EU customers with unrelated ad networks for third-party advertising without clear notice or a valid permission model. What is the primary compliance failure?
- After a customer buys running shoes online and does not opt out of similar-product emails, the retailer also sells the address to unrelated travel brands for their own promotions, claiming the original soft opt-in covers everything. Which statement is correct?
- A children's game website serves behavioural advertising based on play patterns and inferred interests of underage EU users. Which compliance posture is most appropriate?
- A subscriber objects to marketing emails and is added to a suppression list, but a later campaign tool accidentally re-imports the address and sends promotions again. What operational lesson follows?
- A compliance checklist treats postal leaflet campaigns and B2C promotional email as identical under GDPR alone, skipping ePrivacy channel rules. What correction is needed?
- A publisher's real-time bidding stack broadcasts user pseudonymous IDs and URL context to dozens of bid requesters without intelligible notice of recipients or purposes. Which compliance concern is strongest?
- A political campaign plans granular social-media targeting of EU voters and asks what soft-law source should shape its privacy compliance design beyond the GDPR text alone. Which choice best fits CIPP/E expectations?
- A brand hashes customer email addresses before uploading them to an ad platform for matching and claims the data are anonymous so GDPR no longer applies. Is that claim sound?
- A European city migrates citizen casework systems to a US public cloud region without SCCs, adequacy reliance, or other transfer tools, assuming the cloud brand's security brochure is enough. What is missing?
- A public news site blocks all access unless the visitor accepts advertising trackers, offering no equivalent tracking-free path. Which consent issue is central?
- Analytics and advertising cookies on an EU-facing site fire on first page load before the visitor interacts with the consent banner. What is the compliance problem?
- A social platform designs its consent UI so 'Accept all' is prominent while refusal takes multiple obscured steps, nudging EU users toward tracking. How should this be assessed?
- A search-engine marketing toolkit used by an EU retailer forwards raw user search queries containing names and locations to multiple advertisers without filtering or notice. What principle is most clearly at risk?
- An employer trains an automated hiring screen on historical HR data and rejects EU candidates with no human review path, DPIA, or bias assessment, despite significant effects on applicants. Which GDPR-aware concern is most accurate?
- A product owner claims that after adopting enterprise SaaS for EU customer CRM, only the cloud provider is the controller and the company has no further GDPR role. What is the usual correct framing?
- A privacy review treats a strictly necessary load-balancing session cookie the same as third-party advertising trackers, requiring identical pre-consent banners for both. What distinction should be drawn?
- A platform scrapes publicly posted EU user content from the open web to train machine-learning models without informing those individuals or establishing a clear lawful basis. Which statement is correct?
- A generative-AI chatbot logs EU users' prompts that include diagnoses and medication details for model improvement. Which risk framing is most accurate under GDPR?
- A consent management platform's banner summarises partners only as '1200 vendors' with no intelligible explanation of purposes or easy access to meaningful recipient information before acceptance. What consent-quality problem arises?
- A lender deploys an ML credit-scoring model affecting EU consumers without bias testing, explainability review, or GDPR-aligned assessment of profiling safeguards. Which conclusion fits CIPP/E Domain 5 technology compliance?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the International Association of Privacy Professionals (IAPP).