Compliance with European Data Protection Law and Regulation
CIPP/E · 48 questions
- An employer relies solely on employee consent for continuous badge-based location tracking across the workplace. What is the strongest privacy-compliance concern?
- Personnel files containing disciplinary notes are stored on a shared drive with no role-based access limits and no retention schedule. Which remediation best addresses the core GDPR risks?
- Management secretly introduces full workplace email monitoring solely to measure “productivity.” What GDPR-aligned critique is most accurate?
- A DLP tool scans all outbound email, including messages that appear to be privileged HR complaints to external counsel. How should the employer approach design of the control?
- A BYOD programme syncs employees’ personal photo libraries into corporate MDM without clear separation of work and private data. What is the primary privacy risk?
- Before deploying invasive employee monitoring, HR skips Works Council consultation in a Member State that requires it. Why does that matter for CIPP/E-level compliance judgment?
- A whistleblowing hotline processes personal data of persons accused in reports. Which design principle is most aligned with GDPR expectations?
- HR proposes relying on employee consent as the primary lawful basis for ordinary payroll processing. What is the better GDPR-aligned approach?
- A company keeps all former employees’ complete personnel files indefinitely “for references.” Which storage-limitation response is most appropriate?
- Occupational health records sit in the same shared drive folder as ordinary manager KPI spreadsheets. What is the key compliance failure?
- Security proposes a covert camera in the employee break room, justified only as “theft prevention,” without assessing less intrusive options. What is the strongest GDPR critique?
- A BYOD policy authorises wiping an employee’s entire personal phone when employment ends. Which control design better respects privacy?
- HR uses a SaaS whistleblowing platform and is unsure who is controller. The vendor hosts the tool and acts only on documented instructions. How should roles typically be characterised?
- IT enables continuous keystroke logging for every remote worker without a DPIA. Which statement best reflects GDPR accountability expectations?
- A Works Council agreement sets specific conditions for CCTV in warehouses. How should privacy counsel treat that agreement?
- Legal pulls an employee’s personal email from a BYOD device into eDiscovery without a protocol separating work from private messages. What risk does this highlight?
- A city installs CCTV in a busy public square with no signage or other transparency measures. Which compliance theme is most directly engaged?
- Police ask a provider for bulk interception of communications without discussing lawful authority or safeguards. At concept level, what should a privacy professional emphasise?
- A retail shop uses facial recognition to match customers against a shoplifter watchlist. Which characterisation best captures the GDPR risk level?
- A public authority runs citywide ANPR that stores all vehicle movements indefinitely. What compliance theme is most important?
- A consultant treats marketing wristbands that track shopper movement the same as court-ordered geolocation bracelets for parolees. What mistake is being made?
- A private detective uses a drone to film neighbours’ gardens systematically for a client investigation. Which GDPR-oriented statement is most accurate?
- A gym considers fingerprint door entry and asks how EDPB materials should factor into the assessment. What is the best practice answer?
- A telecom operator stores communications metadata for years to support 'any future investigation that might arise,' with no defined statutory purpose, retention limit, or case linkage. Which assessment best reflects European data-protection principles?
- A B2C newsletter publisher buys a cold email list from a broker and begins promotional campaigns to EU recipients with whom it has no prior relationship and no recorded consent. What is the soundest compliance conclusion?
- A retailer's marketing platform sends weekly promotional emails but provides no working unsubscribe or opt-out mechanism in those messages. Which GDPR/ePrivacy-aligned statement is correct?
- An adtech vendor builds cross-site behavioural profiles of EU users by dropping trackers that follow browsing across unrelated publishers. Which compliance theme should the privacy lead prioritise?
- A marketer argues that GDPR legitimate interests alone justify unsolicited promotional emails to cold EU consumer addresses, ignoring ePrivacy consent overlays. What is the better CIPP/E-aligned view?
- A loyalty app shares detailed purchase profiles of EU customers with unrelated ad networks for third-party advertising without clear notice or a valid permission model. What is the primary compliance failure?
- After a customer buys running shoes online and does not opt out of similar-product emails, the retailer also sells the address to unrelated travel brands for their own promotions, claiming the original soft opt-in covers everything. Which statement is correct?
- A children's game website serves behavioural advertising based on play patterns and inferred interests of underage EU users. Which compliance posture is most appropriate?
- A subscriber objects to marketing emails and is added to a suppression list, but a later campaign tool accidentally re-imports the address and sends promotions again. What operational lesson follows?
- A compliance checklist treats postal leaflet campaigns and B2C promotional email as identical under GDPR alone, skipping ePrivacy channel rules. What correction is needed?
- A publisher's real-time bidding stack broadcasts user pseudonymous IDs and URL context to dozens of bid requesters without intelligible notice of recipients or purposes. Which compliance concern is strongest?
- A political campaign plans granular social-media targeting of EU voters and asks what soft-law source should shape its privacy compliance design beyond the GDPR text alone. Which choice best fits CIPP/E expectations?
- A brand hashes customer email addresses before uploading them to an ad platform for matching and claims the data are anonymous so GDPR no longer applies. Is that claim sound?
- A European city migrates citizen casework systems to a US public cloud region without SCCs, adequacy reliance, or other transfer tools, assuming the cloud brand's security brochure is enough. What is missing?
- A public news site blocks all access unless the visitor accepts advertising trackers, offering no equivalent tracking-free path. Which consent issue is central?
- Analytics and advertising cookies on an EU-facing site fire on first page load before the visitor interacts with the consent banner. What is the compliance problem?
- A social platform designs its consent UI so 'Accept all' is prominent while refusal takes multiple obscured steps, nudging EU users toward tracking. How should this be assessed?
- A search-engine marketing toolkit used by an EU retailer forwards raw user search queries containing names and locations to multiple advertisers without filtering or notice. What principle is most clearly at risk?
- An employer trains an automated hiring screen on historical HR data and rejects EU candidates with no human review path, DPIA, or bias assessment, despite significant effects on applicants. Which GDPR-aware concern is most accurate?
- A product owner claims that after adopting enterprise SaaS for EU customer CRM, only the cloud provider is the controller and the company has no further GDPR role. What is the usual correct framing?
- A privacy review treats a strictly necessary load-balancing session cookie the same as third-party advertising trackers, requiring identical pre-consent banners for both. What distinction should be drawn?
- A platform scrapes publicly posted EU user content from the open web to train machine-learning models without informing those individuals or establishing a clear lawful basis. Which statement is correct?
- A generative-AI chatbot logs EU users' prompts that include diagnoses and medication details for model improvement. Which risk framing is most accurate under GDPR?
- A consent management platform's banner summarises partners only as '1200 vendors' with no intelligible explanation of purposes or easy access to meaningful recipient information before acceptance. What consent-quality problem arises?
- A lender deploys an ML credit-scoring model affecting EU consumers without bias testing, explainability review, or GDPR-aligned assessment of profiling safeguards. Which conclusion fits CIPP/E Domain 5 technology compliance?