European Data Processing
CIPP/E · 68 questions
- A city collected festival ticket emails solely for entry control, then reuses them to build a political-donation lookalike model without a compatible further-processing analysis. Which processing principle is primarily at risk?
- A CRM retains every inactive resident record ‘forever just in case,’ with no retention rationale tied to the original purposes. Which principle does that practice primarily undermine?
- A benefits office knows its decision dataset is outdated, yet staff continue to rely on it without reasonable update steps. Which principle is primarily breached?
- A processing activity cites a valid Article 6 basis on paper, but the user experience hides the real use of the data behind deceptive interface patterns. What principle pairing does this scenario highlight?
- A survey collects exact GPS coordinates every second when approximate neighbourhood location would meet the stated research need. Which principle is primarily engaged?
- A hospital configures clinical notes so every intern account can edit any record without need-to-know controls. Which processing principle is most directly undermined?
- A leaflet claims processing is ‘transparent,’ yet the privacy notice is dense, unreadable legalese that individuals cannot reasonably understand. How should transparency be assessed?
- A retention schedule deletes live CRM records on time, but backup tapes indefinitely retain the same personal data with no workable purge path. What does storage limitation require in this situation?
- A team skips a further-processing compatibility assessment because the new use sits in the ‘same database’ as the original collection. Is that reasoning sound under purpose limitation?
- A city publishes incorrect parking-fine personal data online and delays correcting it after the error is known. Which assessment best captures the principle failure?
- A controller instructs a processor to collect forty optional fields ‘for future unknown projects’ with no current necessity. What principle does that instruction primarily conflict with?
- A security incident investigation shows personal data processing lacked basic integrity controls and access discipline. How does that finding map to GDPR processing principles?
- A swimming-pool membership contract needs the member’s contact details to deliver pool access and billing for that service. Which Article 6 lawful basis most directly fits that processing?
- A tax authority processes personal data in tax returns because a statute requires that processing. Which Article 6 lawful basis primarily applies?
- Paramedics process an unconscious patient’s personal data to provide emergency care when the patient cannot consent. Which Article 6 basis is most appropriately considered in that narrow emergency setting?
- A municipal public-health team processes personal data to carry out an official task in the public interest grounded in Member State law. Which Article 6 basis primarily fits?
- A retailer relies on legitimate interests for fraud-prevention analytics and documents a balancing test weighing its interests against data subjects’ rights. What does valid use of Article 6(1)(f) require?
- A health clinic processes genetic data for diagnosis. Beyond identifying an Article 6 lawful basis, what additional GDPR condition is typically required?
- A retail website wants to drop non-essential analytics cookies for EU visitors. Which Art. 6 lawful basis is the controller relying on when it obtains valid consent before setting those cookies?
- An employer requires staff to accept workplace CCTV monitoring as a take-it-or-leave-it condition of keeping their jobs and treats that acceptance as GDPR consent. Why is that approach typically problematic?
- A charity collected donor emails on consent for a fundraising campaign, then silently switched to legitimate interests after many donors withdrew consent. What is the main GDPR concern with that mid-campaign basis swap?
- A product team claims "legitimate interest" for a new profiling feature but has no documented balancing assessment. What should a CIPP/E-minded reviewer expect before relying on Article 6(1)(f)?
- A factory rolls out fingerprint scanners so each worker's attendance is uniquely identified. Beyond an Article 6 basis, what additional GDPR pathway does this biometric processing generally require?
- A controller justifies collecting detailed customer browsing histories solely because "everyone else in our industry does it." How should that justification be treated under Article 6?
- A marketing team proposes using "vital interests" under Article 6(1)(d) to email discount offers because customers "might need deals." Why does that fail GDPR analysis?
- A municipal licensing office must maintain a statutory public register of license holders. Staff suggest relying on consent so individuals can "opt out" of the register. What is the better GDPR approach?
- An employer collects racial-origin data solely for a genuine equality-monitoring programme authorised by applicable Union or Member State law. Which statement best reflects the special-category pathway?
- Before launching a new processing activity on legitimate interests, a privacy counsel reviews current EDPB materials on Article 6(1)(f). What is the sound reason for that step?
- A mobile app starts collecting precise location as soon as it installs, with no explanation of why until weeks later in a buried settings screen. Which transparency failure is most clearly illustrated?
- A company's privacy notice describes purposes and rights but never names the controller or provides required DPO contact details where a DPO is designated. What Art. 13/14 gap does that create?
- A controller publishes a short first-layer privacy summary with clear links to deeper detail on purposes, rights, and transfers. How does GDPR practice generally view that design?
- A retailer buys prospect lists from a data broker and plans to delay any privacy information to those individuals indefinitely. Which statement best reflects Articles 12 and 14?
- A privacy notice describes purposes only as "improving experience and other business purposes." What transparency problem does that wording create?
- A SaaS privacy notice lists EU processors but is silent about recipients in third countries and related transfer safeguards. What notice deficiency is most relevant?
- A notice states retention only as "we keep personal data as long as needed" with no period or determination criteria. What should be corrected?
- A controller omits data-subject rights from its privacy notice because "those rights are already written in the GDPR." Why is that insufficient?
- Before a mobile feature activates the camera in a sensitive context, the app shows a brief contextual explanation of what will be captured and why. What transparency technique does that illustrate?
- A service aimed at children presents its privacy information only in dense adult legalese. What GDPR transparency expectation is most clearly missed?
- A controller materially expands processing from account administration into behavioural advertising but never updates the privacy notice or otherwise informs data subjects. What ongoing transparency duty is breached?
- A privacy notice explains categories of data and retention but never states the lawful basis for each processing purpose. Which required element is missing?
- A building posts CCTV signs with essential facts and a QR code linking to a full camera privacy notice. How is that approach generally characterised under transparency good practice?
- A lender uses solely automated decision-making that produces legal effects for credit applicants, but its privacy notice is silent on that practice. What information is missing?
- For processing on a public marketing website, the only privacy notice is a PDF placed behind an account login wall. What accessibility problem does that create under Article 12?
- A controller’s privacy notice lists an email and phone number, but both bounce and the DPO mailbox is a dead shared inbox. What transparency practice is missing?
- A retailer builds profiles from purchased marketing lists and never tells customers which categories of data came from those third parties. What indirect-collection rule is it missing?
- A startup claims it only needs a privacy notice when consent is the lawful basis and skips notices for contract and legitimate-interest processing. What is wrong with that view?
- A municipal portal serves multilingual residents and adds standardised icons plus short summaries above the full privacy notice. How do these aids relate to transparency?
- A company’s public privacy notice names its cloud processor as if that vendor were the controller deciding purposes and means. What identification error must be fixed?
- An EU employer plans to email employee HR files to a US parent company with no adequacy decision, SCCs, BCRs, or valid derogation in place. What transfer rule applies?
- Counsel confirms the European Commission has adopted an adequacy decision for the destination country where a SaaS vendor stores EU customer data. What does that adequacy finding primarily mean for the transfer?
- Outside counsel drafts a 2026 transfer clause that still relies on the US–EU Safe Harbor framework as the transfer mechanism. What historical point should the privacy team raise?
- A 2026 vendor contract proposes Privacy Shield certification as the sole basis for transferring EU personal data to the United States. What should the controller conclude?
- A project team proposes Commission Standard Contractual Clauses for a processor in a non-adequate third country and asks whether signing SCCs ends all transfer analysis. What is the sound position?
- A multinational wants a reusable mechanism for routine intra-group transfers of HR and customer data among EEA and non-adequate affiliates. Which Chapter V tool fits that group scenario at concept level?
- A startup relies on explicit consent under Article 49 as the standing basis for systematic daily bulk transfers of all EU user records to a non-adequate region. What is the main problem?
- After signing SCCs with a non-adequate vendor, a controller skips any transfer impact assessment because “the clauses are Commission-approved.” What step is still expected?
- Counsel explores an approved code of conduct or certification mechanism, paired with binding enforceable commitments, to support transfers to a non-adequate recipient. How should that option be characterised?
- A team uses SCCs to send personal data to a jurisdiction known for extensive government surveillance but performs no analysis of local access laws or supplementary measures. Which Schrems II theme is being ignored?
- Customer data remain stored in an EU cloud region, yet a third-country support team remotely reads personal data to resolve tickets. How should the privacy team treat that access?
- Engineers ask whether encrypting personal data before it leaves the EEA can help address transfer risks to a challenging third country. Which authority’s transfer guidance is commonly used to frame that supplementary-measures analysis?
- A tourism app stores EU travellers’ photos only on servers in a country covered by a Commission adequacy decision. How does that destination choice affect the transfer analysis?
- A travel platform uses an Article 49 contractual-necessity derogation for occasional transfers needed to complete a guest’s hotel booking abroad, then proposes the same derogation to justify building a permanent offshore analytics data lake. What distinction should counsel draw?
- A colleague calls the company’s ordinary processor Data Processing Agreement its “BCRs” for US transfers. What correction is needed?
- A controller plans to transfer EU customer data to a US vendor “because they are on the Data Privacy Framework,” but nobody verifies the vendor’s active participation status. What verification step is required?
- A DPIA for a new analytics platform leaves the international-transfer section blank even though EU personal data will be hosted and accessed from outside the EEA. What accountability expectation is unmet?
- A signup form includes a single pre-ticked box labelled “I agree to all processing and international transfers” with no destination, risks, or purpose detail. If the company wants to rely on consent as an Article 49 transfer derogation, what is wrong?
- During training, staff ask why the GDPR restricts unrestricted transfers of personal data to third countries. What protective rationale best answers them?
- A vendor markets a “GDPR transfer certification” but offers no binding, enforceable commitments toward data subjects or exporters. Can that certification alone serve as a Chapter V transfer tool?