European Data Protection Law and Regulation
CIPP/E · 92 questions
- A parks department spreadsheet of season-pass holders is called “just names” and therefore “not personal data.” Which GDPR assessment is correct?
- A clinic labels allergy information and genetic markers as ordinary CRM fields. Which GDPR classification should privacy counsel apply?
- An analytics team claims hashing a national ID always makes the dataset anonymous. Which distinction should the DPO enforce?
- A vendor contract calls both parties “joint owners of the data.” Which GDPR role analysis is correct?
- A call-centre staffer asks who the “data subject” is when a CRM row concerns a deceased relative. Which GDPR-focused answer is correct?
- A board slide lists “lawfulness, fairness and transparency” as optional best practices. Which correction is required under GDPR?
- A startup processes only IP addresses and argues they can never be personal data. Which GDPR position is correct?
- A municipality outsources payroll hosting and assumes the host is automatically the controller. Which analysis follows GDPR role concepts?
- A research unit replaces names with codes but keeps the key, then calls the file “anonymous open data.” Which label is correct under GDPR?
- A charity shares volunteer political opinions in a newsletter CRM. Which GDPR classification applies to those political opinions?
- A transport app stores precise disability status so staff can arrange boarding assistance. A product manager treats the field like any other preference checkbox. How should privacy counsel classify that data under the GDPR?
- A processor argues that EDPB guidance on controller and processor roles can be ignored because the written contract already looks clear. Which statement best reflects how that guidance should be used?
- A city open-data portal publishes only aggregates that, after rigorous assessment, cannot identify any resident even when combined with other reasonably available information. How should the GDPR personal-data rules apply?
- An HR system stores trade-union membership for workforce planning. Staff treat the field like a cafeteria preference. What is the correct GDPR characterisation?
- A marketing lead insists that under the GDPR, 'sensitive data' always means passwords and other secrets. Which correction best reflects EU data protection terminology?
- Two cities jointly design a shared resident portal and each decides the purposes and essential means for how resident data will be used in that portal. At a basic GDPR concepts level, how should their relationship be understood?
- A library encrypts staff laptops but leaves shared network drives open to every staff login with no further access restrictions. Leadership claims encryption alone proves GDPR security compliance. What is the best assessment?
- A hospital asks whether access controls that limit which staff can open patient records count only as organisational paperwork, or also as technical security measures under the GDPR. Which view is most accurate?
- During a ransomware tabletop exercise, citizen records are encrypted by an attacker. Leadership asks when GDPR personal-data breach notification clocks start for the controller. Which timing rule is correct?
- A SaaS vendor processing municipal customer data suffers a personal-data breach. The city asks who notifies the supervisory authority under the GDPR. Which allocation of duties is correct?
- A DPO relies on EDPB breach guidelines when deciding whether individuals must be informed after a personal-data breach. Which threshold correctly drives data-subject notification?
- Procurement skips security due diligence on a personal-data vendor because the vendor’s slide deck shows an ISO certification logo. What does responsible vendor management under GDPR security expectations require?
- A city shares resident email lists with a festival partner for joint promotions without clarifying roles or putting protective arrangements in place. What GDPR-aligned principle should guide that third-party sharing?
- An IT team configures cloud storage buckets containing personal data to be publicly readable by default 'for convenience.' How should this default be evaluated under GDPR security requirements?
- A processor subcontracts hosting of the controller’s personal data to another provider without informing the controller or obtaining the required authorisation. Which GDPR theme is primarily violated?
- A council measures ‘security’ solely by counting firewalls and ignores staff training, policies, and procedures that govern how personal data is handled. What does GDPR TOMs thinking require?
- A startup asks whether encryption is mandatory in all GDPR processing scenarios as a universal checkbox. Which framing is most accurate?
- A school discovers that an unencrypted USB stick with pupil personal data was lost three weeks earlier; staff only now become aware of the loss. How should breach-handling duties be timed?
- A vendor-management programme signs data processing agreements then never reviews security posture, access rights, or DPA performance afterward. What does responsible GDPR-aligned vendor oversight require?
- A marketing agency receives a customer list ‘to help with a campaign’ but is given no instructions on permitted purposes, retention, or deletion. Which third-party sharing requirement is most clearly missing?
- A CISO claims that GDPR security of processing is fully satisfied by completing PCI-DSS checklists alone. Which statement best corrects that claim?
- A city open Wi-Fi service logs device MAC addresses for ‘security analytics’ without discussing retention limits or other protective discipline. What GDPR security insight applies?
- A processor detects unauthorised access to personal data it processes for a controller and plans to mention it only at the next monthly quarterly business review. What timing obligation applies?
- A board asks the privacy team for ‘EDPB-aligned’ scoring when deciding whether a breach requires supervisory-authority or individual notification. How should EDPB materials factor into that assessment?
- A shared-services centre hosts multiple municipalities on one platform with no logical separation of each city’s resident data or access paths. Which security-design concern is most directly raised under GDPR TOMs?
- A municipal contractor takes printed citizen case files home overnight to finish work. Leadership calls it harmless because the files never left paper form. Which response best reflects GDPR security of personal data expectations?
- After a ransomware incident, a city restores systems from backups and leadership says there is no personal-data breach because availability was recovered. What should privacy counsel emphasize?
- A software vendor processes citizen contact data under a city contract, then quietly re-uses those contacts to train its own commercial product. What GDPR-aligned limit does this violate most directly?
- A municipality scores vendors only on lowest price and skips security questionnaires and contractual audit rights. Privacy asks for stronger vendor management. Which practice best supports responsible handling of personal data with processors?
- An employee emails a spreadsheet of welfare claimants to the wrong external address. Which characterisation best fits GDPR personal-data breach analysis?
- A cloud administrator disables multi-factor authentication on systems holding citizen personal data to 'reduce friction.' How should this change be viewed under GDPR security expectations?
- A partner hospital shares patient contact lists with another organisation for a joint health fair without assessing the recipient's safeguards. What should privacy practice require before such sharing?
- A DPO documents technical and organisational measures at system launch but never revisits them after a major architecture change that expands personal-data processing. What does GDPR-aligned security require?
- A vendor's public trust portal still lists outdated sub-processors while live support traffic already routes through new providers. Which practice best aligns with responsible processor obligations?
- After unauthorised access to citizen records, a city argues that intact backups make breach notification unnecessary. Which distinction should privacy counsel draw?
- A security policy forbids USB use with personal data, but the organisation has no monitoring, enforcement, or exception process. What lesson should CIPP/E candidates take about organisational measures?
- A processor markets 'GDPR certification' stickers but cannot show encryption, access control, or incident response capable of protecting the personal data. What should the controller prioritise?
- A cross-border vendor support team can open any EU citizen support ticket from multiple countries without role limits. Which TOMs-oriented improvement best addresses the risk?
- A council publishes a breach log that redacts names but leaves unique case IDs that readily re-identify individuals when combined with other public records. How should this disclosure be assessed?
- A vendor-management playbook relies only on a security schedule and skips data-processing agreements because 'security covers GDPR.' What correction is needed?
- An incident response plan lists technical containment steps but never assigns who assesses high risk to data subjects for notification decisions. Which organisational gap does this reveal?
- A smart-meter vendor keeps detailed household consumption profiles indefinitely 'for ML quality.' Beyond retention critiques, what security implication follows?
- A resident emails a city portal: 'Send me everything you have on me.' Which response best reflects the GDPR right of access?
- A citizen finds a wrong home address in a benefits file and demands a correction. Which data-subject right primarily applies?
- A former customer demands erasure of their account after cancelling a service. How should the controller approach the request at concept level?
- A data subject asks the controller to pause certain processing while the accuracy of records is contested. Which right is designed for that situation?
- A person objects to use of their email for direct marketing. What is the GDPR-aligned outcome?
- A signup form uses pre-ticked boxes to collect consent for optional analytics cookies and partner offers. What is wrong with this approach under GDPR consent rules?
- A bank uses purely automated scoring to deny online account applications with no meaningful human review path. Which data-subject protection theme applies?
- A user asks a streaming service to move their playlist and profile data to another provider in a structured form. Which right primarily governs this request when its conditions are met?
- A controller refuses a subject access request in full by citing a police-investigation exception, without checking whether Member State law actually authorises that restriction or whether a narrower response is possible. What is the sound GDPR approach?
- When fulfilling a subject access request, a controller ignores guidance on scope and dumps every system log, including third-party trade secrets and other people’s personal data, without any balancing. What should the controller do instead?
- A mobile app lets users consent to personalised ads with one tap at signup, but burying consent withdrawal five menus deep. What GDPR consent rule does this practice violate?
- A customer requests erasure of all personal data, including an invoice the controller must retain under tax law. How should the controller respond?
- A company uses automated profiling to screen job applicants and never explains the logic involved or available safeguards. What transparency expectation applies?
- A data subject objects to processing that the controller bases on legitimate interests. What must the controller do?
- A controller refuses a data portability request because the personal data were collected on a legal-obligation basis rather than consent or contract. Is that refusal typically aligned with GDPR portability rules?
- A city receives an access request and redacts other residents’ personal data from the response before disclosing the requester’s information. Why is that approach appropriate?
- A marketing email lacks any unsubscribe mechanism and states that GDPR consent is 'forever.' What is wrong with that approach?
- A patient asks a clinic to rectify a diagnosis code that the clinician disputes as inaccurate. While accuracy is being resolved, what GDPR tool is especially relevant?
- A social network refuses an erasure request solely because 'the post is still interesting to other users.' What is the better framing of erasure / right-to-be-forgotten analysis?
- A chatbot makes a solely automated offer decision that significantly affects whether a consumer can enter a contract. What GDPR theme is triggered?
- A controller answers a subject access request after nine months and never communicated any extension. How does that compare with GDPR timing expectations?
- A company demands a notarised passport for every trivial rectification of a typo in an email address. What principle should govern identity verification for rights requests?
- A data subject demands portability of inferred credit scores created solely by the controller’s algorithms. How does portability typically treat such inferred data?
- A child-directed online service relies on the child’s consent alone without considering age thresholds or holder-of-parental-responsibility rules. What is the compliance problem?
- A controller marks processing as restricted after a data-subject request but continues using the same personal data for marketing campaigns. What does restriction require operationally?
- An individual objects to a shop’s CCTV that captures the entrance to their home, where the shop relies on legitimate interests. Which statement best reflects the objection analysis?
- After a controller ignores a valid access request, the data subject wants to escalate. What path does GDPR expressly support?
- A signup form bundles consent for necessary contract terms together with unrelated sharing of personal data with marketing partners, making the service conditional on accepting everything. What consent problem does this create?
- A user withdraws consent for analytics cookies, but the analytics scripts keep firing unchanged. What requirement is failing?
- A company claims the right to rectification never applies to any recorded opinion about a person. How should that claim be assessed?
- A public profiling system decides welfare eligibility through solely automated means and offers no channel for human intervention. What safeguard expectation is missing?
- A data subject requests erasure of personal data that the controller also needs to establish or defend a legal claim. How may the controller respond?
- A controller’s access-request response discloses the personal data but omits recipients or categories of recipients. What Article 15 element is missing?
- A controller publishes a policy stating that every data-subject rights request costs €200 with no exceptions. How should that fee policy be assessed under the GDPR?
- A data subject asks a controller to restrict processing while the controller verifies whether legitimate interests override the objection. What is the appropriate treatment of restriction in this situation?
- A controller answers a data-portability request by sending only an unreadable screenshot PDF of a GUI. What format expectation does that response fail when portability applies?
- After a customer withdraws marketing consent, a preference centre silently re-checks the consent box on the next login without a clear new affirmative action. How should that practice be treated?
- A controller cites ‘trade secrets’ as a reason to refuse an entire access request without any balancing analysis. What is the correct approach?
- A data subject objects to processing for scientific research carried out as a task in the public interest. How does GDPR objection handling in that setting typically differ from a simple marketing opt-out?
- A DPO designs workflows for search-index-style delisting and erasure (RTBF) requests. What role should EDPB guidelines and opinions play in that design?