European Data Protection: Scope and Accountability
CIPP/E · 52 questions
- A US online retailer has no office or staff in the EU, but it runs German-language ads, shows prices in euros, and ships to German addresses. How should territorial scope under the GDPR be analysed?
- An online retailer is established in France and processes customer personal data for its EU shop. Processing equipment is hosted in a non-EU data centre. Which territorial-scope conclusion is correct?
- A non-EU analytics vendor has no EU office but deploys tracking cookies and behavioural profiles on visitors who are in the Union. Which Article 3 analysis is most accurate?
- A multi-country EU controller must identify its lead supervisory authority for one-stop-shop purposes. Which concept, as developed under Article 4(16) and EDPB Opinion 04/2024 themes, should guide that choice?
- A private individual keeps a Christmas card address list for family and friends with no connection to a trade or profession. A colleague claims this list is GDPR-covered business processing. Which material-scope view is correct?
- A Member State police authority processes personal data solely for the prevention, investigation, detection, or prosecution of criminal offences. Which material-scope statement best reflects the GDPR’s design?
- A cloud processor established in Ireland processes personal data only for non-EU controllers about individuals who are not in the Union. How should Article 3 be approached?
- A non-EU controller targets EU users and has no establishment in the Union. Subject to applicable exceptions, which obligation is characteristically linked to that territorial-scope situation?
- An English-language blog hosted outside the EU is merely accessible to occasional EU readers and shows no EU language versions, EU currency, EU shipping, or EU-focused ads. Counsel claims accessibility alone equals GDPR targeting. Which analysis is sound?
- A non-EU parent company operates an EU branch that processes employee personal data for local HR. Which territorial-scope statement is correct?
- A research institute publishes aggregate statistics that are truly anonymous, with no residual identifiers and no reasonable means of re-identification. How does GDPR material scope treat that output?
- A joint venture has establishments in several Member States and decision-making on purposes and means of a processing operation is split across sites. Which approach aligns with main-establishment guidance themes?
- Two separate apps jointly decide the purposes and means of processing for a shared login identity service. Which accountability step is required under GDPR joint-controller rules?
- A controller’s web form, by default, displays and invites completion of thirty optional special-category health fields that are unnecessary for the stated signup purpose. Which accountability principle is most directly engaged?
- A supervisory authority asks a non-exempt controller for its records of processing activities and learns that none exist. Which accountability conclusion follows?
- A school plans a new lobby system that uses facial recognition to log visitor entry on an ongoing basis. Which accountability action is most clearly indicated before go-live?
- A hospital’s core activities consist of processing health data on a large scale as part of care delivery. Which DPO conclusion aligns with GDPR mandatory-appointment criteria?
- A privacy programme documents policies but never tests whether controls operate in practice. Which accountability improvement is most on-point?
- A controller engages a cloud vendor that processes personal data solely on oral instructions with no written contract containing GDPR processor terms. What is the accountability problem?
- A product team launches a personal-data feature and only afterward adds a privacy banner, calling that ‘data protection by design.’ Which correction is required?
- A social platform’s default privacy settings make new user profiles publicly visible worldwide without any affirmative user choice. Which GDPR default-protection critique is strongest?
- A controller plans black-box profiling of vulnerable individuals yet completes only a one-page form ticking ‘low risk’ with no analysis of impacts or mitigations. How should that DPIA practice be judged?
- During a lawful investigation, a supervisory authority requests information from a controller, and the controller refuses all cooperation without a recognised legal ground. Which accountability rule is breached?
- A municipal public authority processes personal data in carrying out its tasks (not as a court acting in its judicial capacity). Which DPO rule applies?
- A controller maintains polished privacy policies that staff never follow, and cannot show how processing complies in practice. Which accountability diagnosis is correct?
- A controller appoints a Data Protection Officer but also makes that person Head of Marketing with conversion-rate KPIs that conflict with privacy advice. What requirement is most clearly breached?
- A DPIA concludes that residual risk to data subjects remains high after all planned measures. The controller wants to start processing immediately. What must the controller do first under GDPR?
- Two companies act as joint controllers but never tell data subjects which party handles access requests or how responsibilities are split. What transparency duty are they most clearly missing?
- A SaaS vendor argues it is 'only hosting' and therefore need not help the controller with data-subject requests or security incidents. Under GDPR processor duties, what is the better view?
- A privacy team builds a shortlist of processing that likely needs a DPIA, including systematic monitoring and large-scale special-category processing. What does that shortlist correctly reflect?
- An organisation's records of processing activities list purposes and data categories but omit categories of recipients and international transfers. What Art. 30 expectation is most clearly unmet?
- Security controls exist in production, but nothing is written down, so the team cannot show a supervisory authority what technical and organisational measures apply. Which accountability gap is this?
- A small enterprise may fall under a records-of-processing exemption for certain activities, yet it still runs large-scale health-data analytics with high residual risk and no risk analysis. What is the sound accountability approach?
- Before coding a new customer portal, the team decides data fields to collect, default encryption, and role-based access as design choices—not afterthoughts. Which GDPR concept do these choices best illustrate?
- An annual privacy audit finds that data-subject request workflows are broken. Leadership files the report for marketing and takes no corrective action. What does accountability most clearly require instead?
- A controller instructs its processor to keep processing in a way the processor reasonably believes infringes the GDPR. What should the processor do?
- A complaint concerns cross-border processing by a pan-EU SaaS whose main establishment is in one Member State. How should supervisory competence typically be approached under the one-stop-shop model?
- A trainee asks whether the EDPB and the EDPS play the same role in issuing binding guidance to all national supervisory authorities. What distinction is most accurate?
- A national supervisory authority opens an investigation into a local bakery that only serves domestic customers in that Member State. What does this scenario best illustrate?
- Cooperation on a cross-border case stalls and parties look to EDPB mechanisms to restore consistency. What EDPB role is most relevant?
- A complainant asks the EDPS to impose an administrative fine on a private German GmbH for GDPR infringements. Why is that request misdirected?
- A controller tries to designate the 'friendliest' supervisory authority as lead while ignoring where its main establishment actually exercises central administration. What is the correct approach?
- In a cross-border GDPR case, authorities other than the lead SA still have a structured role. What concept does that reflect?
- Which statement best surveys supervisory authority corrective powers under the GDPR at concept level?
- At Body of Knowledge depth, how are the GDPR's two administrative-fine tiers commonly described?
- After a personal-data breach linked to a GDPR infringement, a data subject seeks compensation for anxiety and distress without proving financial loss. Which statement best matches GDPR compensation rights?
- A consumer association brings a representative action concerning GDPR infringements affecting multiple individuals. What does this scenario primarily illustrate?
- When calculating an administrative fine, which approach aligns with Article 83?
- A controller asserts that only processors can receive administrative fines under the GDPR. What is the correct position?
- Besides GDPR administrative fines, what is accurate about additional consequences in the European framework?
- A data subject whose personal data was mishandled wants to lodge a complaint with a supervisory authority and also seek compensation in court. Which statement best reflects GDPR remedies?
- When calculating a GDPR fine capped as a percentage of annual turnover, which high-level concept should privacy counsel treat as the relevant turnover base?