Introduction to European Data Protection
CIPP/E · 40 questions
- A city archives board asks why Europe needed special rules for personal data long before the GDPR existed. Which historical rationale best answers them?
- A municipal privacy officer cites the OECD Guidelines as if they were an EU regulation that can impose administrative fines. How should counsel correct that understanding?
- A county counsel wonders whether the Treaty of Lisbon matters for day-to-day GDPR work. Which link to the modern EU legal order is most accurate?
- A library consortium hears “Convention 108” and assumes it is identical to the GDPR. Which distinction should training emphasise?
- A regional DPO asks what a “harmonised European approach” tried to fix when Member States had divergent national data-protection laws. What problem was the drive toward consistent rules mainly addressing?
- A town hall debate treats Brexit as irrelevant to European data-protection history. Which correction best matches the BoK framing of Brexit?
- A university clinic asks whether updating Convention 108 to Convention 108+ changes only paperwork or also modernises protections. What is the sound takeaway?
- A civic tech NGO claims European data protection sprang only from consumer marketing scandals. Which historical framing is more accurate?
- A mayor’s office mixes up the European Commission and the European Council when asking who typically proposes EU legislation such as data-protection measures. Which assignment is correct?
- A city solicitor asks which body is the EU’s primary legislature that co-decides regulations such as the GDPR under the ordinary legislative procedure. Which answer is best?
- A human-rights clinic confuses the European Court of Human Rights with the Court of Justice of the European Union. Which distinction should trainers teach?
- A privacy trainee asks what the Council of Europe is if it is not an EU institution. Which explanation is accurate?
- A regional authority wants the court that interprets the GDPR as EU law and helps ensure its uniform application. Which court fills that role?
- A briefing deck labels the European Council as the day-to-day GDPR supervisor that investigates controllers. What correction is needed?
- A records manager thinks Directive 95/46/EC is still the primary EU personal-data statute for general processing. Which update should training deliver?
- A telecoms compliance lead asks why the ePrivacy Directive still matters after GDPR day one. What is the best explanation?
- A marketplace startup assumes the e-Commerce Directive alone answers all personal-data compliance questions. How should counsel respond?
- A museum digitisation project asks what the Council of Europe Convention 1981 contributed before EU directives. Which contribution is most accurate?
- A city CISO wonders whether NIS/NIS 2 belong in a European data-protection exam conversation. Which placement is correct for CIPP/E Domain I?
- An AI product owner asks how the EU AI Act relates to GDPR study for CIPP/E. What is the right framing?
- A council workshop asks for the GDPR’s main goals in one breath. Which statement captures the twin aims?
- A vendor claims the GDPR only applies to EU companies that keep servers inside the EU. Which response best corrects that myth at Domain I legislative-awareness level?
- A training deck says the ePrivacy Directive was repealed by the GDPR. What should replace that claim?
- A public body asks whether GDPR principles echo earlier Directive 95/46 themes. Which answer is most accurate?
- A logistics firm confuses the GDPR with a voluntary industry code of conduct. Which characterisation is correct?
- A civic open-data group asks why electronic commerce rules appear in a European privacy body of knowledge. Which explanation correctly places the e-Commerce Directive in the European data-protection legislative stack?
- A hospital privacy board wants the short name and official citation style for the GDPR. Which identification is correct?
- A border-town authority asks how national laws interacted with Directive 95/46/EC compared with the GDPR. Which contrast correctly describes the implementation model change?
- A smart-city vendor treats NIS 2 incident rules as identical to GDPR personal-data breach rules. Which statement correctly separates the regimes?
- A charity asks whether Convention 108 still matters after the GDPR. Which assessment is most accurate for CIPP/E framework understanding?
- A startup pitch says “GDPR equals cookie law.” Which correction should privacy counsel give?
- A regional parliament liaison asks which EU institution typically proposes updates to the European data-protection legislative stack. Which answer is correct?
- A university DPO asks what “related legislation” to the GDPR means for CIPP/E exam preparation. Which set correctly reflects BoK-named related European instruments rather than CIPP/US statutes?
- A ferry operator between Member States asks why free flow of personal data is treated as a GDPR goal. Which rationale matches the Regulation’s design?
- A municipal IT board assumes only GDPR principles matter and ignores earlier Convention language on automated processing. Which insight correctly connects that tradition to modern European data protection?
- A compliance intern asks whether the GDPR replaced the Charter right to protection of personal data. Which clarification is correct?
- A tourism board confuses “European data protection legislation principles” with ISO 27001 controls. Which response keeps the answer in the correct CIPP/E legal-principle space?
- A port authority asks why GDPR, ePrivacy, and NIS obligations can all apply to one operational incident. Which explanation is correct?
- A school district wonders whether Directive 95/46/EC case law still informs GDPR interpretation. Which statement is most accurate?
- A civic hackathon sponsor asks for the “principles and goals” headline of significant EU data-protection legislation. Which summary best captures that framework-level headline?