IAPP

Certified Information Privacy Professional/Europe (CIPP/E) practice questions

Master European data protection law and GDPR compliance for the IAPP CIPP/E certification.

New to CIPP-E? Read the how to pass Certified Information Privacy Professional/Europe (CIPP/E) study guide for a domain breakdown, a study plan, and exam-day tips.

Revising? The CIPP-E cheat sheet puts the domain weightings, key facts, and easy-to-confuse traps on one printable page.

Prefer flashcards? See a free sample of the CIPP-E flashcard deck, concept and misconception cards side by side.

90
Questions
150 min
Time allowed
300 / 500
Pass mark
$550
Exam cost (USD)
322
Practice questions

Exam domains and weighting

The CIPP-E blueprint is split across 5 domains. See the official exam guide for the authoritative breakdown.

CIPP-E exam domain weighting - each domain's share of the exam. Full breakdown with links below.
CIPP-E domains by share of the exam
DomainWeight
Introduction to European Data Protection13%
European Data Protection Law and Regulation31%
European Data Processing23%
European Data Protection: Scope and Accountability17%
Compliance with European Data Protection Law and Regulation16%

Free sample questions

No account needed. Every question has a worked explanation, just like the full bank.

Free sampleEuropean Data Protection Law and Regulationhard

A bank uses a fully automated model to decide whether to grant unsecured personal loans, with no human involvement before the decision is communicated to the applicant. A rejected applicant asks to understand and contest the outcome. The bank relies on this automated process because it is necessary for entering into the loan contract the applicant requested. Which safeguard must the bank provide to comply with the rules on solely automated decisions producing legal or similarly significant effects?

  • AIt must implement, at minimum, the right to obtain human intervention, to express the applicant's point of view, and to contest the decision. Correct
  • BIt must obtain fresh explicit consent from the applicant before the automated decision can be relied upon, regardless of the contractual necessity.
  • CIt must disclose the full source code and weights of the scoring model so the applicant can independently reproduce the decision.
  • DIt must escalate every rejected application to the supervisory authority for prior review before the decision becomes final.
Solely automated decisions with significant effects taken on contractual necessity require safeguards of human intervention, expression of view, and the right to contest. Where a solely automated decision with legal or similarly significant effects is permitted because it is necessary for a contract, the controller must implement suitable safeguards, expressly including the data subject's right to obtain human intervention, to express their point of view, and to contest the decision, rather than fresh consent or authority pre-approval.

Why A is correct: Correct: for solely automated decisions with legal or similarly significant effects based on contractual necessity, the controller must put in place suitable measures including at least the right to human intervention, to express a point of view, and to contest the decision.

Why B is wrong: This is tempting because consent is one possible basis, but where the automated decision is necessary for entering into a contract the rules permit it without separate explicit consent, provided suitable safeguards are in place.

Why C is wrong: This overstates the transparency duty: the applicant is owed meaningful information about the logic involved, not the entire source code and weights, which would expose disproportionate detail and is not required.

Why D is wrong: This confuses safeguards with supervision: there is no requirement to send each rejection to the authority for prior review, and the duty is to provide internal safeguards such as human intervention and the right to contest.

Free sampleEuropean Data Protection: Scope and Accountabilitymedium

A national supervisory authority is preparing to adopt a list of processing operations that require a data protection impact assessment in its territory. Before the list takes effect, the authority is required to engage a Union-level mechanism. Which body must it involve, and for what purpose?

  • AThe European Commission, which must approve the list as an implementing measure before it can be applied nationally.
  • BThe European Data Protection Board, which issues an opinion under the consistency mechanism to promote a harmonised approach across authorities. Correct
  • CThe European Data Protection Supervisor, which reviews the list because DPIA obligations originate in the rules governing EU institutions.
  • DThe Court of Justice of the European Union, which validates the list to ensure it complies with the Charter of Fundamental Rights.
Recognise that national DPIA lists go to the EDPB for a consistency opinion to harmonise practice across supervisory authorities. The consistency mechanism requires national authorities to communicate certain measures, including lists of processing requiring a DPIA, to the EDPB. The Board issues an opinion so that comparable processing is treated consistently across Member States, reflecting the EDPB's harmonising mandate rather than approval by the Commission or a court.

Why A is wrong: Tempting because the Commission adopts implementing acts elsewhere in the GDPR, but DPIA lists are communicated to the EDPB for consistency, not submitted to the Commission for approval.

Why B is correct: Correct: lists of processing requiring a DPIA are subject to the consistency mechanism, so the authority communicates the list to the EDPB, which gives an opinion to keep such lists consistent across the Union.

Why C is wrong: Tempting because the EDPS works on data protection at Union level, but it supervises EU institutions and does not review national authorities' DPIA lists, which fall under the EDPB's consistency role.

Why D is wrong: Tempting because the Charter underpins data protection, but the CJEU does not pre-clear administrative lists; consistency review of DPIA lists is an EDPB function under the cooperation framework.

Free sampleIntroduction to European Data Protectionmedium

A Berlin-based SaaS company processes employee and customer personal data and is mapping which EU instruments govern its activities. Its compliance lead notes that one instrument sets out the general, cross-sector rules for processing personal data, while the others address narrower fields such as electronic communications confidentiality and the cybersecurity of essential services. Which instrument provides the general legal framework for the processing of personal data across all sectors in the EU?

  • AThe ePrivacy Directive 2002/58/EC, which sets the baseline rules for processing personal data across sectors
  • BThe NIS 2 Directive, which sets the baseline rules for processing personal data across sectors
  • CThe EU Artificial Intelligence Act, which sets the baseline rules for processing personal data across sectors
  • DRegulation (EU) 2016/679, the General Data Protection Regulation, which sets the baseline rules for processing personal data across sectors Correct
Identify the GDPR as the general cross-sector framework for processing personal data, distinct from sector-specific EU instruments. The GDPR is a directly applicable regulation that establishes the general rules for processing personal data in every sector, while ePrivacy, NIS 2, and the AI Act each address a narrower subject area and supplement the GDPR rather than displace it.

Why A is wrong: The ePrivacy Directive is tempting because it does protect personal data, but it is sector-specific to electronic communications and confidentiality of communications, not the general framework.

Why B is wrong: NIS 2 is tempting because it imposes broad obligations on many entities, but it governs cybersecurity risk management and incident reporting, not the general rules for processing personal data.

Why C is wrong: The AI Act is tempting because it is a recent EU-wide regulation, but it regulates the placing on the market and use of AI systems by risk tier, not personal data processing generally.

Why D is correct: The GDPR is the general, directly applicable instrument governing the processing of personal data across all sectors in the EU, and the other instruments supplement rather than replace it.

More free CIPP-E practice questions with worked answers

Frequently asked questions

How many questions are on the CIPP-E exam?
The Certified Information Privacy Professional/Europe (CIPP/E) exam has 90 questions and runs for 150 minutes. The format is multiple choice, online proctored (pearson vue) or in-person test centre.
What score do I need to pass CIPP-E?
The pass mark is 300 / 500. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
How much does the CIPP-E exam cost?
The exam costs 550 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
Is there a CIPP-E practice exam?
Yes. Examworthy's exam mode runs a timed CIPP-E practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand against the blueprint. Timed mocks are free with an account.
How does Examworthy help me prepare for CIPP-E?
Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
Is Examworthy affiliated with IAPP?
No. Examworthy is not affiliated with or endorsed by IAPP. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.

Related certifications

More certifications you can practise on Examworthy, related to Certified Information Privacy Professional/Europe (CIPP/E).

Browse all certifications

Examworthy is not affiliated with or endorsed by IAPP. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIPP-E and related marks belong to their respective owners.