CIPP-E - Compliance with European Data Protection Law and Regulation - Section 5.3

Understand the compliance requirements for processing personal data for marketing activities and the rules for online behavioural targeting, including EDPB guidelines.

Describe the rules governing direct marketing under the GDPR and the ePrivacy Directive, including the opt-out right for existing customers and consent requirements for new contacts. Apply EDPB guidelines on behavioural targeting to evaluate whether a personalised advertising programme is compliant.

direct marketingbehavioural targetingePrivacy Directiveopt-out

Practice question for this objective

Free sampleCompliance with European Data Protection Law and Regulationmedium

A mobile gaming company collects players' phone numbers during account registration to support two-factor login. A year later, its marketing team begins sending the same players unsolicited SMS messages advertising in-app purchases, without asking whether they wish to receive marketing texts and without offering any way to refuse in the messages. The company assumes that because the players are existing account holders, no further step is needed. Under the ePrivacy regime governing electronic marketing, what is the principal compliance failure here?

  • ASending marketing SMS without prior consent and without offering a simple means to refuse in each message breaches the ePrivacy rules on unsolicited electronic communications. Correct
  • BMarketing by SMS to these players is unlawful only if a national supervisory authority has separately registered each recipient on a do-not-contact list before the messages are sent.
  • CThere is no failure, because collecting the numbers for two-factor login automatically authorises their later use for any related commercial purpose the company chooses.
  • DThe only breach is the failure to carry out a data protection impact assessment before sending the marketing texts, which would have legitimised the campaign.
Apply the ePrivacy rules requiring consent and an opt-out for marketing SMS, and recognise that data collected for security cannot be silently repurposed for marketing. SMS is electronic marketing under the ePrivacy Directive, so it requires prior consent or a narrow existing-customer relationship, and in every case an easy means to refuse must be offered in each message; reusing security data for unconsented marketing also breaches purpose limitation.

Why A is correct: Correct: the ePrivacy Directive treats SMS as electronic marketing requiring consent, and even where a limited existing-customer exception could apply the controller must offer an easy opt-out in every message, which the company failed to provide.

Why B is wrong: Wrong because the lawfulness of marketing SMS does not depend on prior registration of recipients on an authority-held list; the ePrivacy rules require consent or a qualifying existing-customer relationship plus an opt-out, neither met here.

Why C is wrong: Tempting because the numbers were lawfully collected, but a number gathered for authentication may not be repurposed for unconsented marketing; the original security purpose does not extend to marketing SMS.

Why D is wrong: Wrong because a DPIA is not what legitimises a marketing channel; the governing requirement is the ePrivacy consent and opt-out rule for unsolicited electronic communications, which the campaign ignored.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all Compliance with European Data Protection Law and Regulation objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.