CIPP-E - Compliance with European Data Protection Law and Regulation (16% of the exam) - Section 5.3

Understand the compliance requirements for processing personal data for marketing activities and the rules for online behavioural targeting, including EDPB guidelines.

Describe the rules governing direct marketing under the GDPR and the ePrivacy Directive, including the opt-out right for existing customers and consent requirements for new contacts. Apply EDPB guidelines on behavioural targeting to evaluate whether a personalised advertising programme is compliant.

direct marketingbehavioural targetingePrivacy Directiveopt-out

Practice question for this objective

Free sampleCompliance with European Data Protection Law and Regulationmedium

A mobile gaming company collects players' phone numbers during account registration to support two-factor login. A year later, its marketing team begins sending the same players unsolicited SMS messages advertising in-app purchases, without asking whether they wish to receive marketing texts and without offering any way to refuse in the messages. The company assumes that because the players are existing account holders, no further step is needed. Under the ePrivacy regime governing electronic marketing, what is the principal compliance failure here?

  • ASending marketing SMS without prior consent and without offering a simple means to refuse in each message breaches the ePrivacy rules on unsolicited electronic communications. Correct
  • BMarketing by SMS to these players is unlawful only if a national supervisory authority has separately registered each recipient on a do-not-contact list before the messages are sent.
  • CThere is no failure, because collecting the numbers for two-factor login automatically authorises their later use for any related commercial purpose the company chooses.
  • DThe only breach is the failure to carry out a data protection impact assessment before sending the marketing texts, which would have legitimised the campaign.
Apply the ePrivacy rules requiring consent and an opt-out for marketing SMS, and recognise that data collected for security cannot be silently repurposed for marketing. SMS is electronic marketing under the ePrivacy Directive, so it requires prior consent or a narrow existing-customer relationship, and in every case an easy means to refuse must be offered in each message; reusing security data for unconsented marketing also breaches purpose limitation.

Why A is correct: Correct: the ePrivacy Directive treats SMS as electronic marketing requiring consent, and even where a limited existing-customer exception could apply the controller must offer an easy opt-out in every message, which the company failed to provide.

Why B is wrong: Wrong because the lawfulness of marketing SMS does not depend on prior registration of recipients on an authority-held list; the ePrivacy rules require consent or a qualifying existing-customer relationship plus an opt-out, neither met here.

Why C is wrong: Tempting because the numbers were lawfully collected, but a number gathered for authentication may not be repurposed for unconsented marketing; the original security purpose does not extend to marketing SMS.

Why D is wrong: Wrong because a DPIA is not what legitimises a marketing channel; the governing requirement is the ePrivacy consent and opt-out rule for unsolicited electronic communications, which the campaign ignored.

See more CIPP-E practice questions, answers explained.

Exam traps in Compliance with European Data Protection Law and Regulation

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • The objection takes effect only after the controller has confirmed that no compelling legitimate grounds override the data subject's interests in stopping the marketing.

    Why it is wrong: Tempting because that balancing test exists for the general right to object under Article 21(1), but Article 21(2) and (3) deliberately remove any such balancing for direct marketing, making the objection unconditional.

  • The retailer may continue marketing to her if its documented balancing test shows that its legitimate interests still outweigh her objection in this particular case.

    Why it is wrong: Tempting because balancing tests apply when first establishing legitimate interests, but once a data subject objects specifically to direct marketing the controller has no further balancing discretion and must stop.

  • Behavioural advertising is automated decision-making with legal effects under Article 22 GDPR, so it is prohibited unless one of the narrow exceptions in that article applies.

    Why it is wrong: Tempting because profiling is involved, but serving targeted ads does not usually produce legal or similarly significant effects, so Article 22 is not the governing obstacle; the device-access consent rule is.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.