CIPP-E - Compliance with European Data Protection Law and Regulation (16% of the exam) - Section 5.4

Understand the compliance issues related to cloud computing, web cookies, social media dark patterns, search engine marketing, and the ethical and compliance issues related to artificial intelligence and machine learning.

Recognise the GDPR and EDPB cookie guidelines obligations for web cookie consent, the compliance risks of dark patterns in consent UIs, and the contractual and security requirements when using cloud computing providers. Understand the ethical and regulatory considerations that arise when deploying artificial intelligence and machine learning systems that process personal data.

cookiescloud computingdark patternsAI complianceEDPB cookie guidelines

Practice question for this objective

Free sampleCompliance with European Data Protection Law and Regulationhard

A privately owned shopping centre installs a network of CCTV cameras across its car park and entrance halls to deter theft and vandalism. The operator does not seek consent from visitors and instead relies on its legitimate interests. Reviewing the deployment against the EDPB guidelines on processing personal data through video devices, the data protection officer wants to confirm what the legitimate-interests route specifically requires the operator to demonstrate before it can lawfully film these areas. Which requirement most accurately reflects what those guidelines demand?

  • AExplicit written consent from a representative sample of regular visitors, taken as evidence that the wider public accepts the cameras
  • BA genuine, real and present security interest evidenced by documented incidents or risks, with the surveillance being necessary and not outweighed by the visitors' rights Correct
  • CA formal authorisation issued by the competent supervisory authority approving the camera locations before any footage is captured
  • DProof that filming is the only conceivable measure available, ruling out lighting, locks, alarms or any alternative security control whatsoever
Legitimate interests for CCTV under the EDPB video guidelines require a real and present interest plus a necessity and balancing test, not consent or prior regulatory approval. The EDPB guidelines on processing personal data through video devices reject purely hypothetical risks: the controller must point to an actual, documented security interest, show the surveillance is necessary to achieve it, and confirm that the data subjects' rights and freedoms do not override that interest under the Article 6(1)(f) balancing test.

Why A is wrong: Tempting because consent is one lawful basis, but the operator has chosen legitimate interests, and sampled or proxy consent is not a recognised mechanism; valid consent under the GDPR must be specific to each data subject and freely given.

Why B is correct: Correct: the EDPB video guidelines treat purely hypothetical or speculative security concerns as insufficient and require a real and present interest, plus a necessity and balancing assessment, before legitimate interests under Article 6(1)(f) can support CCTV.

Why C is wrong: Tempting because surveillance feels like something a regulator should pre-approve, but the GDPR does not require prior authorisation from a supervisory authority for ordinary CCTV; the controller assesses its own lawful basis under the accountability principle.

Why D is wrong: Tempting because necessity does require considering less intrusive options, but the standard is whether the interest can reasonably be achieved by other equally effective means, not an absolute proof that no alternative of any kind exists.

See more CIPP-E practice questions, answers explained.

Exam traps in Compliance with European Data Protection Law and Regulation

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • The employer may remotely wipe the entire device at any time without notice, because once a personal device touches corporate data the employer becomes the sole controller of all data on it.

    Why it is wrong: Tempting because the employer does control the corporate data, but it does not become controller of the employee's purely personal files; a blanket full wipe is disproportionate and ignores the data minimisation and proportionality principles.

  • Erase the subscriber's personal data in full, because an objection to direct marketing triggers an absolute right to erasure of the entire customer record.

    Why it is wrong: Erasure is a related right and feels decisive, but the objection is to marketing only; the controller still needs the data for the live contract, so full erasure is neither required nor appropriate here.

  • Both categories are permitted subject to a conformity assessment, but only the social-scoring system additionally requires a data protection impact assessment under the GDPR

    Why it is wrong: This wrongly treats social scoring as a permitted high-risk use; the Act bans it outright, so no conformity assessment can make the prohibited practice lawful.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.