CIPP-E - Compliance with European Data Protection Law and Regulation - Section 5.4

Understand the compliance issues related to cloud computing, web cookies, social media dark patterns, search engine marketing, and the ethical and compliance issues related to artificial intelligence and machine learning.

Recognise the GDPR and EDPB cookie guidelines obligations for web cookie consent, the compliance risks of dark patterns in consent UIs, and the contractual and security requirements when using cloud computing providers. Understand the ethical and regulatory considerations that arise when deploying artificial intelligence and machine learning systems that process personal data.

cookiescloud computingdark patternsAI complianceEDPB cookie guidelines

Practice question for this objective

Free sampleCompliance with European Data Protection Law and Regulationhard

A privately owned shopping centre installs a network of CCTV cameras across its car park and entrance halls to deter theft and vandalism. The operator does not seek consent from visitors and instead relies on its legitimate interests. Reviewing the deployment against the EDPB guidelines on processing personal data through video devices, the data protection officer wants to confirm what the legitimate-interests route specifically requires the operator to demonstrate before it can lawfully film these areas. Which requirement most accurately reflects what those guidelines demand?

  • AExplicit written consent from a representative sample of regular visitors, taken as evidence that the wider public accepts the cameras
  • BA genuine, real and present security interest evidenced by documented incidents or risks, with the surveillance being necessary and not outweighed by the visitors' rights Correct
  • CA formal authorisation issued by the competent supervisory authority approving the camera locations before any footage is captured
  • DProof that filming is the only conceivable measure available, ruling out lighting, locks, alarms or any alternative security control whatsoever
Legitimate interests for CCTV under the EDPB video guidelines require a real and present interest plus a necessity and balancing test, not consent or prior regulatory approval. The EDPB guidelines on processing personal data through video devices reject purely hypothetical risks: the controller must point to an actual, documented security interest, show the surveillance is necessary to achieve it, and confirm that the data subjects' rights and freedoms do not override that interest under the Article 6(1)(f) balancing test.

Why A is wrong: Tempting because consent is one lawful basis, but the operator has chosen legitimate interests, and sampled or proxy consent is not a recognised mechanism; valid consent under the GDPR must be specific to each data subject and freely given.

Why B is correct: Correct: the EDPB video guidelines treat purely hypothetical or speculative security concerns as insufficient and require a real and present interest, plus a necessity and balancing assessment, before legitimate interests under Article 6(1)(f) can support CCTV.

Why C is wrong: Tempting because surveillance feels like something a regulator should pre-approve, but the GDPR does not require prior authorisation from a supervisory authority for ordinary CCTV; the controller assesses its own lawful basis under the accountability principle.

Why D is wrong: Tempting because necessity does require considering less intrusive options, but the standard is whether the interest can reasonably be achieved by other equally effective means, not an absolute proof that no alternative of any kind exists.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all Compliance with European Data Protection Law and Regulation objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.