CIPP-E - Compliance with European Data Protection Law and Regulation - Section 5.2

Understand the compliance issues related to surveillance by public authorities, interception of communications, CCTV, geolocation, and biometrics/facial recognition, including EDPB guidelines.

Understand the GDPR and ePrivacy obligations that apply to public-authority surveillance, interception of communications, CCTV, geolocation tracking, and biometric and facial recognition systems. Apply EDPB guidelines to assess whether a proposed surveillance activity is proportionate and identify what safeguards are required.

CCTVbiometricsgeolocationinterception of communicationsfacial recognition

Practice question for this objective

Free sampleCompliance with European Data Protection Law and Regulationhard

A city transport authority plans to deploy live facial recognition at a busy metro interchange. Cameras will capture the face of every passing commuter, convert each face into a biometric template, and match it in real time against a watchlist of persons sought by police, so that the overwhelming majority of those scanned are uninvolved members of the public. The authority concedes the templates are used to uniquely identify individuals. Applying the GDPR and the EDPB guidelines on video devices and on proportionality, which TWO steps must the authority take before it may lawfully launch this processing? (Select TWO.)

  • ACarry out a data protection impact assessment and, where the assessment shows a residual high risk that cannot be mitigated, consult the competent supervisory authority before starting the processing. Correct
  • BIdentify a condition under Article 9(2) GDPR, supported by Union or Member State law providing suitable safeguards, because the facial templates are special category biometric data. Correct
  • CDocument a legitimate interests assessment under Article 6(1)(f) GDPR, which on its own authorises the biometric matching once the authority shows its security interest outweighs commuter privacy.
  • DOffer every scanned commuter the right to data portability under Article 20 GDPR so they can receive and reuse the biometric template generated from their face.
  • EAppoint a representative in the Union under Article 27 GDPR before the cameras begin capturing and matching the biometric data of commuters at the interchange.
Live facial recognition of the public requires both an Article 9(2) condition grounded in law and a DPIA with prior consultation where residual high risk remains. Real-time facial recognition turns each passing face into a biometric template used to uniquely identify people, which is Article 9 special category data, so the authority must find an Article 9(2) condition backed by Union or Member State law rather than rely on an Article 6 basis alone. Because the processing is systematic large-scale monitoring of a publicly accessible area, an Article 35 DPIA is mandatory and Article 36 prior consultation follows where residual high risk persists. Legitimate interests fails because a public authority cannot use it for its tasks and it cannot lift the Article 9 prohibition.

Why A is correct: Systematic large-scale monitoring of a publicly accessible area triggers a mandatory Article 35 DPIA, and Article 36 requires prior consultation where residual high risk remains, so this step is genuinely required.

Why B is correct: Templates used to uniquely identify a person are biometric special category data, so an Article 6 basis alone is insufficient and an Article 9(2) exception backed by law is required before processing.

Why C is wrong: Legitimate interests is tempting because ordinary CCTV often relies on it, but a public authority cannot use it for its tasks and it never lifts the Article 9 prohibition on biometric data, so it is insufficient here.

Why D is wrong: Portability under Article 20 applies only to data the subject provided under consent or contract and is irrelevant to watchlist matching, so invoking it confuses an unrelated data subject right with the required safeguards.

Why E is wrong: Article 27 applies to controllers without an EU establishment caught by the targeting or monitoring criteria, not to a domestic public authority already established in the Union, so it is the wrong obligation.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all Compliance with European Data Protection Law and Regulation objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.