CIPP-E - European Data Processing (23% of the exam) - Section 3.5

Understand the rationale for restricting international data transfers, know the concept of adequate jurisdiction, understand Standard Contractual Clauses, Binding Corporate Rules, the EU-US Data Privacy Framework, and the role of transfer impact assessments.

Compare the available mechanisms for transferring personal data outside the EEA - adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, and the EU-US Data Privacy Framework - and explain the impact of the Schrems II ruling on reliance on them. Apply a transfer impact assessment to determine whether supplementary measures are needed before a transfer proceeds.

Standard Contractual ClausesBinding Corporate RulesEU-US Data Privacy FrameworkSchrems IItransfer impact assessment

Practice question for this objective

Free sampleEuropean Data Processinghard

Conceptually, what is the purpose of a transfer impact assessment carried out before relying on an Article 46 safeguard such as Standard Contractual Clauses?

  • ATo confirm that the data exporter has paid the registration fee required by the supervisory authority before any international transfer takes place.
  • BTo document the commercial value of the data being exported so that the importer can price its services accordingly.
  • CTo obtain the data subject's explicit consent to the specific transfer as the primary lawful basis for exporting the data.
  • DTo assess whether the chosen safeguard will be effective in light of the destination country's laws and practices, and whether supplementary measures are needed. Correct
A transfer impact assessment evaluates whether an Article 46 safeguard is effective given the destination's laws and whether supplementary measures are required. After Schrems II the exporter cannot rely on a transfer tool mechanically; the assessment examines the third country's law and practice, especially government access, to decide whether the safeguard delivers essentially equivalent protection or needs supplementary measures.

Why A is wrong: There is no such registration-fee step gating transfers, so this invents a procedural requirement and misses the substantive purpose of evaluating the destination's legal protection.

Why B is wrong: A transfer impact assessment is a protection exercise, not a commercial valuation, so framing it around pricing the importer's services misunderstands its function entirely.

Why C is wrong: Explicit consent is a separate Article 49 derogation, not the aim of a transfer impact assessment, which evaluates the effectiveness of the safeguard rather than collecting consent.

Why D is correct: Following Schrems II and the EDPB recommendations, the exporter must evaluate whether the third country's law and practice, particularly public-authority access, would undermine the Article 46 safeguard, and identify supplementary measures where it would.

See more CIPP-E practice questions, answers explained.

Exam traps in European Data Processing

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • The US importer must hold ISO 27001 certification, because the Framework recognises that standard as proof of adequate technical protection.

    Why it is wrong: Security certification is good practice but is not the qualifying condition; the Framework turns on self-certification and Commerce Department listing, not ISO 27001.

  • The commercial value of the contract between the exporter and importer, because higher-value relationships justify accepting greater legal risk.

    Why it is wrong: Commercial value is irrelevant to the level of protection for data subjects, so it cannot weigh in a transfer impact assessment focused on essential equivalence.

  • Once data has lawfully arrived under the Framework, the certified organisation may share it onward freely, because the Framework governs only the initial transfer out of the EEA

    Why it is wrong: This is tempting because the Framework's transfer basis concerns the EEA-to-US movement, but it ignores the Framework's Accountability for Onward Transfer principle, which constrains what the certified organisation may do with the data afterwards.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.