CIPP-E - European Data Protection Law and Regulation (31% of the exam) - Section 2.6

Understand the concept of consent under the GDPR including the conditions for valid consent, the right of withdrawal, and restrictions on data subject rights.

Define the conditions for valid consent under the GDPR - freely given, specific, informed, and unambiguous - and recognise when bundled or pre-ticked consent fails them. Apply the Article 7 right of withdrawal to determine what a controller must do when consent is withdrawn and the limits restriction places on processing.

consentArticle 7 GDPRwithdrawal of consentfreely given consent

Practice question for this objective

Free sampleEuropean Data Protection Law and Regulationmedium

A health research platform wants to collect detailed data about users' diagnosed medical conditions and rely on consent under the GDPR to do so. Its lawyer notes that the consent standard for this category of data differs from the consent the platform uses for ordinary newsletter sign-ups. Which condition must the platform satisfy that does not apply to its ordinary newsletter consent?

  • AThe consent must be obtained in writing and physically signed, because special category data can only be processed on the basis of a signed paper record.
  • BThe consent must be renewed by the data subject every twelve months, because consent to process health data automatically expires after one year.
  • CThe consent must be approved by an accredited ethics committee before the platform may rely on it as a lawful basis.
  • DThe consent must be explicit, requiring a clear affirmative statement that specifically addresses the processing of the health data. Correct
Distinguish the explicit consent required for special category data under Article 9 from the unambiguous consent sufficient for ordinary data. Processing special category data such as health information on consent requires explicit consent under Article 9(2)(a). Explicit consent demands a clear affirmative statement targeting that processing, a stricter standard than the unambiguous indication that suffices for ordinary personal data.

Why A is wrong: Tempting because a signature feels more robust for sensitive data, but the GDPR does not mandate a handwritten or paper signature; explicit consent can be given electronically, so the writing-and-signature requirement is invented.

Why B is wrong: Tempting because periodic refresh is sometimes good practice, but the GDPR sets no fixed expiry period for consent; whether consent remains valid depends on context, not a hard annual deadline.

Why C is wrong: Tempting because health research is often associated with ethics review, but ethics committee approval is not a GDPR condition for the validity of consent; it may arise under separate research rules, not as a consent requirement under Article 9.

Why D is correct: Correct: Article 9(2)(a) requires explicit consent to process special category data such as health data, which is a higher bar than the unambiguous consent sufficient for ordinary personal data like a newsletter list.

See more CIPP-E practice questions, answers explained.

Exam traps in European Data Protection Law and Regulation

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • Freely given, explicit, documented and revocable

    Why it is wrong: This is tempting because consent must indeed be capable of withdrawal and explicit consent exists for special categories, but explicit and documented are not part of the general four-part definition; the standard is unambiguous, not explicit, for ordinary consent.

  • Erase every marketing email it has already sent and delete the personalised offers it generated while her consent was still valid, treating the past processing as if it had never been lawful.

    Why it is wrong: Article 7(3) states that withdrawal does not affect the lawfulness of processing carried out beforehand, so the retailer is not required to unwind or erase that prior processing.

  • No right to intervene, because a general written authorisation permanently waives any further controller involvement in sub-processor changes.

    Why it is wrong: Tempting because the authorisation is general rather than case-by-case, but Article 28(2) preserves the controller's ability to object; it is not a permanent waiver of involvement.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.