CIPP-E - European Data Protection Law and Regulation - Section 2.5

Understand the full suite of data subject rights under the GDPR: access, rectification, erasure/right to be forgotten, restriction, objection, data portability, and rights related to automated decision-making including profiling.

Define each GDPR data subject right - access, rectification, erasure, restriction, objection, portability, and rights related to automated decision-making and profiling - including the conditions and exemptions that apply. Choose the correct response procedure and deadline for a given subject rights request, using EDPB guidelines where applicable.

right of accessright to erasuredata portabilityautomated decision-makingEDPB guidelines

Practice question for this objective

Free sampleEuropean Data Protection Law and Regulationhard

A music streaming service receives a data portability request from a subscriber who wants to take her listening history and the playlists she created to a competitor. Her account also contains play-count statistics the service generated by analysing her behaviour to power its recommendation algorithm, plus billing records the service keeps to meet tax law. The subscriber's account is provided under a contract she agreed to. Which data is the service required to provide under the right to data portability?

  • AThe listening history and playlists she actively provided, but not the inferred play-count analytics the service derived, nor the billing records retained under a legal obligation. Correct
  • BAll personal data the service holds about her, including the inferred analytics and the billing records, because portability extends to every category of data linked to her account.
  • COnly the playlists she manually typed in, because portability covers data the subject consciously enters and never the listening history observed through her use of the service.
  • DThe listening history, playlists, and inferred analytics, but not the billing records, because portability includes any data generated about the user except records kept for legal compliance.
Data portability covers data the subject provided, including observed activity, but excludes inferred or derived data and data not based on consent or contract. Article 20(1) applies only to personal data the data subject provided, processed by automated means on a consent or contract basis; the EDPB treats actively given and observed data as provided, but inferred or derived data created by the controller, and data held under a legal obligation, fall outside the right.

Why A is correct: Correct. Article 20 covers personal data the data subject has provided, processed by automated means on the basis of consent or contract; this includes data she actively gave and observed activity, but EDPB guidance excludes inferred or derived data, and records held under a legal obligation fall outside the contract or consent basis required by Article 20(1).

Why B is wrong: This is too broad; Article 20 is limited to data provided by the data subject and processed on consent or contract, so inferred analytics and legally mandated billing records are outside its scope.

Why C is wrong: This is too narrow; EDPB guidance treats data observed from the use of a service, such as listening history, as data provided by the data subject, so it is portable alongside manually entered playlists.

Why D is wrong: Including the inferred analytics is the error; data the controller creates by its own analysis is derived data that the EDPB excludes from portability, even though excluding the billing records is correct.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all European Data Protection Law and Regulation objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.