CIPP-E - European Data Protection Law and Regulation (31% of the exam) - Section 2.1

Know the concepts of personal data, sensitive personal data, and special categories of personal data, and understand the concepts of pseudonymous and anonymous data and the differences between them.

Define personal data, special categories of personal data, pseudonymisation, and anonymisation as the GDPR uses those terms. Distinguish pseudonymised data, which remains personal data, from truly anonymised data, which falls outside the GDPR's scope.

personal dataspecial categoriespseudonymisationanonymisation

Practice question for this objective

Free sampleEuropean Data Protection Law and Regulationmedium

A human resources team is sorting the personal data it processes about employees into the correct GDPR regimes and must identify which items are special categories of personal data under Article 9(1), as distinct from data governed by other rules. Which two of the following items are special categories of personal data within the meaning of Article 9(1)? (Select TWO.)

  • AA note recording that an employee follows a strict religious dietary requirement at catered company events. Correct
  • BAn employee's bank account number and monthly salary figure held for payroll purposes.
  • CA fingerprint template generated and stored specifically to verify an employee's identity at a building entrance. Correct
  • DA record of an employee's spent and unspent criminal convictions gathered during a pre-employment safeguarding check.
  • EAn employee's home postal address and personal mobile number recorded in the staff contact directory.
Article 9(1) special categories include data revealing religious belief and biometric data used to identify a person, but exclude financial, contact and criminal-conviction data. Article 9(1) lists a closed set of special categories, including data revealing religious or philosophical beliefs and biometric data processed for the purpose of uniquely identifying a natural person. A dietary note that reveals religion and a fingerprint template used to identify staff both fall in that list. Financial and contact details are ordinary personal data not enumerated in Article 9. Criminal-conviction data is a frequent trap: it is sensitive but is regulated under Article 10, a distinct regime, rather than as an Article 9(1) special category.

Why A is correct: A record revealing religious belief is a special category under Article 9(1), even when captured incidentally through a dietary note.

Why B is wrong: Financial details are ordinary personal data; Article 9 does not list financial status, so this is a tempting but incorrect choice.

Why C is correct: Biometric data processed for the purpose of uniquely identifying a person is a special category under Article 9(1).

Why D is wrong: Criminal conviction data is governed by Article 10, a separate regime, not by the Article 9(1) special category list, so it does not belong in the set.

Why E is wrong: Contact details are ordinary identifying data and are not among the categories Article 9(1) singles out as sensitive.

See more CIPP-E practice questions, answers explained.

Exam traps in European Data Protection Law and Regulation

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • Pseudonymised data falls outside the GDPR in the same way as anonymous data, provided the key is held by a different team, so the institute has no further obligations.

    Why it is wrong: This is tempting because separating the key feels like a clean break, but the GDPR treats data as anonymous only when re-identification is no longer reasonably possible; while the key exists, the data is still personal data and in scope.

  • Both versions are anonymous and outside the GDPR, because in each case the working data on its own carries no names.

    Why it is wrong: This is tempting because neither working set displays names, but version one retains a key that permits re-identification, so it is pseudonymised and remains personal data rather than anonymous.

  • Anonymous data, because the names have been removed and replaced with random reference codes that do not reveal identity on their face.

    Why it is wrong: This is tempting because removing visible names feels like it breaks the link to a person, but the data remains pseudonymous: a mapping table still exists that allows re-identification, so the data is not anonymous and stays in scope of the GDPR.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.