CIPP-E - European Data Protection Law and Regulation - Section 2.2

Know the key principles of lawful processing and understand the concepts of controller and processor, including EDPB guidelines and opinions on those roles.

Distinguish a data controller from a data processor and apply the six Article 5 GDPR processing principles, including the lawfulness principle, to real processing activities. Use EDPB guidelines to determine how responsibilities are allocated when multiple parties are involved.

data controllerdata processorEDPB guidelineslawfulness principle

Practice question for this objective

Free sampleEuropean Data Protection Law and Regulationmedium

The principle of lawfulness in Article 5(1)(a) GDPR requires that processing be lawful. In conceptual terms, what does this principle most directly demand of a controller?

  • AThat the controller keeps written records of processing activities and registers them with the supervisory authority before starting.
  • BThat each processing operation rests on at least one valid lawful basis set out in Article 6, and a further condition under Article 9 where special category data is involved. Correct
  • CThat the controller obtains the data subject's freely given consent before any personal data is processed.
  • DThat the controller processes the data only in ways the data subject would reasonably expect given the context of collection.
Lawfulness under Article 5(1)(a) requires every processing operation to rest on a valid Article 6 basis, plus an Article 9 condition for special category data. The lawfulness principle is given operational content by Article 6, which requires at least one of six lawful bases for any processing, and by Article 9, which demands an additional condition for special categories of data. Without such a basis the processing is unlawful regardless of how fairly or transparently it is carried out.

Why A is wrong: Record-keeping under Article 30 is an accountability measure and prior registration was a feature of the old Directive that the GDPR largely abolished. Neither is what the lawfulness principle itself requires, so this confuses a separate obligation with lawful grounding.

Why B is correct: Lawfulness means processing must be grounded in a legal basis. Article 5(1)(a) is operationalised through Article 6, which lists the six bases, and Article 9 adds a condition for special category data, so identifying a valid basis is the direct demand of the principle.

Why C is wrong: Consent is only one of the six lawful bases in Article 6, and is often not the most appropriate. Treating lawfulness as a consent-only requirement is a common error, since contract, legal obligation, vital interests, public task and legitimate interests are equally valid bases.

Why D is wrong: Reasonable expectation relates more closely to the fairness and purpose limitation principles than to lawfulness. It is a relevant consideration, but the lawfulness limb specifically requires an identifiable legal basis rather than a mere alignment with expectations.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all European Data Protection Law and Regulation objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.