CIPP-E - European Data Protection Law and Regulation (31% of the exam) - Section 2.3

Understand what appropriate technical and organisational measures are, including encryption and access controls, and know the requirements for breach notification under the GDPR and EDPB guidelines.

Describe the technical and organisational measures required under Article 32 GDPR, including encryption and access controls, as proportionate responses to processing risk. Apply the breach notification timelines and thresholds set by the GDPR and EDPB guidelines to decide when to notify a supervisory authority or affected individuals.

encryptionaccess controlsbreach notificationArticle 32 GDPR

Practice question for this objective

Free sampleEuropean Data Protection Law and Regulationmedium

A controller confirms on a Monday morning that an attacker copied a file containing the names and bank details of several thousand customers, and assesses the incident as likely to result in a high risk to those individuals. The security team is still establishing the full scope of the records affected. Which statements correctly describe the controller's breach-notification obligations under the GDPR and EDPB guidelines? (Select TWO.)

  • ABecause the full scope is not yet known, the controller may delay all notification until its investigation is complete and the exact number of affected records is confirmed.
  • BThe controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Correct
  • CNotifying the supervisory authority within 72 hours automatically discharges any duty owed to the affected individuals, who need not be separately contacted.
  • DIf notification to the supervisory authority is made after 72 hours, the controller may submit it without any explanation, since the deadline is merely advisory.
  • EBecause the breach is likely to result in a high risk to individuals, the controller must also communicate the breach to the affected data subjects without undue delay. Correct
Distinguish the 72-hour supervisory-authority notification under Article 33 from the high-risk communication to individuals under Article 34 as separate breach duties. Article 33 sets a without-undue-delay, where-feasible-within-72-hours duty to notify the regulator, with phased notification permitted and reasons required for any delay. Article 34 imposes a separate duty to communicate to individuals only where the breach is likely to result in a high risk, so meeting one duty does not discharge the other.

Why A is wrong: This is tempting because complete information seems preferable, but it is wrong: Article 33(4) allows information to be provided in phases, so the controller must still notify on time and supply further detail later rather than wait for a finished investigation.

Why B is correct: Correct: Article 33(1) requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of the controller becoming aware, which is the headline timeline for the regulator notification.

Why C is wrong: This conflates two distinct duties: Article 33 notification to the authority and Article 34 communication to individuals are separate obligations with different thresholds, so notifying the regulator does not remove the high-risk duty to inform data subjects.

Why D is wrong: This is wrong because Article 33(1) requires that a notification not made within 72 hours be accompanied by reasons for the delay, so a late notification must be justified rather than treated as optional timing.

Why E is correct: Correct: Article 34(1) requires communication to affected individuals without undue delay where a breach is likely to result in a high risk, and the high-risk assessment here triggers that separate duty alongside the regulator notification.

See more CIPP-E practice questions, answers explained.

Exam traps in European Data Protection Law and Regulation

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • To obtain the prior written authorisation of the lead supervisory authority before appointing any external cloud processor.

    Why it is wrong: Tempting because supervisory authorities oversee processing, but Article 28 requires no prior authorisation to appoint a processor; the controller selects and remains accountable itself.

  • It removes the obligation to notify the supervisory authority, but the controller must still communicate the breach directly to every affected individual.

    Why it is wrong: This inverts the rule: the supervisory-authority test in Article 33 turns on risk generally, while encryption most directly affects whether the data is intelligible and therefore whether the high-risk individual-communication duty under Article 34 is triggered.

  • The controller satisfies its obligations once it has notified the supervisory authority, which then decides whether to inform the public on the controller's behalf

    Why it is wrong: Authority notification under Article 33 does not discharge the separate Article 34 duty to the individuals, and the supervisory authority does not assume responsibility for informing affected customers in the controller's place.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.