CIPP-E - European Data Protection: Scope and Accountability (17% of the exam) - Section 4.2

Understand the accountability requirements of controllers, joint controllers, and processors including data protection by design and by default, documentation requirements, and cooperation with regulators.

Describe the accountability obligations the GDPR places on controllers, joint controllers, and processors, including data protection by design and by default under Article 25 and Records of Processing Activities. Apply EDPB Opinion 22/2024 on reliance on processors and sub-processors to allocate responsibility along a chain of processing.

accountability principledata protection by designArticle 25 GDPRjoint controllersEDPB Opinion 22/2024

Practice question for this objective

Free sampleEuropean Data Protection: Scope and Accountabilityhard

A controller engages a SaaS payroll provider as its processor under an Article 28 contract that grants a general written authorisation to use sub-processors. The provider in turn engages a sub-processor in another Member State to run pension calculations, and that sub-processor uses a further hosting sub-processor of its own. The controller's privacy lead is mapping which accountability obligations genuinely apply along this processing chain. Drawing on Article 30, the EDPB Opinion 22/2024 on processors and sub-processors, and the accountability framework, which TWO statements correctly state an obligation that applies here? (Select TWO.)

  • ABecause the payroll provider employs fewer than 250 people, it is wholly exempt from keeping any record of the categories of processing it carries out for this controller.
  • BThe payroll provider, acting as processor, must maintain its own record of processing activities listing the categories of processing carried out on behalf of the controller. Correct
  • CBy engaging sub-processors in the chain, the payroll provider and its pension sub-processor become joint controllers who must agree an Article 26 arrangement.
  • DEven with a general authorisation, the controller stays responsible for ensuring sufficient guarantees exist throughout the chain, and the provider must impose equivalent data protection obligations on each sub-processor by contract. Correct
  • EEach sub-processor in the chain must contract its data protection obligations directly with the controller itself, bypassing the payroll provider that actually engaged it.
Along a processing chain, each processor keeps its own Article 30 record and flows down equivalent obligations, while the controller retains responsibility for verifying sufficient guarantees throughout. Article 30(2) obliges every processor to record the categories of processing it performs for each controller, and Article 28(4) read with EDPB Opinion 22/2024 makes the engaging processor impose equivalent obligations on each sub-processor while the controller keeps a residual duty to ensure sufficient guarantees exist throughout the chain. The strongest distractor, the 250-employee exemption, fails because that derogation does not cover regular, non-occasional processing such as payroll.

Why A is wrong: Tempting because the Article 30(5) derogation references 250 employees, but it does not apply where processing is regular rather than occasional, so a payroll processor must still keep a record.

Why B is correct: Article 30(2) requires each processor to keep a record of the categories of processing performed for every controller, so this is a genuine accountability obligation on the provider.

Why C is wrong: This confuses the chain with joint control, but the parties remain processor and sub-processor under Article 28 unless they jointly determine the purposes and means, which they do not here.

Why D is correct: Article 28(4) and EDPB Opinion 22/2024 confirm the controller's residual verification duty and the flow-down of equivalent obligations to every sub-processor along the chain.

Why E is wrong: This inverts Article 28(4): the engaging processor, not the controller, imposes the equivalent obligations on its sub-processor, so a direct controller contract is not what the chain requires.

See more CIPP-E practice questions, answers explained.

Exam traps in European Data Protection: Scope and Accountability

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • The requirement to carry out a data protection impact assessment whenever a service makes profiles searchable by third parties

    Why it is wrong: A DPIA may be advisable for large-scale profiling, but that duty sits in Article 35 and addresses risk assessment, not the default settings of the product; it is the wrong obligation for the by-default complaint.

  • Purpose limitation permits collecting data for unspecified future features provided the controller documents a general business interest before any later use of that data.

    Why it is wrong: This is tempting because purpose limitation is genuinely engaged, but it misstates the rule: Article 5(1)(b) requires specified, explicit purposes determined at collection, not a deferred general business interest.

  • Accountability is satisfied so long as the marketplace can later prove compliance in court, so it may decline the authority's documentation request until litigation begins.

    Why it is wrong: This is tempting because accountability is about demonstrating compliance, but it ignores the separate Article 31 duty to cooperate with the authority and the access powers in Article 58, neither of which waits for litigation.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.