CIPP-E - European Data Protection: Scope and Accountability (17% of the exam) - Section 4.1

Understand what constitutes establishment and non-establishment in the EU and know the GDPR's scope of processing and the exemptions it allows, including EDPB guidelines on territorial scope.

Understand the Article 3 GDPR establishment test and the targeting criterion for non-EU organisations, and distinguish the processing activities each limb covers. Apply EDPB guidelines on territorial scope to determine whether a given controller or processor must comply with the GDPR.

Article 3 GDPRterritorial scopeestablishmenttargeting criterion

Practice question for this objective

Free sampleEuropean Data Protection: Scope and Accountabilityhard

A controller signs a processing agreement that gives its processor a general written authorisation to engage sub-processors. The processor later adds two sub-processors deep in its supply chain. The controller's compliance team, mindful of recent EDPB guidance on controller and processor obligations along a processing chain, asks what the controller itself must still do despite having granted the general authorisation. Which obligation continues to rest on the controller?

  • ANothing further, because a general written authorisation transfers full responsibility for vetting every sub-processor onto the lead processor alone
  • BPersonally negotiate and sign a separate Article 28 contract directly with each sub-processor before that sub-processor may begin work
  • CNotify the lead supervisory authority of each new sub-processor and obtain its prior approval before processing may continue
  • DVerify that sufficient guarantees are provided throughout the chain and be able to demonstrate it, retaining the means to obtain information about the sub-processors engaged Correct
Even under a general sub-processor authorisation, the controller retains an Article 28(1) duty to ensure and demonstrate sufficient guarantees throughout the processing chain. EDPB Opinion 22/2024 clarifies that a controller's accountability for choosing processors that provide sufficient guarantees does not stop at the first processor. The controller remains responsible across the sub-processing chain, must be able to verify those guarantees, and should retain the practical ability to obtain information about which sub-processors are engaged, so it can demonstrate compliance with Article 28(1).

Why A is wrong: This is the common misreading the guidance warns against; a general authorisation lets the processor add sub-processors without case-by-case sign-off, but it does not extinguish the controller's own accountability for the chain.

Why B is wrong: Article 28(4) requires the back-to-back contractual obligations to be imposed by the processor on its sub-processor, not signed directly by the controller; the controller is not made a party to each sub-processor contract.

Why C is wrong: There is no GDPR requirement to seek supervisory authority approval for adding sub-processors; the control mechanism is the controller's own verification of guarantees and the processor's contractual flow-down, not regulator pre-clearance.

Why D is correct: EDPB Opinion 22/2024 confirms that the controller's duty under Article 28(1) to use only processors offering sufficient guarantees extends across the whole chain; the controller must be able to verify and demonstrate this and should be able to obtain the identities of sub-processors, even under a general authorisation.

See more CIPP-E practice questions, answers explained.

Exam traps in European Data Protection: Scope and Accountability

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • The processor remains a processor but breaches the contract, and the only consequence is a contractual remedy the controller may pursue under Article 28.

    Why it is wrong: This is tempting because a contract breach has occurred, but it understates the position: by determining its own purpose the processor is treated as a controller, which carries statutory consequences beyond contract.

  • Article 3(1), because operating servers that reach German users amounts to an establishment in the Union.

    Why it is wrong: Tempting because servers feel like a physical presence, but the establishment test looks at stable arrangements and human and technical resources exercising real activity, not the mere reachability of remote servers, so Article 3(1) is not the basis.

  • Because the servers process the personal data of data subjects who are in the Union, which by itself triggers Article 3(1) regardless of any establishment.

    Why it is wrong: Tempting because it sounds like territorial scope, but Article 3(1) turns on an EU establishment, not merely on data subjects being in the Union; the location of data subjects matters under Article 3(2), which uses different conditions.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.