CIPP-E domain - 13% of the exam

Introduction to European Data Protection

Introduction to European Data Protection is 13% of the Certified Information Privacy Professional/Europe (CIPP/E) exam. These are the objectives it covers, each with practice questions, with every answer explained.

The domain in numbers

39
Practice questions
4
Objectives
20
Easy
19
Medium

Where people go wrong

  • Confusing the Council of Europe with EU institutions

    The wrong answers blur the Council of Europe and the EU institutions: they credit the European Commission, the European Council, or the Court of Justice with adopting Convention 108, give EU institutions a membership or reach beyond the European Union, or have the Council of Europe supervising GDPR compliance. The Council of Europe is a separate international organisation, distinct from the European Union, responsible for Convention 108 and the European Convention on Human Rights, while the European Commission is the EU institution that monitors how Member States apply EU law, including the GDPR.

    See it in a sample question
  • Confusing the ECtHR with the CJEU

    The wrong answers hand the ECtHR cases that belong to the CJEU, and the CJEU cases that belong to the ECtHR. They offer the CJEU as the court for a Convention complaint, the ECtHR as the interpreter of EU law, and the ECtHR as the source of a binding ruling on the GDPR. The ECtHR rules on the Convention; the CJEU rules on EU law.

  • Treating the GDPR as though it needs transposition

    The wrong answers describe the GDPR as a directive that Member States must transpose into national law before it applies, or say it takes effect only once each state passes an implementing statute. The GDPR is a regulation, binding in its entirety and directly applicable in every Member State, while the earlier Directive was the instrument that needed national transposition.

    See it in a sample question
  • Crediting the Treaty of Lisbon with the GDPR

    The wrong answers say the Treaty of Lisbon created or enacted the General Data Protection Regulation. The GDPR was adopted separately, years after Lisbon entered into force, as its own regulation. The Treaty of Lisbon gave the Charter of Fundamental Rights the same legal value as the Treaties, making the Charter's protection of personal data binding.

    See it in a sample question

Objectives in this domain

What to study

The official documents this domain's practice questions cite most.

Sample questions from this domain

Free sampleIntroduction to European Data Protectionmedium

A French data protection officer is explaining why, despite the GDPR being a directly applicable regulation, the level of data protection law still differs in some respects between Member States. A junior colleague assumes a regulation must mean fully identical rules everywhere. Which feature of the GDPR best explains why some genuine national variation persists?

  • AThe GDPR contains opening clauses that permit Member States to specify or further restrict certain matters in their national law Correct
  • BThe GDPR must be transposed into a national statute by each Member State before it can take effect domestically
  • CEach supervisory authority is free to rewrite the operative articles of the GDPR for application in its own territory
  • DThe GDPR applies only to Member States that have chosen to opt in, and the rest may set entirely separate rules
Recognise that the GDPR's opening clauses allow limited national specification, so full harmonisation is not absolute. Although the GDPR is a directly applicable regulation, it contains numerous opening clauses that let Member States legislate on specified matters such as employment data, special category exemptions, and the age of consent, which is why national data protection laws still vary within the GDPR's framework.

Why A is correct: The GDPR includes opening clauses, for example on the age of consent for information society services and on processing in the employment context, which deliberately leave room for national specification.

Why B is wrong: This is tempting because it describes a directive, but a regulation needs no transposition to take effect, so transposition is not the source of the remaining variation.

Why C is wrong: Supervisory authorities interpret and enforce the GDPR but cannot rewrite its articles, so this overstates their powers and is not why variation exists.

Why D is wrong: There is no opt-in mechanism for the GDPR across Member States; it binds them all, so an opt-in cannot explain the residual national differences.

Free sampleIntroduction to European Data Protectioneasy

A policy analyst is explaining how the Treaty of Lisbon, in force from 2009, strengthened the legal footing of data protection in the European Union. Which change should she correctly attribute to that treaty?

  • AIt created the General Data Protection Regulation as directly applicable EU law
  • BIt established the Council of Europe and opened Convention 108 for signature
  • CIt made the Charter of Fundamental Rights of the European Union legally binding, giving data protection treaty-level recognition as a fundamental right Correct
  • DIt introduced the OECD fair information principles into binding EU law
Attribute to the Treaty of Lisbon the binding force given to the EU Charter and the resulting fundamental-right status of data protection. By granting the Charter the same legal value as the EU treaties, the Treaty of Lisbon anchored Article 8 protection of personal data as an enforceable fundamental right within the EU legal order.

Why A is wrong: This is tempting because both concern EU data protection, but the GDPR was adopted in 2016 as a separate regulation and was not created by the Treaty of Lisbon.

Why B is wrong: The Council of Europe and Convention 108 predate the Treaty of Lisbon and are products of the Council of Europe, a separate organisation, so the treaty did not establish them.

Why C is correct: The Treaty of Lisbon conferred legally binding force on the Charter, whose Article 8 expressly recognises protection of personal data, thereby elevating data protection to a fundamental right at EU level.

Why D is wrong: The OECD principles influenced EU law through other instruments, but the Treaty of Lisbon did not transpose those guidelines, so attributing that step to it is incorrect.

Free sampleIntroduction to European Data Protectioneasy

A privacy manager is briefing colleagues on the origin of Convention 108, the first binding international instrument on automated processing of personal data. Which body adopted Convention 108 and continues to act as the principal pan-European human rights organisation behind it?

  • AThe European Commission, which proposes and enforces European Union legislation
  • BThe European Council, made up of the heads of state or government of European Union members
  • CThe Court of Justice of the European Union, which rules on the interpretation of Union law
  • DThe Council of Europe, a separate international organisation distinct from the European Union Correct
Recognise that Convention 108 was adopted by the Council of Europe, an organisation distinct from the European Union. Convention 108 is a Council of Europe treaty; the Council of Europe is a separate international human rights organisation that is not an institution of the European Union and was founded before it.

Why A is wrong: The Commission is tempting because it drafts much EU data protection law, but it is an EU institution and did not adopt Convention 108, which is a Council of Europe instrument.

Why B is wrong: The similar name makes this tempting, but the European Council sets the European Union's political direction and is unrelated to the Council of Europe that produced Convention 108.

Why C is wrong: The CJEU is a judicial body that interprets European Union law and does not adopt international conventions such as Convention 108.

Why D is correct: Convention 108 (1981) was adopted by the Council of Europe, an international organisation of 46 member states that is separate from the European Union and predates it.

Other domains in this exam

See also the CIPP-E cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.