CIPP-E - Introduction to European Data Protection - Section 1.2

Understand how the need for a harmonised European approach to data protection developed and know the challenges involved in implementing it, including the implications of Brexit.

Describe how the fragmented approach of the Data Protection Directive 95/46/EC drove the push for GDPR harmonisation across EU member states. Understand the practical consequences of Brexit for UK-EU data transfers and regulatory alignment.

Data Protection Directive 95/46/ECGDPR harmonisationBrexit

Practice question for this objective

Free sampleIntroduction to European Data Protectionmedium

A UK-headquartered software firm processes the personal data of customers in France and Germany and routinely receives further customer records sent to it from its group's Irish subsidiary. Its new privacy lead is briefing the board on two points: why the GDPR replaced the Data Protection Directive to deliver a harmonised European approach, and what now lawfully governs the ongoing flow of personal data from the Irish subsidiary to the UK firm after the Brexit transition period. Which two statements accurately describe the position? (Select TWO.)

  • AThe Data Protection Directive 95/46/EC bound Member States only as to the result and had to be transposed nationally, producing divergent regimes that the GDPR's single directly applicable text was designed to harmonise. Correct
  • BThe Data Protection Directive 95/46/EC was already directly applicable in every Member State, so the GDPR merely re-enacted the identical rules without altering the type of legal instrument used.
  • CBecause the United Kingdom is now a third country, every ordinary transfer from the Irish subsidiary must be covered by Standard Contractual Clauses backed by a transfer impact assessment before any data may flow.
  • DThe European Commission's adequacy decision for the United Kingdom currently lets most personal data flow from the Irish subsidiary to the UK firm without additional Chapter V safeguards while that decision remains in force. Correct
  • EThe EU-US Data Privacy Framework is the mechanism that now legitimises the transfer of the customer records from the Irish subsidiary to the United Kingdom firm following Brexit.
Recognise that the Directive's national transposition caused fragmentation the GDPR replaced, and that an EU adequacy decision now underpins routine EU-to-UK transfers after Brexit. Directive 95/46/EC bound Member States only as to result, so transposition diverged and the GDPR was adopted as a directly applicable regulation to harmonise the field. Brexit made the UK a third country, but the Commission's adequacy decision lets most EU-to-UK data flow without extra Chapter V safeguards, so Standard Contractual Clauses are not needed and the US-specific Data Privacy Framework is irrelevant here.

Why A is correct: Correct: as a directive it left transposition to each Member State, so national rules diverged, and the GDPR was adopted as a directly applicable regulation precisely to replace that fragmented landscape with one uniform text.

Why B is wrong: Tempting because both instruments share subject matter, but a directive is not directly applicable and requires transposition, so the move to a regulation did change the instrument type, making this a reversal of the actual mechanism.

Why C is wrong: Tempting because it echoes the Schrems II requirement for third countries lacking adequacy, but the United Kingdom benefits from a Commission adequacy decision, so Standard Contractual Clauses are not the route required for these routine flows.

Why D is correct: Correct: after Brexit the United Kingdom became a third country, but the Commission's adequacy decision permits most EU-to-UK transfers to continue freely without further transfer tools for as long as the decision stands.

Why E is wrong: Tempting as a familiar named transfer mechanism, but the EU-US Data Privacy Framework concerns certified transfers to the United States, not transfers to the United Kingdom, so it does not govern this EU-to-UK flow.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all Introduction to European Data Protection objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.