CIPP-E - Introduction to European Data Protection - Section 1.4

Understand the main principles and goals of significant data protection legislation including the GDPR, the NIS/NIS 2 Directives, the ePrivacy Directive, and the EU Artificial Intelligence Act.

Compare the objectives and scope of the GDPR, the NIS 2 Directive, the ePrivacy Directive 2002/58/EC, and the EU AI Act as overlapping layers of the EU digital regulatory framework. Recognise which instrument governs a given scenario involving network security, electronic communications, or automated systems.

GDPR (EU) 2016/679NIS 2 DirectiveePrivacy Directive 2002/58/ECEU AI Act

Practice question for this objective

Free sampleIntroduction to European Data Protectionmedium

A multinational retailer's legal team is preparing a memo on what changed in legal form when the GDPR replaced the Data Protection Directive in 2018. They want to capture the single most significant change in the type of EU instrument used, because it altered how the rules take effect in each Member State. Which change in legal instrument did the move from the Directive to the GDPR represent?

  • AA move from a non-binding recommendation to a binding directive that Member States then had to transpose into national law
  • BA move from a regulation that applied uniformly to a directive granting Member States wide discretion over implementation
  • CA move from an international treaty requiring ratification by each state to a Commission decision applied centrally
  • DA move from a directive requiring national transposition to a regulation that is directly applicable in every Member State Correct
Identify that the GDPR replaced the Directive by changing the instrument type from a directive to a directly applicable regulation. A directive binds Member States as to the result but leaves transposition to them, whereas a regulation is binding in its entirety and directly applicable; the GDPR adopted the regulation form so a single text would apply uniformly across the Union without separate national statutes.

Why A is wrong: This is tempting because it correctly involves a directive, but the 1995 instrument was already a binding directive, not a recommendation, so this mischaracterises the starting point.

Why B is wrong: This reverses the actual direction of travel, which is a common trap; the 1995 instrument was the directive and the 2018 instrument is the regulation, not the other way round.

Why C is wrong: Neither instrument is a treaty or a Commission decision; this conflates separate categories of EU and international law and so does not describe the actual change in instrument.

Why D is correct: The shift from a directive to a regulation is the defining change, because a regulation is binding in its entirety and directly applicable without national implementing legislation.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all Introduction to European Data Protection objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.