CIPP-E - Introduction to European Data Protection (13% of the exam) - Section 1.4

Understand the main principles and goals of significant data protection legislation including the GDPR, the NIS/NIS 2 Directives, the ePrivacy Directive, and the EU Artificial Intelligence Act.

Compare the objectives and scope of the GDPR, the NIS 2 Directive, the ePrivacy Directive 2002/58/EC, and the EU AI Act as overlapping layers of the EU digital regulatory framework. Recognise which instrument governs a given scenario involving network security, electronic communications, or automated systems.

GDPR (EU) 2016/679NIS 2 DirectiveePrivacy Directive 2002/58/ECEU AI Act

Practice question for this objective

Free sampleIntroduction to European Data Protectionmedium

A multinational retailer's legal team is preparing a memo on what changed in legal form when the GDPR replaced the Data Protection Directive in 2018. They want to capture the single most significant change in the type of EU instrument used, because it altered how the rules take effect in each Member State. Which change in legal instrument did the move from the Directive to the GDPR represent?

  • AA move from a non-binding recommendation to a binding directive that Member States then had to transpose into national law
  • BA move from a regulation that applied uniformly to a directive granting Member States wide discretion over implementation
  • CA move from an international treaty requiring ratification by each state to a Commission decision applied centrally
  • DA move from a directive requiring national transposition to a regulation that is directly applicable in every Member State Correct
Identify that the GDPR replaced the Directive by changing the instrument type from a directive to a directly applicable regulation. A directive binds Member States as to the result but leaves transposition to them, whereas a regulation is binding in its entirety and directly applicable; the GDPR adopted the regulation form so a single text would apply uniformly across the Union without separate national statutes.

Why A is wrong: This is tempting because it correctly involves a directive, but the 1995 instrument was already a binding directive, not a recommendation, so this mischaracterises the starting point.

Why B is wrong: This reverses the actual direction of travel, which is a common trap; the 1995 instrument was the directive and the 2018 instrument is the regulation, not the other way round.

Why C is wrong: Neither instrument is a treaty or a Commission decision; this conflates separate categories of EU and international law and so does not describe the actual change in instrument.

Why D is correct: The shift from a directive to a regulation is the defining change, because a regulation is binding in its entirety and directly applicable without national implementing legislation.

See more CIPP-E practice questions, answers explained.

Exam traps in Introduction to European Data Protection

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-E bank for this domain.

  • The ePrivacy Directive fully replaces the GDPR for any organisation that operates a website or sends electronic communications

    Why it is wrong: This is tempting because ePrivacy clearly governs cookies and communications, but it complements rather than replaces the GDPR, which continues to apply to the underlying personal data.

  • It sets out the general rules for processing personal data across all sectors of the economy.

    Why it is wrong: The general cross-sector rules for processing personal data are the GDPR's role; the ePrivacy Directive is a sector-specific instrument focused on the electronic communications field, so this confuses the two.

  • To grant every individual a free-standing right to demand a human review of any decision made about them by software.

    Why it is wrong: A right not to be subject to certain solely automated decisions, with safeguards including human intervention, is a GDPR mechanism under the automated-decision rules; the AI Act is a product-safety style framework and does not create a general right to human review of all software decisions.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.