15 real CIPP-E sample questions, each with a worked explanation and a rationale for every option, right and wrong. No account, no card. This is the reasoning the CIPP-E tests: knowing why the tempting answer is wrong, not just spotting the right one.
The real CIPP-E is 90 questions in 150 minutes, pass mark 300 / 500. For a domain-by-domain breakdown and a study plan, read the CIPP-E study guide. The full bank has 322 questions.
lock_openFree sampleEuropean Data Protection Law and Regulationhard
A bank uses a fully automated model to decide whether to grant unsecured personal loans, with no human involvement before the decision is communicated to the applicant. A rejected applicant asks to understand and contest the outcome. The bank relies on this automated process because it is necessary for entering into the loan contract the applicant requested. Which safeguard must the bank provide to comply with the rules on solely automated decisions producing legal or similarly significant effects?
- AIt must implement, at minimum, the right to obtain human intervention, to express the applicant's point of view, and to contest the decision.check_circle Correct
- BIt must obtain fresh explicit consent from the applicant before the automated decision can be relied upon, regardless of the contractual necessity.
- CIt must disclose the full source code and weights of the scoring model so the applicant can independently reproduce the decision.
- DIt must escalate every rejected application to the supervisory authority for prior review before the decision becomes final.
Solely automated decisions with significant effects taken on contractual necessity require safeguards of human intervention, expression of view, and the right to contest. Where a solely automated decision with legal or similarly significant effects is permitted because it is necessary for a contract, the controller must implement suitable safeguards, expressly including the data subject's right to obtain human intervention, to express their point of view, and to contest the decision, rather than fresh consent or authority pre-approval.
Why A is correct: Correct: for solely automated decisions with legal or similarly significant effects based on contractual necessity, the controller must put in place suitable measures including at least the right to human intervention, to express a point of view, and to contest the decision.
Why B is wrong: This is tempting because consent is one possible basis, but where the automated decision is necessary for entering into a contract the rules permit it without separate explicit consent, provided suitable safeguards are in place.
Why C is wrong: This overstates the transparency duty: the applicant is owed meaningful information about the logic involved, not the entire source code and weights, which would expose disproportionate detail and is not required.
Why D is wrong: This confuses safeguards with supervision: there is no requirement to send each rejection to the authority for prior review, and the duty is to provide internal safeguards such as human intervention and the right to contest.
lock_openFree sampleEuropean Data Protection Law and Regulationmedium
A retailer's laptop holding a spreadsheet of 4,000 customer email addresses and order totals is stolen from a parked car. The entire disk was protected with strong, state-of-the-art full-disk encryption, the key was not stored on or with the device, and no copy of the key was compromised. How does this encryption affect the retailer's GDPR obligation to communicate the breach to the affected customers?
- AIt removes the obligation to notify the supervisory authority, but the controller must still communicate the breach directly to every affected individual.
- BIt has no effect on the communication duty, because the theft of the device is itself a high-risk event regardless of the technical measures applied to the data.
- CIt removes the obligation to communicate to individuals, because robust encryption rendering the data unintelligible can mean the breach is unlikely to result in a high risk to them.check_circle Correct
- DIt has no effect, because Article 34 only allows the encryption exemption where the data subjects have separately consented to encrypted processing.
Understand that encryption rendering data unintelligible can exempt a controller from communicating a breach to individuals under Article 34. Article 34(1) requires communication to individuals only when a breach is likely to result in a high risk, and Article 34(3)(a) lets a controller avoid that communication where it has applied measures, such as encryption that makes the data unintelligible to unauthorised persons, that mean the high risk is no longer likely to materialise.
Why A is wrong: This inverts the rule: the supervisory-authority test in Article 33 turns on risk generally, while encryption most directly affects whether the data is intelligible and therefore whether the high-risk individual-communication duty under Article 34 is triggered.
Why B is wrong: This is tempting because device theft sounds inherently serious, but it is wrong: Article 34(3)(a) expressly lets appropriate technical measures such as encryption reduce the assessed risk so that individual communication is not required.
Why C is correct: Correct: Article 34(3)(a) exempts communication to individuals where the controller has applied protection measures, such as encryption, that render the data unintelligible to anyone not authorised to access it, so properly implemented encryption can defeat the high-risk threshold.
Why D is wrong: This invents a condition: Article 34(3)(a) does not require any consent to encrypted processing; it simply asks whether the implemented protective measures render the personal data unintelligible to unauthorised persons.
lock_openFree sampleEuropean Data Protection Law and Regulationmedium
A subscription fitness app presents new users with a single tick box during sign-up that reads "I agree to the terms of service and to receiving personalised health and nutrition advertising from our partners". A user cannot complete registration without ticking it, and the partner advertising is not needed to deliver the core fitness tracking service. Under the GDPR, why is this most likely an invalid basis for processing personal data for the partner advertising?
- AConsent is invalid because the controller failed to obtain explicit consent, which is the standard required for all marketing activities under the GDPR.
- BConsent is invalid only because the user was not told the identity of every partner that would receive the data before ticking the box.
- CConsent is valid because the user actively ticked the box and was therefore given a clear affirmative action that signals agreement.
- DConsent has been bundled with acceptance of the terms of service, so it is not specific and is not freely given for the separate advertising purpose.check_circle Correct
Recognise that bundling consent for an unrelated purpose into a precondition of service makes that consent neither specific nor freely given. Valid consent under Article 7 and Recital 32 must be freely given and specific to each purpose. Tying advertising consent to a mandatory term of service removes genuine choice and merges distinct purposes, defeating both requirements regardless of the affirmative tick.
Why A is wrong: Tempting because explicit consent sounds like a higher and safer standard, but ordinary marketing does not require explicit consent under Article 9; the defect here is bundling and lack of free choice, not the absence of an explicit form of consent.
Why B is wrong: Tempting because transparency about recipients matters, but a missing recipient list is a separate information defect; even a fully informed user is denied a free and specific choice here because consent is tied to completing registration.
Why C is wrong: Tempting because a ticked box is an affirmative action, but an affirmative action alone does not cure the lack of freely given and specific consent when agreement is a non-negotiable condition of using an unrelated service.
Why D is correct: Correct: Article 7(2) requires a request for consent to be clearly distinguishable from other matters, and Recital 32 requires consent to be specific to each purpose, so bundling advertising consent into the terms of service makes it neither specific nor freely given.
lock_openFree sampleEuropean Data Processinghard
An employer wants to rely on the consent condition in Article 9(2)(a) to process the trade union membership of staff for an internal diversity programme. A data protection officer warns that this consent route carries a heightened standard compared with ordinary Article 6(1)(a) consent. What is the key additional requirement that makes Article 9(2)(a) consent harder to satisfy?
- AThe consent must be obtained in writing on a physical document, because electronic consent is insufficient for any special category of personal data.
- BThe consent must be explicit, meaning expressed through a clear affirmative statement rather than inferred from conduct or a pre-ticked arrangement.check_circle Correct
- CThe consent must be renewed by the data subject every six months, because special category consent automatically expires under the storage limitation principle.
- DThe consent must be approved in advance by the competent supervisory authority before the trade union data can be processed.
Article 9(2)(a) requires explicit consent, a higher standard than ordinary Article 6 consent, demanding an express affirmative statement. Explicit consent under Article 9(2)(a) means the data subject gives an express statement of agreement to the specific special category processing. It cannot be inferred from conduct or a pre-ticked box, which raises the bar above ordinary consent.
Why A is wrong: A signed paper form feels rigorous, but the GDPR does not mandate a particular medium; electronic consent is valid, so form of recording is not the distinguishing requirement.
Why B is correct: Correct: Article 9(2)(a) requires explicit consent, a higher bar than ordinary consent, demanding an express statement of agreement rather than consent inferred from action, which distinguishes it from Article 6(1)(a).
Why C is wrong: Periodic renewal sounds prudent given storage limitation, but the GDPR sets no fixed expiry for consent; validity depends on it remaining freely given and informed, not on a mandatory interval.
Why D is wrong: Prior authorisation is plausible because some high-risk activities involve the supervisory authority, but Article 9(2)(a) consent requires no regulator sign-off; prior consultation under Article 36 is a separate, narrow mechanism.
lock_openFree sampleEuropean Data Processinghard
An online marketplace plans to run a fraud-detection engine that scores buyer accounts and intends to rely on legitimate interests under Article 6(1)(f) GDPR. Its privacy counsel is structuring the legitimate-interests assessment to follow the cumulative three-part test as interpreted by EDPB guidance and Court of Justice case law. Which of the following accurately describe what the marketplace must establish for that test to be satisfied? (Select TWO.)
- AIt must obtain the explicit consent of each scored buyer under Article 9(2)(a), because account fraud signals are inferred from behaviour and so amount to special category data requiring a heightened condition.
- BIt must identify a lawful, clearly articulated, and real interest being pursued, such as preventing fraud on the platform, rather than asserting a vague or speculative purpose.check_circle Correct
- CIt must register the legitimate-interests assessment with the competent supervisory authority and obtain prior authorisation before the scoring engine may go live.
- DIt must weigh its interest against the interests, rights, and reasonable expectations of the buyers, and that balancing is decisive in determining whether the basis is available.check_circle Correct
- EIt must show that the scoring is strictly necessary to perform the buyer's purchase contract, because fraud prevention forms part of delivering the marketplace service the buyer signed up for.
Identify the purpose limb and the balancing limb as the controller-side requirements of the Article 6(1)(f) three-part legitimate-interests assessment. The cumulative test under Article 6(1)(f) has three limbs: a real and lawful interest, necessity of the processing, and a balance against the data subject's rights and reasonable expectations. Options B and D capture the purpose and balancing limbs. The strongest distractor, E, imports the Article 6(1)(b) necessity standard, which is a different basis the EDPB reads narrowly.
Why A is wrong: Tempting because explicit consent sounds like a strong safeguard, but Article 9(2)(a) governs the separate special category list, and ordinary account-fraud signals are not Article 9 data, so this requirement does not belong to the Article 6(1)(f) test at all.
Why B is correct: Correct: the first limb of the three-part test is the purpose test, and Recital 47 names fraud prevention as a legitimate interest, so the interest must be lawful, sufficiently specific, and present rather than hypothetical.
Why C is wrong: Tempting because high-risk processing can trigger prior consultation, but Article 6(1)(f) requires no registration or authorisation of the assessment itself, so making regulator sign-off a precondition misstates the test.
Why D is correct: Correct: the third limb is the balancing test, where the controller's interest is weighed against the data subjects' interests, fundamental rights, and reasonable expectations, and a buyer's expectation that a marketplace screens for fraud supports reliance.
Why E is wrong: Tempting because fraud screening feels bound up with the service, but necessity for the contract is the Article 6(1)(b) test, not the Article 6(1)(f) test, and the EDPB reads contractual necessity narrowly, so this confuses two distinct bases.
lock_openFree sampleEuropean Data Processingmedium
A logistics company runs a customer satisfaction survey and, to gather richer feedback, asks every respondent to supply their date of birth, national identity number, and annual household income, none of which it uses when analysing the survey results. Which Article 5 principle does this practice most clearly breach?
- ALawfulness, fairness and transparency, because the company failed to tell respondents how their answers would be analysed.
- BPurpose limitation, because the company is processing the survey responses for an undisclosed secondary purpose.
- CData minimisation, because the data collected must be adequate, relevant and limited to what is necessary for the purpose.check_circle Correct
- DIntegrity and confidentiality, because holding identity numbers and income increases the harm if the survey data is breached.
Identify that collecting data fields not necessary for the stated purpose breaches the data minimisation principle. Article 5(1)(c) demands that personal data be adequate, relevant and limited to what is necessary; collecting identity numbers and income that play no part in satisfaction analysis is data that is not necessary, making minimisation the principle breached.
Why A is wrong: This principle is tempting because transparency duties always apply, but the scenario gives no indication of hidden processing; the defect is collecting fields that serve no purpose at all.
Why B is wrong: Purpose limitation is plausible because excessive collection can hint at hidden uses, but nothing here shows a second purpose; the fields are simply collected and ignored, which is a minimisation failure.
Why C is correct: Article 5(1)(c) requires data to be limited to what is necessary for the stated purpose, and gathering identity numbers and income that are never used for satisfaction analysis is precisely the excess this principle forbids.
Why D is wrong: Integrity and confidentiality is tempting because sensitive fields raise breach stakes, but Article 5(1)(f) concerns security measures, not whether the data should have been collected in the first place.
lock_openFree sampleEuropean Data Protection: Scope and Accountabilitymedium
A national supervisory authority is preparing to adopt a list of processing operations that require a data protection impact assessment in its territory. Before the list takes effect, the authority is required to engage a Union-level mechanism. Which body must it involve, and for what purpose?
- AThe European Commission, which must approve the list as an implementing measure before it can be applied nationally.
- BThe European Data Protection Board, which issues an opinion under the consistency mechanism to promote a harmonised approach across authorities.check_circle Correct
- CThe European Data Protection Supervisor, which reviews the list because DPIA obligations originate in the rules governing EU institutions.
- DThe Court of Justice of the European Union, which validates the list to ensure it complies with the Charter of Fundamental Rights.
Recognise that national DPIA lists go to the EDPB for a consistency opinion to harmonise practice across supervisory authorities. The consistency mechanism requires national authorities to communicate certain measures, including lists of processing requiring a DPIA, to the EDPB. The Board issues an opinion so that comparable processing is treated consistently across Member States, reflecting the EDPB's harmonising mandate rather than approval by the Commission or a court.
Why A is wrong: Tempting because the Commission adopts implementing acts elsewhere in the GDPR, but DPIA lists are communicated to the EDPB for consistency, not submitted to the Commission for approval.
Why B is correct: Correct: lists of processing requiring a DPIA are subject to the consistency mechanism, so the authority communicates the list to the EDPB, which gives an opinion to keep such lists consistent across the Union.
Why C is wrong: Tempting because the EDPS works on data protection at Union level, but it supervises EU institutions and does not review national authorities' DPIA lists, which fall under the EDPB's consistency role.
Why D is wrong: Tempting because the Charter underpins data protection, but the CJEU does not pre-clear administrative lists; consistency review of DPIA lists is an EDPB function under the cooperation framework.
lock_openFree sampleEuropean Data Protection: Scope and Accountabilitymedium
A hospital's newly designated DPO also chairs the committee that decides which clinical IT systems the hospital purchases and how patient data flows between them. The supervisory authority raises concerns during an audit. Which GDPR principle does this dual role most directly threaten, and what is the correct conclusion?
- AIt threatens the DPO's independence because determining the purposes and means of processing creates a conflict of interest with the DPO's oversight role.check_circle Correct
- BIt threatens the data minimisation principle, so the hospital must reduce the volume of patient data the DPO can access.
- CIt threatens the accuracy principle, so the hospital must give the DPO authority to correct patient records directly.
- DIt threatens the storage limitation principle, so the DPO must be barred from approving any system that retains data long term.
Recognise that a DPO who determines the purposes and means of processing has a prohibited conflict of interest under Article 38(6). Under Article 38(6) a DPO may take on other duties only if those duties do not give rise to a conflict of interest, and case guidance treats roles that determine the purposes and means of processing, such as chairing IT procurement and data-flow decisions, as inherently conflicting with the DPO's independent monitoring function. The dual role therefore undermines the DPO's required independence.
Why A is correct: Article 38(6) allows a DPO to hold other tasks only where they do not result in a conflict of interest, and deciding the purposes and means of processing puts the DPO in the position of overseeing decisions they themselves made, which is the conflict the GDPR forbids.
Why B is wrong: Data minimisation concerns limiting the data collected to what is necessary and is unrelated to the DPO's organisational position, so this misdiagnoses the issue as a data-volume problem rather than a role-conflict one.
Why C is wrong: Accuracy concerns keeping personal data correct and up to date and has nothing to do with the DPO's seat on a procurement committee, so granting record-editing powers neither addresses nor fits the conflict described.
Why D is wrong: Storage limitation governs retention periods, not the DPO's governance role, so reframing the conflict as a retention concern misses that the real problem is the DPO setting the very processing they must monitor.
lock_openFree sampleEuropean Data Protection: Scope and Accountabilitymedium
A compliance lead is briefing colleagues on the European Data Protection Supervisor and wants to state its principal supervisory remit accurately. Which description best captures the core role of the EDPS under the EU data protection framework?
- AIt is the independent authority that supervises the processing of personal data by the Union's own institutions, bodies, offices and agencies.check_circle Correct
- BIt is the supervisory authority that enforces the GDPR against private-sector controllers established in countries that lack their own national authority.
- CIt is the body that adopts binding consistency decisions in cross-border disputes between national supervisory authorities.
- DIt is the secretariat that drafts adequacy decisions for transfers of personal data to third countries.
Recall that the EDPS is the independent authority supervising data processing by the EU's own institutions, bodies, offices and agencies. The EDPS exists to ensure that the Union's institutions and bodies respect data protection rules when they process personal data, and it advises on legislation and policy. It is distinct from national authorities, which supervise controllers in the Member States, and from the EDPB, which delivers collective opinions and binding decisions.
Why A is correct: Correct: the EDPS is the independent supervisory authority responsible for monitoring and enforcing data protection rules as applied to the EU's institutions and bodies, ensuring they respect data subjects' rights.
Why B is wrong: Tempting because both bodies sit in the supervision landscape, but the EDPS supervises EU institutions and bodies, not private controllers, and every Member State must have its own national authority, so no such gap exists.
Why C is wrong: Tempting because the EDPS is a member of the EDPB, but binding consistency and dispute-resolution decisions are adopted by the EDPB as a collective body, not by the EDPS acting alone.
Why D is wrong: Tempting because adequacy is central to transfers, but adequacy decisions are adopted by the European Commission; the EDPS advises EU institutions and supervises their processing rather than issuing adequacy findings.
lock_openFree sampleCompliance with European Data Protection Law and Regulationhard
An airport operator wants to let passengers pass through boarding gates using live facial recognition matched against a template created at check-in. Legal asks whether the GDPR treats the facial templates as a special category of data and, if so, what that means for the lawful basis. Which statement best reflects the GDPR position on this processing?
- AThe templates are ordinary personal data because a photograph only becomes special category data once it is published, so Article 6 alone governs the boarding gates.
- BBecause boarding is a contractual necessity, Article 9 is automatically satisfied and no separate special category condition needs to be identified.
- CFacial recognition for access control falls under the general prohibition on automated decision-making, so the only requirement is offering passengers human review of any non-match.
- DThe templates are biometric data processed for unique identification and therefore special category data, so an Article 9 exception, typically explicit consent, must apply on top of an Article 6 basis.check_circle Correct
Identify that biometric data processed for unique identification is special category data requiring both an Article 6 basis and an Article 9 condition. Article 9(1) classifies biometric data processed for the purpose of uniquely identifying a natural person as special category data, which is prohibited unless an Article 9(2) exception applies; the controller must therefore layer a special category condition such as explicit consent over an ordinary lawful basis.
Why A is wrong: This conflates a plain photograph with biometric processing; publication is irrelevant, and once the image is processed through specific technical means for unique identification it becomes biometric special category data, so Article 6 alone is insufficient.
Why B is wrong: Contractual necessity is an Article 6 basis only; Article 9 contains its own exhaustive list of conditions, and necessity for a contract is not among them, so a separate Article 9 condition is still required.
Why C is wrong: Automated decision rights may be engaged, but they do not displace the Article 9 special category analysis; the question of whether a valid exception authorises the biometric processing remains, so this answer misidentifies the core issue.
Why D is correct: Biometric data processed for the purpose of uniquely identifying a person is special category data under Article 9(1), so the controller needs an Article 9 condition such as explicit consent in addition to an Article 6 lawful basis.
lock_openFree sampleCompliance with European Data Protection Law and Regulationhard
An EU-based controller engages a US cloud provider to host customer records and signs the provider's processor agreement, which incorporates the EU standard contractual clauses for the transfer. Following the principles set out in the Schrems II ruling, what must the controller do before relying on those clauses to legitimise the transfer?
- AConduct a transfer impact assessment of the destination country's laws and adopt supplementary measures where the clauses alone do not ensure essentially equivalent protection.check_circle Correct
- BObtain prior authorisation of the standard contractual clauses from the lead supervisory authority before the first transfer takes place.
- CCollect the explicit consent of every affected data subject as a separate derogation reinforcing the standard contractual clauses.
- DNotify the European Commission of the transfer so it can verify that an adequacy decision covers the importer's sector.
Reliance on standard contractual clauses after Schrems II requires a transfer impact assessment and supplementary measures where local law weakens protection. Schrems II preserved the clauses as a transfer tool but added an active duty: the exporter must evaluate the importer country's legal regime and implement supplementary measures, because a contract cannot bind foreign public authorities to the equivalent protection the GDPR demands.
Why A is correct: Schrems II held that controllers using the clauses must assess whether the importer's local laws, particularly government access powers, undermine the protection, and must add technical or organisational supplementary measures where they do.
Why B is wrong: The Commission-approved clauses do not require prior authorisation for each use, which is a plausible confusion with ad hoc clauses, and this answer ignores the case-by-case assessment Schrems II actually mandates.
Why C is wrong: Explicit consent is a distinct Article 49 derogation, not a supplement to a transfer-tool transfer; stacking it onto the clauses confuses two separate transfer mechanisms and is not what the ruling requires.
Why D is wrong: There is no Commission notification step, and an adequacy decision would remove the need for clauses entirely, so this confuses the adequacy route with the appropriate-safeguards route the controller has chosen.
lock_openFree sampleCompliance with European Data Protection Law and Regulationmedium
A French employer plans to deploy software that continuously inspects the content of employees' work email and flags messages containing competitor names, as an anti-fraud measure. Before rolling it out, which step most directly reflects the GDPR requirement that applies because of the systematic and large-scale monitoring of individuals in the workplace?
- ACarrying out a data protection impact assessment, because systematic monitoring of employees on a large scale is the kind of high-risk processing that Article 35 targets.check_circle Correct
- BRegistering the monitoring tool with the European Data Protection Board so it can be added to the public register of high-risk technologies.
- CObtaining unanimous consent from every affected employee, since email content scanning cannot lawfully proceed on any other basis.
- DAppointing an external data protection officer specifically for the duration of the monitoring project, as Article 37 requires a dedicated DPO per monitoring tool.
Identify that systematic, large-scale workplace monitoring triggers the obligation to conduct a DPIA before processing begins. Article 35(1) requires a DPIA where processing is likely to result in a high risk to individuals, and Article 35(3)(c) expressly names systematic monitoring on a large scale, so the assessment of necessity, proportionality and safeguards must be completed before content-scanning surveillance goes live.
Why A is correct: Correct: Article 35(3)(c) and the criteria in EDPB DPIA guidance flag systematic and extensive monitoring as high-risk, so a DPIA assessing necessity, proportionality and mitigations must precede deployment of content-scanning email surveillance.
Why B is wrong: Tempting because the EDPB does publish guidance, but there is no GDPR register of high-risk technologies maintained by the EDPB; the obligation triggered here is to carry out a data protection impact assessment.
Why C is wrong: Tempting because the processing is intrusive, but consent is generally not freely given in employment and is not the only available basis; the step the facts trigger is a DPIA, not unanimous consent.
Why D is wrong: Tempting because large-scale monitoring can trigger a mandatory DPO under Article 37(1)(b), but the DPO is appointed at the controller level, not per tool, and the immediate pre-deployment step here is a DPIA.
lock_openFree sampleIntroduction to European Data Protectionmedium
A Berlin-based SaaS company processes employee and customer personal data and is mapping which EU instruments govern its activities. Its compliance lead notes that one instrument sets out the general, cross-sector rules for processing personal data, while the others address narrower fields such as electronic communications confidentiality and the cybersecurity of essential services. Which instrument provides the general legal framework for the processing of personal data across all sectors in the EU?
- AThe ePrivacy Directive 2002/58/EC, which sets the baseline rules for processing personal data across sectors
- BThe NIS 2 Directive, which sets the baseline rules for processing personal data across sectors
- CThe EU Artificial Intelligence Act, which sets the baseline rules for processing personal data across sectors
- DRegulation (EU) 2016/679, the General Data Protection Regulation, which sets the baseline rules for processing personal data across sectorscheck_circle Correct
Identify the GDPR as the general cross-sector framework for processing personal data, distinct from sector-specific EU instruments. The GDPR is a directly applicable regulation that establishes the general rules for processing personal data in every sector, while ePrivacy, NIS 2, and the AI Act each address a narrower subject area and supplement the GDPR rather than displace it.
Why A is wrong: The ePrivacy Directive is tempting because it does protect personal data, but it is sector-specific to electronic communications and confidentiality of communications, not the general framework.
Why B is wrong: NIS 2 is tempting because it imposes broad obligations on many entities, but it governs cybersecurity risk management and incident reporting, not the general rules for processing personal data.
Why C is wrong: The AI Act is tempting because it is a recent EU-wide regulation, but it regulates the placing on the market and use of AI systems by risk tier, not personal data processing generally.
Why D is correct: The GDPR is the general, directly applicable instrument governing the processing of personal data across all sectors in the EU, and the other instruments supplement rather than replace it.
lock_openFree sampleIntroduction to European Data Protectioneasy
An individual believes a member state's surveillance practices breach the right to respect for private life guaranteed by the European Convention on Human Rights. After exhausting domestic remedies, which court is designed to hear that complaint?
- AThe Court of Justice of the European Union, which rules on the interpretation and validity of Union law
- BThe European Commission, which monitors member states' compliance with Union obligations
- CThe European Court of Human Rights, which adjudicates alleged breaches of the European Convention on Human Rightscheck_circle Correct
- DThe European Parliament, which can investigate matters of concern to Union citizens
Identify the European Court of Human Rights as the body that hears complaints alleging breaches of the European Convention on Human Rights. The ECtHR is the Council of Europe court that rules on individual and state applications alleging a contracting state has violated the Convention, including the right to respect for private and family life.
Why A is wrong: The CJEU is tempting because it handles fundamental rights within Union law, but it does not adjudicate complaints brought directly under the European Convention on Human Rights.
Why B is wrong: The Commission can pursue states for breaching Union law, but it is not a court and does not hear Convention complaints from individuals.
Why C is correct: The ECtHR, a Council of Europe court in Strasbourg, hears applications alleging that a contracting state has breached rights under the Convention, such as the Article 8 privacy right.
Why D is wrong: Parliament may run inquiries and receive petitions, but it is a legislative body and cannot deliver binding judgments on Convention breaches.
lock_openFree sampleIntroduction to European Data Protectionmedium
Following the end of the Brexit transition period, a UK-headquartered analytics company that processes the personal data of customers located in Germany and Spain asks whether the EU GDPR still has any bearing on it now that the United Kingdom has left the European Union. From the perspective of EU data protection law, which statement most accurately describes the position?
- AThe EU GDPR ceased to have any relevance to the company the moment the United Kingdom left the European Union
- BThe company is automatically bound by the EU GDPR as if the United Kingdom were still a Member State, with no change to its status
- COnly the United Kingdom's own data protection law can ever apply to the company, since EU law cannot reach an organisation outside the Union
- DThe EU GDPR can continue to apply to the company on an extraterritorial basis where it offers goods or services to, or monitors, individuals in the EUcheck_circle Correct
Explain that after Brexit the EU GDPR can still apply extraterritorially to a UK organisation that targets or monitors individuals in the EU. Brexit removed the UK from the Union, but the EU GDPR's territorial scope extends to controllers and processors outside the EU who offer goods or services to, or monitor the behaviour of, individuals located in the EU, so a UK firm serving EU customers can remain subject to it.
Why A is wrong: This is tempting because the UK is no longer a Member State, but the EU GDPR can still apply extraterritorially to a UK firm that targets or monitors individuals in the EU.
Why B is wrong: This ignores that the UK left the Union; the company is no longer established in the EU, so it is not bound as a Member State organisation, even though extraterritorial reach can still apply.
Why C is wrong: This is tempting on a territorial reading, but EU law expressly reaches certain processing by controllers outside the Union, so it is wrong to say EU law can never apply.
Why D is correct: The EU GDPR has extraterritorial scope, so a non-EU controller that offers goods or services to, or monitors the behaviour of, people in the Union remains within its reach despite Brexit.
Examworthy is not affiliated with or endorsed by IAPP. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIPP-E and related marks belong to their respective owners.