Free CIPP/E Practice Questions
Last reviewed: · By Victor Humenhuk (CIPP/E certified)
20 free CIPP/E practice questions written by a certified privacy professional, covering all the main areas of the European data protection exam. Every question is scenario-based, just like the real thing, and comes with a full explanation of the correct answer and why each wrong option fails. No signup needed - work through them at your own pace and follow the links to revise any topic you miss.
All 20 questions are original and free - no signup. Work through them, then check each answer. When you are ready for more, the full question bank has every topic covered, or start with the complete study guide.
Foundations of European Data Protection Law
Q1. A policy adviser in a South American country wants her government to join a legally binding international data protection treaty that is open to countries outside Europe. Which instrument should she recommend?
- The OECD Privacy Guidelines of 1980
- Council of Europe Convention 108
- The EU Charter of Fundamental Rights
- Directive 95/46/EC
Show answer & explanation
Answer: B. Convention 108 (1981) was the first legally binding international data protection instrument, and crucially it is open to accession by states outside the Council of Europe - countries such as Uruguay and Argentina have joined. The OECD Guidelines are influential but non-binding, so they fail the 'legally binding' requirement. The EU Charter binds only EU institutions and member states implementing EU law - a non-European state cannot join it. Directive 95/46/EC was internal EU legislation addressed to member states and has in any case been repealed by the GDPR.
Q2. A journalist believes a member state's intelligence service violated her right to private life under Article 8 of the European Convention on Human Rights. After exhausting domestic remedies, where should she bring her claim?
- The Court of Justice of the European Union in Luxembourg
- The European Data Protection Board
- The European Court of Human Rights in Strasbourg
- The European Commission's enforcement directorate
Show answer & explanation
Answer: C. The European Court of Human Rights in Strasbourg is the Council of Europe court that hears individual applications alleging breaches of the ECHR, including Article 8, once domestic remedies are exhausted. The CJEU in Luxembourg interprets EU law - it does not hear individual complaints under the ECHR, and national security largely falls outside EU competence. The EDPB is a regulatory body issuing guidance and consistency decisions, not a court. The European Commission enforces EU treaties against member states but does not adjudicate individual human rights applications.
Q3. A developer argues that his analytics tool needs no consent for placing identifiers on users' devices because the identifiers are 'completely anonymous' and never linked to a name. Under the ePrivacy Directive, is he right?
- Yes - the ePrivacy rules only apply where personal data is processed
- Yes - analytics tools benefit from an automatic exemption
- No - but consent is only required from users located in the developer's own member state
- No - Article 5(3) protects the terminal equipment itself, so consent is needed whether or not the stored data is personal data
Show answer & explanation
Answer: D. Article 5(3) of the ePrivacy Directive requires consent for storing information or gaining access to information already stored on a user's device, regardless of whether that information is personal data - the provision protects the confidentiality of the terminal equipment itself. The first option repeats exactly the misconception the provision was designed to close. There is no blanket analytics exemption; the only exemptions cover transmission of a communication and services strictly necessary at the user's request. The location-based option is wrong because Article 5(3) has been transposed across every member state - the consent requirement applies to users throughout the EU, not only in the developer's home country.
Related note: Privacy and Electronic Communications (ePrivacy) Directive →
Q4. A newly hired analyst in the counter-fraud unit of a Rotterdam insurance company assumes the unit's work - analysing claims to detect fraudulent ones, occasionally passing files to the police - is governed by the Law Enforcement Directive, 'because it's all about detecting crime'. Is he correct?
- No - the LED applies only to processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences; a private insurer investigating fraud for its own purposes processes under the GDPR
- Yes - any processing whose purpose is detecting criminal offences falls under the LED, whoever carries it out
- Yes - but only once the unit registers with the national police as a recognised data intermediary
- No - because the LED was repealed when the GDPR came fully into force in 2018
Show answer & explanation
Answer: A. The Law Enforcement Directive (Directive (EU) 2016/680) is the criminal-justice regime, and it has two limbs: the processing must be for law-enforcement purposes AND carried out by a competent authority - police, prosecutors and similar bodies. A private insurer protecting itself against fraudulent claims satisfies neither the actor requirement nor the public-function test, so its processing sits squarely under the GDPR (typically on the legitimate interests basis), even though crime is the subject matter. The second option ignores the competent-authority limb - purpose alone does not trigger the LED. The third invents a registration scheme that exists nowhere in the Directive. The fourth is doubly wrong: the LED was not repealed by the GDPR - the two were agreed together in 2016 as a package, and the LED, being a directive, required member states to transpose it into national law by 6 May 2018.
Personal Data, Scope, Principles and Lawful Bases
Q5. A Canadian online homeware retailer with no EU presence runs a website in French and German, quotes prices in euros, and offers delivery to Belgium and Austria. A Belgian customer places an order. Does the GDPR apply to the retailer's processing of her data?
- No - the GDPR only applies to companies established in the EU
- No - because the contract is concluded under Canadian law
- Yes, under Article 3(2)(a), because the retailer is manifestly offering goods to data subjects in the Union
- Yes, but only if the retailer processes data of more than 5,000 EU residents per year
Show answer & explanation
Answer: C. Article 3(2)(a) extends the GDPR to non-EU controllers who offer goods or services to data subjects in the Union, and the classic indicators of 'targeting' are all present: EU languages, euro pricing and delivery to member states. The first option ignores the GDPR's deliberate extraterritorial reach. The governing law of the sales contract is irrelevant to the regulatory question, so the second fails. The fourth invents a numerical threshold - Article 3(2) contains no minimum volume of data subjects; even a single targeted EU customer suffices.
Related note: Article 3(2): the targeting and monitoring tests →
Q6. An airline collected passport details to fulfil bookings. Its marketing team now wants to use the same details to build detailed traveller profiles for sale to hotel chains. Which Article 5 principle is most directly engaged?
- Accuracy
- Purpose limitation
- Storage limitation
- Integrity and confidentiality
Show answer & explanation
Answer: B. Purpose limitation (Article 5(1)(b)) requires that data collected for specified, explicit and legitimate purposes not be further processed in a manner incompatible with those purposes - selling booking data to third parties for profiling is a textbook incompatible further use, absent a compatibility assessment, fresh consent or another lawful gateway. Accuracy concerns keeping data correct and up to date, which is not the issue here. Storage limitation concerns how long data is kept, not what it is reused for. Integrity and confidentiality concerns security against unauthorised access or loss, not deliberate repurposing by the controller itself.
Q7. A recipe website shows a banner stating: 'By continuing to use this site you accept marketing emails from us and our 40 partners.' There is no way to use the site without accepting. Which consent condition is most clearly breached?
- Consent must be given by a person over 18
- Consent must be renewed every 12 months
- Consent must be witnessed in writing
- Consent must be freely given - access to the service cannot be made conditional on unnecessary consent
Show answer & explanation
Answer: D. Article 7(4) and the EDPB's guidance make clear that consent is not freely given where access to a service is bundled with consent to processing that is not necessary for that service - a take-it-or-leave-it wall for marketing from 40 partners is coercive conditionality, and 'continuing to browse' is not an unambiguous affirmative act either. The first option is wrong because the GDPR sets no general age of 18 for consent; the child-consent rule for information society services is 16 (which member states may lower to 13). There is no fixed 12-month renewal rule in the GDPR. Nor is written or witnessed form required - consent can be given by any clear affirmative act.
Related note: Freely given consent - bundling, imbalance, cookie walls →
Q8. A boutique gym wants members to record injuries and medical conditions in its app so trainers can adapt workouts. Which is the most appropriate way to lift the Article 9 prohibition on processing this health data?
- Obtain the member's explicit consent to processing the health information for that purpose
- Rely on legitimate interests, since safer training benefits everyone
- Rely on the vital interests condition, since injuries relate to health
- No condition is needed because members volunteer the information themselves
Show answer & explanation
Answer: A. Health data is special category data under Article 9(1), and processing is prohibited unless one of the Article 9(2) conditions applies; for a commercial fitness service, explicit consent under Article 9(2)(a) is the realistic gateway. Legitimate interests is an Article 6 basis only - it appears nowhere in Article 9 and cannot lift the prohibition. Vital interests under Article 9(2)(c) is confined to situations where the data subject is physically or legally incapable of consenting, such as a medical emergency - not routine workout planning. And volunteering data does not disapply Article 9; the 'manifestly made public' condition requires deliberate publication to the world at large, not disclosure within an app.
Q9. A Toulouse medical-research charity prepares a dataset for a university partner. Names and patient numbers are stripped out, but each record keeps the patient's full date of birth, five-digit postcode and diagnosis - including several rare conditions affecting only a handful of people nationally. The project lead declares: 'There are no identifiers left, so the GDPR no longer applies.' Is she right?
- Yes - once direct identifiers such as names are removed, a dataset is anonymous by definition
- Yes - provided the university signs a contract promising never to attempt re-identification
- No - any dataset that was ever derived from personal data remains personal data permanently, whatever is removed
- No - under the Recital 26 test the data remain personal if individuals can be identified by means reasonably likely to be used, and combining birth date, postcode and a rare diagnosis can single people out
Show answer & explanation
Answer: D. Identifiability is judged under Recital 26: take account of all the means reasonably likely to be used to identify a person, considering cost, time and available technology. Identification can be indirect - piecing together data points that individually identify nobody, known as jigsaw identification. A full date of birth, a postcode and a rare diagnosis are classic quasi-identifiers: for a rare condition that combination can point to a single individual, so the dataset is at best pseudonymised-style de-identified data and remains personal data within the GDPR. The first option confuses removing direct identifiers with anonymisation - indirect identification counts too. The second fails because a contractual promise does not change what the data are: if identification remains reasonably likely, the GDPR applies regardless of what the recipient undertakes (though such a contract may be a sensible safeguard). The third overshoots in the other direction - genuinely anonymised data, for example irreversibly aggregated statistics, do fall outside the GDPR; the problem here is the residual identifiability, not some permanent taint.
Related note: Identifiability, Anonymisation and Pseudonymisation →
Transparency and Data Subject Rights
Q10. A car insurer buys prospect lists from a data broker on 1 March and plans to start postal marketing to those individuals on 20 May. It has no earlier contact with them. By when must it provide the Article 14 privacy information?
- By 20 May, whenever the marketing letters are actually sent
- Within 72 hours of receiving the list
- By 1 April - within one month of obtaining the data
- Only if a data subject asks where their data came from
Show answer & explanation
Answer: C. Where data is not obtained from the data subject, Article 14(3) requires the information within a reasonable period and at the latest within one month of obtaining the data - here, by 1 April. If the data is used to communicate with the individual sooner, the information must accompany that first communication, but the insurer cannot wait until 20 May because the one-month backstop expires first. The 72-hour period belongs to breach notification under Article 33, not transparency. And transparency is a proactive duty - it is not triggered only by a data subject's request, so the final option fails.
Q11. On 3 June a bank receives a subject access request from a customer with fifteen years of account history across several systems. The privacy team says the search will genuinely take months. What may the bank lawfully do?
- Take as long as reasonably necessary, provided it keeps the customer informed
- Refuse the request as manifestly excessive because of the volume involved
- Charge a fee proportionate to the search effort and pause the clock until payment
- Respond within one month, or within that month inform the customer it is extending by up to two further months given the complexity
Show answer & explanation
Answer: D. Article 12(3) requires a response within one month, extendable by two further months where requests are complex or numerous - but the controller must tell the data subject about the extension, with reasons, within the first month. There is no open-ended 'reasonable time' allowance, so the first option fails. A request is not 'manifestly excessive' merely because the controller holds a lot of data - that ground targets abusive or repetitive requests, not ordinary large ones. And the first copy must be provided free of charge; fees are only possible for manifestly unfounded or excessive requests or additional copies, and there is no clock-stopping mechanism pending payment.
Q12. A former employee demands that his ex-employer erase every record about him, including payroll records that national tax law requires the company to keep for ten years. How should the company respond?
- Erase everything - the right to erasure is absolute once employment ends
- Erase what is no longer needed, but retain the payroll records because processing remains necessary to comply with a legal obligation
- Refuse the entire request because he was an employee, not a customer
- Transfer the records to the tax authority and then delete them
Show answer & explanation
Answer: B. Article 17 is not absolute: Article 17(3)(b) disapplies erasure where processing is necessary to comply with a legal obligation, such as statutory tax retention periods - so payroll records stay for the mandated period while data with no continuing basis should be erased. The first option overstates the right, which is why it fails. The third fails because data subject rights apply to employees exactly as to anyone else, and the request must be assessed record by record, not rejected wholesale. The fourth is a made-up procedure - the retention obligation rests on the employer, and shipping records to the tax authority neither satisfies it nor complies with data minimisation.
Q13. A user of a fitness platform wants to move to a competitor and asks for 'all her data' under the right to data portability. Her account runs on consent, and processing is fully automated. Which dataset must the platform provide in a structured, machine-readable format?
- The workout logs and profile details she provided, including activity data generated by her use of the service
- Everything the platform holds, including its internal risk scores and derived analytics about her
- Nothing - portability only applies between telecoms providers
- Only data the platform chooses to designate as portable in its terms
Show answer & explanation
Answer: A. Article 20 applies where processing is based on consent or contract and carried out by automated means, and covers data the data subject 'provided' - which the WP29/EDPB interpret to include observed data generated by her activity (workout logs, tracker readings), delivered in a structured, commonly used, machine-readable format. It does not extend to inferred or derived data created by the controller, such as internal scores and analytics, so the second option overshoots. The third invents a sector restriction that does not exist. The fourth fails because the scope of the right is fixed by the Regulation, not by the controller's terms of service.
Q14. An online lender's algorithm automatically declines a loan application with no human involvement, significantly affecting the applicant. The lender relied on the contract-necessity gateway in Article 22(2)(a). What must it still provide to the applicant?
- Nothing further - using a permitted gateway removes all additional obligations
- Safeguards including the right to obtain human intervention, to express her point of view and to contest the decision
- A full copy of the algorithm's source code
- Compensation equal to the value of the declined loan
Show answer & explanation
Answer: B. Even where solely automated decision-making with significant effects is permitted under Article 22(2)(a) or (c), Article 22(3) requires suitable safeguards - at minimum the right to obtain human intervention, to express one's point of view and to contest the decision, alongside meaningful information about the logic involved under Articles 13-15. The first option fails because the gateways permit the processing but do not strip away the safeguards. Transparency obligations cover meaningful information about the logic, significance and envisaged consequences - not disclosure of source code. And no automatic compensation attaches to a lawful automated refusal; Article 82 damages require an infringement causing harm.
Related note: Right not to be subject to solely automated decision-making →
Security, Accountability and International Transfers
Q15. Attackers exfiltrate an online pharmacy's database containing customers' names, medication histories and payment card details, all in plain text. The pharmacy notified its supervisory authority. Must it also tell the affected customers?
- No - notifying the supervisory authority always discharges the controller's breach duties
- Yes - the breach is likely to result in a high risk to individuals, so Article 34 requires communication to them without undue delay
- Only if more than 10,000 customers are affected
- Only if the supervisory authority publishes the breach first
Show answer & explanation
Answer: B. Article 34 requires communication to data subjects without undue delay where a breach is likely to result in a high risk - unencrypted health-related and payment data taken by attackers is a paradigm high-risk case, and telling individuals lets them protect themselves. Notifying the authority under Article 33 is a separate, lower-threshold duty and does not substitute for Article 34, so the first option fails. There is no numerical headcount threshold in the Regulation. And while an authority can order communication, the duty arises from the risk itself - the controller must not wait for regulatory publicity.
Related note: Article 34 - communicating the breach to data subjects →
Q16. A software company's newly appointed DPO reports that a flagship product breaches the GDPR. The chief operating officer, annoyed, proposes moving the DPO to report to the head of marketing and reducing her bonus. Which GDPR protections does this proposal offend?
- None - DPOs are ordinary employees subject to normal management discretion
- Only the rule that DPOs must be lawyers
- The DPO's independence: she must report to the highest management level, receive no instructions on her tasks, and must not be penalised or dismissed for performing them
- The rule that DPOs may only be external consultants
Show answer & explanation
Answer: C. Article 38(3) guarantees that the DPO reports directly to the highest management level, receives no instructions regarding the exercise of her tasks, and is not dismissed or penalised for performing them - demoting her reporting line and cutting her bonus in retaliation for unwelcome advice strikes at all three. The first option ignores these express statutory protections. There is no requirement that a DPO be a lawyer - expert knowledge of data protection law and practice suffices. And Article 37(6) allows the DPO to be either a staff member or an external contractor, so the internal appointment itself is entirely proper.
Q17. A Munich logistics group is contracting with an analytics vendor in Singapore and plans to rely on the Commission's 2021 standard contractual clauses. The group's commercial lawyer wants to shorten the document by deleting the third-party beneficiary clause and softening the audit obligations, arguing that parties to a contract are free to negotiate its terms. Is he right?
- Yes - amendments to the SCCs are valid whenever both parties agree to them in writing
- Yes - amendments are permitted provided the importer holds an ISO 27001 certification covering the data
- No - the SCCs may be embedded in a wider commercial contract and supplemented, but their substance cannot be amended; a cut-down version ceases to be the Commission-approved safeguard and would count as ad hoc clauses needing supervisory authority authorisation
- No - the SCCs may never even be included in a broader contract; they must always be signed as a standalone document
Show answer & explanation
Answer: C. The value of standard contractual clauses is precisely that they are standard: a set of model clauses adopted by the Commission whose protections - including the third-party beneficiary rights that let data subjects enforce the contract, and the audit provisions - come pre-approved as an Article 46 appropriate safeguard. Parties may incorporate them into a wider commercial agreement and add business terms, so long as the additions do not contradict the clauses or reduce data subjects' protections. What they cannot do is edit the substance: deleting or diluting clauses produces a bespoke contract that no longer benefits from Commission approval, leaving the transfer without a valid safeguard unless the parties seek authorisation for ad hoc clauses from the competent supervisory authority. The first option mistakes contractual freedom for regulatory approval - mutual agreement cannot convert negotiated clauses into a pre-approved instrument. The second invents a certification shortcut; security certification is no substitute for a transfer mechanism. The fourth overshoots in the opposite direction - embedding the clauses in a broader contract is expressly permitted.
Related note: Providing adequate safeguards - SCCs and the transfer impact assessment →
Compliance in Practice: Employment, Marketing, Online and Enforcement
Q18. A shop owner installs CCTV covering the till area after a series of thefts, posts clear signage, sets a short retention period and relies on legitimate interests. A customer complains that any camera use requires her consent. Who is right?
- The customer - video surveillance always requires the consent of everyone filmed
- The shop owner - proportionate CCTV for security can rest on legitimate interests, provided the balancing test is met, signage gives transparency and retention is limited
- The customer - CCTV in shops is prohibited under the ePrivacy Directive
- The shop owner - property owners may film without any GDPR obligations on their own premises
Show answer & explanation
Answer: B. The EDPB's Guidelines 3/2019 confirm that security CCTV typically relies on legitimate interests under Article 6(1)(f): a real interest (documented incidents help), necessity (targeted coverage of the till, not blanket surveillance), a balancing test respecting reasonable expectations, layered signage and short retention. Consent from every person filmed is neither required nor workable, so the first option fails. The ePrivacy Directive governs electronic communications services, not shop CCTV. And the fourth option overcorrects - filming customers on business premises is squarely within the GDPR; the household exemption does not cover commercial surveillance.
Related note: Video surveillance (CCTV): lawful basis and proportionality →
Q19. An online stationery shop wants to email past customers about similar new products without fresh consent, using the ePrivacy 'soft opt-in'. Which set of conditions must it satisfy?
- The emails may be sent to anyone whose address was lawfully obtained from any source
- The soft opt-in applies only to business-to-business emails, never to consumers
- It obtained the address in the context of a sale, markets only its own similar products, offered a refusal opportunity at collection, and includes an opt-out in every message
- It registered the campaign with its supervisory authority in advance
Show answer & explanation
Answer: C. Article 13(2) of the ePrivacy Directive permits electronic mail marketing without prior consent only where the sender obtained the contact details from the customer in the context of a sale (or, in some member states, negotiations for one), markets its own similar products or services, gave a clear, free opportunity to refuse when the details were collected, and repeats that opportunity in every message. The first option ignores all four conditions - bought-in lists can never qualify. The second inverts the position: the soft opt-in is precisely the consumer-facing exception, while B2B rules vary by member state. There is no campaign registration requirement anywhere in the regime.
Related note: Marketing by electronic mail and the soft opt-in →
Q20. A social media company has its EU headquarters and decision-making centre for data processing in Ireland, with sales offices in France, Spain and Poland. Users in several member states complain about its news feed algorithm. Under the one-stop-shop, who leads the investigation?
- The Irish supervisory authority, as lead authority for the company's main establishment, cooperating with the other authorities concerned
- The supervisory authority of whichever country received the most complaints
- The European Commission, because the case is cross-border
- Each national authority investigates independently and may reach conflicting decisions
Show answer & explanation
Answer: A. For cross-border processing, Article 56 makes the supervisory authority of the controller's main establishment - where decisions on purposes and means are taken, here Ireland - the lead supervisory authority, acting as sole interlocutor and cooperating with concerned authorities under the Article 60 procedure. Complaint volume does not determine competence, so the second option fails. The Commission has no role in adjudicating individual GDPR enforcement cases; consistency is managed through the EDPB. And the fourth option describes the pre-GDPR fragmentation that the one-stop-shop was expressly designed to end - concerned authorities feed in through cooperation, with EDPB dispute resolution under Article 65 if they disagree.
Related note: Competence, the one-stop shop and the lead supervisory authority →
Unlock the full 1248-question practice bank → See the full study guide