CIPP/E Study Guide
Reference - Numbers cheat-sheet

Reference · Key Articles, thresholds & timeframes cheat-sheet

The single highest-yield recall sheet for the exam: the article numbers, thresholds and timeframes that scenario questions hinge on. Drill these until they are automatic.

Definitions (Article 4) and core concepts
ConceptArticle
Personal dataArt 4(1)
ProcessingArt 4(2)
Restriction of processingArt 4(3)
Controller / ProcessorArt 4(7) / 4(8)
Personal data breachArt 4(12)
Biometric dataArt 4(14)
Cross-border processingArt 4(23)
Principles, lawful bases, scope
TopicArticle
Material scope / Territorial scopeArt 2 / Art 3 (3(1) establishment; 3(2) targeting & monitoring)
The seven principlesArt 5
Six lawful basesArt 6
Conditions for consent / Children's consentArt 7 / Art 8 (16, Member States may lower to 13)
Special-category data / Criminal data / No-ID processingArt 9 / Art 10 / Art 11
Transparency, rights, accountability
TopicArticle
Transparency / Info if collected directly / indirectlyArt 12 / Art 13 / Art 14
Access · Rectification · ErasureArt 15 · 16 · 17
Restriction · Portability · Object · Automated decisionsArt 18 · 20 · 21 · 22
Accountability / DP by design & defaultArt 24 / Art 25
EU representative / Processor contractArt 27 / Art 28
Records of processingArt 30 (threshold: 250 employees, plus other triggers)
Security of processingArt 32 (CIAR)
Breach: notify SA / inform data subjectsArt 33 (72 hours) / Art 34 (high risk)
DPIA / Prior consultationArt 35 / Art 36
DPO (designation, position, tasks)Art 37–39
Transfers, enforcement, money
TopicArticle / figure
International transfersChapter V (Art 44–49)
Adequacy / Appropriate safeguards / BCRs / DerogationsArt 45 / 46 / 47 / 49
Third-country authority ordersArt 48
Representation by bodies / CompensationArt 80 / Art 82
Supervisory-authority powersArt 58 (investigative, corrective, authorisation/advisory)
Administrative fines - two tiersArt 83: €10m or 2% / €20m or 4% (whichever is higher)
Timeframes & dates to lock in
ItemValue
Respond to a data-subject request (access, rectification, etc.)1 month (extendable by 2 for complex requests)
Notify the supervisory authority of a breach72 hours (where feasible)
GDPR fully effective25 May 2018
Certification validityUp to 3 years (renewable)
NIS2 effective17 January 2025
Children's consent age (Art 8)16, Member States may lower to 13

Key terms - quick answers

What is “Chapter V”?
The GDPR chapter (Articles 44–49) governing transfers of personal data to third countries and international organisations.