Free CIPP-E Practice Test Questions and Answers (2026)
Last Update Check
Q: 1
In the event of a data breach, which type of information are data controllers NOT required to provide
to either the supervisory authorities or the data subjects?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Which sentence best describes proper compliance for an international organization using Binding
Corporate Rules (BCRs) as a controller or processor?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
A mobile device application that uses cookies will be subject to the consent requirement of which of
the
following?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
What is the MAIN reason GDPR Article 4(22) establishes the concept of the “concerned supervisory
authority”?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending
any future European Commission decision to the contrary?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Under Article 9 of the GDPR, which of the following categories of data is NOT expressly prohibited
from data processing?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Based on GDPR Article 35, which of the following situations would trigger the need to complete a
DPIA?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
What was the aim of the European Data Protection Directive 95/46/EC?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
According to Article 14 of the GDPR, how long does a controller have to provide a data subject with
necessary privacy information, if that subject’s personal data has been obtained from other sources?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
In which situation would a data controller most likely be able to justify the processing of the data of a
child without parental consent?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified
by Article 3?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data
protection, while Frank is a lecturer in the engineering department. The University maintains a
number of types of records:
Student records, including names, student numbers, home addresses, pre-university information,
university attendance and performance records, details of special educational needs and financial
information.
Staff records, including autobiographical materials (such as curricula, professional contact files,
student evaluations and other relevant teaching files).
Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of
degrees. These records are available to former students after registering through Granchester’s
Alumni portal. Department for Education records, showing how certain demographic groups (such as
first-generation students) could be expected, on average, to progress. These records do not contain
names or identification numbers.
Under their security policy, the University encrypts all of its personal data records in transit and at
rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in
relational to Department for Education expectations. He has attended one of Anna’s data protection
training courses and knows that he should use no more personal data than necessary to accomplish
his goal. He creates a
program that will only export some student data: previous schools attended, grades originally
obtained, grades currently obtained and first time university attended. He wants to keep the records
at the individual student level. Mindful of Anna’s training, Frank runs the student numbers through
an algorithm to transform them into different reference numbers. He uses the same algorithm on
each occasion so that he can update each record over time.
One of Anna’s tasks is to complete the record of processing activities, as required by the GDPR. After
receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank
informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this
new use
of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be
carried out before the data processing can take place. Anna arranges to discuss this further with
Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop
(which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it
on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he
needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Before Anna determines whether Frank’s performance database is permissible, what additional
information does she need?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German
metropolitan cities. However, after a recent merger with another German-based company that was
selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider
audience. These efforts included a complete redesign of its logo to reflect the recent merger, and
improvements to its website meant to capture more information about visitors through the use of
cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While
Germany continued to host T-Craze’s headquarters and main product-design office, its French
affiliate became responsible for all marketing and sales activities. The French affiliate recently
procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its
latest marketing campaign. After thorough research, Right Target determined that T-Craze is most
successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university
students in several European capitals, which yielded nearly 40% new customers for T-Craze in one
quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe
requests, including a large number in Spain. In fact, the Spanish data protection authority received a
complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing
communication even after unsubscribing from such communications from the Right Target on behalf
of T-Craze.
Why does the Spanish supervisory authority notify the French supervisory authority when it opens
an investigation into T-Craze based on Sofia’s complaint?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
What is the key difference between the European Council and the Council of the European Union?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
Which aspect of the GDPR will likely have the most impact on the consistent implementation of data
protection
laws throughout the European Union?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Which EU institution is vested with the competence to propose new data protection legislation on its
own initiative?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Which of the following demonstrates compliance with the accountability principle found in Article 5,
Section 2 of the GDPR?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
A well-known video production company, based in Spain but specializing in documentaries filmed
worldwide, has just finished recording several hours of footage featuring senior citizens in the streets
of Madrid. Under what condition would the company NOT be required to obtain the consent of
everyone whose image they use for their documentary?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
What is true of both the General Data Protection Regulation (GDPR) and the Council of Europe
Convention 108?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20