Free CIPP-E Practice Test Questions and Answers (2026)

Last Update Check

View Mode
Q: 1
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
Options
12 comments in the community discussion
1
A
1
Totally makes sense to me that it's A. The predicted consequences do need to be reported, but only the likely ones, not speculative predictions. GDPR lists specific info you have to provide, and while measures and DPO contacts are required, they never mention you must report all possible predicted fallout. I think this
Q: 2
Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?
Options
13 comments in the community discussion
1
I get what you're saying Alex. I'd pick C for this.
1
I remember a similar scenario from labs and picked C. My logic was that employees should follow the privacy rules of where they're working, since sometimes local law can override BCRs. Maybe I'm mixing up BCR scope with local compliance requirements though. Happy to hear if I'm missing something here!
Q: 3
A mobile device application that uses cookies will be subject to the consent requirement of which of the following?
Options
20 comments in the community discussion
1
Always so much talk about A, but honestly B tbh. The E-Commerce Directive covers online services so it feels like apps with cookies would fall under it too.
1
Why do so many pick B here? Only A (ePrivacy Directive) actually covers cookie consent on apps, B is just online services. Doesn't seem like a close call.
Q: 4
What is the MAIN reason GDPR Article 4(22) establishes the concept of the “concerned supervisory authority”?
Options
12 comments in the community discussion
1
Seriously, I wish IAPP would stop making these options so similar to real exam trip-ups. D.
1
Probably D, since B is a bit of a trap. It's about representing data subjects outside the lead authority's area.
Q: 5
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?
Options
18 comments in the community discussion
1
Its D, seen similar wording in official guide and practice exams.
D imo
Q: 6
Under Article 9 of the GDPR, which of the following categories of data is NOT expressly prohibited from data processing?
Options
22 comments in the community discussion
2
Option C makes sense here. Article 9 lists out the special categories like health, biometric, union membership etc, but financial data doesn't fall under those strictly prohibited types. Still protected by GDPR generally but not as a special category. I think C is right but open to other views if I've missed somethi
1
C imo, financial data isn’t a special category under Article 9-trick option since it sounds sensitive.
Q: 7
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
Options
11 comments in the community discussion
3
C. but if the dating app wasn’t using third-party data for profiling, it might not hit that DPIA threshold. Anyone else think adding third-party sources is what actually flips this into high risk under Article 35?
1
Its C for this one. Building a dating app that profiles users based on both location and third-party data definitely hits the "systematic and extensive evaluation" requirement in Article 35. That combo is high risk for privacy, so a DPIA would be needed. Pretty sure A and B aren't quite there legally but correct me if
Q: 8
What was the aim of the European Data Protection Directive 95/46/EC?
Options
19 comments in the community discussion
1
D , had something like this on a mock and D was correct there as well.
1
D is what the official text and guide both point to. Practice exams cover this exact aim for the Directive too.
Q: 9
Under Article 30 of the GDPR, controllers are required to keep records of all of the following EXCEPT?
Options
11 comments in the community discussion
1
I was leaning toward B because data mapping isn't always specifically listed in Article 30, but thinking about it more, controllers do need to document categories of data and recipients. Not too confident here though, the wording is tricky.
A Article 30 doesn’t require keeping breach records specifically, only processing activities. That’s outlined separately under Article 33 I think. Disagree?
Q: 10
According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject’s personal data has been obtained from other sources?
Options
18 comments in the community discussion
6
Option C
6
C . Official text and most practice tests point to that one, worth double-checking those resources for GDPR timing specifics.
Q: 11
In which situation would a data controller most likely be able to justify the processing of the data of a child without parental consent?
Options
8 comments in the community discussion
1
Probably B. GDPR Recital 38 specifically allows preventive or counselling services to be provided to a child without needing parental consent.
I don’t think it’s C. B is more likely since GDPR Recital 38 specifically allows processing for preventive or counselling services without parental consent. Market research or legit interest (D) is a common trap here. Anyone see a reason it’d be C?
Q: 12
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?
Options
4 comments in the community discussion
B tbh, that's the core extraterritorial scenario GDPR covers when a non-EU org processes EU citizens' data. Makes sense per Article 3.
Nice clear scenario, B is right.
Q: 13
SCENARIO Please use the following to answer the next question: Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records: Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information. Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files). Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees. These records are available to former students after registering through Granchester’s Alumni portal. Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers. Under their security policy, the University encrypts all of its personal data records in transit and at rest. In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna’s data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna’s training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time. One of Anna’s tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database. Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research. Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time. Before Anna determines whether Frank’s performance database is permissible, what additional information does she need?
Options
6 comments in the community discussion
1
I’d say D here. What students have been told and how the research will be used ties directly to transparency and lawful basis under GDPR. Without that info, you can't assess if they're compliant. Pretty sure that's what matters most for permissibility.
1
Its C, right? I thought the masking algorithm would be most important here. Not sure, can someone confirm?
Q: 14
SCENARIO Please use the following to answer the next question: T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies. T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze’s headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success. The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze. Why does the Spanish supervisory authority notify the French supervisory authority when it opens an investigation into T-Craze based on Sofia’s complaint?
Options
3 comments in the community discussion
7
Option C fits here. The French affiliate runs all marketing and sales, so under GDPR, the French supervisory authority is the lead for those processing activities. That’s why Spain notifies France if it opens an investigation about marketing to Spanish users. Pretty sure that’s how the one-stop-shop mechanism works. Le
1
Makes sense to pick C. Since all marketing and sales for T-Craze run through the French affiliate, France acts as the main establishment under GDPR's one-stop-shop. The Spanish authority is just keeping the lead authority in the loop, I think. Correct me if I'm missing something.
Q: 15
What is the key difference between the European Council and the Council of the European Union?
Options
6 comments in the community discussion
1
Its D, European Council has the heads of each EU country. That’s a common fact in the official guide and pops up in a lot of practice tests too. Pretty clear split, but correct me if I’m off.
D on this one. The big difference is who's sitting at the table: European Council is all heads of state, Council of the EU is ministers. Pretty sure that's what they're looking for here, not legislative role. Let me know if you see it different.
Q: 16
Which aspect of the GDPR will likely have the most impact on the consistent implementation of data protection laws throughout the European Union?
Options
3 comments in the community discussion
1
B is the way to go here. Since GDPR is a Regulation, it applies directly in all EU member states without them having to pass national laws first, which wasn't the case with Directives. That creates real consistency across countries. The other options are important, but none guarantee uniform implementation like this. P
Likely it's B here, not A. Regulation has direct effect, unlike a Directive, so that's key for harmonization.
Q: 17
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?
Options
4 comments in the community discussion
Not quite B-a lot of people mix this up. C (European Commission) is the only one that can initiate new laws here.
C Had something like this in a mock, Commission is the one that proposes legislation in the EU.
Q: 18
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?
Options
5 comments in the community discussion
2
Option B
1
Feels like B, I've seen similar practice questions match this from the official guide and some mock exams.
Q: 19
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?
Options
8 comments in the community discussion
1
Had something like this in a mock, legit interest under D is the exception for journalistic work here.
If it's considered journalistic or artistic, legit interest applies. D
Q: 20
What is true of both the General Data Protection Regulation (GDPR) and the Council of Europe Convention 108?
Options
3 comments in the community discussion
B
Nice, that's D. Similar question popped up in some official practice material. Both frameworks require notifying a supervisory authority when processing personal data. Would your answer change if the question said "only ongoing notification required" instead of just "notification"?
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top