Browse all practice questions for the IAPP Certified Information Privacy Professional/Europe (CIPP/E) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CIPP/E Practice Test 2026 – Complete Guide for Exam Preparation course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which institution is regarded as the EU's main legislative body?
  • How should organizations manage requests from data subjects?
  • According to GDPR, when is consent not needed for direct marketing?
  • What is a requirement for the information provided when collecting personal data directly from the data subject?
  • A data subject may object to the processing of personal data for which categories?
  • The right to be forgotten is part of which data subject right?
  • Which of the following should NOT be included in a processor contract?
  • The Universal Declaration of Human Rights is a product of which institution?
  • Which of the following criteria determines the territorial scope of the GDPR?
  • Which of the following is not considered a data protection consideration when collecting personal data via CCTV?
  • What mechanism facilitates a collaborative process between supervisory authorities and the European Data Protection Board for consistent GDPR application?
  • Which of the following is NOT a mechanism for GDPR enforcement?
  • True or false: A contract protects a processor from being held to the same legal obligations as the controller.
  • What role does the Data Protection Officer (DPO) play according to the GDPR?
  • What is an example of direct marketing?
  • Which of the following rights do individuals have under the GDPR regarding their personal data?
  • In what scenarios can personal data be processed without consent?
  • What is the concept of 'data protection by default'?
  • True or false: A data protection officer is required to be an expert in data protection law and practices?
  • What type of measures must be implemented to protect personal data according to the regulations?
  • What does the "one-stop-shop" mechanism allow organizations to do in the EU?
  • What does the term 'pseudonymization' mean?
  • Which of the following is a requirement for private sector surveillance compliance?
  • What is essential for organizations when collecting personal data under GDPR?
  • What is the principle of data minimization under the GDPR?
  • Which of the following data subject rights provides individuals with entitlements to specific information from the controller upon request?
  • What role does the European Data Protection Board (EDPB) play?
  • What must be provided to data subjects when the personal data will be processed and was collected indirectly?
  • How can organizations demonstrate compliance with GDPR?
  • Which GDPR principles were violated when a control system was misused for unauthorized employee monitoring?
  • What does CIAR stand for in the context of data protection?
  • What must organizations provide to data subjects as per GDPR?
  • How should data breaches be documented according to GDPR?
  • Which of the following types of personal data elements belong to special categories under the GDPR?
  • What must organizations do in case of a data breach?
  • Which exception to the prohibition on processing special categories of data must be explicit?
  • Which of the following must be true regarding surveillance conducted by private sector entities?
  • What role do contracts play in data processing under GDPR?
  • What role does the Court of Justice of the EU play in the legal system?
  • What are the legal grounds for processing personal data under GDPR?
  • Which type of data subjects' rights is typically required to be shared during data processing?
  • What does data minimization in GDPR require?
  • What is a Data Protection Impact Assessment (DPIA)?
  • What qualifies as "sensitive personal data" under GDPR?
  • What is the maximum fine for non-compliance with GDPR?
  • A processor may process personal data only on what type of instructions?
  • What obligation does GDPR impose on organizations regarding data breaches?
  • What is the main role of the European Commission?
  • What are the consequences of failing to provide data subject rights?
  • Which is NOT a compatible purpose for processing data beyond the purpose originally specified at the time of collection?
  • What constitutes a high-risk processing activity under GDPR?
  • What is a key part of the equation when assessing risk?
  • What information is necessary to provide to data subjects when their personal data will be shared with an outside organization for a service?
  • What obligations do organizations have regarding technical and organizational measures under GDPR?
  • True or False: Personal data either belongs to special categories or does not. There is no grey area.
  • What is the essential purpose of a privacy notice?
  • What does "privacy by design" refer to within the context of the GDPR?
  • What does the term "data subject" refer to under GDPR?
  • Which type of data subject is NOT covered by the GDPR?
  • Are individuals allowed an absolute right to object to any form of direct marketing under GDPR?
  • According to GDPR, what is the definition of a 'controller'?
  • What is the commonly used legitimate processing criterion when a customer purchases a good or service?
  • What approach is suggested for protecting employment data held by an organization?
  • What is the impact of GDPR on companies outside the EU?
  • What principle does GDPR support regarding personal data and location tracking?
  • True or False: Data protection by design begins prior to processing and incorporates data protection considerations into the planning phase.
  • In risk management, expected loss is primarily associated with which of the following aspects?
  • According to the GDPR, the right to data portability applies:
  • Which treaty enabled the establishment of the GDPR and the Data Protection Directive as harmonization measures for European member states?
  • Which of the following is NOT a valid reason for processing personal data under GDPR?
  • Under which condition is processing sensitive employee data acceptable?
  • When is an organization required to conduct a Data Protection Impact Assessment (DPIA)?
  • What recourse do individuals have if their rights under GDPR are violated?
  • True or False: A processor may decide where and how to process personal data.
  • Which of the following data protection milestones is a treaty among member states of the Council of Europe?
  • Are exclusions to the material scope of GDPR interpreted broadly?
  • Why is documentation critical for GDPR compliance?
  • Which of the following is NOT classified as a special category of data under the GDPR?
  • Along with legitimacy, what is another condition that must be met when carrying out employee monitoring?
  • Which types of data does the ePrivacy Directive specifically govern the processing of?
  • Which characteristic describes the European Council?
  • What does the Council of the EU primarily handle?
  • What action must organizations take if a data breach occurs under the GDPR?
  • What is the primary purpose of the General Data Protection Regulation (GDPR)?
  • True or False: Anonymising personal data is always possible.
  • Under the GDPR, how are breaches in data protection generally classified?
  • What is consent withdrawal under GDPR?
  • What are the key principles of data protection under the GDPR?
  • What is meant by the concept of "data minimization"?
  • What must a controller do if they process data for direct marketing purposes?
  • What are potential solutions to lengthy privacy notices?
  • Which of the following statements accurately reflects the need for management buy-in in data security?
  • Under GDPR, what is required for obtaining valid consent?
  • When is a controller required to notify the supervisory authority of a loss of personal information that could harm an individual?
  • Do BYOD policies aim to protect employees' personal data?
  • Which right allows data subjects to request that their data be deleted?
  • Which phrase correctly completes the statement about implementation costs in Article 32?
  • What is true for a contract based on European Commission Standard Contractual Clauses with a processor outside the European Economic Area?
  • What is the significance of Article 30 in GDPR?
  • What principle requires that personal data must be processed lawfully, fairly, and transparently?
  • How can individuals exercise their 'right to object' under GDPR?
  • Which of the following is NOT a method for restricting processing of personal data according to GDPR?
  • What is data processing?
  • What is the main purpose of GDPR?
  • How is "personal data" defined under GDPR?
  • What must be provided to employees when processing their personal data?
  • Which of the following is not required to be included in information provided to data subjects?
  • Why do BCRs prohibit the transfer of employee names to telecom providers?
  • What type of data is subject to special protections under GDPR?
  • Which principle requires that personal data must be processed lawfully, fairly, and in a transparent manner?
  • Regarding the transparency principle in privacy notices, which statement is accurate?
  • Which of the following must be recorded by controllers but not by processors regarding personal data processing?
  • What rights do data subjects have under GDPR?
  • What does the "right to data portability" enable data subjects to do?
  • What role do supervisory authorities play under the GDPR?
  • Which characteristic describes the European Commission?
  • How is an employer obliged to proceed before engaging in the general monitoring of email traffic and internet use of all of its employees?
  • Is it true that under the GDPR, controllers must always contact the supervisory authority following a DPIA?
  • Which institution holds the power to shape the legislative agenda of the EU?
  • What does 'legitimate interests' refer to in data processing?
  • Which of the following is a core principle of GDPR?
  • The GDPR requires that the data controller notify the supervisory authority of a personal data breach unless:
  • Under the GDPR, would a European company be allowed to use video surveillance to monitor employee access to inventory?
  • Are the criteria for derogations in the GDPR strictly interpreted?
  • Is the statement true or false: The ePrivacy Directive governs data processing by both private and public carriers?
  • Which institution is responsible for ensuring that directives are implemented properly by the member states?
  • Which entity is responsible for enforcing GDPR compliance in the EU?
  • Which of the following is considered personal data under GDPR?
  • What is the GDPR's stance on consent for data processing?
  • Which items must be included in a processor contract?
  • True or false: When personal data is being processed, there is always a controller.
  • What is the significance of "privacy by design"?
  • Which channel of direct marketing requires opt-in consent under GDPR?
  • Which element must a data processing agreement include under GDPR?
  • When assessing data processing, how is 'legitimate interest' typically viewed?
  • Which of the following is a right granted to data subjects under GDPR?
  • Which institution has the authority to adopt adequacy findings for the European Union?
  • What information must be provided to data subjects when their personal data will be stored in a database hosted in the United States?
  • Are employers sometimes required to consult with works councils or trade unions to process employee's personal data?
  • Which of the following best describes the role of supervisory authorities under GDPR?
  • Which of the following is NOT a right under GDPR?
  • Which data protection milestone applies to public electronic communications services and networks?
  • How long can personal data be retained under GDPR?
  • Which option refers to a determination by the European Commission that a third country has achieved an EU-level of personal data protection?
  • What is a responsibility of the Data Protection Officer in an organization?
  • How is "profiling" defined in terms of personal data?
  • How should data breaches be reported according to GDPR?
  • What is a Data Subject Request (DSR) under GDPR?
  • In what order should options for cross-border data transfers be considered?
  • True or false: Pseudonymous data is protected by the GDPR.
  • What is the 'accountability principle' in GDPR?
  • Can organizations transfer personal data to third countries outside the EU?
  • According to the GDPR, which consideration is NOT required to determine appropriate technical and organizational measures for data security?
  • What is the current status of notification requirements under the GDPR?
  • Which of the following principles is crucial for the security of personal data under GDPR?
  • Which characteristic describes the European Parliament?
  • When the controller's necessity is the legal basis for processing, what must be provided to the data subjects?
  • What is the role of a Data Protection Officer (DPO) under GDPR?
  • What is one of the main purposes for appointing a Data Protection Officer?
  • Which European institution is composed of 47 member states?
  • What is the primary responsibility of a Data Protection Officer (DPO)?
  • Which of the following can be classified as non-personal data under GDPR?
  • How long can personal data be kept under GDPR?
  • Which document outlines cross-border data transfer rules according to GDPR?
  • What is the primary objective of GDPR?
  • What additional information must be included in processing records maintained by the data controller under GDPR?
  • Which of the following does NOT need to be included in the data protection policy?
  • What falls under the material scope of the GDPR?
  • Which entity is primarily responsible for enforcing GDPR compliance?
  • Which mechanism facilitates the provision of relevant information between supervisory authorities?
  • How is "consent" defined under GDPR?
  • In the context of GDPR, what does the term "third-party" refer to?
  • What is the definition of profiling in the context of GDPR?
  • What law governs the transfer of personal data outside the European Economic Area (EEA)?
  • Under what condition must a controller notify the supervisory authority of a personal data breach?
  • What does the principle of 'data minimization' require?
  • Is the following statement true or false: Under GDPR, web cookies are considered personal data while IP addresses are not.
  • What is the purpose of a Data Protection Impact Assessment (DPIA)?
  • Which is the most accurate statement concerning the obligations imposed by the GDPR?
  • Which of the following is a key component of GDPR compliance?
  • True or false: Organizations must implement the Privacy Shield principles annually.
  • What does "transparency" under the GDPR framework imply for organizations?
  • A processor is responsible for implementing measures to keep personal data secure. True or False?
  • What does GDPR stand for?
  • What is required for valid consent under GDPR?
  • What are the main values of a Data Protection Impact Assessment (DPIA)?
  • What is the 'right to erasure' also known as?
  • True or false: A data controller may be a natural person or a legal entity, while a data processor must be a legal entity.
  • What is a 'data breach' under GDPR?
  • What does the term "processing" encompass under GDPR?
  • Under GDPR, what is the "right to be forgotten"?
  • The right of access grants data subjects access to which types of information?
  • Which appropriate safeguard allows large multinational companies to adopt a policy suite with rules for handling personal data?
  • Does the GDPR mandate a data protection policy to be used when it is proportionate to processing activities?
  • Which aspect of GDPR focuses on accountability for data processing activities?
  • What information must be provided to data subjects in all circumstances?
  • Which of the following are requirements under the EU-US Privacy Shield? Select all that apply.
  • How many of the legitimate processing criteria must be met for personal data to be processed legally under GDPR?
  • Which criteria are used to identify personal data?
  • What is required by the Sarbanes-Oxley Act (SOX) for companies regarding complaints about potential wrongdoing?
  • What is a required element for a GDPR compliant data processing agreement?
  • Which measures serve as appropriate safeguards for cross-border data transfers? Select all that apply.
  • What is the primary goal of data protection regulations such as GDPR?
  • When processing employees' personal data, which types of laws should be considered?
  • Which countries have been deemed adequate by the European Commission? Select all that apply.
  • Which is an example of cloud computing?
  • Which characteristic describes the Court of Justice of the EU?
  • What is the purpose of the "right to access" for data subjects?
  • Who is tasked with promoting monitoring and enforcing the GDPR?
  • Which of the following should be considered for a holistic approach to data security?
  • Which of the following is true regarding employee monitoring under GDPR?
  • What is the main purpose of the mutual assistance mechanism under GDPR?
  • What should be included in a privacy notice?
  • Is it true that information provided to data subjects about the processing of their personal data should be clear and understandable?
  • Is it true that information provision should happen within a reasonable timeframe after indirect collection?
  • The ePrivacy Directive 2002/58/EC states which provision regarding cookies?
  • True or False: The most cutting-edge security is always the best choice for optimal security measures.
  • How many active participants are expected in the European Data Protection Board?
  • True or False: Both controllers and processors have accountability obligations under GDPR.
  • Which of the following represents a breach of the GDPR related to personal data processing?
  • A controller must notify the data subjects of a personal data breach if the breach is likely to result in a high risk to the rights and freedoms of those individuals unless what condition is met?
  • What is purpose limitation in the context of GDPR?
  • True or false: Information provision is required even if it entails disproportionate effort.
  • Can a controller charge an administrative fee for providing information in oral format to data subjects?
  • Which of the following is a key aspect of binding corporate rules?
  • According to Article 32, what must the Controller and the processor implement?
  • In which situation is a Data Protection Officer required to be appointed?
  • Which principle emphasizes the accuracy of personal data under GDPR?
  • Which characteristic describes the Council of the EU?
  • When does an organization need to legitimize cross-border transfers of personal data according to GDPR?
  • What is the role of a 'processor' under GDPR?
  • What is the role of 'intention to transfer data internationally' in data transparency?
  • In a layered privacy notice, where would one find a full version of the privacy notice?
  • What is the function of the 4 step test?
  • Should privacy notices utilize visualization where appropriate?
  • What is the maximum fine for non-compliance with GDPR?
  • What characterizes the nature of risk assessment in data protection?
  • Which exemption to the e-Privacy Directive 2002/58/EC allows the data controller to send electronic marketing information?
  • Which circumstances require an organization to appoint a Data Protection Officer (DPO)? Select all that apply.
  • Which of the following is a key element of the accountability principle under the GDPR?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy