Certified Information Privacy Professional/Europe · every answer carries the reasoning, and why each
other option fails.
513 questions
9 chapters of notes
EN + ZH languages
Tap an option to see the answer, the reasoning, and why the other three fail.
Question 1 of 10
A U. S. -based pharmaceutical company, Pharma, receives pseudonymised patient information from clinical sites all over the world, including the EU, as part of a clinical trial. How must Pharma process the data?
APharma must de-pseudonymise all data they receive before it can be processed under any jurisdiction.Pseudonymised data is itself a security measure recognised by the GDPR (Art. 4(5), Art. 32); processing does not require mandatory re-identification, which would in fact increase privacy risk.
BPharma can process the data as is because it is part of a clinical trial and will be processed only in the U. S.The location where data is processed does not determine which law applies. As long as the data originates from an EU data subject, the GDPR can still apply, and processing "only in the U.S." cannot be used to exclude the compliance obligation.
CPharma must comply with all applicable privacy laws based on the country where the data subject resides.
DPharma need only comply with the privacy laws concerning data processing that are in effect in the U. S. and the GDPR.Complying only with U.S. law and the GDPR is not sufficient. If data subjects come from jurisdictions outside the scope of the GDPR (such as other countries involved in the clinical trial), the applicable law of that data subject's location must still be complied with.
Why C is correct
Under the GDPR's extraterritorial (territorial) scope rule in Art. 3, data protection obligations do not depend solely on where the controller is located, but on where the data subject resides and the nature of the processing activity. In a multinational clinical trial, even though Pharma is headquartered in the U.S. and the data has been pseudonymised, as long as the processing concerns data subjects located in different jurisdictions, Pharma must comply with the applicable privacy laws of the country where each data subject resides (e.g., GDPR for EU data subjects, local law for data subjects in other jurisdictions). It cannot avoid multi-jurisdictional compliance obligations merely by claiming to process data "only in the U.S." or by pointing to pseudonymisation. Pseudonymisation is distinct from anonymisation: pseudonymised data remains personal data and remains subject to the laws of the relevant jurisdiction.
Question 2 of 10
Failure to provide fair information to data subjects with regards to the processing of their personal data is likely to?
ARequire the processor to obtain a new authorisation to process the data subject’s data.The GDPR does not provide for the institutional consequence that 'the processor must obtain a new authorisation'; the legal effect of inadequate notice is that the processing itself is unlawful, not that a new authorisation procedure is triggered.
BRender the data unusable and require the processor to indefinitely suspend the processing of the data.'Rendering the data unusable and indefinitely suspending processing' is not a statutory consequence the GDPR attaches to a breach of the notice obligation; this option has no legal basis.
CRequire the processor to notify the data subject that their personal data has been permanently deleted.The GDPR does not require notifying the data subject that their data has been 'permanently deleted' due to inadequate notice; this statement conflates the right to erasure (Art. 17) with the information provision obligation, which are distinct regimes.
DRender the processing unfair, as well as constitute a violation of the Regulation’s information provision obligations.
Why D is correct
GDPR Art. 5(1)(a) lists lawfulness, fairness and transparency as one of the core principles governing the processing of personal data, while Art. 12-14 specifically set out the controller's information provision obligations to the data subject. Failing to provide fair information to the data subject not only directly breaches the specific information provision obligations under Art. 12-14, but also causes the processing as a whole to be found unfair for lack of transparency, thereby violating the principled requirement of Art. 5(1)(a) — a double violation, rather than the outcomes described in the other options such as rendering the data unusable or requiring reauthorisation.
Question 3 of 10
Under the GDPR, the copy of personal data provided to data subjects upon exercising their right of access shall:
ABe in a machine-readable formMachine-readable form is a requirement of the right to data portability under Article 20, not a mandatory form for a copy under the right of access in Article 15.
BBe in a human-readable form
CExplain the general logic involved in the decision-making, including profiling, regardless of the type of decision-makingThe obligation to explain the general logic involved in automated decision-making (including profiling) (Article 15(1)(h)) applies only where there is solely automated decision-making as referred to in Article 22(1) and (4); it does not apply to all types of decision-making.
DAlways be provided to data subjects in a commonly used electronic form"Commonly used electronic form" applies only where the data subject makes the request by electronic means and does not otherwise request a different form — it is not mandatory in all circumstances.
Why B is correct
GDPR Article 15(3) provides that the controller shall provide the data subject with a copy of the personal data undergoing processing. This provision does not mandate that the copy be provided in machine-readable form; rather, it requires that the information be provided in an intelligible form, i.e., a human-readable form. The requirement of machine-readable form in a commonly used electronic form falls within the scope of the right to data portability under Article 20, and the two should not be conflated. It is only where the data subject makes the request by electronic means, and unless otherwise requested, that the copy should be provided in a commonly used electronic form — but this is not an absolute requirement in all cases.
Question 4 of 10
When should a data subject be informed where personal data relating them is disclosed to another recipient?
ABefore the personal data is first disclosed to the recipientThe GDPR does not require the controller to notify the data subject in advance, before disclosure, of every specific act of disclosure — the standard timing for the transparency obligation is 'when first disclosed', not prior notice before disclosure.
BWhen the personal data is first disclosed to the recipient
CAfter the personal data is first disclosed to the recipientNotifying only after disclosure does not meet the GDPR's requirement of timely transparency, and may result in delayed protection of the data subject's rights.
DWithin a reasonable period, depending on the circumstances of the caseThe flexible phrase 'within a reasonable period, depending on the circumstances' is not an accurate statement of the GDPR's rule on the timing of notification of recipients upon disclosure — the correct standard is that it should be simultaneous with the first disclosure.
Why B is correct
Under the transparency requirements of GDPR Article 19 and Articles 13(1)(e)/14(1)(e), when personal data is disclosed to a new recipient, the controller should, in principle, inform the data subject of the identity or category of the recipient when the personal data is first disclosed to that recipient, so as to ensure the data subject can promptly understand where their data is flowing and thereby effectively exercise the right to be informed and subsequent rights such as access and rectification. This is a concrete application of the transparency principle in the context of data sharing.
Question 5 of 10
Which one is incorrect about the designation of a DPO under the GDPR?
APublic authorities cannot designate a staff member as the DPO
BA group of undertakings may appoint a single data protection officerArt. 37(2) expressly provides that a group of undertakings may designate a single DPO, as long as that DPO is easily accessible from each establishment. This is a correct statement.
CA single data protection officer may be designated for several authoritiesArt. 37(3) allows several public authorities or bodies, taking account of their organisational structure and size, to jointly designate a single DPO. This is a correct statement.
DDesignation of a DPO is obligatory if the controller carries out regular and systematic large-scale monitoring of data subjectsArt. 37(1)(b) expressly requires the designation of a DPO where the core activities of the controller or processor consist of processing operations which, by virtue of their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale. This is a correct statement.
Why A is correct
Under GDPR Art. 37(1), a public authority or body (except courts acting in their judicial capacity under national law) must designate a DPO, but the GDPR does not prohibit a public authority from designating an internal staff member as the DPO. On the contrary, Art. 37(6) expressly states that the DPO may be a staff member of the controller or processor, or may fulfil the tasks on the basis of a service contract. Therefore the statement that "public authorities cannot designate a staff member as the DPO" is incorrect, making it the answer to this question. B, C, and D are all arrangements permitted under the GDPR: Art. 37(2) allows a group of undertakings to designate a single DPO, Art. 37(3) allows several public authorities to jointly designate one DPO, and Art. 37(1)(b) makes designation of a DPO mandatory where the core activities involve regular and systematic large-scale monitoring of data subjects.
Question 6 of 10
According to the EDPB Guidelines 01/2021 on Examples regarding Personal Data Breach Notification, if exfiltration of job application data (submitted through online application forms and stored on a webserver) resulted in personal information being accessible to unauthorized persons, this would be primarily considered what kind of breach?
AAn integrity breach.An integrity breach refers to unauthorized alteration or tampering of data; here the content of the data was not changed, so this classification does not apply.
BAn accuracy breach.Accuracy is not an independent category within the EDPB's breach classification framework; this term does not fall within any of the three categories.
CAn availability breach.An availability breach refers to loss, deletion, or unlawful deprivation of access to data; here the controller could still access the data normally, it was merely obtained by an unauthorized third party, which is not an availability issue.
DA confidentiality breach.
Why D is correct
EDPB Guidelines 01/2021 classify personal data breaches into three categories: confidentiality breach (unauthorized disclosure of or access to data), integrity breach (unauthorized or accidental alteration of data), and availability breach (loss of or inability to access data). Where exfiltrated job application data resulted in unauthorized persons being able to access that personal information, the data itself was neither altered nor lost, but its confidentiality was compromised, so it should primarily be classified as a confidentiality breach.
Question 7 of 10
How is the retention of communications traffic data for law enforcement purposes addressed by European data protection law?
AThe ePrivacy Directive allows individual EU member states to engage in such data retention.
BThe ePrivacy Directive harmonizes EU member states’ rules concerning such data retention.The ePrivacy Directive does not harmonize member states' data retention rules at the EU level. On the contrary, it leaves the decision of whether and how to retain data to individual member states, resulting in significant differences between national laws.
CThe Data Retention Directive’s annulment makes such data retention now permissible.The annulment of the Data Retention Directive does not mean that data retention has thereby become freely permissible. Member states must still regulate it lawfully in accordance with the ePrivacy Directive and the proportionality requirements established by subsequent case law, rather than allowing unrestricted retention.
DThe GDPR allows the retention of such data for the prevention, investigation, detection or prosecution of criminal offences only.The GDPR primarily governs general personal data processing. The retention of communications traffic data is governed preferentially by the ePrivacy Directive as lex specialis, rather than having its specific retention conditions set directly and exclusively by the GDPR.
Why A is correct
After the Data Retention Directive (2006/24/EC) was declared invalid by the Court of Justice of the European Union (CJEU), the retention of communications traffic data for law enforcement purposes reverted to being governed by the ePrivacy Directive (2002/58/EC). Article 15(1) of the ePrivacy Directive allows member states to adopt national legislation imposing data retention obligations on communications service providers, subject to conditions such as necessity and proportionality, for purposes including national security, defense, public security, and the prevention, investigation, detection and prosecution of criminal offences. This means data retention is not harmonized at the EU level, but rather "allows individual member states to decide, through their own legislation, whether and how to carry out such data retention." Subsequent CJEU case law (such as Tele2/Watson) has further imposed strict proportionality limits on such member state legislation.
Question 8 of 10
Since blockchain transactions are classified as pseudonymous, are they considered to be within the material scope of the GDPR or outside of it?
AOutside the material scope of the GDPR, because transactions do not include personal data about data subjects m the European Union.Pseudonymisation is not the same as anonymisation; transaction records may still allow an EU data subject to be identified by linking additional information, so it cannot simply be assumed that no personal data is involved and thus excluded from scope.
BWithin the material scope of the GDPR to the extent that transactions include data subjects in the European Union.
CWithin the material scope of the GDPR but outside of the territorial scope, because blockchains are decentralized.Material scope and territorial scope are two independent dimensions of analysis; blockchain's decentralized nature has no necessary bearing on whether it falls within territorial scope, and this option conflates the two concepts.
DOutside the material scope of the GDPR, because transactions are for personal or household purposesThe household exemption applies to purely private, non-commercial processing; blockchain transactions involving businesses or platform operations generally do not meet the conditions for this exemption.
Why B is correct
Whether the GDPR's material scope applies depends on whether what is being processed is "personal data" — that is, information that identifies or can identify a natural person — not on whether that data is "pseudonymous." Under Recital 26 and Article 4(1), pseudonymous data remains personal data because re-identification of the data subject may still be possible using additional information; only data that has been truly anonymized to the point where re-identification is no longer possible falls outside the scope of the GDPR. If a blockchain transaction involves a data subject within the EU, then even if information such as public keys or hashes appears anonymous, as long as there is a reasonable possibility of re-identification, it constitutes personal data and falls within the GDPR's material scope.
Question 9 of 10
What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?
AThe establishment of a list of legitimate data processing criteriaEstablishing a list of legitimate data processing criteria was not a shared goal that these three instruments "largely failed" to achieve; while the OECD principles and Convention 108 did set out processing principles, "enumeration in list form" was not their shared core failed goal.
BThe creation of legally binding data protection principlesCreating legally binding data protection principles was not a shared failed goal of the three — Convention 108 itself is binding on contracting states as a treaty, and Directive 95/46/EC was also binding on member states at the directive level, so this statement does not match the facts.
CThe synchronization of approaches to data protection
DThe restriction of cross-border data flowRestricting cross-border data flow was not the goal of these frameworks; on the contrary, the purpose of these frameworks was to promote the free flow of data while protecting privacy, not to restrict flow, so this option contradicts the purpose of the instruments.
Why C is correct
The OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (1980), the Council of Europe's Convention 108 (1981), and the EU Data Protection Directive (Directive 95/46/EC, 1995) shared, among their common goals, the aim of achieving synchronization/harmonization of approaches to data protection across Europe and globally, thereby facilitating the free cross-border flow of personal data while safeguarding fundamental rights. In practice, however — particularly in the era of Directive 95/46/EC — because the directive gave member states considerable discretion in domestic transposition, significant divergences emerged among member states in data protection standards, enforcement intensity, and penalty regimes, meaning the goal of "harmonization" was not fully achieved. This is also the important legislative background for the 2016 GDPR replacing the directive with a "Regulation" (directly applicable, requiring no transposition) — aiming to achieve genuinely uniform application.
Question 10 of 10
Which institution within the European Union holds the exclusive authority to independently propose new laws related to data protection?
AThe European Council
BThe European Parliament
CThe European Commission
DThe Council of the European Union
Why C is correct
Within the European Union’s legislative framework, the exclusive right to initiate new legislation, including laws related to data protection, lies with the European Commission. The Commission serves as the EU’s executive body and is tasked with drafting legislative proposals, implementing decisions, and ensuring adherence to EU treaties. For data protection legislation such as the General Data Protection Regulation (GDPR), the process begins with the Commission preparing and submitting the proposal. This proposal is then reviewed and amended through a co-legislative process involving the European Parliament and the Council of the European Union, which jointly debate and adopt the law. However, neither of these institutions can propose legislation independently. The other institutions mentioned have important but distinct roles: The European Council (Option A) comprises the heads of state or government of member countries. While it sets the EU’s overall political priorities, it does not possess legislative initiative powers. The European Parliament (Option B) functions as a co-legislator, debating and voting on laws. Although it influences legislation and can request the Commission to introduce proposals, it cannot initiate laws by itself. The Council of the European Union (Option D), often referred to as the Council, represents the governments of member states and shares legislative power with the Parliament. However, it cannot independently propose laws. This centralized approach, with the European Commission holding exclusive legislative initiative, is designed to ensure consistency, coordination, and efficiency across the EU, especially in sensitive and harmonized policy areas such as data protection. The Commission’s role allows it to consider wide-ranging interests and expertise before presenting legislative drafts to the co-legislators. Thus, the institution with sole authority to independently propose new data protection legislation within the EU is the European Commission, making C the correct answer.
These 10 are a sample
✓513 questions, each with the full reasoning
✓Every wrong option explained, not just the right one
✓9 chapters of syllabus notes, written from a cold start
✓Full-length mock exam with per-domain scoring
✓Printable PDF included — one purchase, no renewal