PassFish

CIPP-E practice questions — 10 free

Certified Information Privacy Professional/Europe · every answer carries the reasoning, and why each other option fails.
513 questions
9 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

A U. S. -based pharmaceutical company, Pharma, receives pseudonymised patient information from clinical sites all over the world, including the EU, as part of a clinical trial. How must Pharma process the data?

Why C is correct

Under the GDPR's extraterritorial (territorial) scope rule in Art. 3, data protection obligations do not depend solely on where the controller is located, but on where the data subject resides and the nature of the processing activity. In a multinational clinical trial, even though Pharma is headquartered in the U.S. and the data has been pseudonymised, as long as the processing concerns data subjects located in different jurisdictions, Pharma must comply with the applicable privacy laws of the country where each data subject resides (e.g., GDPR for EU data subjects, local law for data subjects in other jurisdictions). It cannot avoid multi-jurisdictional compliance obligations merely by claiming to process data "only in the U.S." or by pointing to pseudonymisation. Pseudonymisation is distinct from anonymisation: pseudonymised data remains personal data and remains subject to the laws of the relevant jurisdiction.

Question 2 of 10

Failure to provide fair information to data subjects with regards to the processing of their personal data is likely to?

Why D is correct

GDPR Art. 5(1)(a) lists lawfulness, fairness and transparency as one of the core principles governing the processing of personal data, while Art. 12-14 specifically set out the controller's information provision obligations to the data subject. Failing to provide fair information to the data subject not only directly breaches the specific information provision obligations under Art. 12-14, but also causes the processing as a whole to be found unfair for lack of transparency, thereby violating the principled requirement of Art. 5(1)(a) — a double violation, rather than the outcomes described in the other options such as rendering the data unusable or requiring reauthorisation.

Question 3 of 10

Under the GDPR, the copy of personal data provided to data subjects upon exercising their right of access shall:

Why B is correct

GDPR Article 15(3) provides that the controller shall provide the data subject with a copy of the personal data undergoing processing. This provision does not mandate that the copy be provided in machine-readable form; rather, it requires that the information be provided in an intelligible form, i.e., a human-readable form. The requirement of machine-readable form in a commonly used electronic form falls within the scope of the right to data portability under Article 20, and the two should not be conflated. It is only where the data subject makes the request by electronic means, and unless otherwise requested, that the copy should be provided in a commonly used electronic form — but this is not an absolute requirement in all cases.

Question 4 of 10

When should a data subject be informed where personal data relating them is disclosed to another recipient?

Why B is correct

Under the transparency requirements of GDPR Article 19 and Articles 13(1)(e)/14(1)(e), when personal data is disclosed to a new recipient, the controller should, in principle, inform the data subject of the identity or category of the recipient when the personal data is first disclosed to that recipient, so as to ensure the data subject can promptly understand where their data is flowing and thereby effectively exercise the right to be informed and subsequent rights such as access and rectification. This is a concrete application of the transparency principle in the context of data sharing.

Question 5 of 10

Which one is incorrect about the designation of a DPO under the GDPR?

Why A is correct

Under GDPR Art. 37(1), a public authority or body (except courts acting in their judicial capacity under national law) must designate a DPO, but the GDPR does not prohibit a public authority from designating an internal staff member as the DPO. On the contrary, Art. 37(6) expressly states that the DPO may be a staff member of the controller or processor, or may fulfil the tasks on the basis of a service contract. Therefore the statement that "public authorities cannot designate a staff member as the DPO" is incorrect, making it the answer to this question. B, C, and D are all arrangements permitted under the GDPR: Art. 37(2) allows a group of undertakings to designate a single DPO, Art. 37(3) allows several public authorities to jointly designate one DPO, and Art. 37(1)(b) makes designation of a DPO mandatory where the core activities involve regular and systematic large-scale monitoring of data subjects.

Question 6 of 10

According to the EDPB Guidelines 01/2021 on Examples regarding Personal Data Breach Notification, if exfiltration of job application data (submitted through online application forms and stored on a webserver) resulted in personal information being accessible to unauthorized persons, this would be primarily considered what kind of breach?

Why D is correct

EDPB Guidelines 01/2021 classify personal data breaches into three categories: confidentiality breach (unauthorized disclosure of or access to data), integrity breach (unauthorized or accidental alteration of data), and availability breach (loss of or inability to access data). Where exfiltrated job application data resulted in unauthorized persons being able to access that personal information, the data itself was neither altered nor lost, but its confidentiality was compromised, so it should primarily be classified as a confidentiality breach.

Question 7 of 10

How is the retention of communications traffic data for law enforcement purposes addressed by European data protection law?

Why A is correct

After the Data Retention Directive (2006/24/EC) was declared invalid by the Court of Justice of the European Union (CJEU), the retention of communications traffic data for law enforcement purposes reverted to being governed by the ePrivacy Directive (2002/58/EC). Article 15(1) of the ePrivacy Directive allows member states to adopt national legislation imposing data retention obligations on communications service providers, subject to conditions such as necessity and proportionality, for purposes including national security, defense, public security, and the prevention, investigation, detection and prosecution of criminal offences. This means data retention is not harmonized at the EU level, but rather "allows individual member states to decide, through their own legislation, whether and how to carry out such data retention." Subsequent CJEU case law (such as Tele2/Watson) has further imposed strict proportionality limits on such member state legislation.

Question 8 of 10

Since blockchain transactions are classified as pseudonymous, are they considered to be within the material scope of the GDPR or outside of it?

Why B is correct

Whether the GDPR's material scope applies depends on whether what is being processed is "personal data" — that is, information that identifies or can identify a natural person — not on whether that data is "pseudonymous." Under Recital 26 and Article 4(1), pseudonymous data remains personal data because re-identification of the data subject may still be possible using additional information; only data that has been truly anonymized to the point where re-identification is no longer possible falls outside the scope of the GDPR. If a blockchain transaction involves a data subject within the EU, then even if information such as public keys or hashes appears anonymous, as long as there is a reasonable possibility of re-identification, it constitutes personal data and falls within the GDPR's material scope.

Question 9 of 10

What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?

Why C is correct

The OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (1980), the Council of Europe's Convention 108 (1981), and the EU Data Protection Directive (Directive 95/46/EC, 1995) shared, among their common goals, the aim of achieving synchronization/harmonization of approaches to data protection across Europe and globally, thereby facilitating the free cross-border flow of personal data while safeguarding fundamental rights. In practice, however — particularly in the era of Directive 95/46/EC — because the directive gave member states considerable discretion in domestic transposition, significant divergences emerged among member states in data protection standards, enforcement intensity, and penalty regimes, meaning the goal of "harmonization" was not fully achieved. This is also the important legislative background for the 2016 GDPR replacing the directive with a "Regulation" (directly applicable, requiring no transposition) — aiming to achieve genuinely uniform application.

Question 10 of 10

Which institution within the European Union holds the exclusive authority to independently propose new laws related to data protection?

Why C is correct

Within the European Union’s legislative framework, the exclusive right to initiate new legislation, including laws related to data protection, lies with the European Commission. The Commission serves as the EU’s executive body and is tasked with drafting legislative proposals, implementing decisions, and ensuring adherence to EU treaties. For data protection legislation such as the General Data Protection Regulation (GDPR), the process begins with the Commission preparing and submitting the proposal. This proposal is then reviewed and amended through a co-legislative process involving the European Parliament and the Council of the European Union, which jointly debate and adopt the law. However, neither of these institutions can propose legislation independently. The other institutions mentioned have important but distinct roles: The European Council (Option A) comprises the heads of state or government of member countries. While it sets the EU’s overall political priorities, it does not possess legislative initiative powers. The European Parliament (Option B) functions as a co-legislator, debating and voting on laws. Although it influences legislation and can request the Commission to introduce proposals, it cannot initiate laws by itself. The Council of the European Union (Option D), often referred to as the Council, represents the governments of member states and shares legislative power with the Parliament. However, it cannot independently propose laws. This centralized approach, with the European Commission holding exclusive legislative initiative, is designed to ensure consistency, coordination, and efficiency across the EU, especially in sensitive and harmonized policy areas such as data protection. The Commission’s role allows it to consider wide-ranging interests and expertise before presenting legislative drafts to the co-legislators. Thus, the institution with sole authority to independently propose new data protection legislation within the EU is the European Commission, making C the correct answer.

These 10 are a sample

See the full bank