GDPR Cheat Sheet 2026

The 30 highest-yield GDPR facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

90 questions
150 min time limit
65.00% to pass
  1. A data subject objects to the processing of their personal data for direct marketing purposes under Article 21(2) GDPR. What is the controller's obligation? Cease processing for direct marketing immediately and without exception
  2. What is the value of isolating variables during troubleshooting? It identifies the specific cause by changing one factor at a time
  3. What is the role of a supervisory authority under GDPR? Monitor and enforce GDPR compliance
  4. The 'public task' lawful basis under Article 6(1)(e) applies when processing is necessary for: Performance of a task carried out in the public interest or exercise of official authority
  5. Which architectural pattern provides the best fault isolation? Microservices architecture with independent service boundaries
  6. A system architect is designing a logging pipeline that ingests application logs containing IP addresses. Under GDPR, IP addresses are classified as: Personal data when they can be linked to an identifiable individual
  7. Which principle requires that data be collected for specific, explicit, and legitimate purposes? Purpose limitation
  8. A controller relies on 'legitimate interests' as the lawful basis for processing. What additional balancing test must be satisfied? The legitimate interest must not be overridden by the data subject's interests or rights
  9. A marketing team wants to enrich its CRM with social media profile data scraped from public platforms. Under GDPR, the most significant concern is: The lack of a compatible purpose and the absence of transparency to data subjects
  10. Which GDPR provision explicitly requires organisations to test, assess, and evaluate the effectiveness of security measures on an ongoing basis? Article 32(1)(d) — regular testing and evaluation of technical and organisational measures
  11. Which of the following organizations is NOT required to designate a Data Protection Officer (DPO) under Article 37 GDPR? A small retailer processing employee payroll data only
  12. Under GDPR, within what timeframe must a controller generally respond to a data subject's request, and what extension is permitted? One month; extendable by a further two months for complex or numerous requests
  13. When configuring automated retention enforcement in a data management tool, which GDPR principle is most directly operationalized? Storage limitation
  14. What is a primary responsibility of a data controller under GDPR? Determining purposes and means of data processing
  15. Under GDPR's accountability principle, which document must a controller with 250 or more employees maintain? Records of Processing Activities
  16. What is the primary purpose of security auditing? To identify vulnerabilities and verify compliance with security policies
  17. Which GDPR mechanism allows personal data to be transferred to a third country that the European Commission has deemed to provide adequate protection? Adequacy Decision
  18. Which document must processors maintain under GDPR? Record of processing activities
  19. Under GDPR, a data breach notification to the supervisory authority must be made within what timeframe after the controller becomes aware of it? 72 hours
  20. A data subject submits a Subject Access Request (SAR) to a controller. What is the standard deadline for the controller to respond? 30 days
  21. Which scenario best demonstrates the principle of 'integrity and confidentiality' under GDPR Article 5(1)(f)? Using encryption and access controls to prevent unauthorised processing
  22. A healthcare provider's automated appointment reminder system processes patient data. Which legal basis is most appropriate under GDPR? Performance of a contract or compliance with a legal obligation
  23. What is the principle of least privilege? Granting users only the minimum access necessary to perform their duties
  24. When is a controller NOT required to notify data subjects about a personal data breach under Article 34? When the affected data was protected by appropriate encryption
  25. Which approach best embeds the GDPR principle of integrity and confidentiality into an automated data processing script? Implementing encryption in transit and at rest, access controls, and audit logging
  26. When configuring retention schedules in a document management system, what must the technical implementation include to meet GDPR requirements? Automated expiry workflows that delete or anonymize data when the retention period ends
  27. What is the first step in performance optimization? Establish baseline measurements and identify bottlenecks
  28. An audit tool reveals that a third-party processor sub-contracted processing to another vendor without informing the controller. Under GDPR, this violates: Article 28(2) — sub-processors require controller authorization
  29. What is the right to rectification under GDPR? The right to correct inaccurate data
  30. How should a root cause analysis be conducted? Systematically investigate underlying causes rather than just symptoms
Turn these facts into recall:
Was this helpful?