GDPR Cheat Sheet 2026
The 30 highest-yield GDPR facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
90 questions
150 min time limit
65.00% to pass
- A data subject objects to the processing of their personal data for direct marketing purposes under Article 21(2) GDPR. What is the controller's obligation? → Cease processing for direct marketing immediately and without exception
- What is the value of isolating variables during troubleshooting? → It identifies the specific cause by changing one factor at a time
- What is the role of a supervisory authority under GDPR? → Monitor and enforce GDPR compliance
- The 'public task' lawful basis under Article 6(1)(e) applies when processing is necessary for: → Performance of a task carried out in the public interest or exercise of official authority
- Which architectural pattern provides the best fault isolation? → Microservices architecture with independent service boundaries
- A system architect is designing a logging pipeline that ingests application logs containing IP addresses. Under GDPR, IP addresses are classified as: → Personal data when they can be linked to an identifiable individual
- Which principle requires that data be collected for specific, explicit, and legitimate purposes? → Purpose limitation
- A controller relies on 'legitimate interests' as the lawful basis for processing. What additional balancing test must be satisfied? → The legitimate interest must not be overridden by the data subject's interests or rights
- A marketing team wants to enrich its CRM with social media profile data scraped from public platforms. Under GDPR, the most significant concern is: → The lack of a compatible purpose and the absence of transparency to data subjects
- Which GDPR provision explicitly requires organisations to test, assess, and evaluate the effectiveness of security measures on an ongoing basis? → Article 32(1)(d) — regular testing and evaluation of technical and organisational measures
- Which of the following organizations is NOT required to designate a Data Protection Officer (DPO) under Article 37 GDPR? → A small retailer processing employee payroll data only
- Under GDPR, within what timeframe must a controller generally respond to a data subject's request, and what extension is permitted? → One month; extendable by a further two months for complex or numerous requests
- When configuring automated retention enforcement in a data management tool, which GDPR principle is most directly operationalized? → Storage limitation
- What is a primary responsibility of a data controller under GDPR? → Determining purposes and means of data processing
- Under GDPR's accountability principle, which document must a controller with 250 or more employees maintain? → Records of Processing Activities
- What is the primary purpose of security auditing? → To identify vulnerabilities and verify compliance with security policies
- Which GDPR mechanism allows personal data to be transferred to a third country that the European Commission has deemed to provide adequate protection? → Adequacy Decision
- Which document must processors maintain under GDPR? → Record of processing activities
- Under GDPR, a data breach notification to the supervisory authority must be made within what timeframe after the controller becomes aware of it? → 72 hours
- A data subject submits a Subject Access Request (SAR) to a controller. What is the standard deadline for the controller to respond? → 30 days
- Which scenario best demonstrates the principle of 'integrity and confidentiality' under GDPR Article 5(1)(f)? → Using encryption and access controls to prevent unauthorised processing
- A healthcare provider's automated appointment reminder system processes patient data. Which legal basis is most appropriate under GDPR? → Performance of a contract or compliance with a legal obligation
- What is the principle of least privilege? → Granting users only the minimum access necessary to perform their duties
- When is a controller NOT required to notify data subjects about a personal data breach under Article 34? → When the affected data was protected by appropriate encryption
- Which approach best embeds the GDPR principle of integrity and confidentiality into an automated data processing script? → Implementing encryption in transit and at rest, access controls, and audit logging
- When configuring retention schedules in a document management system, what must the technical implementation include to meet GDPR requirements? → Automated expiry workflows that delete or anonymize data when the retention period ends
- What is the first step in performance optimization? → Establish baseline measurements and identify bottlenecks
- An audit tool reveals that a third-party processor sub-contracted processing to another vendor without informing the controller. Under GDPR, this violates: → Article 28(2) — sub-processors require controller authorization
- What is the right to rectification under GDPR? → The right to correct inaccurate data
- How should a root cause analysis be conducted? → Systematically investigate underlying causes rather than just symptoms
Turn these facts into recall:
Was this helpful?