IAPP CIPP/E — Certified Information Privacy Professional/Europe (GDPR) — Questions and Answers
Question 1: A company's CI/CD pipeline automatically deploys code changes to a system that processes personal data. What GDPR consideration must be embedded in this pipeline?
- Security and privacy impact reviews must gate production deployments (Correct answer)
- Supervisory authority must approve each deployment
- Automated deployments are prohibited under GDPR Article 32
- All deployments must pause for 72 hours for DPA notification
Correct answer: Security and privacy impact reviews must gate production deployments
Article 25 (privacy by design) and Article 32 (security of processing) require that privacy and security controls be integrated into development and deployment processes.
Question 2: A data subject reads about a breach affecting their bank in the news before receiving any notification. Which GDPR obligation has most likely been violated?
- Article 83 — administrative fine structure
- Article 6 — lawfulness of processing
- Article 34 — obligation to communicate breach to data subjects without undue delay (Correct answer)
- Article 17 — right to erasure
Correct answer: Article 34 — obligation to communicate breach to data subjects without undue delay
Article 34 requires high-risk breaches to be communicated to data subjects without undue delay, and learning of it through media before official notification indicates the controller failed that obligation.
Question 3: What role does documentation play in system architecture?
- It slows down development
- It enables team understanding, maintenance, and future development decisions (Correct answer)
- It is optional for small systems
- It is only needed for compliance audits
Correct answer: It enables team understanding, maintenance, and future development decisions
Architecture documentation is essential for team understanding, system maintenance, and informed decision-making about future development and changes.
Question 4: Which architectural approach to database design best supports the GDPR principle of storage limitation?
- Using denormalized schemas with all data duplicated across tables for performance
- Compressing old records to reduce storage costs while retaining them
- Implementing automated data lifecycle management with expiration policies per data category (Correct answer)
- Keeping all historical records indefinitely for potential future analytics value
Correct answer: Implementing automated data lifecycle management with expiration policies per data category
Automated lifecycle management with per-category expiration policies ensures personal data is not retained longer than necessary for its specified purpose.
Question 5: A national tax authority processes citizen financial data to carry out its statutory collection functions. Which lawful basis is most appropriate?
- Contract
- Legitimate interests
- Consent
- Public task (Correct answer)
Correct answer: Public task
Processing by public authorities performing statutory functions is governed by Article 6(1)(e), the public task basis.
Question 6: Which technical measure is specifically required when implementing a GDPR-compliant data subject access request (DSAR) portal?
- Verifying the requester's identity before disclosing personal data (Correct answer)
- Responding only to requests submitted via certified mail
- Limiting DSAR responses to data collected in the last 12 months
- Charging a fee for each request to discourage abuse
Correct answer: Verifying the requester's identity before disclosing personal data
Identity verification is essential before responding to a DSAR to prevent unauthorized disclosure of another person's data.
Question 7: How should security be incorporated into system architecture?
- Handled entirely by the network team
- Integrated from the initial design phase as a foundational requirement (Correct answer)
- Added after all functional features are complete
- Only addressed when vulnerabilities are discovered
Correct answer: Integrated from the initial design phase as a foundational requirement
Security must be integrated from the initial design phase (security by design) to be effective, as retrofitting security is more costly and less thorough.
Question 8: Which of the following best describes the 'one-stop-shop' mechanism under GDPR?
- Data subjects can lodge complaints with any EU supervisory authority
- All GDPR enforcement is centralized through the EDPB
- Controllers need only register with one national authority
- A controller with cross-border processing has a single lead supervisory authority (Correct answer)
Correct answer: A controller with cross-border processing has a single lead supervisory authority
The one-stop-shop mechanism means that a controller operating in multiple EU Member States deals primarily with the supervisory authority of its main establishment.
Question 9: What is a Legitimate Interests Assessment (LIA) and when is it required?
- An assessment required only when processing special category data
- A three-part test used to determine whether legitimate interests can be relied upon as a lawful basis (Correct answer)
- A mandatory form submitted to the supervisory authority for every processing activity
- A DPIA alternative used for low-risk processing activities
Correct answer: A three-part test used to determine whether legitimate interests can be relied upon as a lawful basis
An LIA involves a purpose test, necessity test, and balancing test, and should be documented whenever legitimate interests under Article 6(1)(f) is the intended basis.
Question 10: Under GDPR Article 25, which approach satisfies 'data protection by default'?
- Providing users a dashboard to configure their own privacy settings
- Enabling all optional data-sharing features unless the user opts out
- Storing personal data in encrypted form at rest
- Setting privacy-protective options as the system default without user action (Correct answer)
Correct answer: Setting privacy-protective options as the system default without user action
Data protection by default means only necessary data is processed and privacy-protective settings apply automatically without requiring any user action.
Question 11: When must a controller notify the supervisory authority of a personal data breach?
- Without undue delay and within 72 hours of becoming aware (Correct answer)
- Within 30 days of detection
- Only if the breach affects more than 1,000 individuals
- Within 24 hours of becoming aware
Correct answer: Without undue delay and within 72 hours of becoming aware
Article 33 requires controllers to notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach.
Question 12: A GDPR-compliant automated consent management platform must be capable of which function?
- Preventing users from withdrawing consent once given
- Recording timestamped consent and enabling granular withdrawal at any time (Correct answer)
- Storing consent records for a minimum of 6 months only
- Requiring users to consent to all processing in a single click
Correct answer: Recording timestamped consent and enabling granular withdrawal at any time
Article 7(3) requires that withdrawal of consent be as easy as giving it, and Article 5(2) accountability requires detailed consent records.
Question 13: What supplementary measure might organizations adopt when SCCs alone are insufficient after a Schrems II transfer impact assessment?
- Requesting a new adequacy decision for every transfer
- Filing a complaint with the EDPB
- Requiring data subjects to waive their GDPR rights
- Applying end-to-end encryption so that data is unintelligible to the importing country's authorities (Correct answer)
Correct answer: Applying end-to-end encryption so that data is unintelligible to the importing country's authorities
Encryption that renders data unintelligible to third-country authorities is a recognized technical supplementary measure that can shore up inadequate SCC protections.
Question 14: Under GDPR, what is the performance implication of implementing encryption at rest for personal data, and how should it be addressed?
- I/O latency increases; use hardware-accelerated encryption (AES-NI) to minimize overhead (Correct answer)
- Encryption at rest has no performance impact and requires no optimization
- Encryption at rest must be disabled for production databases due to performance costs
- Only encrypt data during transfer, not at rest, to maintain performance
Correct answer: I/O latency increases; use hardware-accelerated encryption (AES-NI) to minimize overhead
Hardware-accelerated AES-NI virtually eliminates the CPU overhead of AES encryption, making at-rest encryption practical without significant performance degradation.
Question 15: Under GDPR, what is the maximum timeframe for notifying a supervisory authority after discovering a personal data breach that poses a risk to individuals?
- 24 hours
- 72 hours (Correct answer)
- 48 hours
- 7 days
Correct answer: 72 hours
Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Question 16: Which scenario would most likely require direct notification to data subjects under Article 34?
- An attacker accessed encrypted credit card data but lacked the decryption key
- An employee accidentally emailed a list of customer names and email addresses to the wrong recipient with no evidence of onward sharing (Correct answer)
- A backup tape containing encrypted HR records was lost
- A server misconfiguration briefly exposed aggregate, anonymized statistics
Correct answer: An employee accidentally emailed a list of customer names and email addresses to the wrong recipient with no evidence of onward sharing
Exposing names and email addresses to an unintended recipient creates a real risk of phishing or spam, likely meeting the high-risk threshold that triggers direct notification to affected individuals.
Question 17: Which type of monitoring tool would best help an organization detect 'function creep' — processing personal data beyond the original stated purpose?
- Network firewall log analyzer
- Password manager
- Backup verification tool
- Data flow mapping and purpose-tagging tool (Correct answer)
Correct answer: Data flow mapping and purpose-tagging tool
A data flow mapping tool that tags data by stated purpose can flag when data is used for functions not matching its original purpose, detecting function creep.
Question 18: What is a Transfer Impact Assessment (TIA)?
- A formal DPIA required before any cross-border transfer
- A DPA's inspection of a company's international transfer practices
- An internal audit of all personal data held by a processor
- An evaluation of whether the legal system of a destination country undermines the effectiveness of transfer safeguards (Correct answer)
Correct answer: An evaluation of whether the legal system of a destination country undermines the effectiveness of transfer safeguards
A TIA assesses the laws and practices of the destination country to determine whether they undermine the protections offered by the chosen transfer mechanism such as SCCs.
Question 19: What is the role of the 'lead supervisory authority' under GDPR's One-Stop-Shop mechanism?
- It supervises all processors regardless of location
- It is the supervisory authority in any EU member state where a complaint is filed
- It is appointed by the European Data Protection Board
- It is the supervisory authority of the member state where the controller has its main establishment (Correct answer)
Correct answer: It is the supervisory authority of the member state where the controller has its main establishment
The lead supervisory authority is determined by the location of the controller's or processor's main establishment, serving as the primary regulatory contact for cross-border processing.
Question 20: When should architectural decisions be reviewed and potentially revised?
- Never, once architecture is set it should not change
- When requirements change significantly or performance targets are not met (Correct answer)
- Only during annual reviews
- Only when migrating to new hardware
Correct answer: When requirements change significantly or performance targets are not met
Architectural decisions should be reviewed when requirements change significantly or performance issues arise, ensuring the system continues to meet evolving needs.
Question 21: In event-driven architectures, how should personal data included in events be handled to support GDPR compliance?
- Include full personal data in every event to ensure consumers have complete context
- Encrypt all event payloads with a single shared key accessible to all consumers
- Store events in perpetuity to enable full audit replay of all personal data changes
- Use event references with IDs and let consumers fetch personal data from authoritative sources under access control (Correct answer)
Correct answer: Use event references with IDs and let consumers fetch personal data from authoritative sources under access control
Referencing data by ID rather than embedding it limits personal data propagation across the event bus and ensures access-controlled retrieval from the authoritative source.
Question 22: A controller receives a valid erasure request from a data subject whose data is also held by five downstream processors. What obligation does the controller have regarding those processors?
- Issue a formal legal notice to each processor within 72 hours
- Take reasonable steps to inform each processor of the erasure request under Article 17(2) (Correct answer)
- Notify the data subject that the processors must handle the erasure independently
- Only erase the data held directly; processors are responsible for their own deletion
Correct answer: Take reasonable steps to inform each processor of the erasure request under Article 17(2)
Article 17(2) requires the controller, where it has made data public or shared it, to take reasonable steps to inform other controllers and processors processing that data of the erasure request.
Question 23: When relying on the 'legal obligation' lawful basis, what must the controller be able to demonstrate?
- That a data protection authority has approved the specific legal obligation
- That the processing is commercially necessary to meet the obligation
- That the data subject has agreed to the underlying legal obligation
- That processing is based on EU law or the law of a Member State to which the controller is subject (Correct answer)
Correct answer: That processing is based on EU law or the law of a Member State to which the controller is subject
Article 6(3) requires that the legal obligation must be laid down by Union or Member State law applicable to the controller.
Question 24: An employee uses company software to process personal data beyond what their role requires. From a compliance standpoint, this most directly breaches which principle?
- Integrity and confidentiality
- Data minimisation (Correct answer)
- Storage limitation
- Purpose limitation
Correct answer: Data minimisation
The data minimisation principle (Article 5(1)(c)) requires that personal data be adequate, relevant, and limited to what is necessary — processing beyond role scope violates this.
Question 25: A controller using Google Analytics must address what key GDPR configuration issue to ensure lawful processing?
- Configure IP anonymization and ensure a valid transfer mechanism covers the US data transfer (Correct answer)
- Switch to a first-party analytics solution immediately
- Obtain supervisory authority approval before using any third-party analytics
- Enable server-side rendering to prevent JavaScript from loading analytics
Correct answer: Configure IP anonymization and ensure a valid transfer mechanism covers the US data transfer
Google Analytics transfers data to the US, so a valid transfer mechanism (e.g., SCCs) plus IP anonymization are required to lawfully use it under GDPR.
Question 26: When configuring role-based access control (RBAC) for a system holding personal data, which GDPR principle directly drives the principle of least privilege?
- Purpose limitation
- Data minimization and integrity & confidentiality (Correct answer)
- Lawfulness
- Accuracy
Correct answer: Data minimization and integrity & confidentiality
Least-privilege access reduces the volume of data any one user can access (minimization) and protects confidentiality (integrity & confidentiality principle under Article 5(1)(f)).
Question 27: Under GDPR, which factor is NOT listed in Article 83(2) as relevant when determining the level of an administrative fine?
- The nationality of the data subjects affected (Correct answer)
- Categories of personal data affected
- Degree of cooperation with the supervisory authority
- Nature, gravity, and duration of the infringement
Correct answer: The nationality of the data subjects affected
Article 83(2) lists multiple factors including nature, gravity, cooperation, and data categories, but the nationality of data subjects is not among them.
Question 28: Under GDPR, which of the following best describes a 'personal data breach' that triggers notification obligations?
- Any unauthorised access attempt, even if unsuccessful
- Only breaches involving sensitive categories of data under Article 9
- Any system outage affecting services that process personal data
- A security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data (Correct answer)
Correct answer: A security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data
Article 4(12) defines a personal data breach as a security incident leading to destruction, loss, alteration, unauthorised disclosure or access to personal data — covering confidentiality, integrity, and availability breaches.
Question 29: What is the primary consideration when designing system architecture?
- Using the newest technology available
- Scalability, reliability, and alignment with business requirements (Correct answer)
- Matching competitor architectures
- Minimizing the number of components
Correct answer: Scalability, reliability, and alignment with business requirements
System architecture must prioritize scalability, reliability, and alignment with business requirements to ensure long-term viability and value delivery.
Question 30: A cloud data platform provider processes personal data exclusively on documented instructions from its customer (the controller). If the provider independently decides to use that data for its own analytics, it becomes:
- A controller in respect of that unauthorised processing (Correct answer)
- A data broker outside GDPR scope
- A sub-processor requiring a new DPA
- A joint controller under Article 26
Correct answer: A controller in respect of that unauthorised processing
Under Article 28(10), a processor that determines the purposes and means of processing beyond the controller's instructions becomes a controller and bears full GDPR liability for that processing.
IAPP CIPP/E — Certified Information Privacy Professional/Europe (GDPR)
The CIPP/E certifies knowledge of European data protection law and privacy regulation, covering GDPR principles, lawful processing, data subject rights, international transfers, and compliance obligations under EU law.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds