GDPR Study Guide 2026
Everything you need to pass the GDPR exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.
๐ GDPR Exam Format at a Glance
๐ GDPR Topics to Study (69)
โ๏ธ Sample GDPR Questions & Answers
1. Which scenario would most likely require direct notification to data subjects under Article 34?
Exposing names and email addresses to an unintended recipient creates a real risk of phishing or spam, likely meeting the high-risk threshold that triggers direct notification to affected individuals.
2. A company processes biometric data for employee time-tracking. Under GDPR, what additional security consideration applies to this data specifically?
Biometric data processed to uniquely identify individuals is special category data under Article 9, requiring explicit consent or another Article 9(2) basis plus enhanced security.
3. Which principle must both controllers and processors follow under GDPR?
GDPR emphasizes accountability as a core principle for both controllers and processors. This means organizations must not only comply with the regulation but also be able to demonstrate their compliance through documented policies, procedures, and records. Accountability ensures that responsibility for data protection is clearly assigned and verifiable.
4. Which of the following organizations is NOT required to designate a Data Protection Officer (DPO) under Article 37 GDPR?
A small retailer processing employee payroll incidentally does not meet the Article 37 thresholds (public authority, large-scale monitoring, or large-scale special category processing).
5. An organization conducts a DPIA and concludes that high residual risk remains after mitigation. What is the required next step?
Article 36 requires prior consultation with the supervisory authority when a DPIA indicates that high residual risk cannot be mitigated by the controller.
6. An ETL pipeline automatically enriches customer records by joining internal data with purchased third-party datasets. What GDPR obligation is most likely triggered?
Article 35 and Recital 91 require a DPIA when systematic and extensive profiling or combination of personal data occurs at scale.