IAPP · CIPP/E

IAPP CIPP/E Exam Practice Questions

319 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 319 questions in this pack

Question 1

Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?

  1. The right to privacy is an absolute right
  2. The right to privacy has to be balanced against other rights under the ECHR
  3. The right to freedom of expression under Article 10 of the ECHR will always override the right to privacy
  4. The right to privacy protects the right to hold opinions and to receive and impart ideas without interference
Show answer and explanation

Correct answer: B. The right to privacy has to be balanced against other rights under the ECHR

rights under the ECHR Article 8 of the ECHR protects the right to privacy, but this right is not absolute. It must be balanced against other fundamental rights and legitimate state interests. Article 10 (freedom of expression) does not automatically override privacy; courts conduct proportionality assessments to balance competing rights. Option D describes freedom of opinion and expression, which is Article 10, not Article 8.

Why the other options are wrong

  • A. The right to privacy is qualified, not absolute; it can be restricted under Article 8(2) for legitimate purposes.
  • C. Neither right automatically overrides the other; they must be balanced on a case-by- case basis through proportionality analysis.
  • D. This describes Article 10 (freedom of expression), not Article 8 (privacy).

Question 2

What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?

  1. The establishment of a list of legitimate data processing criteria
  2. The creation of legally binding data protection principles
  3. The synchronization of approaches to data protection
  4. The restriction of cross-border data flow
Show answer and explanation

Correct answer: C. The synchronization of approaches to data protection

All three instruments were built on a common set of fair information principles and shared the ambition of bringing national regimes into line so that personal data could move freely with equivalent protection. That harmonization never materialised: the OECD Guidelines were applied inconsistently, Convention 108 left Parties wide discretion, and the Directive was transposed differently in each Member State. The resulting patchwork of national rules is precisely what the GDPR, as a directly applicable regulation, was designed to correct.

Why the other options are wrong

  • A. A list of lawful processing criteria was actually delivered, most clearly in Article 7 of the Directive, so it is not the shared objective that failed.
  • B. The OECD Guidelines were issued as non-binding recommendations and never sought binding force, while Convention 108 and the Directive did produce legal obligations, so this cannot be the common unmet goal.
  • D. None of the three instruments aimed to restrict cross-border data flows; each sought to enable them safely by raising baseline protection.

Question 3

A key component of the OECD Guidelines is the “Individual Participation Principle”.

What parts of the General Data Protection Regulation (GDPR) provide the closest equivalent to that principle?

  1. The lawful processing criteria stipulated by Articles 6 to 9
  2. The information requirements set out in Articles 13 and 14
  3. The breach notification requirements specified in Articles 33 and 34
  4. The rights granted to data subjects under Articles 12 to 22
Show answer and explanation

Correct answer: D. The rights granted to data subjects under Articles 12 to 22

to 22 The OECD Guidelines' Individual Participation Principle grants individuals rights to know about data held about them and to correct inaccurate information. The GDPR's Articles 12- 22 provide the closest equivalent, granting data subjects rights including access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and objection (Article 21), which collectively enable individual participation in data processing.

Why the other options are wrong

  • A. Articles 6-9 establish lawful processing criteria, not individual participation rights.
  • B. Articles 13-14 concern transparency and information provision, but don't encompass the full scope of participation rights.
  • C. Articles 33-34 address breach notification, which is not related to individual participation in processing.

See all 10 free questions Get the full pack, US$39

319 practice questions for IAPP Certified Information Privacy Professional/Europe (CIPP/E), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 319 questions mapped to the CIPP/E exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A CIPP/E attempt costs US$550, plus a US$250 annual maintenance fee. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 319 questions

What makes the CIPP/E hard

CIPP/E is the gold standard European data protection credential and the most sought after privacy certification for anyone working with the GDPR. If the role touches EU personal data, this is the badge employers look for.

The exam covers the GDPR end to end: lawful bases, data subject rights, controller and processor obligations, international data transfers after Schrems II, and the roles of supervisory authorities and the EDPB, plus the wider European framework including the ePrivacy rules and how enforcement and fines actually work. It rewards precise knowledge of the regulation’s articles and how they apply to real scenarios, not general privacy intuition.

About the exam

CIPP/E validates knowledge of European data protection law and practice, centred on the GDPR. It is a leading credential for privacy professionals, DPOs, and legal and compliance staff working with EU personal data.

Exam domains

  • Introduction to European data protection
  • European regulatory institutions
  • Legislative framework and the GDPR
  • Compliance with European data protection law and practice

90 questions (75 scored plus 15 unscored), 150 minutes, US$550 per attempt plus a US$250 annual certification maintenance fee, maintained through continuing privacy education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the IAPP CIPP/E pack?

319 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.