10 free IAPP CIPP/E practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 319 questions. Work through them, then open each answer to check your reasoning.
Get all 319 questions (US$39) · Download these 10 as a PDF
Question 1
Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?
Show answer and explanation
Correct answer: B. The right to privacy has to be balanced against other rights under the ECHR
Article 8 of the ECHR protects the right to privacy, but this right is not absolute. It must be balanced against other fundamental rights and legitimate state interests. Article 10 (freedom of expression) does not automatically override privacy; courts conduct proportionality assessments to balance competing rights. Option D describes freedom of opinion and expression, which is Article 10, not Article 8.
Why the other options are wrong
- A. The right to privacy is qualified, not absolute; it can be restricted under Article 8(2) for legitimate purposes.
- C. Neither right automatically overrides the other; they must be balanced on a case-b-ase basis through proportionality analysis.
- D. This describes Article 10 (freedom of expression), not Article 8 (privacy).
Question 2
What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?
Show answer and explanation
Correct answer: C. The synchronization of approaches to data protection
All three instruments were built on a common set of fair information principles and shared the ambition of bringing national regimes into line so that personal data could move freely with equivalent protection. That harmonization never materialised: the OECD Guidelines were applied inconsistently, Convention 108 left Parties wide discretion, and the Directive was transposed differently in each Member State. The resulting patchwork of national rules is precisely what the GDPR, as a directly applicable regulation, was designed to correct.
Why the other options are wrong
- A. A list of lawful processing criteria was actually delivered, most clearly in Article 7 of the Directive, so it is not the shared objective that failed.
- B. The OECD Guidelines were issued as non-binding recommendations and never sought binding force, while Convention 108 and the Directive did produce legal obligations, so this cannot be the common unmet goal.
- D. None of the three instruments aimed to restrict cross-border data flows; each sought to enable them safely by raising baseline protection.
Question 3
A key component of the OECD Guidelines is the “Individual Participation Principle”.
What parts of the General Data Protection Regulation (GDPR) provide the closest equivalent to that principle?
Show answer and explanation
Correct answer: D. The rights granted to data subjects under Articles 12 to 22
The OECD Guidelines' Individual Participation Principle grants individuals rights to know about data held about them and to correct inaccurate information. The GDPR's Articles 1-2 provide the closest equivalent, granting data subjects rights including access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and objection (Article 21), which collectively enable individual participation in data processing.
Why the other options are wrong
- A. Articles 6-9 establish lawful processing criteria, not individual participation rights.
- B. Articles 13-14 concern transparency and information provision, but don't encompass the full scope of participation rights.
- C. Articles 33-34 address breach notification, which is not related to individual participation in processing.
Question 4
Which EU institution is vested with the competence to propose new data protection legislation on its own initiative?
Show answer and explanation
Correct answer: C. The European Commission
Under the EU constitutional framework, only the European Commission possesses the formal right to initiate legislative proposals on its own initiative. The European Council, European Parliament, and Council of the European Union can request proposals, but the Commission retains the exclusive power to propose new legislation, including data protection laws.
Why the other options are wrong
- A. The European Council sets political direction but cannot propose legislation.
- B. The European Parliament can request proposals but cannot initiate them independently.
- D. The Council of the European Union negotiates and adopts legislation but cannot propose it.
Question 5
What is an important difference between the European Court of Human Rights (ECHR) and the Court of Justice of the European Union (CJEU) in relation to their roles and functions?
Show answer and explanation
Correct answer: B. CJEU can force national governments to implement and honor EU law, while the ECHR cannot.
The CJEU can compel Member States to implement and apply EU law: the Commission can bring infringement proceedings, the Court's rulings bind national courts, and financial penalties can be imposed under Article 260 TFEU for continued non-compliance. The European Court of Human Rights decides individual applications once domestic remedies are exhausted and can award just satisfaction, but it cannot annul national law or order a state to legislate, and execution of its judgments is supervised politically by the Committee of Ministers. That difference in coercive power over national implementation is the key functional distinction.
Why the other options are wrong
- A. Both courts adjudicate privacy as a fundamental right, the CJEU doing so under Articles 7 and 8 of the Charter of Fundamental Rights.
- C. The CJEU is not an appellate body for national court decisions; it answers preliminary references on the interpretation and validity of EU law.
- D. The Strasbourg court's judgments bind the respondent state, but it has no mechanism of its own to force implementation, so it does not hold an enforcement power the CJEU lacks.
Question 6
Show the case study this question is based on
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees. These records are available to former students after registering through Granchester’s Alumni portal.
Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna’s data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna’s training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna’s tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Which of the University’s records does Anna NOT have to include in her record of processing activities?
Show answer and explanation
Correct answer: D. Department for Education records
The Department for Education records do not contain names or identification numbers; they show only aggregated statistical information about demographic groups and their expected average progression. Since these records contain no personal data as defined by the GDPR, they are not subject to the requirement to include them in the record of processing activities. All other record types contain identifiable personal data requiring documentation.
Why the other options are wrong
- A. Student records contain personal data (names, numbers, addresses, performance) and must be documented.
- B. Staff and alumni records contain personal data (autobiographical materials, birthplaces, names via alumni portal access) and must be documented.
- C. Frank's performance database, despite using transformed student numbers, still contains personal data traceable to individuals and must be documented.
Question 7
Show the case study this question is based on
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees. These records are available to former students after registering through Granchester’s Alumni portal.
Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna’s data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna’s training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna’s tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Before Anna determines whether Frank’s performance database is permissible, what additional information does she need?
Show answer and explanation
Correct answer: D. More information about what students have been told and how the research will be used.
Before determining whether Frank's database is permissible, Anna must understand what students have been told about data use and how the research findings will be used. The GDPR requires that any new processing be compatible with the original purpose for which data was collected. Students may have only consented to data use for enrollment and academic purposes; Anna needs to establish whether educational research improvement is compatible with original purposes or requires fresh consent, and whether students have been adequately informed.
Why the other options are wrong
- A. The quality of Frank's training is not relevant to assessing whether the new processing is permissible under GDPR.
- B. Information about the laptop loss relates to a security breach and notification obligations, not to determining processing compatibility.
- C. The algorithm's technical soundness doesn't determine whether processing is permissible; compatibility with original purpose is the key issue.
Question 8
Show the case study this question is based on
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees. These records are available to former students after registering through Granchester’s Alumni portal.
Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna’s data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna’s training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna’s tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Anna will find that a risk analysis is NOT necessary in this situation as long as?
Show answer and explanation
Correct answer: B. The processing will not negatively affect the rights of the data subjects
A data protection impact assessment (risk analysis) is necessary when processing is likely to result in a high risk to the rights and freedoms of data subjects. Anna will find it NOT necessary as long as the processing will not negatively affect the rights of data subjects. If the risk to data subject rights is acceptably low or mitigated, a DPIA is not required under Article 35 of the GDPR.
Why the other options are wrong
- A. Whether subjects are current or former students does not determine DPIA necessity; the presence of risk to any individuals' rights is the determining factor.
- C. The technological soundness of algorithms does not exempt an organization from DPIA requirements when high-risk processing is involved.
- D. Original consent does not eliminate the need for DPIA; new processing of existing data requires fresh risk assessment regardless of original consent.
Question 9
Which institution has the power to adopt findings that confirm the adequacy of the data protection level in a non-EU country?
Show answer and explanation
Correct answer: B. The European Commission
The European Commission has the institutional power to adopt adequacy decisions under GDPR Article 45, which formally confirm that a non-EU country provides an adequate level of data protection. This is an executive function of the Commission and is essential to enabling personal data transfers to third countries.
Why the other options are wrong
- A. The European Parliament does not have the power to adopt adequacy decisions; it has a consultative and legislative role only.
- C. The Article 29 Working Party (now the European Data Protection Board) provides advisory opinions but lacks the institutional power to formally adopt binding adequacy decisions.
- D. The European Council sets political direction but does not possess the executive power to adopt adequacy decisions.
Question 10
What is true of both the General Data Protection Regulation (GDPR) and the Council of Europe Convention 108?
Show answer and explanation
Correct answer: A. Both govern international transfers of personal data
Both instruments regulate the movement of personal data across borders. Chapter V of the GDPR sets out adequacy decisions, appropriate safeguards and derogations, while Convention 108 and its modernised version, Convention 108+, contain transborder data flow provisions requiring an appropriate level of protection in the recipient jurisdiction. That shared coverage of international transfers is the common element.
Why the other options are wrong
- B. The original Convention 108 covers automated processing of personal data files and reaches manual files only where a Party declares an extension, while the GDPR covers manual processing only within a filing system, so this is not equally true of both.
- C. Convention 108 is a Council of Europe treaty open to non-EU states and has been ratified well beyond the European Union.
- D. Convention 108 imposes no general obligation to notify processing activities to a supervisory authority, and the GDPR replaced the old notification regime with internal record keeping.
That was 10 of 319.
The full IAPP CIPP/E pack has all 319 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
