1. Home
  2. IAPP
  3. CIPP-E Exam

CIPP-E Certified Information Privacy Professional/Europe Exam Topics and Questions

Let's Practice Free IAPP CIPP-E Questions Aligned with Official Exam Topics

Follows IAPP's official outline Updated 11 Sep, 2026 5 Topics
Reviewed by Thomas Lee, IAPP CIPP-E Certified Professional
Topic Content

This opening topic puts the law into four operational contexts where compliance failures are most visible and most expensive. Employment, surveillance, marketing and internet communications each carry distinct obligations, and each generates its own pattern of enforcement action. The exam expects you to recognise which rules apply in which setting, and where the boundaries shift when context changes. – Workplace data and employment relationships Employment processing sits at the intersection of data protection law, labour law and fundamental rights. You...

See More

The question below places you in a marketing scenario and asks you to identify the compliance step that must be taken under the ePrivacy framework.

Sample Questions for Topic 1 : Compliance with European Data Protection Law and Regulation
Q1

SCENARIO

Please use the following to answer the next question:

Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.

Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:

Name

Address

Date of Birth

Payroll number

National Insurance number

Sick pay entitlement

Maternity/paternity pay entitlement

Holiday entitlement

Pension and benefits contributions

Trade union contributions

Jenny is the compliance officer at Company

A . She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.

Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.

Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.

This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.

Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.

The GDPR requires sufficient guarantees of a company's ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?

Topic Content

Before the law itself comes the machinery that makes and enforces it. This topic covers the institutional architecture of the European Union, the historical path that led to the GDPR, and the legislative instruments that give data protection its binding force. You need to understand how directives differ from regulations, which institutions propose and adopt legislation, and why the 1995 Directive was replaced. The exam assumes you know the framework well enough to recognise which body does what and how...

See More

The question that follows asks you to identify the correct characterisation of an EU legislative instrument and its effect on member states.

Sample Questions for Topic 2 : Introduction to European Data Protection
Q2

To comply with the GDPR and the EU Court of Justice's decision in Schrems II, the European Commission issued what are commonly referred to as the new standard contractual clauses (SCCs). As a result, businesses must do all of the following EXCEPT?

Topic Content

With the framework in place, the topic shifts to the substance of the GDPR itself. Three areas dominate: the definitions and concepts that underpin every obligation, the security requirements that protect personal data from breach, and the catalogue of rights that data subjects may exercise. Each area is tested heavily, and each penalises vague or approximate knowledge. The exam expects you to apply definitions precisely, match security measures to risk, and know which right applies in which circumstance. How European...

See More

The question below tests your ability to apply a GDPR concept correctly in a processing scenario involving multiple parties.

Topic Content

Processing is only lawful when it rests on one of the six legal bases, and the choice of basis determines every downstream obligation. This topic also covers the transparency requirements that accompany any processing, and the rules governing transfers of personal data outside the EEA. Transfers remain one of the most frequently tested areas, because the mechanisms are specific, the risks are high, and the case law continues to evolve. You must know what each basis permits, when information must...

See More

The question that follows asks you to identify the appropriate lawful basis for a processing operation described in a workplace setting.

Topic Content

The final topic addresses two questions: when does the GDPR apply, and what must organisations do to demonstrate compliance? Scope determines jurisdiction. Accountability translates principles into operational requirements. Supervision and enforcement bring consequences for failure. You need to know when the GDPR's territorial reach extends beyond the EEA, which accountability measures are mandatory and which are risk-based, how supervisory authorities coordinate, and what penalties are available. This topic ties the entire syllabus together, because every obligation discussed earlier depends on...

See More

The question below presents a cross-border processing scenario and asks you to identify which supervisory authority mechanism applies.

Ready to Start Practicing?

Access all questions and start your exam preparation journey

Upgrade to Full CIPP-E Exam Questions πŸš€
Exams Made Simple. Success Made Possible.