CIPP-E Certified Information Privacy Professional/Europe Exam Topics and Questions
These IAPP Certified Information Privacy Professional/Europe (CIPP-E) exam topics are organized according to official exam domains to help candidates quickly verify coverage and focus on assessment rather than theory. Each domain is paired with topic-wise CIPP-E sample questions that reflect how objectives are tested in the actual exam. This structure enables efficient review, targeted self-assessment, and rapid identification of weak areas when preparing for the IAPP Certified Information Privacy Professional/Europe certification exam.
Let's Practice Free IAPP CIPP-E Questions Aligned with Official Exam Topics
This opening topic puts the law into four operational contexts where compliance failures are most visible and most expensive. Employment, surveillance, marketing and internet communications each carry distinct obligations, and each generates its own pattern of enforcement action. The exam expects you to recognise which rules apply in which setting, and where the boundaries shift when context changes. β Workplace data and employment relationships Employment processing sits at the intersection of data protection law, labour law and fundamental rights. You...
This opening topic puts the law into four operational contexts where compliance failures are most visible and most expensive. Employment, surveillance, marketing and internet communications each carry distinct obligations, and each generates its own pattern of enforcement action. The exam expects you to recognise which rules apply in which setting, and where the boundaries shift when context changes.
β Workplace data and employment relationships
Employment processing sits at the intersection of data protection law, labour law and fundamental rights. You need to know when consent is viable as a basis for processing employee data and when the power imbalance makes it unworkable. Monitoring of email, internet use and location raises questions of proportionality and transparency. Pre-employment screening, background checks and references all demand a lawful basis and a clear retention schedule. Employee rights to access, rectification and erasure do not disappear at the workplace door, but they bend around legitimate employer interests. Collective bargaining agreements and works councils introduce a layer of complexity absent from other processing contexts. The exam will test whether you can identify when workplace processing crosses into unlawful surveillance or when transparency obligations have been met in an employment notice.
β Surveillance, marketing and online communications
Surveillance compliance turns on necessity and proportionality. CCTV, access control systems and behavioural monitoring all require a lawful basis, clear signage and a defined retention period. The ePrivacy Directive governs electronic marketing, cookies and direct communication by automated means. You must distinguish opt-in from opt-out regimes, know when prior consent is required, and understand the limited scope of the soft opt-in for existing customers. Internet technology brings cookie walls, tracking pixels, device fingerprinting and the interplay between ePrivacy and the GDPR. Processing of communications metadata, use of analytics tools and third-party embeds all raise compliance questions. The exam expects you to apply the right rule to the right channel, recognise when consent is mandatory, and spot the difference between what the GDPR permits and what ePrivacy constrains.
How Compliance with European Data Protection Law and Regulation is tested
Items from this topic present a scenario in one of the four contexts and ask you to identify the compliance obligation or the deficiency. You will be given a workplace monitoring arrangement, a marketing campaign, a website feature or a surveillance measure and asked what must change to bring it into line with the law. The trap is applying a general GDPR principle when a specific sectoral rule controls, or assuming that a practice lawful in one context transfers unchanged to another. Candidates lose marks by confusing ePrivacy consent requirements with GDPR lawful bases, or by failing to recognise when the employment relationship renders consent invalid. The questions reward precision: knowing which transparency obligation applies, which exemption is available, and where the boundary between lawful monitoring and intrusive surveillance is drawn. Read the scenario for context first, then identify the controlling rule.
The practice test lets you work through scenario-based items in all four compliance contexts before the exam. The PDF bank groups questions by workplace, surveillance, marketing and online settings, so you can isolate weak areas and drill them separately without re-reading the entire syllabus.
The question below places you in a marketing scenario and asks you to identify the compliance step that must be taken under the ePrivacy framework.
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company
A . She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
The GDPR requires sufficient guarantees of a company's ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?
Before the law itself comes the machinery that makes and enforces it. This topic covers the institutional architecture of the European Union, the historical path that led to the GDPR, and the legislative instruments that give data protection its binding force. You need to understand how directives differ from regulations, which institutions propose and adopt legislation, and why the 1995 Directive was replaced. The exam assumes you know the framework well enough to recognise which body does what and how...
Before the law itself comes the machinery that makes and enforces it. This topic covers the institutional architecture of the European Union, the historical path that led to the GDPR, and the legislative instruments that give data protection its binding force. You need to understand how directives differ from regulations, which institutions propose and adopt legislation, and why the 1995 Directive was replaced. The exam assumes you know the framework well enough to recognise which body does what and how the legal hierarchy works.
How Introduction to European Data Protection is tested
Items drawn from this topic ask you to identify the role of a specific EU institution, distinguish between types of legislative act, or place a development on the timeline that runs from the 1995 Directive through national implementation to the GDPR. You may be asked why the GDPR took the form it did, or which body has the power to issue adequacy decisions. The trap is confusing the European Commission with the European Parliament, or assuming that a directive has the same direct effect as a regulation. Candidates lose marks by misremembering the chronology or by attributing enforcement powers to an institution that only advises. The questions are factual and test whether you have absorbed the structure. There is no room for inference: either you know which institution adopts implementing acts or you do not. Read carefully when a question names multiple bodies, because the distinctions matter.
Institutional and legislative framework questions are short, factual and easy to miss under time pressure. The practice test surfaces them in timed conditions so you learn to answer quickly and move on, rather than second-guessing recall that should be automatic.
The question that follows asks you to identify the correct characterisation of an EU legislative instrument and its effect on member states.
To comply with the GDPR and the EU Court of Justice's decision in Schrems II, the European Commission issued what are commonly referred to as the new standard contractual clauses (SCCs). As a result, businesses must do all of the following EXCEPT?
With the framework in place, the topic shifts to the substance of the GDPR itself. Three areas dominate: the definitions and concepts that underpin every obligation, the security requirements that protect personal data from breach, and the catalogue of rights that data subjects may exercise. Each area is tested heavily, and each penalises vague or approximate knowledge. The exam expects you to apply definitions precisely, match security measures to risk, and know which right applies in which circumstance. How European...
With the framework in place, the topic shifts to the substance of the GDPR itself. Three areas dominate: the definitions and concepts that underpin every obligation, the security requirements that protect personal data from breach, and the catalogue of rights that data subjects may exercise. Each area is tested heavily, and each penalises vague or approximate knowledge. The exam expects you to apply definitions precisely, match security measures to risk, and know which right applies in which circumstance.
How European Data Protection Law and Regulation is tested
Items from this topic fall into three clusters. Concept questions test whether you can distinguish personal data from anonymous data, identify when processing occurs, or recognise the boundary between controller and processor. Security questions present a breach scenario or a risk profile and ask which measure is required or which obligation has been missed. Rights questions describe a data subject request and ask whether it must be honoured, whether an exemption applies, or what the time limit is. The trap across all three is reaching for an intuitive answer when the GDPR defines the term more narrowly. Candidates lose marks by assuming that pseudonymised data is anonymous, that any technical measure satisfies the security obligation, or that all rights requests must be granted without exception. The questions reward exact recall of definitions, thresholds and timelines. If the GDPR specifies a period or a condition, the exam will test it.
Definitions, security measures and data subject rights generate the highest question count across the exam. The PDF bank gives you volume across all three areas, so repeated exposure reveals which distinctions you consistently miss and which rights you confuse.
The question below tests your ability to apply a GDPR concept correctly in a processing scenario involving multiple parties.
Processing is only lawful when it rests on one of the six legal bases, and the choice of basis determines every downstream obligation. This topic also covers the transparency requirements that accompany any processing, and the rules governing transfers of personal data outside the EEA. Transfers remain one of the most frequently tested areas, because the mechanisms are specific, the risks are high, and the case law continues to evolve. You must know what each basis permits, when information must...
Processing is only lawful when it rests on one of the six legal bases, and the choice of basis determines every downstream obligation. This topic also covers the transparency requirements that accompany any processing, and the rules governing transfers of personal data outside the EEA. Transfers remain one of the most frequently tested areas, because the mechanisms are specific, the risks are high, and the case law continues to evolve. You must know what each basis permits, when information must be provided, and which transfer tool applies to which situation.
β Lawful bases and their application
The six lawful bases are not interchangeable, and the exam tests whether you know which one applies when. Consent must be freely given, specific, informed and unambiguous; it is rarely available in employment or public authority contexts. Contract covers processing necessary to perform an agreement with the data subject, not processing that is merely useful. Legitimate interests require a balancing test and cannot be used by public authorities in the performance of their tasks. Legal obligation and public task are narrow and must be anchored in EU or member state law. Vital interests apply in emergencies, not as a convenience. The choice of basis affects whether you can rely on automated decision-making, whether data subjects can object, and what you must say in your privacy notice. Candidates lose marks by selecting the easiest basis rather than the correct one, or by assuming that any legitimate purpose justifies processing under legitimate interests.
β Transparency and international transfers
Transparency obligations are detailed and non-negotiable. You must provide identity of the controller, contact details of the data protection officer if one is appointed, purposes and legal basis, legitimate interests if relied upon, recipients or categories of recipients, retention period or criteria, and the full catalogue of data subject rights. When data are collected indirectly, additional information is required. The timing, form and exceptions are all specified. International transfers demand a legal mechanism: adequacy decision, standard contractual clauses, binding corporate rules, or one of the derogations in Article 49. Post-Schrems II, you must also assess whether the destination country's laws undermine the protection the mechanism provides. The exam will present a transfer scenario and ask which tool is appropriate, or describe a transfer and ask what is missing. Candidates stumble when they assume that standard clauses alone suffice, forgetting the supplementary measures now required.
How European Data Processing is tested
Lawful basis items describe a processing operation and ask which basis applies, or present a basis and ask whether it is valid in the given context. Transparency items give you a privacy notice or a collection scenario and ask what is missing or what must be added. Transfer items describe a cross-border data flow and ask which mechanism is legally adequate, or which additional step is required following a transfer impact assessment. The trap in all three areas is choosing the answer that sounds reasonable over the one the GDPR mandates. Consent feels like the safe default, but it often is not. Standard clauses sound sufficient, but case law now requires more. Candidates lose marks by conflating what should be disclosed with what must be disclosed, or by assuming that any contractual arrangement legitimises a transfer. Read the scenario for the detail that determines which rule applies, then match it to the text.
Lawful bases and transfer mechanisms are tested in combination, not isolation, and the practice test reflects that. Timed sessions force you to distinguish consent from contract and adequacy from derogation under exam pressure, which is where approximate knowledge fails.
The question that follows asks you to identify the appropriate lawful basis for a processing operation described in a workplace setting.
The final topic addresses two questions: when does the GDPR apply, and what must organisations do to demonstrate compliance? Scope determines jurisdiction. Accountability translates principles into operational requirements. Supervision and enforcement bring consequences for failure. You need to know when the GDPR's territorial reach extends beyond the EEA, which accountability measures are mandatory and which are risk-based, how supervisory authorities coordinate, and what penalties are available. This topic ties the entire syllabus together, because every obligation discussed earlier depends on...
The final topic addresses two questions: when does the GDPR apply, and what must organisations do to demonstrate compliance? Scope determines jurisdiction. Accountability translates principles into operational requirements. Supervision and enforcement bring consequences for failure. You need to know when the GDPR's territorial reach extends beyond the EEA, which accountability measures are mandatory and which are risk-based, how supervisory authorities coordinate, and what penalties are available. This topic ties the entire syllabus together, because every obligation discussed earlier depends on scope, and every compliance measure is an accountability requirement.
β Territorial and material scope
The GDPR applies to controllers and processors established in the Union, regardless of where processing takes place. It also applies to non-EU entities that offer goods or services to data subjects in the Union or monitor their behaviour, even if no establishment exists. Material scope is narrower: the GDPR covers processing of personal data, wholly or partly by automated means, or in structured manual files. It does not cover processing by individuals for purely personal or household activities, or by competent authorities for law enforcement purposes. The exam tests whether you can identify when a non-EU controller falls within scope under the targeting or monitoring criteria, and when an exemption applies. Candidates lose marks by assuming that any online service triggers GDPR obligations, or by failing to recognise that an establishment in one member state brings the entire organisation within scope.
β Accountability measures and records
Accountability means demonstrating compliance, not merely achieving it. Records of processing activities are mandatory for most controllers and processors, with limited exceptions for small enterprises. Data protection impact assessments are required when processing is likely to result in a high risk, and prior consultation with the supervisory authority is required when the assessment shows that risk cannot be mitigated. Data protection officers must be appointed by public authorities, bodies that carry out large-scale monitoring, or those that process special categories or criminal data at scale. Codes of conduct and certification mechanisms are voluntary but can serve as evidence of compliance. Contracts with processors must include specific mandatory clauses. The exam expects you to know which measures are always required and which are triggered by risk or scale.
β Supervision, enforcement and penalties
Each member state designates one or more supervisory authorities with investigative, corrective and authorisation powers. The lead authority mechanism coordinates cross-border cases. The European Data Protection Board ensures consistent application through guidelines and binding decisions. Supervisory authorities can issue warnings, reprimands, orders to bring processing into compliance, bans on processing, and administrative fines. Fines are tiered: up to ten million euros or two percent of annual worldwide turnover for certain infringements, and up to twenty million euros or four percent for others, whichever is higher. The exam tests whether you know which authority has jurisdiction, how the one-stop-shop mechanism works, and which violations attract the higher fine tier. Candidates lose marks by assuming that any breach triggers the maximum penalty, or by confusing the roles of national authorities and the Board.
How European Data Protection: Scope and Accountability is tested
Scope items present a fact pattern involving a non-EU entity or an edge case and ask whether the GDPR applies. Accountability items describe an organisation or a processing operation and ask which measure is required: a DPIA, a DPO, a record of processing activities, or a specific contract clause. Enforcement items ask which supervisory authority has competence, how the cooperation mechanism operates, or which fine tier applies to a described infringement. The trap is applying a rule of thumb when the GDPR specifies a threshold or a condition. Candidates lose marks by assuming that any high-risk processing requires prior consultation when only some do, or by choosing the lead authority based on where the data subject resides rather than where the main establishment is located. The questions reward precise knowledge of triggers, thresholds and procedural rules. Read the scenario for the detail that determines jurisdiction or the obligation, then apply the rule exactly as written.
Scope and accountability questions often turn on a single factual detail buried in a longer scenario. The practice test trains you to extract that detail under timed conditions and apply the correct rule, which is the skill the exam measures across every topic.
The question below presents a cross-border processing scenario and asks you to identify which supervisory authority mechanism applies.
Ready to Start Practicing?
Access all questions and start your exam preparation journey
Upgrade to Full CIPP-E Exam Questions π