Try 12 Certified Information Privacy Professional/Europe (CIPP/E) sample questions on GDPR concepts, lawful bases, data-subject rights, controllers, processors, transfers, and enforcement.
Certified Information Privacy Professional/Europe (CIPP/E) preparation focuses on European data-protection principles, GDPR roles, lawful bases, rights, transfers, security, accountability, and supervisory authority concepts.
Use these 12 original sample questions for initial self-assessment. They are not official IAPP questions and do not reproduce a live exam.
Verify current certification names, exam policies, and requirements with the IAPP certification page .
Topic: controller role
Who is most likely the controller in a processing arrangement?
Best answer: B
Explanation: A controller determines why and how personal data is processed. Role classification drives obligations.
Topic: processor obligations
A processor receives personal data from a controller. What is a core processor obligation?
Best answer: C
Explanation: Processor duties commonly include documented instructions, security, assistance, subprocessor controls, and deletion or return.
Topic: lawful basis
Why must an organization identify a lawful basis before processing?
Best answer: A
Explanation: A lawful basis supports the legitimacy of processing and must fit the specific purpose.
Topic: data minimization
Which practice best reflects data minimization?
Best answer: D
Explanation: Data minimization limits collection and processing to what is necessary for the purpose.
Topic: data-subject rights
A data subject requests access to their personal data. What should the organization do?
Best answer: D
Explanation: Rights handling requires identity, scope, exceptions, timing, and evidence of response.
Topic: DPIA
When is a data protection impact assessment especially relevant?
Best answer: B
Explanation: DPIAs support prior assessment and mitigation for high-risk processing.
Topic: breach notification
What should be assessed after a personal-data breach?
Best answer: A
Explanation: Breach response depends on facts, risk to individuals, notification thresholds, and documentation.
Topic: international transfers
Why are transfers outside the European Economic Area reviewed?
Best answer: C
Explanation: International transfer mechanisms and risk assessment are central CIPP/E topics.
Topic: accountability
Which evidence supports accountability?
Best answer: A
Explanation: Accountability requires being able to demonstrate compliance through governance and records.
Topic: privacy by default
What does privacy by default emphasize?
Best answer: D
Explanation: Privacy by default means protective settings and necessary processing are the baseline.
Topic: special categories
Why do special categories of personal data require careful review?
Best answer: C
Explanation: Special-category data is more sensitive and often subject to stricter processing conditions.
Topic: supervisory authority
What is a supervisory authority’s role?
Best answer: B
Explanation: Supervisory authorities oversee compliance and enforcement within the data-protection framework.