About the Exam

The ANAB-accredited CIPP/E exam assesses knowledge of European privacy laws and regulations, including GDPR and requirements for the responsible transfer of sensitive personal data. It is intended for privacy professionals working within GDPR and European national compliance frameworks. Passing demonstrates understanding of pan-European and national data protection laws, key privacy terminology, and practical concepts for protecting personal data and trans-border data flows.

Exam Topics

  • Introduction to European Data Protection15%
  • European Data Protection Law and Regulation30%
  • European Data Processing20%
  • European Data Protection: Scope and Accountability30%
  • Compliance with European Data Protection Law and Regulation5%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 7, 2026 at 2:18 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

European Data Protection: Scope and Accountability

Under which of the following circumstances does the General Data Protection Regulation not apply to personal-data processing?

Explanation

GDPR Article 2(2)(c) excludes processing performed by a natural person in the course of a purely personal or household activity. The Regulation can still cover non-automated data in a filing system, pseudonymised personal data, and storage of personal data.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

European Data Protection: Scope and Accountability

Which type of data falls outside the scope of the General Data Protection Regulation?

Explanation

GDPR Recital 26 provides that the Regulation does not apply to anonymous information, including personal data anonymized so that the data subject is no longer identifiable. Pseudonymization, encryption, and masking can preserve the ability to identify or re-identify a person and therefore do not by themselves take data outside GDPR scope.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Compliance with European Data Protection Law and Regulation

Before Anna decides whether Frank’s performance database is permissible, what further information does she require?

Explanation

Compatibility of further processing depends on the original collection context and the relationship with the data subjects, as well as the proposed new purpose and its effects. The GDPR also requires the controller to inform data subjects of a new purpose before further processing where applicable. Therefore, the students’ existing notices and the intended research use must be established.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

European Data Protection: Scope and Accountability

Which of the following would most likely not fall within the GDPR definition of “personal data”?

Explanation

GDPR personal data includes information relating to an identified or identifiable natural person, including identification numbers. Unlinked aggregated statistical data do not relate to an identified or identifiable individual; as anonymous information, they are outside the GDPR’s personal-data scope.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Compliance with European Data Protection Law and Regulation

Which statement correctly summarizes Bedrock’s obligation concerning Louis’s data portability request?

Explanation

Under GDPR Article 20(2), direct controller-to-controller transmission is required only where it is technically feasible. The GDPR encourages interoperable formats but does not require controllers to adopt or maintain technically compatible systems; providing the portable data in structured, commonly used, machine-readable formats satisfies the separate portability requirement.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home