CIPP 4 UPDATED ACTUAL EXAM QUESTIONS CORRECT ANSWERS GRADED A PLUS
CIPP/E 65 Exam Questions and Answers (2026/2027)
| Full Questions and Answers with Rationales | A+
Verified
Question:
Outliers work on their website to company x, employee of Company X steals the data -delete it -
tells boss. Q: What is company x legally obliged to do?
Answer:
A: NotifyOutliers
Question:
Outliers work on their website to company x, employee of Company X steals the data -delete it -
tells boss. Q: What does Outliers then need to do?
Answer:
A: Nothingas data was deleted
Question:
Outliers work on their website to company x, employee of Company X steals the data -delete it -
tells boss. Q: Follows on with Cookies question?
Answer:
A: Consentto opt-in to cookies
Question:
Privacy notice for new Health App collecting sensitive data. Q: What is the problem with the draft?
Answer:
A: Them form is asking for health information from the outset, which is not legal
,Question:
Privacy notice for new Health App collecting sensitive data Q: Potential problem with collecting
children data?
Answer:
A: Need to demonstrate steps to gain parental consent
Question:
Anna is lawyer foruniversity tasked with Student Records. Frank is a professor. Four types of
data:Student Data - personal infoEmployee Data - personal infoAlumni Data - personal
infoDepartment of Education Data:demographic data - no personal identifiers (used to see how first
year students progress, etc.)Frank wants to build a database to process data and see how first year
students in his class progressed. Frank builds algorithm to process data without identifiers. All
university systems are encrypted. Takes data to his home laptop which is not encrypted. Loses
laptop Q: Which types of data does Anna NOT have to include in her record of processing
activities?
Answer:
Department of Education Records
Question:
Q: What should the Anna/DPO checkto confirm he can process those data?
Answer:
More information about the algorithm he has developed
Question:
Q: He losses the data, what should happen next? Should they inform the students?
Answer:
Question:
, Answer:
Yes because potential high risk since data was not encrypted Case study on guy gets photo taken at a
gym in Germany consents to them using it for marketing Gym HQ in France Gyms all over EU He
lives in UK Submits request to ICO in UK
Question:
ICO refers to CNIL (this is the SA in France) Q: In effort of Cooperation (the lead SA, CNIL, gets
their judgement) what should the they do now?
Answer:
Draft a draft decision and submit to supporting SAs for their opinion.
Question:
What does he have to do for lawsuit? (each location is a controller!)
Answer:
Answer: Go to each gym branch.
Question:
Question on what he should do if he wants tosue
Answer:
Sue ANY relevant branch as each can be liable for entire damage
Question:
ABC Insurance gives data to subsidiary which begins direct marketing to Jason. Jason decides to
switch insurance companies. ABC Insurance is direct marketing to Jason. Jason asks them to stop
but they say that there is a line in the contract he signed saying he consents to direct marketing and
he doesn't stop. Wants to transfer data - they give it to him in PDF format. He asks for them to
transfer and they can't because it's too time-consuming and not feasible. Q: According to GDPR
regulations on direct marketing(note:I think the wording here is key), can Jason stop ABC from
direct marketing?
CIPP/E 65 Exam Questions and Answers (2026/2027)
| Full Questions and Answers with Rationales | A+
Verified
Question:
Outliers work on their website to company x, employee of Company X steals the data -delete it -
tells boss. Q: What is company x legally obliged to do?
Answer:
A: NotifyOutliers
Question:
Outliers work on their website to company x, employee of Company X steals the data -delete it -
tells boss. Q: What does Outliers then need to do?
Answer:
A: Nothingas data was deleted
Question:
Outliers work on their website to company x, employee of Company X steals the data -delete it -
tells boss. Q: Follows on with Cookies question?
Answer:
A: Consentto opt-in to cookies
Question:
Privacy notice for new Health App collecting sensitive data. Q: What is the problem with the draft?
Answer:
A: Them form is asking for health information from the outset, which is not legal
,Question:
Privacy notice for new Health App collecting sensitive data Q: Potential problem with collecting
children data?
Answer:
A: Need to demonstrate steps to gain parental consent
Question:
Anna is lawyer foruniversity tasked with Student Records. Frank is a professor. Four types of
data:Student Data - personal infoEmployee Data - personal infoAlumni Data - personal
infoDepartment of Education Data:demographic data - no personal identifiers (used to see how first
year students progress, etc.)Frank wants to build a database to process data and see how first year
students in his class progressed. Frank builds algorithm to process data without identifiers. All
university systems are encrypted. Takes data to his home laptop which is not encrypted. Loses
laptop Q: Which types of data does Anna NOT have to include in her record of processing
activities?
Answer:
Department of Education Records
Question:
Q: What should the Anna/DPO checkto confirm he can process those data?
Answer:
More information about the algorithm he has developed
Question:
Q: He losses the data, what should happen next? Should they inform the students?
Answer:
Question:
, Answer:
Yes because potential high risk since data was not encrypted Case study on guy gets photo taken at a
gym in Germany consents to them using it for marketing Gym HQ in France Gyms all over EU He
lives in UK Submits request to ICO in UK
Question:
ICO refers to CNIL (this is the SA in France) Q: In effort of Cooperation (the lead SA, CNIL, gets
their judgement) what should the they do now?
Answer:
Draft a draft decision and submit to supporting SAs for their opinion.
Question:
What does he have to do for lawsuit? (each location is a controller!)
Answer:
Answer: Go to each gym branch.
Question:
Question on what he should do if he wants tosue
Answer:
Sue ANY relevant branch as each can be liable for entire damage
Question:
ABC Insurance gives data to subsidiary which begins direct marketing to Jason. Jason decides to
switch insurance companies. ABC Insurance is direct marketing to Jason. Jason asks them to stop
but they say that there is a line in the contract he signed saying he consents to direct marketing and
he doesn't stop. Wants to transfer data - they give it to him in PDF format. He asks for them to
transfer and they can't because it's too time-consuming and not feasible. Q: According to GDPR
regulations on direct marketing(note:I think the wording here is key), can Jason stop ABC from
direct marketing?