CIPP-E EXAM, PRACTICE EXAM AND STUDY
GUIDE 2025 WITH ACTUAL CORRECT
QUESTIONS AND VERIFIED DETAILED
ANSWERS |FREQUENTLY TESTED
QUESTIONS AND SOLUTIONS |ALREADY
GRADED A+|NEWEST |LATEST UPDATE
|GUARANTEED PASS
CIPP-E EXAM
What is a derogation?
An exemption (granted under very limited circumstances) from the prohibition on transferring
personal data outside the EEA.
Under what circumstances might derogation be granted?
- Explicit consent
- Where necessary for performance of a contract with the data subject (i.e., data subject wants
to book a hotel in a foreign country)
- Public interest
- Establishment, exercise, or defensive legal claims
- Protection of vital interests of the data subject or other persons
- Transfer from a register of public information
- Legitimate interests of the controller
What are the six purposes of a supervisory authority?
1|Page
,- Promote, monitor, enforce the GDPR
- Promote awareness
- Conduct investigations
- Protect fundamental human rights
- Draw up annual reports
- Facilitate free flow of personal data within the EU
What are the three categories of power of the supervisory authority?
- Investigative
- Corrective
- Authorization and advisory
What is the methodology for identifying the lead supervisory authority?
- If only a single establishment in the EU, then simply that place of establishment.
- If multiple establishments, then the lead is the place of central administration. Unless
decisions about some processing take place at a different location, then that is the location of
the lead for that particular processing. (Thus, there can be multiple leads for various processing
activities.)
What are the six cooperation and consistency mechanisms in Chapter VII of the GDPR?
- Cooperation
- Mutual assistance
- Joint operations
- Consistency mechanism
- Dispute resolution
2|Page
,- Urgency procedure
What is the "cooperation" mechanism in Chapter VII of the GDPR?
Cooperation between the lead supervisory authority and other concerned supervisory
authorities to reach consensus.
What is the "mutual assistance" mechanism in Chapter VII of the GDPR?
Provision of relevant information between supervisory authorities.
What is the "joint operations" mechanism in Chapter VII of the GDPR?
Joint supervisory authority investigations and enforcement measures of controllers or
processors in several member states or when data subjects are in more than one member state.
What is the "consistency mechanism" mechanism in Chapter VII of the GDPR?
A specific collaborative process between supervisory authorities, the commission and the
European Data Protection Board for adopting certain measures and ensuring consistent GDPR
application.
What is the "dispute resolution" mechanism in Chapter VII of the GDPR?
Mechanism to dispute or decision (if not jointly agreed upon by the supervisory authorities) and
the issuance of binding decisions.
What is the "urgency procedure" mechanism in Chapter VII of the GDPR?
Procedure for the immediate adoption of provisional measures within a member state.
What does the European Data Protection Board replace and what is a comprised of?
- EDPB replaces the Article 29 Working Party
- Comprised of a representative of every member states supervisory authority
- 31 member states of EEA sit on EDPB, but only 28 EU member states actively participate
What are the roles of the EDPB?
- Monitor for correct application of the GDPR
- Oversee the consistency mechanism for ensuring a consistent approach to data
3|Page
, - Issue guidance and advice to the commission for personal data protection on a pan-European
basis
- Preside over the dispute resolution process
What is the lower level fine for infringements of the GDPR?
10M Euro or 2% or global annual turnover
What is the upper level fine for infringements of the GDPR?
20M Euro or 4% or global annual turnover
Infringements relating to what will lead to the lower level fine of the GDPR?
- Integrating data protection by design and by default
- Records
- Cooperation with the supervisory authority
- Security of processing data
- Notification of a personal data breach to the supervisory authority
- Notification of a personal data breach to a data subject
- Data protection impact assessment
- Prior consultation
- Designation, position, or tasks of the DPO
- Certification
Infringements relating to what will lead to the upper level fine of the GDPR?
(BPRT = Basic principle, rights, transfers)
- The basic principle of processing, including conditions for consent, lawfulness of processing,
and processing of special categories of personal data
4|Page
GUIDE 2025 WITH ACTUAL CORRECT
QUESTIONS AND VERIFIED DETAILED
ANSWERS |FREQUENTLY TESTED
QUESTIONS AND SOLUTIONS |ALREADY
GRADED A+|NEWEST |LATEST UPDATE
|GUARANTEED PASS
CIPP-E EXAM
What is a derogation?
An exemption (granted under very limited circumstances) from the prohibition on transferring
personal data outside the EEA.
Under what circumstances might derogation be granted?
- Explicit consent
- Where necessary for performance of a contract with the data subject (i.e., data subject wants
to book a hotel in a foreign country)
- Public interest
- Establishment, exercise, or defensive legal claims
- Protection of vital interests of the data subject or other persons
- Transfer from a register of public information
- Legitimate interests of the controller
What are the six purposes of a supervisory authority?
1|Page
,- Promote, monitor, enforce the GDPR
- Promote awareness
- Conduct investigations
- Protect fundamental human rights
- Draw up annual reports
- Facilitate free flow of personal data within the EU
What are the three categories of power of the supervisory authority?
- Investigative
- Corrective
- Authorization and advisory
What is the methodology for identifying the lead supervisory authority?
- If only a single establishment in the EU, then simply that place of establishment.
- If multiple establishments, then the lead is the place of central administration. Unless
decisions about some processing take place at a different location, then that is the location of
the lead for that particular processing. (Thus, there can be multiple leads for various processing
activities.)
What are the six cooperation and consistency mechanisms in Chapter VII of the GDPR?
- Cooperation
- Mutual assistance
- Joint operations
- Consistency mechanism
- Dispute resolution
2|Page
,- Urgency procedure
What is the "cooperation" mechanism in Chapter VII of the GDPR?
Cooperation between the lead supervisory authority and other concerned supervisory
authorities to reach consensus.
What is the "mutual assistance" mechanism in Chapter VII of the GDPR?
Provision of relevant information between supervisory authorities.
What is the "joint operations" mechanism in Chapter VII of the GDPR?
Joint supervisory authority investigations and enforcement measures of controllers or
processors in several member states or when data subjects are in more than one member state.
What is the "consistency mechanism" mechanism in Chapter VII of the GDPR?
A specific collaborative process between supervisory authorities, the commission and the
European Data Protection Board for adopting certain measures and ensuring consistent GDPR
application.
What is the "dispute resolution" mechanism in Chapter VII of the GDPR?
Mechanism to dispute or decision (if not jointly agreed upon by the supervisory authorities) and
the issuance of binding decisions.
What is the "urgency procedure" mechanism in Chapter VII of the GDPR?
Procedure for the immediate adoption of provisional measures within a member state.
What does the European Data Protection Board replace and what is a comprised of?
- EDPB replaces the Article 29 Working Party
- Comprised of a representative of every member states supervisory authority
- 31 member states of EEA sit on EDPB, but only 28 EU member states actively participate
What are the roles of the EDPB?
- Monitor for correct application of the GDPR
- Oversee the consistency mechanism for ensuring a consistent approach to data
3|Page
, - Issue guidance and advice to the commission for personal data protection on a pan-European
basis
- Preside over the dispute resolution process
What is the lower level fine for infringements of the GDPR?
10M Euro or 2% or global annual turnover
What is the upper level fine for infringements of the GDPR?
20M Euro or 4% or global annual turnover
Infringements relating to what will lead to the lower level fine of the GDPR?
- Integrating data protection by design and by default
- Records
- Cooperation with the supervisory authority
- Security of processing data
- Notification of a personal data breach to the supervisory authority
- Notification of a personal data breach to a data subject
- Data protection impact assessment
- Prior consultation
- Designation, position, or tasks of the DPO
- Certification
Infringements relating to what will lead to the upper level fine of the GDPR?
(BPRT = Basic principle, rights, transfers)
- The basic principle of processing, including conditions for consent, lawfulness of processing,
and processing of special categories of personal data
4|Page