Complete Exam Preparation (98% Pass Rate, MCQs & Practice Questions)
Academic Year 2025/2026.
CHAPTER I: DATA PROTECTION LAWS (50 Questions)
Foundational Level (Questions 1-15)
Q1: Which EU institution is primarily responsible for proposing new data protection
legislation?
A. The European Data Protection Board (EDPB)
B. The European Commission
C. The Court of Justice of the European Union (CJEU)
D. The European Data Protection Supervisor (EDPS)
Correct Answer: B
Topic: EU Institutional Framework
Rationale: The European Commission holds the sole right of legislative initiative in the
EU, meaning it is the only institution that can propose new laws, including data
protection regulations like the GDPR. The EDPB (A) is an independent body that ensures
consistent application of GDPR but doesn't propose legislation. The CJEU (C) interprets
EU law through its judgments but doesn't create legislation. The EDPS (D) is an
independent supervisory authority that advises EU institutions on data protection
matters but lacks legislative initiative.
Q2: Under Article 3(1) GDPR, territorial scope applies to the processing of personal data
when:
,A. The data subject is physically located within the EU at the time of processing
B. The processing activities are related to the offering of goods or services to data
subjects in the EU
C. The data controller or processor is established in the EU, regardless of where
processing occurs
D. The processing involves monitoring the behavior of EU residents outside the EU
Correct Answer: C
Topic: Territorial Scope (Article 3)
Rationale: Article 3(1) establishes that the GDPR applies to processing by a controller or
processor established in the EU, regardless of whether the processing takes place in the
EU or not. This is the primary territorial scope test. Option A is incorrect because the
data subject's physical location isn't the determining factor under Article 3(1). Options B
and D describe the scenarios covered under Article 3(2) for non-EU established
controllers/processors, not Article 3(1).
Q3: The ePrivacy Directive (2002/58/EC) primarily regulates:
A. The general processing of personal data by automated means
B. The processing of personal data in the electronic communications sector
C. Data transfers to third countries outside the European Economic Area
D. The establishment of national data protection authorities
Correct Answer: B
Topic: ePrivacy Directive and Sector-Specific Laws
Rationale: The ePrivacy Directive (Directive on privacy and electronic communications)
specifically addresses the processing of personal data and the protection of privacy in
the electronic communications sector, complementing the GDPR. It covers areas like
cookies, email marketing, and confidentiality of communications. Option A describes
,the general scope of the GDPR. Option C relates to Chapter V of the GDPR. Option D
concerns the independence and powers of supervisory authorities under GDPR Chapter
VI.
Q4: Which of the following best describes the relationship between the GDPR and
Member State law?
A. The GDPR is entirely self-executing and leaves no room for Member State
derogations
B. Member States may implement stricter rules only with prior Commission approval
C. The GDPR provides for opening clauses allowing Member States to specify or restrict
its provisions in certain areas
D. Member States can unilaterally modify GDPR provisions to suit national preferences
Correct Answer: C
Topic: Relationship Between GDPR and Member State Law
Rationale: The GDPR contains numerous "opening clauses" (also called flexibility
clauses or derogations) that explicitly permit Member States to maintain or introduce
specific rules in areas such as employment (Article 88), freedom of expression (Article
85), and processing for archiving purposes in the public interest (Article 89). These are
not unilateral modifications (D) nor do they require Commission approval (B). While the
GDPR is directly applicable, it is not entirely self-executing (A) due to these opening
clauses.
Q5: The Court of Justice of the European Union (CJEU) plays what role in data
protection law?
A. It enforces GDPR compliance directly against controllers and processors
B. It ensures the uniform interpretation and application of EU data protection law
C. It proposes amendments to the GDPR based on technological developments
, D. It supervises the activities of national data protection authorities
Correct Answer: B
Topic: Role of the CJEU
Rationale: The CJEU's primary function is to ensure that EU law is interpreted and
applied uniformly across all Member States. In data protection, it has issued landmark
rulings such as the "right to be forgotten" (Google Spain case, C-131/12) and the
invalidation of the Safe Harbor (Schrems I, C-362/14) and Privacy Shield (Schrems II,
C-311/18) frameworks. The CJEU does not directly enforce against controllers (A) -
that's the role of supervisory authorities. It doesn't propose legislation (C) - that's the
Commission's role. It doesn't supervise DPAs (D) - the EDPB coordinates them.
Q6: Which legal instrument did the GDPR replace?
A. The ePrivacy Directive (2002/58/EC)
B. The Data Protection Directive (95/46/EC)
C. The Charter of Fundamental Rights of the European Union
D. The Convention for the Protection of Individuals with regard to Automatic Processing
of Personal Data (Convention 108)
Correct Answer: B
Topic: Historical Development of EU Data Protection Law
Rationale: Regulation (EU) 2016/679 (GDPR) replaced Directive 95/46/EC (the Data
Protection Directive) as of May 25, 2018. The GDPR was designed to harmonize data
protection laws across the EU and modernize the legal framework for the digital age.
The ePrivacy Directive (A) remains in force (though being updated). The Charter (C) is a
fundamental rights document, not a data protection instrument being replaced.