CIPP 9 UPDATED ACTUAL EXAM QUESTIONS CORRECT ANSWERS GRADED A PLUS
CIPP/E Exam Questions and Answers | Detailed
Explanations and Full Rationales | Grade A+
2026/2027
Question:
What is the one major goal that the OECD Guidelinges, Convention 108, and the Directive all had in
common but largely failed to achieve in Europe?
Answer:
The restriction of cross-border data flow
Question:
Which EU institution is vested with the competence to propose new data protection legislation on its
own initiative?
Answer:
Commission
Question:
Which institution has the power to adopt findings that confirm the adequacy of the data protection
level in a non-EU country?
Answer:
European Commission
Question:
What type of data lies beyond the scope of the GDPR?
Answer:
Anonymised
,Question:
What is the consequence if a processor makes an independent decision regarding the purposes and
means of processing it carries out on behalf of a controller?
Answer:
The processor will be considered to be a controller
Question:
With the issue of consent, the GDPR allows member states some choice regarding what?
Answer:
The age which children must be required to obtain parental consent
Question:
Which sentence BEST summarizes the concepts of Fairness, lawfullness, and transparency, as
expressly required by Article 5 of the GDPR?
Answer:
Fairness and transparency refer to the communication of key information before collecting data;
lawfulness refers to compliance with government regulations
Question:
Assuming that the "without undue delay" provison is followed, what is the time limit for complying
with a data access request?
Answer:
1 month + additional 2 months
Question:
Company X has entrusted the processing of their payroll data provider to Y. Provider Y stores this
encrypted data on its server. The IT department of Provider Y finds out that someone managed to
hack into the system and take a copy of the data from its server. In this scenario, whom does
Provider Y have the obligation to notify?
, Answer:
Company X
Question:
Which of the following would require designationg a data protection officer?
Answer:
The core activites of the controller or processor consist of processing operations that require
systematic monitoring of data subjects on a large scale. (public authority or large scal sensitive data
would apply as well)
Question:
When is a data sharing agreement MOST likely to be needed?
Answer:
When personal data is being shared between commercial orgs acting as joint data controllers
Question:
An employee of company X has just noticed a memory stick containing records of client data,
including their names, addresses and full contact details has disappeared. The data on the stick is
unencrypted and in clear text. It is uncertain what has happened to the stick as this stage, but it likely
was lost during the travel of an employee. What should the company do?
Answer:
Notify as soon as possible the data protection supervisory authority that a data breach may have
taken place
Question:
The GDPR specifies fines that may be levied against data controllers for certain infringements.
Which of the following infringements would be subject to the less severe administrative fine of up
to 10 million Euros?
Answer:
CIPP/E Exam Questions and Answers | Detailed
Explanations and Full Rationales | Grade A+
2026/2027
Question:
What is the one major goal that the OECD Guidelinges, Convention 108, and the Directive all had in
common but largely failed to achieve in Europe?
Answer:
The restriction of cross-border data flow
Question:
Which EU institution is vested with the competence to propose new data protection legislation on its
own initiative?
Answer:
Commission
Question:
Which institution has the power to adopt findings that confirm the adequacy of the data protection
level in a non-EU country?
Answer:
European Commission
Question:
What type of data lies beyond the scope of the GDPR?
Answer:
Anonymised
,Question:
What is the consequence if a processor makes an independent decision regarding the purposes and
means of processing it carries out on behalf of a controller?
Answer:
The processor will be considered to be a controller
Question:
With the issue of consent, the GDPR allows member states some choice regarding what?
Answer:
The age which children must be required to obtain parental consent
Question:
Which sentence BEST summarizes the concepts of Fairness, lawfullness, and transparency, as
expressly required by Article 5 of the GDPR?
Answer:
Fairness and transparency refer to the communication of key information before collecting data;
lawfulness refers to compliance with government regulations
Question:
Assuming that the "without undue delay" provison is followed, what is the time limit for complying
with a data access request?
Answer:
1 month + additional 2 months
Question:
Company X has entrusted the processing of their payroll data provider to Y. Provider Y stores this
encrypted data on its server. The IT department of Provider Y finds out that someone managed to
hack into the system and take a copy of the data from its server. In this scenario, whom does
Provider Y have the obligation to notify?
, Answer:
Company X
Question:
Which of the following would require designationg a data protection officer?
Answer:
The core activites of the controller or processor consist of processing operations that require
systematic monitoring of data subjects on a large scale. (public authority or large scal sensitive data
would apply as well)
Question:
When is a data sharing agreement MOST likely to be needed?
Answer:
When personal data is being shared between commercial orgs acting as joint data controllers
Question:
An employee of company X has just noticed a memory stick containing records of client data,
including their names, addresses and full contact details has disappeared. The data on the stick is
unencrypted and in clear text. It is uncertain what has happened to the stick as this stage, but it likely
was lost during the travel of an employee. What should the company do?
Answer:
Notify as soon as possible the data protection supervisory authority that a data breach may have
taken place
Question:
The GDPR specifies fines that may be levied against data controllers for certain infringements.
Which of the following infringements would be subject to the less severe administrative fine of up
to 10 million Euros?
Answer: