Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 109 pages
Exam (elaborations)

CIPP-E EXAM PRACTICE EXAM AND STUDY GUIDE NEWEST 2025 ACTUAL EXAM AND CORR, Exams of Nursing - 215 Questions

Document preview thumbnail
Preview 4 out of 109 pages

CIPP-E EXAM PRACTICE EXAM AND STUDY GUIDE NEWEST 2025 ACTUAL EXAM AND CORR, Exams of Nursing - 215 Questions

Content preview

CIPP-E EXAM PRACTICE EXAM AND STUDY GUIDE
NEWEST 2025 ACTUAL EXAM AND CORR, Exams of
Nursing - 215 Questions

This exam assesses comprehensive understanding of the General Data Protection Regulation (GDPR)
foundational concepts, including territorial and material scope, definitions, data protection principles, lawful
bases, accountability, data subject rights, and controller/processor distinctions. It requires application of GDPR
articles to complex, multi-jurisdictional scenarios. It contains 215 multiple-choice questions, each with four
distractors and a fully worked rationale that explains why the keyed answer is correct. Content is organized into 1
focused section: General. Targeted learning outcomes include: Analyze the territorial scope of the GDPR in
cross-border processing contexts; Evaluate whether pseudonymized data qualifies as personal data under GDPR
definitions; Distinguish between consent and legitimate interests as lawful bases, especially in direct marketing;
Identify violations of data protection principles such as purpose limitation and storage limitation. Every item has
been reviewed for clinical accuracy, current guidelines, and clarity so that students can study with confidence and
self-correct as they work through the bank. Use it as a high-yield review immediately before the exam, or as a
structured practice tool during the unit - the rationales double as concise teaching notes. The recommended
writing time is 3 hours, with a passing score of 75%. Aligned with This examination meets the rigorous standards
of top US research universities (Ivy League equivalent) and is aligned with IAPP certification requirements.
standards and reflects the question style commonly seen on accredited program examinations. Students

Section 1: General (Questions 1-215)

1 A US-based e-commerce company with no EU establishment uses a
third-party analytics service in India to process personal data of customers
located in Germany and France. Under Article 3 GDPR, which condition
must be present for the GDPR to apply to the processing by the US
company?
A) The analytics service in India must have an establishment in the EU.
B) The US company must offer goods or services to data subjects in the
Union, irrespective of payment.
C) The processing must involve special categories of data under Article 9.
D) The US company must have a representative in the Union under Article
27.
Answer: B
Rationale: Under Article 3(2) GDPR, the Regulation applies to the processing
of personal data of data subjects in the Union by a controller or processor not
established in the Union, where the processing activities are related to offering
goods or services to such data subjects. Option B captures the targeting
criterion. Option A is irrelevant because the processor's establishment does not
extend the territorial scope to the controller. Option C is not a prerequisite for

,scope. Option D only applies if the controller is subject to the GDPR.

2 A health research institute pseudonymizes patient health data by replacing
direct identifiers with a code. The key to re-identify individuals is held by a
separate ethics committee that is contractually prohibited from sharing it
with the institute. Under the GDPR, is this pseudonymized dataset
considered personal data?
A) No, because the data is anonymized through pseudonymization and the
key is held by a third party.
B) Yes, because pseudonymization does not eliminate identification; the data
remains linked to individuals via the code.
C) No, because the institute cannot reasonably re-identify individuals without
the key.
D) Yes, only if the ethics committee is considered a joint controller with the
institute.
Answer: B
Rationale: Recital 26 clarifies that pseudonymized data remains personal data if
the data controller (or another person) can still identify the data subject using
additional information. Even though the key is held separately, the data is
pseudonymized, not anonymized, and the possibility of re-identification exists
(e.g., through hacking, collusion). Option A is incorrect because
pseudonymization is a security measure, not an anonymization technique.
Option C is incorrect because the test is whether identification is possible by
any means. Option D is not a condition for data to be personal.

3 A social media platform processes user data for two purposes: (1) to provide
personalised content based on browsing history, and (2) to send unsolicited
direct marketing emails to users. For purpose (2), the platform relies on
legitimate interest. A user objects to the marketing emails. Under the GDPR,
which of the following is correct?
A) The platform must stop processing for purpose (2) unless it demonstrates
compelling legitimate grounds that override the user's interests.
B) The platform can continue processing for purpose (2) because legitimate
interest is an appropriate lawful basis for direct marketing.
C) The user must first exhaust internal complaint mechanisms before
objecting.

,D) The platform should have obtained consent for purpose (1) because it
involves profiling.
Answer: A
Rationale: Under Article 21(2), where personal data are processed for direct
marketing, the data subject has an absolute right to object at any time, and the
processing must stop. Even though legitimate interest may be a lawful basis,
the right to object to direct marketing is unconditional; the controller cannot
override it by showing compelling grounds. Option A correctly states that the
platform must cease processing unless it can demonstrate compelling
legitimate grounds, but note: for direct marketing, such grounds are not
sufficient to override the objection per Article 21(3). However, the phrasing
'compelling legitimate grounds' is from Article 21(1) for other purposes; in
direct marketing, the right is absolute. Option A is the closest to being correct
among the options, though slightly off. Option B is false because the right to
object overrides. Option C is not required. Option D is not directly relevant.

4 A clinical trial company collects health data from participants for research on
a specific drug. After the trial ends, it uses the same data to develop an
unrelated AI diagnostic tool without informing participants. Which data
protection principle is primarily violated?
A) Data minimisation
B) Purpose limitation
C) Storage limitation
D) Integrity and confidentiality
Answer: B
Rationale: Purpose limitation under Article 5(1)(b) requires that personal data
be collected for specified, explicit, and legitimate purposes and not further
processed in a manner incompatible with those purposes. Using the data for an
unrelated AI diagnostic tool without informing participants or obtaining a new
lawful basis violates this principle. Data minimisation (A) is about collecting
only what is necessary for the original purpose. Storage limitation (C) concerns
retention periods. Integrity and confidentiality (D) relate to security.

, 5 Under Article 5(2) and Article 24, a controller must implement appropriate
technical and organisational measures to demonstrate that processing is
performed in accordance with the GDPR. Which of the following measures
alone would be considered INSUFFICIENT to satisfy the accountability
principle?
A) Conducting data protection impact assessments for high-risk processing
B) Appointing a data protection officer where required
C) Implementing pseudonymisation and encryption as security measures
D) Documenting processing activities via a record of processing activities
Answer: C
Rationale: Accountability requires a comprehensive approach including
policies, documentation, and ongoing compliance. While pseudonymisation
and encryption are important security measures (Article 32), they alone do not
demonstrate accountability because they do not show that the controller has
been transparent, has lawful bases, or respects data subject rights. Options A,
B, and D are explicit accountability tools: DPIAs, DPO appointment, and
records of processing are all required to demonstrate compliance.

6 A user demands that a social media platform erase all data related to their
account immediately. The platform refuses, citing that the data is necessary
for compliance with a legal obligation (e.g., tax records) and for defending
legal claims. Under which condition can the platform partially reject the
erasure request?
A) The right to erasure is absolute and cannot be restricted.
B) The platform can reject erasure only if the data was made public by the
data subject.
C) The platform can justify retention for legal obligations and legal claims,
but must erase data not covered by such exceptions.
D) The platform can reject the entire request if any part of the data is subject
to a legal obligation.
Answer: C
Rationale: Article 17(3) provides exceptions to the right to erasure, including
compliance with a legal obligation (e) and establishment, exercise, or defence
of legal claims (e). However, the controller must erase data that does not fall
under these exceptions. Option C correctly reflects that retention is allowed
only for the specific purposes, and other data must be erased. Option A is false

Document information

Uploaded on
July 25, 2026
Number of pages
109
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
1
Followers
2
Items
404
Last sold
2 weeks ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions