IAPP CIPP-E Exam Prep
Certified Information Privacy Professional/Europe (CIPP/E) (Page 6 )

Updated On: 30-Sep-2026

How does the GDPR now define “processing”?

  1. Any act involving the collecting and recording of personal data.
  2. Any operation or set of operations performed on personal data or on sets of personal data.
  3. Any use or disclosure of personal data compatible with the purpose for which the data was collected.
  4. Any operation or set of operations performed by automated means on personal data or on sets of personal data.

Answer(s): B


Reference:

https://gdpr-info.eu/issues/processing/



What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

  1. The controller will be liable to pay an administrative fine
  2. The processor will be liable to pay compensation to affected data subjects
  3. The processor will be considered to be a controller in respect of the processing concerned
  4. The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved

Answer(s): B


Reference:

https://gdpr-info.eu/art-28-gdpr/data-processing-on-behalf-of-a-controller/



According to the GDPR, how is pseudonymous personal data defined?

  1. Data that can no longer be attributed to a specific data subject without the use of additional information kept separately.
  2. Data that can no longer be attributed to a specific data subject, with no possibility of re-identifying the data.
  3. Data that has been rendered anonymous in such a manner that the data subject is no longer identifiable.
  4. Data that has been encrypted or is subject to other technical safeguards.

Answer(s): A


Reference:

https://www.chino.io/blog/what-is-pseudonymous-data-according-to-the-gdpr/



Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?

  1. When the personal data is processed only in non-electronic form
  2. When the personal data is collected and then pseudonymised by the controller
  3. When the personal data is held by the controller but not processed for further purposes
  4. When the personal data is processed by an individual only for their household activities

Answer(s): D


Reference:

https://gdpr-info.eu/art-3-gdpr/



According to the E-Commerce Directive 2000/31/EC, where is the place of “establishment” for a company providing services via an Internet website confirmed by the GDPR?

  1. Where the technology supporting the website is located
  2. Where the website is accessed
  3. Where the decisions about processing are made
  4. Where the customer’s Internet service provider is located

Answer(s): C


Reference:

https://gdpr-info.eu/art-4-gdpr/



Viewing page 6 of 65
Viewing questions 26 - 30 out of 319 questions


Post your Comments and Discuss IAPP CIPP-E exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!