Try 12 free IAPP CIPP/E practice questions
Real exam-style questions taken word for word from the IAPP CIPP/E study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.
Unlock the full sampler
Three questions to try right now
Work each one before you open the answer. These are the same style and depth as the Certified Information Privacy Professional/Europe (CIPP/E) exam expects.
Question 1. The Court of Justice of the European Union issued rulings that invalidated the EU-US Safe Harbor framework in 2015 (Schrems I) and the EU-US Privacy Shield in 2020 (Schrems II). What does this BEST illustrate about the CJEU's role in European data protection?
- A. The CJEU enforces the European Convention on Human Rights and can strike down national laws that violate it.
- B. The CJEU interprets and enforces EU law, including the GDPR, and can invalidate Commission adequacy decisions that fail to ensure a level of data protection essentially equivalent to that guaranteed within the EU.
- C. The CJEU acts as the court of last resort for individual data subjects who have exhausted national remedies and wish to challenge a supervisory authority decision.
- D. The CJEU issues preliminary rulings on ECHR compliance at the request of the European Court of Human Rights.
Show the answer
Answer: B. Schrems I (C-362/14, 2015) and Schrems II (C-311/18, 2020) both arose from preliminary references under Article 267 TFEU and resulted in the CJEU invalidating Commission adequacy decisions (Safe Harbor and Privacy Shield respectively) on the ground that US surveillance law did not offer protection essentially equivalent to EU fundamental rights standards. These rulings confirm that the CJEU has the power to annul binding EU acts, including Commission decisions, when they conflict with primary EU law and the Charter of Fundamental Rights. The CJEU is the supreme interpreter of EU law.
- A: Enforcement of the ECHR is the role of the European Court of Human Rights (ECtHR), a Council of Europe body; the CJEU applies the EU Charter, not the ECHR directly.
Question 2. A privacy professional is explaining to a new colleague why the GDPR alone does not fully harmonise data protection across Europe. The colleague asks why some non-EU countries such as Norway and Iceland apply GDPR-equivalent rules. What is the BEST explanation?
- A. The GDPR applies extraterritorially to any country whose residents interact with EU-based data controllers.
- B. Norway and Iceland are members of the European Economic Area, which incorporates EU data protection law into its treaty framework, making the GDPR applicable in those states.
- C. The Council of Europe recommended that all member states adopt GDPR-equivalent legislation and both countries complied voluntarily.
- D. Norway and Iceland entered bilateral adequacy agreements with the European Commission that require them to mirror GDPR requirements.
Show the answer
Answer: B. Norway, Iceland, and Liechtenstein are members of the European Economic Area (EEA) but not the EU. The EEA Agreement incorporates large parts of EU single-market law, including data protection rules, via the EEA Joint Committee process. The GDPR was incorporated into the EEA Agreement and became applicable in all three EEA-EFTA states. This is distinct from adequacy decisions, which concern third countries outside the EEA.
- A: While the GDPR has extraterritorial provisions under Article 3(2), the reason Norway and Iceland apply GDPR rules is not extraterritoriality but their EEA membership and treaty incorporation.
Question 3. The OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data were adopted in 1980. What is the PRIMARY significance of these Guidelines in the development of European data protection?
- A. They created legally binding obligations on OECD member states to enact national data protection legislation.
- B. They prohibited the transfer of personal data to non-OECD countries that lacked equivalent legal protections.
- C. They introduced the concept of supervisory authority independence for the first time in international privacy law.
- D. They established eight foundational principles that influenced subsequent national laws, the EU Directive 95/46/EC, and the GDPR.
Show the answer
Answer: D. The 1980 OECD Guidelines are voluntary, not legally binding, but their eight principles (Collection Limitation, Data Quality, Purpose Specification, Use Limitation, Security Safeguards, Openness, Individual Participation, and Accountability) provided a widely adopted conceptual template. Those principles can be traced through the 1995 Data Protection Directive and into the GDPR's Article 5 processing principles and Chapter III rights. The Guidelines' significance lies in their normative influence, not in creating binding legal duties.
- A: The OECD Guidelines are explicitly non-binding; they represent a soft-law instrument and a policy recommendation, not a treaty obligation.
Unlock the full 12-question sampler
All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.
What you get
The sampler is free. Here is exactly what lands in your inbox.
Print it or work it on screen, then score yourself against the answer key.
Nothing is written for marketing. Every question is lifted from the study guide itself.
A few days later we send one email with a code for the full study guide. That is the entire sequence.
The full IAPP CIPP/E study guide
The complete guide covers the Certified Information Privacy Professional/Europe (CIPP/E) exam objective by objective in plain English, with the full practice question bank behind these samples.
From $20.99
Simply Certified is an independent publisher. CIPP/E is a trademark of the IAPP, which does not sponsor or endorse this product. This page and the sampler are independent study material and are not affiliated with, endorsed by, or sponsored by IAPP.