European data protection
CIPP/E exam prep.
Know what to study next.
Free lessons. A diagnostic that finds your weak areas. Practice with an explanation for every answer.
Start free. No account needed.
Independent study material for CIPP/E. Study in your browser, at your own pace.
A clear place to start
10 questions.
A more focused study plan.
See which topics need your attention, then go straight to the lessons that help.
Find my weak areasEuropean data protection
CIPP/E study guide and practice questions
Free lessons on every topic in the published CIPP/E outline, a ten-question diagnostic that shows your weak areas, and a 1,122-question practice bank with worked explanations. Written by someone who passed the exam.
Practice question bank
1,122 exam-style questions for $29.99, once.
A 90-question timed practice set, a worked explanation for every answer and weak-area tracking. No subscription. Try nine sample questions free before you decide.
Continue studying
Start with the guide
Core study guide
Chapter 1: Origins of European data protection10 lessons
Chapter 2: EU institutions7 lessons
Chapter 3: The legislative framework12 lessons
- Background to European data protection law
- Council of Europe Convention 108
- Data Protection Directive 95/46/EC
- Reform of the EU framework and the road to the GDPR
- The General Data Protection Regulation (GDPR)
- Law Enforcement Directive (LED)
- Privacy and Electronic Communications (ePrivacy) Directive
- Reform of the ePrivacy Directive - ePrivacy Regulation
- NIS Directive and NIS 2
- EU Artificial Intelligence Act
- Data Retention Directive
- Impact on member states - implementation, enforcement, direct effect
Chapter 4: Data protection concepts11 lessons
- Introduction to Data Protection Concepts
- Personal Data and Its Four Building Blocks
- 'Relating to' - Content, Purpose and Result
- Identifiability, Anonymisation and Pseudonymisation
- Natural Person, Deceased Persons and PII
- Special Categories of Personal Data
- Controller vs Processor - Roles and Liability
- The Five Building Blocks of 'Controller'
- Joint Controllership
- The Processor and the Article 28 Contract
- Processing and Data Subject
Chapter 5: Territorial and material scope6 lessons
- Introduction and overview of scope
- Article 3(1): EU-established controllers and processors
- Article 3(2): the targeting and monitoring tests
- Public international law, EU representatives and Brexit
- Material scope: matters outside EU law and the household exemption
- Law enforcement, EU institutions, ePrivacy and E-Commerce
Chapter 6: Data processing principles8 lessons
Chapter 7: Lawful bases for processing12 lessons
- Background & the role of consent
- Consent - definition and the four conditions
- Freely given consent - bundling, imbalance, cookie walls
- Specific, informed & unambiguous consent
- Necessity & the contract, legal obligation and vital interests bases
- Public task / official authority basis
- Legitimate interests & the balancing test
- Consent vs legitimate interests - choosing correctly
- Legal obligation & public interest - extra detail; documenting the basis
- Sensitive data - Article 9 framework
- Article 9 exceptions - the ten conditions
- Criminal convictions data (Article 10) & processing without identification (Article 11)
Chapter 8: Information and transparency obligations8 lessons
- Transparency principle
- Article 13 vs Article 14 - what must be provided
- Situations requiring additional information
- When information must be provided (timing)
- How information must be provided (manner and format)
- Exemptions to the obligation to provide information
- Requirements of the ePrivacy Directive
- Fair processing notices and best practice
Chapter 9: Data subject rights11 lessons
- Background - the rights and their Articles
- Modalities - to whom, how, and when
- Transparent communication and the right to information
- Right of access (DSAR)
- Right to rectification
- Right to erasure ('right to be forgotten')
- Right to restriction of processing
- Right to data portability
- Right to object
- Right not to be subject to solely automated decision-making
- Restrictions of data subject rights
Chapter 10: Security and breach notification10 lessons
- Background - why security is an A-list principle
- Security principle and the risk-based approach (Article 32)
- Employees, the insider threat, and the controller-processor relationship
- Risk reporting and the meaning of 'personal data breach'
- Article 33 - notifying the supervisory authority
- Article 34 - communicating the breach to data subjects
- Article 33 vs Article 34 - side-by-side comparison
- Delivering on security - programmes, people, paperwork
- Incident response
- The NIS Directive (and NIS 2)
Chapter 11: Accountability8 lessons
- Introduction and background to accountability
- Responsibility of the controller
- Data protection by design and by default
- Documentation and records of processing (Article 30)
- The under-250-employees records exemption
- Data protection impact assessment (DPIA)
- The data protection officer (DPO)
- Binding corporate rules and conclusion
Chapter 12: International data transfers10 lessons
- The general restriction on transfers outside the EEA
- Scope of data transfers - what counts as a transfer
- Meaning of an 'adequate level of protection'
- Procedure to designate adequate countries
- The United States - Safe Harbor, Snowden and Schrems I
- The United States - Privacy Shield, Schrems II and the Data Privacy Framework
- Providing adequate safeguards - SCCs and the transfer impact assessment
- Binding corporate rules (BCRs) for intra-group transfers
- Relying on the Article 49 derogations
- Comparing the transfer mechanisms & the future of restrictions
Chapter 13: Supervision and enforcement9 lessons
- Introduction: the toolkit of supervision and enforcement
- Self-regulation: accountability, DPOs, codes and certification
- Regulation by the citizen: rights, remedies, representation and compensation
- Independent national regulators and their tasks (Articles 51–57, 59)
- Regulators' powers under Article 58: investigatory, corrective, authorisation/advisory
- Competence, the one-stop shop and the lead supervisory authority
- Cooperation, consistency and the EDPB (Articles 60–66, 68–71)
- Administrative fines: the two tiers and how they are set (Article 83)
- Setting fines, guidelines and the Law Enforcement Directive
Chapter 14: Employment and HR data13 lessons
- Employee data
- Legal basis for processing employee personal data
- Why consent is problematic at work
- Processing sensitive employee data
- Providing notice
- Storage of personnel records
- Workplace monitoring: principles, background checks, DLP
- Necessity and the DPIA
- Legitimacy and proportionality of monitoring
- Transparency, AUPs and covert monitoring
- Works councils
- Whistleblowing schemes
- Bring your own device (BYOD)
Chapter 15: Surveillance and monitoring6 lessons
Chapter 16: Direct marketing, cookies and ePrivacy12 lessons
- Data protection and direct marketing
- Right to opt out of direct marketing
- ePrivacy laws: unsolicited messages and cookies
- Online behavioural advertising (OBA)
- OBA, cookies and ePrivacy (Article 5(3))
- The ePrivacy Regulation (proposal)
- Channel-by-channel rules: the consent matrix
- Postal marketing
- Marketing by electronic mail and the soft opt-in
- Telephone marketing
- Location-based marketing
- Enforcement and conclusion
Chapter 17: Cloud computing and internet technologies18 lessons
- Introduction and scope
- Cloud computing: models and applicable law
- Cloud: controllership issues
- Cloud service contracts (Article 28)
- Cloud: international data transfers
- EU Cloud Code of Conduct
- Cookies and similar technologies
- ePrivacy consent and cookie controllership
- Cookie scrutiny, third-party cookie demise, ePrivacy Regulation
- IP addresses as personal data (Breyer)
- Search engines and the right to be forgotten
- Social media: roles, joint controllership, transparency
- Social media: legal basis, special category data, children
- Targeted online advertising: ecosystem and law
- Adtech legal basis and automated decisions
- Applications on mobile devices
- Internet of Things (IoT)
- Artificial Intelligence and the EU AI Act
Chapter 18: Outsourcing and processors8 lessons
- Introduction to outsourcing
- Roles of the parties: controller and processor
- Suppliers as controllers, AI, and chains of processors
- Mandatory Article 28(3) contract terms
- Subcontracting conditions
- Offshoring and international transfers
- Binding corporate rules for processors
- Conclusion: recalibrating responsibilities
Supplementary study modules
Training Module 15 lessons
Training Module 23 lessons
Training Module 33 lessons
Training Module 47 lessons
- Module 4, The data processing life cycle
- Module 4, Data processing principles (OECD + Article 5)
- Module 4, Territorial and material scope
- Module 4, The six Article 6 lawful bases
- Module 4, Consent - the four conditions and children
- Module 4, Legitimate interests and the balancing test
- Module 4, Special-category data and Article 9 exceptions
Training Module 56 lessons
Training Module 63 lessons
Training Module 74 lessons
Training Module 812 lessons
- Module 8, Employee data - legal layers, works councils & legal bases
- Module 8, Sensitive employee data, record retention & BYOD
- Module 8, Lawful employee monitoring & whistleblowing
- Module 8, Surveillance framework - Article 23, content vs metadata
- Module 8, CCTV / video surveillance & Guidelines 3/2019
- Module 8, ePrivacy Directive, location data & biometric data
- Module 8, Direct marketing - GDPR vs ePrivacy & the absolute right to object
- Module 8, Direct marketing channel rules & the soft opt-in
- Module 8, Online behavioural advertising (OBA) & cloud computing
- Module 8, Web cookies, Article 5(3) & the Planet49 ruling
- Module 8, Search engines, Google Spain & social media targeting
- Module 8, Dark patterns (Guidelines 03/2022), AI & the EU AI Act
Training Module 94 lessons
Training Module 107 lessons
- Module 10, Accountability defined (Article 24)
- Module 10, Data protection by design and by default (Article 25)
- Module 10, Data protection impact assessment (DPIA, Articles 35 and 36)
- Module 10, Data protection policy (Article 24(2))
- Module 10, Records of processing (Article 30)
- Module 10, The data protection officer (DPO, Articles 37–39)
- Module 10, The EU representative (Article 27)