Study resourcesCIPP/E

The complete study library

Explore the CIPP/E study library

Search 257 free study resources for CIPP/E. Find a lesson, review a term or choose a practice session.

257 resources

Guide · CIPP/E

CIPP/E exam format and blueprint

Current CIPP/E format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.

Guide · CIPP/E

CIPP/E exam questions

How to approach CIPP/E questions using scope, legal basis, rights, accountability and enforcement.

Guide · CIPP/E

CIPP/E practice exam

Independent CIPP/E practice questions, a timed-study method and an evidence-led review routine.

Guide · CIPP/E

CIPP/E study guide

A free CIPP/E study guide structured around the published IAPP outline and active recall.

Guide · CIPP/E

CIPP/E study plan

A four-week CIPP/E study plan using the published outline, retrieval practice and scenario questions.

Practice · CIPP/E

CIPP/E cram sheet

The complete CIPP/E memorisation sheet: key dates, fines and numbers, the principles, lawful bases, rights, transfers, cases and the classic exam traps.

Practice · CIPP/E

Find the CIPP/E areas to study next.

Take a free 10-question CIPP/E diagnostic. Get an immediate domain score and a personalised study plan without creating an account.

Glossary · CIPP/E

CIPP/E glossary

Plain-language definitions for recurring terms in the CIPP/E study guide.

Guide · CIPP/E

How to pass the CIPP/E

How to prepare for the IAPP CIPP/E exam using current format details, a flexible study plan, common mistakes and exam-style practice.

Guide · CIPP/E

Is the CIPP/E exam hard?

Is the CIPP/E exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.

Practice · CIPP/E

Free CIPP/E mini mock

Try 25 exam-style CIPP/E practice questions free, with explanations and a domain score. No account or payment required.

Practice · CIPP/E

Which of these is NOT a data-protection consideration for CCTV under the training?

Which of these is NOT a data-protection consideration for CCTV under the training? Answer with a worked explanation and related free lesson.

Lesson · CIPP/E

Accountability and telling the principles apart

The GDPR reinforces every principle by adding accountability: it places the burden of proof on organisations to demonstrate proper implementation, and…

Lesson · CIPP/E

Accuracy

The accuracy principle requires controllers to take reasonable measures to keep personal data accurate and, where necessary, up to date. This means…

Lesson · CIPP/E

Administrative fines: the two tiers and how they are set (Article 83)

The fines regime (Article 83) has two tiers. The lower tier (Art 83(4)) caps fines at €10 million or 2% of total worldwide annual turnover, whichever is…

Lesson · CIPP/E

Adtech legal basis and automated decisions

Adtech relies on either consent or legitimate interest. Consent is hard: it must be informed and demonstrable, and firms without a direct relationship…

Lesson · CIPP/E

Applications on mobile devices

Mobile apps collect large volumes of often intimate data via sensors (location, audio, video) and stored data (contacts, photos). Devices are rarely…

Lesson · CIPP/E

Article 13 vs Article 14 - what must be provided

The primary information duties sit in Article 13 (data collected directly from the data subject) and Article 14 (data obtained from another source). Both…

Lesson · CIPP/E

Article 3(1): EU-established controllers and processors

Under Article 3(1) the GDPR applies to processing 'in the context of the activities of an establishment of a controller or a processor in the Union'…

Lesson · CIPP/E

Article 3(2): the targeting and monitoring tests

Article 3(2) is the long-arm rule for organisations not established in the EU. It catches their processing of personal data of data subjects who are in…

Lesson · CIPP/E

Article 33 - notifying the supervisory authority

Article 33 requires the controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours…

Lesson · CIPP/E

Article 33 vs Article 34 - side-by-side comparison

Both Article 33 and Article 34 are risk-reporting duties on the controller, but they differ on who is told, the threshold , the deadline and the content …

Lesson · CIPP/E

Article 34 - communicating the breach to data subjects

Article 34 requires controllers to inform affected individuals without undue delay where a breach is likely to result in a high risk to their rights and…

Lesson · CIPP/E

Article 9 exceptions - the ten conditions

Article 9's prohibition is lifted by ten conditions. The headline ones: explicit consent (more than ordinary consent); employment/social-security law…

Lesson · CIPP/E

Artificial Intelligence and the EU AI Act

AI systems may process personal data during design, training, testing and deployment, so the GDPR can apply throughout the lifecycle. Articles 13 and 14…

Lesson · CIPP/E

Background - Lisbon Treaty and institutional reform

The Treaty of Lisbon reformed the EU's institutional structure to cut bureaucracy and speed up decision-making after enlargement. Article 13 of the EU…

Lesson · CIPP/E

Background - the rights and their Articles

European data protection law has always given individuals enforceable rights, but the GDPR is far more extensive than the old Data Protection Directive…

Lesson · CIPP/E

Background & the role of consent

The GDPR requires controllers to process personal data lawfully, fairly and in a transparent manner. Article 6 and Article 9 set out the criteria for…

Lesson · CIPP/E

Background to European data protection law

European data protection law grew out of fears that new technologies - phone-tapping, surveillance, large mainframe computers - threatened individual…

Lesson · CIPP/E

Background - why security is an A-list principle

Security is not just one principle among many; it underpins compliance with all the others. Insecurity can trigger unlawful transfers, inaccuracy, data…

Lesson · CIPP/E

Binding corporate rules and conclusion

Binding corporate rules (BCRs) can support an accountability framework. Sometimes called the gold standard of global data protection, they are a single…

Lesson · CIPP/E

Binding corporate rules (BCRs) for intra-group transfers

BCRs are a global set of internal rules based on European privacy standards that a multinational group adopts voluntarily and a regulator approves, to…

Lesson · CIPP/E

Binding corporate rules for processors

Binding corporate rules (BCRs) are internal, legally binding data protection rules adopted by multinationals. The original BCR model applied only where a…

Lesson · CIPP/E

Biometric data as special-category data

Biometric data is defined in Article 4(14) as personal data from specific technical processing of physical, physiological or behavioural characteristics…

Lesson · CIPP/E

Blueprint Check, Domain coverage map (I–III)

A cross-check of the CIPP/E Exam Blueprint against this guide. Every competency in Domains I, II and III is covered by both this guide chapters and the…

Lesson · CIPP/E

Blueprint Check, Domain coverage map (IV–V) & gap analysis

The cross-check for Domains IV (Scope & Accountability) and V (Compliance), plus the short list of items the official training reinforced on top of this…

Lesson · CIPP/E

Brexit and UK data protection

After Brexit, withdrawal legislation repealed the European Communities Act 1972, converted the GDPR into the UK GDPR (retained EU law, amended by the 2019…

Lesson · CIPP/E

Bring your own device (BYOD)

Under BYOD, employees use personal devices for work. The employer remains the controller for work-related personal data processed on the device, yet the…

Lesson · CIPP/E

Channel-by-channel rules: the consent matrix

This is the heart of the chapter for exam purposes. Post is GDPR-only (no ePrivacy), usually consent or legitimate interests. Live phone calls are left to…

Lesson · CIPP/E

Cloud computing: models and applicable law

Cloud computing is IT services delivered over the internet, split into IaaS, PaaS and SaaS by how much the supplier provides. Cloud infrastructure is…

Lesson · CIPP/E

Cloud: controllership issues

In most supply-of-services cases the customer is the controller (it decides purposes and means) and the supplier is a processor. But in cloud this can't…

Lesson · CIPP/E

Cloud: international data transfers

Cloud almost always involves international transfers, and the cloud customer (exporter) is responsible for compliance. Options to provide appropriate…

Lesson · CIPP/E

Cloud service contracts (Article 28)

A GDPR-subject customer must put an Article 28 contract in place with its cloud provider. The GDPR lists mandatory processor terms: processing only on…

Lesson · CIPP/E

Communications data: content, metadata and retention

Electronic communications generate two categories of data: content and metadata (data about data). Metadata splits into traffic data, location data and…

Lesson · CIPP/E

Comparing the transfer mechanisms & the future of restrictions

This pulls the four main routes together - adequacy decision, standard contractual clauses|SCCs, BCRs, and Article 49 derogation|derogations - and this…

Lesson · CIPP/E

Competence, the one-stop shop and the lead supervisory authority

Each DPA is competent in its own territory (Article 55). For cross-border processing, the lead supervisory authority - the DPA of the…

Lesson · CIPP/E

Conclusion: recalibrating responsibilities

The GDPR's biggest change to outsourcing is the recalibration of responsibilities between controllers and processors. Controllers remain primarily…

Lesson · CIPP/E

Consent - definition and the four conditions

Consent is the first Article 6 basis. It is defined as any freely given, specific, informed and unambiguous indication of the data subject's wishes, by a…

Lesson · CIPP/E

Consent vs legitimate interests - choosing correctly

Exam scenarios frequently turn on consent vs legitimate interests. Consent gives the subject control but can be withdrawn at any time, forcing the…

Lesson · CIPP/E

Controller vs Processor - Roles and Liability

A controller is the person or body that alone or jointly determines the purposes and means of processing - the key decision-maker, who carries most GDPR…

Lesson · CIPP/E

Convention 108+

A modernisation protocol - colloquially Convention 108+ - was signed by 21 states on 10 October 2018 after more than seven years of work begun in January…

Lesson · CIPP/E

Convention 108

Convention 108 was opened for signature on 28 January 1981 by the Council of Europe. It was the first legally binding international instrument in data…

Lesson · CIPP/E

Cookies and similar technologies

A cookie is a small text file placed on a device that 'remembers' it. Other tracking tech includes device fingerprinting, tags, pixels, web beacons…

Lesson · CIPP/E

Cooperation, consistency and the EDPB (Articles 60–66, 68–71)

Cross-border cases run through the cooperation procedure (Article 60): the lead authority circulates a draft decision; other concerned DPAs may agree or…

Lesson · CIPP/E

Council of Europe Convention 108

Opened for signature on 28 January 1981, Convention 108 was the first legally binding international instrument in data protection. It rests on data…

Lesson · CIPP/E

Council of the European Union

The Council of the European Union (Council of Ministers) is the EU's main decision-making body and the co-legislator with the Parliament. Do not confuse…

Lesson · CIPP/E

Court of Justice of the European Union (CJEU)

The Court of Justice of the European Union|CJEU, based in Luxembourg, is the EU's judicial body, deciding issues of EU law and enforcing EU decisions. It…

Lesson · CIPP/E

Criminal convictions data (Article 10) & processing without identification (Article 11)

Article 10 data - criminal convictions, offences and related security measures - needs greater protection but is NOT a special category under Article 9…

Lesson · CIPP/E

Data minimisation

Data minimisation means collecting and processing only data that is relevant, necessary and adequate for the purpose - collect only what you really need…

Lesson · CIPP/E

Data protection and direct marketing

Direct marketing is one of the hardest areas of data protection law because it triggers both DP rules and other consumer-protection rules that vary by…

Lesson · CIPP/E

Data protection by design and by default

Article 25 requires data protection by design and data protection by default - the technical and organisational measures a controller builds in to protect…

Lesson · CIPP/E

Data Protection Directive 95/46/EC

Adopted on 24 October 1995, Directive 95/46 was the EU's flagship data protection law, set up as an internal market harmonisation measure under the Treaty…

Lesson · CIPP/E

Data protection impact assessment (DPIA)

A DPIA (also called a PIA) systematically identifies and addresses the data protection impacts of new products, services or activities. Under Article 35…

Lesson · CIPP/E

Data Retention Directive

Directive 2006/24/EC (the Data Retention Directive) aligned national rules on retaining traffic and location data for serious crime and anti-terrorism. In…

Lesson · CIPP/E

Delivering on security - programmes, people, paperwork

A strong security programme is board-endorsed, multidisciplinary, and connects security professionals with data protection and legal staff. Practitioners…

Lesson · CIPP/E

Documentation and records of processing (Article 30)

The GDPR abolished the Directive's notify/register requirement: controllers no longer file processing activities with a DPA. Instead they must keep…

Lesson · CIPP/E

Employee data

Employers process personal data on employees past, present and potential for recruitment, salary, benefits, personnel files, sickness records, monitoring…

Lesson · CIPP/E

Employees, the insider threat, and the controller-processor relationship

Article 32(4) covers employees and other workers acting under the controller's or processor's authority - read with Article 5(1)(f) and Article 28(3)(b)…

Lesson · CIPP/E

Enforcement and conclusion

Enforcement of direct-marketing rules - especially cookies and unsolicited communications - is rising: class actions (Lloyd v Google in the UK…

Lesson · CIPP/E

ePrivacy consent and cookie controllership

Cookie consent must meet GDPR standards. Planet49 confirmed consent is not valid via a pre-ticked box, and users must be told the cookie's duration and…

Lesson · CIPP/E

ePrivacy laws: unsolicited messages and cookies

The ePrivacy Directive adds consent/information rules to digital marketing by phone, fax and electronic mail (incl. SMS, IM, push). The general rule: most…

Lesson · CIPP/E

EU Cloud Code of Conduct

The EU Cloud Code was approved by Belgium's DPA in May 2021 after a positive EDPB opinion. It sets requirements for B2B cloud services where the provider…

Lesson · CIPP/E

European Commission

The European Commission is the EU's executive body but also far more: it holds the right to initiate legislation ('Union legislative acts may only be…

Lesson · CIPP/E

European Council

The European Council gives the EU its political impetus and direction but does not exercise legislative functions. It began as an informal body in 1974…

Lesson · CIPP/E

European Court of Human Rights (ECtHR)

The European Court of Human Rights|ECtHR is not an EU institution. It sits in Strasbourg as part of the Council of Europe, which has 46 member states…

Lesson · CIPP/E

European Parliament

The European Parliament is the only EU institution directly elected by EU citizens, giving it democratic weight. It has four roles: legislative…

Lesson · CIPP/E

Exam Prep, A study plan that actually works

The IAPP advises a minimum of 30 hours of study. But hours alone don't pass exams - active recall and spaced retrieval do. Re-reading and highlighting…

Lesson · CIPP/E

Exam Prep, After the course - next steps to certify

Completing the training is a step, not the finish line. To convert it into a pass, layer on this guide, the blueprint, practice questions and spaced…

Lesson · CIPP/E

Exam Prep, How the questions are written (Bloom's taxonomy)

Not every question is a definition. The IAPP writes questions at different Bloom's taxonomy levels. The verb in a performance indicator (define, identify…

Lesson · CIPP/E

Exam Prep, Test-day strategy & the classic traps

On the day, technique matters. Read the full stem, watch for absolutes ("always", "never"), and pick the best answer, not merely a true one. Most lost…

Lesson · CIPP/E

Exam Prep, The CIPP/E exam at a glance

The CIPP/E exam tests the IAPP Body of Knowledge across five domains. Knowing the weighting tells you where to spend your time: Domain II is the single…

Lesson · CIPP/E

Exemptions to the obligation to provide information

The GDPR has its own exemptions (no national law needed) and permits member states to create more. For Article 13 (direct collection) there is essentially…

Lesson · CIPP/E

Fair processing notices and best practice

Unlike the Directive, the GDPR specifies methods for informing data subjects, so fair processing notices (privacy notices) remain the convenient way to…

Lesson · CIPP/E

Freely given consent - bundling, imbalance, cookie walls

Freely given means a genuine choice and the ability to refuse or withdraw. Consent bundled with other matters (e.g. buying a service) is invalid; under…

Lesson · CIPP/E

How information must be provided (manner and format)

Article 12 governs the manner: information must be concise, transparent, intelligible and easily accessible, using clear and plain language, and language…

Lesson · CIPP/E

Human rights law foundations

European data protection rests on human rights law. The Universal Declaration of Human Rights (1948) set the values: Article 12 protects privacy, Article…

Lesson · CIPP/E

Identifiability, Anonymisation and Pseudonymisation

A person is identifiable when, though not yet identified, it is possible to identify them - directly (by name) or indirectly (by an identifier, or by…

Lesson · CIPP/E

Impact on member states - implementation, enforcement, direct effect

Directives are not directly applicable: states transpose them, so approaches vary - the great challenge of EU privacy law. The Commission can take…

Lesson · CIPP/E

Incident response

Putting in place incident response is an implicit requirement of the security principle and the breach rules. A good incident response plan needs senior…

Lesson · CIPP/E

Independent national regulators and their tasks (Articles 51–57, 59)

Only the DPA|DPAs hold administrative supervisory and enforcement powers under the GDPR. They must be independent public authorities (Articles 51–52) with…

Lesson · CIPP/E

Integrity and confidentiality

Article 5(1)(f) - integrity and confidentiality (the 'security principle') - requires processing in a manner that ensures appropriate security, including…

Lesson · CIPP/E

Internet of Things (IoT)

The IoT is physical objects ('connected objects') that connect, sense and transmit data - wearables, smart meters, connected vehicles, and VVA-paired…

Lesson · CIPP/E

Introduction and background to accountability

The GDPR formally embeds accountability into EU data protection law. Accountability means the obligations an organisation must meet to show and evidence…

Lesson · CIPP/E

Introduction and overview of scope

Chapter 5 sets out two filters that decide whether the GDPR applies at all: territorial scope (which organisations, by location or by who they target) and…

Lesson · CIPP/E

Introduction and scope

Chapter 17 maps how European data protection concepts apply to a range of internet technologies - cloud, cookies, IP addresses, search engines, social…

Lesson · CIPP/E

Introduction and surveillance technology

Surveillance means observing an individual or group, and it is getting cheaper, more capable and more pervasive. The classic concern is the nation state…

Lesson · CIPP/E

Introduction: the toolkit of supervision and enforcement

A regulatory system is only as good as the means by which it is supervised and enforced. The GDPR spreads enforcement firepower across many actors, not…

Lesson · CIPP/E

Introduction to Data Protection Concepts

The core data protection concepts pre-date the GDPR: they were set by the 1995 Data Protection Directive and remain essentially unchanged in the GDPR…

Lesson · CIPP/E

Introduction to outsourcing

Data protection law was born in the early 1970s as computers spread, and early service bureaux (also called computer bureaux) processed data on behalf of…

Lesson · CIPP/E

IP addresses as personal data (Breyer)

An IP address is a numerical label assigned to a device. It can be static IP address|static (always the same) or dynamic IP address|dynamic (changes each…

Lesson · CIPP/E

Joint Controllership

Joint controllership arises where two or more entities jointly determine the purposes and means of processing - either by a common decision or through…

Lesson · CIPP/E

Law Enforcement Directive (LED)

Agreed alongside the GDPR, the Law Enforcement Directive (Directive (EU) 2016/680) governs personal data processed by criminal law enforcement…

Lesson · CIPP/E

Law enforcement, EU institutions, ePrivacy and E-Commerce

Article 2(2)(d) exempts processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences (and…

Lesson · CIPP/E

Lawfulness, fairness and transparency

The first principle bundles three ideas. Lawfulness means there must be a legal ground (and the processing must comply with all applicable laws). Fairness…

Lesson · CIPP/E

Legal basis for processing employee personal data

Employers usually rely on one of four grounds: consent, necessity for the employment contract, compliance with a legal obligation, or legitimate…

Lesson · CIPP/E

Legal obligation & public interest - extra detail; documenting the basis

For both the legal obligation and public task bases, Recital 45 says the processing must have a basis in EU or member-state law, which may specify the…

Lesson · CIPP/E

Legitimacy and proportionality of monitoring

Monitoring needs a lawful basis - usually the legitimate-interests balancing test, not consent, whose use the WP29 said is very limited for monitoring…

Lesson · CIPP/E

Legitimate interests & the balancing test

Legitimate interests (6(1)(f)) is the most flexible basis and the one on which most processing relies, but public authorities cannot use it for their…

Lesson · CIPP/E

Location-based marketing

Using location data from devices for marketing engages both the GDPR and ePrivacy. ePrivacy Art 9 requires opt-in consent to use location data for a…

Lesson · CIPP/E

Location data and contact tracing

Location-based services (LBS) use location to deliver navigation, advertising, gaming, payments and more, drawn from satellite (GPS/Galileo), cell-based…

Lesson · CIPP/E

Mandatory Article 28(3) contract terms

Processing by a processor must be governed by a written contract (or other binding legal act). Article 28(3) sets out the mandatory terms. From the…

Lesson · CIPP/E

Marketing by electronic mail and the soft opt-in

Email/SMS/MMS marketing needs prior opt-in consent (ePrivacy Art 13(1)) - typically a tick box at data capture. The exception is the soft opt-in…

Lesson · CIPP/E

Material scope: matters outside EU law and the household exemption

Even an in-scope organisation has some processing carved out of the GDPR by Article 2. Article 2(2)(a) excludes activities outside the scope of Union law…

Lesson · CIPP/E

Meaning of an 'adequate level of protection'

Under Article 45(1), the Commission can decide a third country, a territory, a sector, or an international organisation ensures an adequate level of…

Lesson · CIPP/E

Modalities - to whom, how, and when

Article 12(2) requires controllers to facilitate the exercise of rights. Unlike the Directive, the GDPR requires the controller to use all reasonable…

Lesson · CIPP/E

Module 1, Council of Europe vs the EU

A critical exam distinction. The European Union (EU) is an economic and political union of 27 Member States; the Council of Europe (CoE) is an…

Lesson · CIPP/E

Module 1, Directive vs Regulation, the EDPB and ePrivacy

A Directive obliges Member States to implement it in local law; a Regulation is directly applicable with no local implementation needed - the GDPR is a…

Lesson · CIPP/E

Module 1, EU institutions and the legislative process

The EU's institutions split into legislative, policy and judicial roles. The European Commission proposes legislation; the European Parliament (MEPs) and…

Lesson · CIPP/E

Module 1, European data protection timeline

The road to the GDPR: the OECD Guidelines (1980) set harmonised data-flow principles; Convention 108 (1981) was the first binding data protection treaty…

Lesson · CIPP/E

Module 1, Foundations: UDHR and ECHR

European data protection grows from two human-rights instruments. The Universal Declaration of Human Rights (UDHR) was adopted on 10 December 1948 and is…

Lesson · CIPP/E

Module 10, Accountability defined (Article 24)

Article 24(1) makes the controller responsible for implementing appropriate technical and organisational measures to ensure and be able to demonstrate…

Lesson · CIPP/E

Module 10, Data protection by design and by default (Article 25)

Article 25 sets two linked duties. Data protection by design begins before processing and bakes data protection into the planning/design phase. Data…

Lesson · CIPP/E

Module 10, Data protection impact assessment (DPIA, Articles 35 and 36)

A DPIA has two values: incorporate data protection into planning and demonstrate compliance to SAs. A PIA is broader and lighter and can run on any…

Lesson · CIPP/E

Module 10, Data protection policy (Article 24(2))

A data protection policy (Article 24(2)) is an internal tool to train employees and set out what may and may not be done, plus the consequences of breach…

Lesson · CIPP/E

Module 10, Records of processing (Article 30)

Records of processing (Article 30) apply to organisations with 250+ employees, OR - regardless of size - where processing is likely to result in a risk…

Lesson · CIPP/E

Module 10, The data protection officer (DPO, Articles 37–39)

The DPO (formerly the Personal Data Protection Official) advises on and monitors compliance and must be an expert in data protection law and practices…

Lesson · CIPP/E

Module 10, The EU representative (Article 27)

Under Article 27, controllers/processors caught by Article 3(2) - those offering goods/services to, or monitoring, people in the EU while not established…

Lesson · CIPP/E

Module 11, Lead SA, one-stop-shop & cooperation/consistency

For cross-border processing a single lead supervisory authority (LSA) coordinates the concerned supervisory authorities through the one-stop-shop. The LSA…

Lesson · CIPP/E

Module 11, Remedies, liabilities & administrative fines

The GDPR sets two fine tiers: up to €10 million or 2% of worldwide annual turnover (lower) and up to €20 million or 4% (higher), whichever is higher…

Lesson · CIPP/E

Module 11, Supervisory authorities & Article 58 powers

Supervisory authorities (a.k.a. data protection authorities) are the bodies the GDPR tasks with promoting, monitoring and enforcing the regulation. Their…

Lesson · CIPP/E

Module 11, The EDPB & the EDPS

The European Data Protection Board (EDPB) replaced the Article 29 Working Party and ensures consistent application of the GDPR. The 30 EEA SAs each send a…

Lesson · CIPP/E

Module 2, Anonymous vs pseudonymous data

Anonymous data is rendered unidentifiable and is NOT protected by the GDPR, but true anonymisation is hard. Pseudonymous data is NOT fully anonymous -…

Lesson · CIPP/E

Module 2, Defining and identifying personal data

Article 4(1) GDPR defines personal data as "any information relating to an identified or identifiable natural person." The course uses a four-step test…

Lesson · CIPP/E

Module 2, Special categories of personal data (Article 9)

Article 9(1) prohibits processing of special-category data unless an exception applies. The categories cover racial/ethnic origin, political opinions…

Lesson · CIPP/E

Module 3, Controller vs processor

Who decides the purposes and means of processing? Whoever determines the "why" and the "how" is the controller (Article 4(7)); whoever processes on the…

Lesson · CIPP/E

Module 3, Sub-processors and Opinion 22/2024

A sub-processor is an entity engaged by a processor to help carry out the processing. EDPB Opinion 22/2024 makes three things clear: the controller must…

Lesson · CIPP/E

Module 3, Vendor management and the Article 28 contract

Choosing a good processor is part of the controller's accountability - there is a pre-contractual due-diligence duty, and failing it leaves the controller…

Lesson · CIPP/E

Module 4, Consent - the four conditions and children

Valid consent must be freely given, specific, informed and unambiguous - a clear affirmative act, clearly distinguishable and in plain language, with…

Lesson · CIPP/E

Module 4, Data processing principles (OECD + Article 5)

The GDPR's Article 5 principles - lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity…

Lesson · CIPP/E

Module 4, Legitimate interests and the balancing test

Legitimate interests (Art 6(1)(f)) is a flexible "safety net," but it demands a Legitimate Interest Assessment (LIA). EDPB Guidelines 1/2024 set three…

Lesson · CIPP/E

Module 4, Special-category data and Article 9 exceptions

Processing special-category data is prohibited by default. To do it lawfully you need BOTH an Article 6 basis AND an Article 9 exception. The exceptions…

Lesson · CIPP/E

Module 4, Territorial and material scope

Article 3 sets territorial scope - and only one criterion need be met: the establishment criterion (Art 3(1)), the targeting/monitoring criterion (Art…

Lesson · CIPP/E

Module 4, The data processing life cycle

Processing is defined sweepingly in Article 4(2): any operation performed on personal data, automated or not - from collection and storage right through…

Lesson · CIPP/E

Module 4, The six Article 6 lawful bases

Processing personal data needs a lawful basis. Article 6 offers six, and only one is needed: consent, contract, legal obligation, vital interests, public…

Lesson · CIPP/E

Module 5, Access and rectification (Articles 15 & 16)

Two foundational data subject rights. The right of access (Article 15) lets a person obtain confirmation that their data is processed, a copy of their…

Lesson · CIPP/E

Module 5, Automated decision-making and profiling (Article 22)

Article 22 gives the data subject the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal…

Lesson · CIPP/E

Module 5, Data portability (Article 20)

Data portability (Article 20) extends the right of access: the data subject can receive their data in a structured, commonly used, machine-readable format…

Lesson · CIPP/E

Module 5, Erasure / right to be forgotten (Article 17)

Right to erasure (Article 17), also called the right to be forgotten, lets a data subject have their data deleted in defined cases - e.g. data no longer…

Lesson · CIPP/E

Module 5, Restriction of processing (Article 18)

Restriction of processing (Article 18) means marking stored personal data to limit future processing - a kind of legal hold. Per Article 4(3), the data is…

Lesson · CIPP/E

Module 5, Right to object (Article 21)

Right to object (Article 21) applies where processing is for direct marketing (an absolute right - processing must cease, including profiling for…

Lesson · CIPP/E

Module 6, Article 13 vs Article 14 (direct vs indirect collection)

Article 13 governs data collected directly from the data subject - provide the information at the time of collection. Article 14 governs data obtained…

Lesson · CIPP/E

Module 6, Privacy notices and formats

A privacy notice describes how an organisation collects, uses, retains and discloses personal data (a.k.a. privacy statement / fair processing statement /…

Lesson · CIPP/E

Module 6, Transparency (Article 12)

Transparency (Article 12) requires controllers to communicate concisely, transparently, intelligibly and in clear and plain language (adapted for…

Lesson · CIPP/E

Module 7, Adequacy decisions & the Schrems/DPF saga

An adequacy decision is a European Commission finding that a third country's laws provide essentially equivalent protection - so transfers there need no…

Lesson · CIPP/E

Module 7, Appropriate safeguards: SCCs, BCRs & codes

Used when there is no adequacy decision, appropriate safeguards bind the recipient to an EU standard. Standard Contractual Clauses (SCCs) are the most…

Lesson · CIPP/E

Module 7, Derogations & restrictions (Article 49)

Derogations under Article 49 are last-resort exemptions, narrowly interpreted, that allow a transfer in specific situations only when neither adequacy nor…

Lesson · CIPP/E

Module 7, The landscape: three options in order

When personal data leaves the EEA (the EU plus Iceland, Liechtenstein and Norway) it must stay protected to an EU-equivalent standard, and this applies to…

Lesson · CIPP/E

Module 8, CCTV / video surveillance & Guidelines 3/2019

CCTV footage contains personal data and images may be biometric data. Compliance turns on lawfulness (often legitimate interest; consent is usually not…

Lesson · CIPP/E

Module 8, Dark patterns (Guidelines 03/2022), AI & the EU AI Act

Dark patterns are deceptive interface designs that manipulate users about their personal data; EDPB Guidelines 03/2022 set out six categories. AI can make…

Lesson · CIPP/E

Module 8, Direct marketing channel rules & the soft opt-in

Channel rules differ sharply. Postal marketing is outside ePrivacy and can often rely on legitimate interests. Person-to-person phone calls need no…

Lesson · CIPP/E

Module 8, Direct marketing - GDPR vs ePrivacy & the absolute right to object

Direct marketing is a communication, by any advertising means, directed towards specific individuals. It is regulated by both the GDPR and the ePrivacy…

Lesson · CIPP/E

Module 8, Employee data - legal layers, works councils & legal bases

Employee data sits under more than the GDPR: local data-protection AND employment law also apply, and these are not fully harmonised. Article 88 lets…

Lesson · CIPP/E

Module 8, ePrivacy Directive, location data & biometric data

The ePrivacy Directive (2002/58) governs data from terminal equipment over public electronic communications networks - its main basis is consent and it…

Lesson · CIPP/E

Module 8, Lawful employee monitoring & whistleblowing

Lawful employee monitoring must pass four tests - it must be necessary, have a legitimate, lawful basis, be proportionate and be transparent. Monitoring…

Lesson · CIPP/E

Module 8, Online behavioural advertising (OBA) & cloud computing

OBA targets website ads on observed behaviour over time, often via third-party ad networks placing cookies with unique identifiers. OBA data is personal…

Lesson · CIPP/E

Module 8, Search engines, Google Spain & social media targeting

Search engines determine purposes/means, so they are controllers. Google Spain (2014, CJEU) established the right to be forgotten and held search engines…

Lesson · CIPP/E

Module 8, Sensitive employee data, record retention & BYOD

Sensitive employee data needs an Article 9 condition; the employment/social-security exception is the usual route, with explicit consent only as a last…

Lesson · CIPP/E

Module 8, Surveillance framework - Article 23, content vs metadata

Surveillance is observation of individuals - covert or overt, real-time or stored. Article 23 lets EU/Member State law restrict data-subject rights, but…

Lesson · CIPP/E

Module 8, Web cookies, Article 5(3) & the Planet49 ruling

A cookie is a text file on a device; cookie data is personal data (Recital 30) and processing is subject to the GDPR. ePrivacy Article 5(3) requires…

Lesson · CIPP/E

Module 9, Appropriate technical and organisational measures (Article 32)

Security of processing is a prerequisite for compliance - most EU enforcement relates to security incidents, and failures can attract fines up to €20…

Lesson · CIPP/E

Module 9, Data breach notification (Articles 33 and 34)

Article 4(12) defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised…

Lesson · CIPP/E

Module 9, Security controls - the CIAR attributes

Security has four attributes - CIAR: Confidentiality, Integrity, Availability and Resilience. Resilience is new to EU data-protection law via the GDPR…

Lesson · CIPP/E

Module 9, The NIS and NIS2 Directives

The original NIS Directive was the first EU-wide cybersecurity law. The NIS2 Directive entered into force on 16 January 2023. Member States had to…

Lesson · CIPP/E

Natural Person, Deceased Persons and PII

Personal data protects natural persons (living humans) universally, regardless of nationality or residence (subject to Article 3 territorial scope). The…

Lesson · CIPP/E

Necessity and the DPIA

Before monitoring, the employer must be confident it is really necessary and consider less-intrusive methods first. A DPIA is required where monitoring is…

Lesson · CIPP/E

Necessity & the contract, legal obligation and vital interests bases

Every Article 6 basis except consent requires the processing to be necessary. 'Necessary' has an objective meaning - a close and substantial connection…

Lesson · CIPP/E

Need for a harmonised approach & the Data Protection Directive

Leaving implementation of Convention 108 and the OECD Guidelines to member states produced a diverse, fragmented set of regimes, threatening both…

Lesson · CIPP/E

NIS Directive and NIS 2

The original NIS Directive, adopted on 6 July 2016, was the first EU-wide cybersecurity law. The NIS2 Directive, Directive (EU) 2022/2555, replaced it…

Lesson · CIPP/E

OBA, cookies and ePrivacy (Article 5(3))

The key cookie rule is Article 5(3) ePrivacy Directive: storing or accessing information on a user's device (a cookie) needs the user's consent after…

Lesson · CIPP/E

OECD Guidelines

In 1980 the OECD issued Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. They are not legally binding but set out eight…

Lesson · CIPP/E

Offshoring and international transfers

Article 44 limits transfers of personal data outside the EEA unless the transfer meets a Chapter V condition. Available routes include an adequacy…

Lesson · CIPP/E

Online behavioural advertising (OBA)

OBA targets ads at people based on their behaviour observed over time. First-party OBA is run by the publisher itself; the trickier case is third-party ad…

Lesson · CIPP/E

Personal Data and Its Four Building Blocks

Personal data is any information relating to an identified or identifiable natural person (the 'data subject'). The definition is intentionally broad. The…

Lesson · CIPP/E

Postal marketing

Postal marketing is not digital, so the ePrivacy Directive does not apply - only the GDPR. There is no express GDPR requirement to obtain consent for…

Lesson · CIPP/E

Privacy and Electronic Communications (ePrivacy) Directive

Directive 2002/58/EC (the ePrivacy Directive) adds specific rules for electronic communications. It applies to publicly available electronic…

Lesson · CIPP/E

Procedure to designate adequate countries

The Commission designates adequacy by implementing act, guided by the WP29 Adequacy Referential (6 February 2018) on essential equivalence. Each decision…

Lesson · CIPP/E

Processing and Data Subject

Processing is defined extremely broadly: any operation or set of operations on personal data, whether or not automated - collection, recording, storage…

Lesson · CIPP/E

Processing sensitive employee data

Special-category (sensitive) employee data - racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic…

Lesson · CIPP/E

EU Artificial Intelligence Act

The Commission proposed an AI regulation on 21 April 2021. The adopted EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and…

Lesson · CIPP/E

Providing adequate safeguards - SCCs and the transfer impact assessment

Where there is no adequacy decision, controllers/processors must use appropriate safeguards. The GDPR lists several: binding instruments between public…

Lesson · CIPP/E

Providing notice

Whatever lawful basis is used, employers must still give employees a clear notice about how their data is used. It can sit in an employee handbook or a…

Lesson · CIPP/E

Public international law, EU representatives and Brexit

Article 3(3) applies the GDPR where a controller not established in the Union processes in a place where member state law applies by virtue of public…

Lesson · CIPP/E

Public task / official authority basis

Basis 6(1)(e) covers processing necessary for a task carried out in the public interest or in the exercise of official authority vested in the controller…

Lesson · CIPP/E

Purpose limitation

Purpose limitation means data must be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those…

Lesson · CIPP/E

Rationale for data protection

In the early 1970s, the spread of mainframe computers and telecommunications let governments and large firms build huge data banks, while trade through…

Lesson · CIPP/E

Reference, EDPB & WP29 guidelines and opinions (must-knows)

The Exam Blueprint repeatedly asks you to know "EDPB guidelines and opinions" on a topic. You don't need to memorise document numbers, but you SHOULD…

Lesson · CIPP/E

Reference, Key Articles, thresholds & timeframes cheat-sheet

The single highest-yield recall sheet for the exam: the article numbers, thresholds and timeframes that scenario questions hinge on. Drill these until…

Lesson · CIPP/E

Reference, Landmark CJEU/ECtHR cases & major fines

A handful of cases and fines come up again and again. Know what each one decided and the principle it established - examiners use them as scenario anchors.

Lesson · CIPP/E

Reform of the EU framework and the road to the GDPR

Divergent national measures and new technology pushed the Commission to reform the Directive. In January 2012 it published two proposals: a regulation…

Lesson · CIPP/E

Regulating surveillance: the legal framework

Surveillance by public and state agencies for national security or law enforcement is mostly legislated by member states, with compliance with the Charter…

Lesson · CIPP/E

Regulation by the citizen: rights, remedies, representation and compensation

Citizens are the 'second line of defence' - and the ~500 million citizens across the EU and UK are massive enforcement firepower. The GDPR gives…

Lesson · CIPP/E

Regulators' powers under Article 58: investigatory, corrective, authorisation/advisory

Article 58 grants the DPAs three types of power: investigatory (Art 58(1)), corrective (Art 58(2)), and authorisation and advisory (Art 58(3))…

Lesson · CIPP/E

Related legislation: LED & ePrivacy

Alongside the GDPR, the EU adopted the Law Enforcement Directive for processing by criminal-law authorities. The ePrivacy Directive governs…

Lesson · CIPP/E

'Relating to' - Content, Purpose and Result

For information to be personal data it must be about an individual, but the link is not always obvious. WP29 says one of three elements must apply (they…

Lesson · CIPP/E

Relying on the Article 49 derogations

Where there is neither adequacy nor appropriate safeguards, a transfer may still rely on an Article 49 derogation. The EDPB says these must be interpreted…

Lesson · CIPP/E

Requirements of the ePrivacy Directive

The ePrivacy Directive (2002/58/EC, as amended) adds information requirements for cookies and similar technologies on websites, apps and connected…

Lesson · CIPP/E

Responsibility of the controller

Accountability is first introduced in Article 5: Article 5(1) lists the six principles, and Article 5(2) adds the new duty that the controller must be…

Lesson · CIPP/E

Restrictions of data subject rights

Despite the GDPR's prescriptive nature, Union or member-state law may restrict the scope of the obligations and rights in Articles 12 to 22 (and the…

Lesson · CIPP/E

Right not to be subject to solely automated decision-making

Despite its title, Article 22 is a general prohibition, not a right to be invoked - it applies regardless of the data subject's actions. It is narrow: it…

Lesson · CIPP/E

Right of access (DSAR)

Article 15 is the active counterpart to the passive right to information: on request, a data subject must be told whether their data are processed and, if…

Lesson · CIPP/E

Right to data portability

Article 20 is entirely new to EU data protection law. It lets data subjects receive their own data, which they provided to a controller, in a structured…

Lesson · CIPP/E

Right to erasure ('right to be forgotten')

Article 17 lets a data subject have personal data erased - verbally or in writing - on specified grounds (data no longer needed, consent withdrawn…

Lesson · CIPP/E

Right to object

Article 21(1) lets a data subject object to processing based on the controller's legitimate interests. The objection shifts the burden of proof to the…

Lesson · CIPP/E

Right to opt out of direct marketing

Whatever the lawful basis, the GDPR gives individuals an absolute right to object to direct marketing. On consent, they withdraw consent; on legitimate…

Lesson · CIPP/E

Right to rectification

Article 16 lets data subjects have inaccurate personal data corrected and incomplete data completed. Its scope is largely unchanged from the Directive…

Lesson · CIPP/E

Right to restriction of processing

Article 18 is the GDPR's successor to the Directive's right to 'blocking' - a temporary freezing of data. On listed grounds (accuracy contested, unlawful…

Lesson · CIPP/E

Risk reporting and the meaning of 'personal data breach'

Article 33 requires notifying the regulator and Article 34 requires communicating to data subjects - both only where there is risk (or high risk) to…

Lesson · CIPP/E

Roles of the parties: controller and processor

In a typical outsourcing deal the customer is the controller and the supplier is the processor. A controller determines the purposes and means of…

Lesson · CIPP/E

Scope of data transfers - what counts as a transfer

The GDPR does not define 'transfer'. A key distinction is that a transfer is not the same as mere transit: it is the processing in the third country that…

Lesson · CIPP/E

Search engines and the right to be forgotten

Search engines process IP addresses, cookies, user log files and third-party webpages (which they crawl and index). In Google Spain, the CJEU held a…

Lesson · CIPP/E

Security principle and the risk-based approach (Article 32)

Article 5(1)(f) sets the security principle ('integrity and confidentiality'); Article 32 expands on it, requiring appropriate technical and…

Lesson · CIPP/E

Self-regulation: accountability, DPOs, codes and certification

Self-regulation is arguably the most effective tool because controllers and processors directly control the measures protecting data. The GDPR advances it…

Lesson · CIPP/E

Sensitive data - Article 9 framework

Article 9 prohibits processing of special-category data unless an exception applies. The categories are: racial/ethnic origin, political opinions…

Lesson · CIPP/E

Setting fines, guidelines and the Law Enforcement Directive

The WP29 (adopted by the EDPB) and the EDPB's 2022 guidelines steer how fines are calculated. A fine is not a mere mathematical exercise. Minor…

Lesson · CIPP/E

Situations requiring additional information

Beyond Articles 13/14, the GDPR triggers extra information duties in specific situations, whether or not the data came from the subject: data subject…

Lesson · CIPP/E

Social media: legal basis, special category data, children

SMP processing needs an Article 6 basis, and Article 9 applies to special category data. One Art 9 route is data manifestly made public by the data…

Lesson · CIPP/E

Social media: roles, joint controllership, transparency

Social media platforms (SMPs) collect data users provide, observe, and infer/predict. The SMP is a controller. The pivotal case is Wirtschaftsakademie…

Lesson · CIPP/E

Special Categories of Personal Data

Article 9 identifies special categories (sensitive) of personal data needing extra protection because their processing risks individuals' fundamental…

Lesson · CIPP/E

Specific, informed & unambiguous consent

Consent must be specific to the operation (purpose specification guards against function creep), informed (language the average person understands, not…

Lesson · CIPP/E

Storage limitation

Storage limitation (Article 5(1)(e)) means personal data must not be kept longer than necessary for the purpose; once no longer needed, it must be…

Lesson · CIPP/E

Storage of personnel records

Personnel records span recruitment, sick leave, medical insurance, salary, appraisals, evaluations and severance. They must not be kept longer than…

Lesson · CIPP/E

Subcontracting conditions

Where outsourcing forms a chain, Articles 28(2) and (4) set conditions on engaging a sub-processor. The customer must give prior specific or general…

Lesson · CIPP/E

Suppliers as controllers, AI, and chains of processors

A supplier that goes beyond its mandate and acquires a real role in determining the purposes or essential means of processing becomes a controller in its…

Lesson · CIPP/E

Targeted online advertising: ecosystem and law

Most free internet services are funded by targeted online advertising, which builds profiles and routes ads to people who meet criteria. The adtech…

Lesson · CIPP/E

Telephone marketing

Telemarketing is digital marketing, so both the GDPR and ePrivacy apply. For live person-to-person calls, Art 13(3) lets member states choose opt-in or…

Lesson · CIPP/E

The Article 5 principles overview

Chapter 6 covers the data processing principles now expressly listed in Article 5 of the GDPR. These principles did not start with the GDPR: they were…

Lesson · CIPP/E

The data protection officer (DPO)

Not every company needs a DPO, but Article 37 makes one mandatory in three cases: a public authority; where core activities consist of regular and…

Lesson · CIPP/E

The Five Building Blocks of 'Controller'

EDPB Guidelines 07/2020 break 'controller' into five building blocks: the person/body; 'determines'; 'alone or jointly with others'; 'the purposes and…

Lesson · CIPP/E

The General Data Protection Regulation (GDPR)

The GDPR is a directly applicable regulation with 173 recitals and 99 articles in eleven chapters. Unlike the Directive it binds processors directly…

Lesson · CIPP/E

The General Data Protection Regulation

The Directive could not keep pace with technology and globalisation, so the Commission proposed the GDPR in January 2012. It entered into force May 2016…

Lesson · CIPP/E

The general restriction on transfers outside the EEA

The GDPR lets personal data flow freely between member states, but transfers to any country outside the EEA are restricted. A transfer to a third country…

Lesson · CIPP/E

The NIS Directive (and NIS 2)

The original NIS Directive advanced EU cybersecurity and complemented the GDPR. NIS2, Directive (EU) 2022/2555, replaced that regime from 18 October 2024…

Lesson · CIPP/E

The Processor and the Article 28 Contract

A processor is a separate legal entity that processes personal data on behalf of a controller. Two building blocks: (1) separate legal entity, (2)…

Lesson · CIPP/E

The under-250-employees records exemption

There is an exemption from the Article 30 record-keeping duty for companies with fewer than 250 people. But it is heavily caveated and the chapter says it…

Lesson · CIPP/E

The United States - Privacy Shield, Schrems II and the Data Privacy Framework

Privacy Shield replaced Safe Harbor (adequacy decision 12 July 2016, in force 1 August 2016) with seven strengthened principles and extra safeguards. The…

Lesson · CIPP/E

The United States - Safe Harbor, Snowden and Schrems I

Safe Harbor (Commission decision 26 July 2000) was a self-certification framework treated as adequate for EU-US transfers. Criticised for weak…

Lesson · CIPP/E

Transparency, AUPs and covert monitoring

Transparency both meets the notice requirement and sets expectations: employees told in advance that use is monitored have less scope to claim they didn't…

Lesson · CIPP/E

Transparency principle

The first GDPR processing principle is that personal data must be processed lawfully, fairly and in a transparent manner. Transparency means being open…

Lesson · CIPP/E

Transparent communication and the right to information

Transparency underpins the whole system: individuals cannot protect their privacy if they are not properly informed. Article 12(1) requires information to…

Lesson · CIPP/E

Treaty of Lisbon

The Treaty of Lisbon was signed 13 December 2007 and took effect 1 December 2009. It amends the EU's two core treaties, renaming one the TFEU. Article…

Lesson · CIPP/E

Video surveillance (CCTV): lawful basis and proportionality

CCTV that captures images identifying people is processing personal data and must comply with the GDPR and, if applicable, the LED. The usual lawful basis…

Lesson · CIPP/E

When information must be provided (timing)

Timing is one of the key practical differences between the two Articles. Under Article 13 the information must be given at the time the personal data are…

Lesson · CIPP/E

Whistleblowing schemes

Whistleblowing lets employees report illegal or improper activity with privacy safeguards. SOX (2002) drove their prominence and reaches EU subsidiaries…

Lesson · CIPP/E

Why consent is problematic at work

Consent looks easy but should be a measure of last resort. Valid consent must be freely given, specific, informed and unambiguous - and the imbalance of…

Lesson · CIPP/E

Workplace monitoring: principles, background checks, DLP

An employee does not lose their right to privacy at work; their private sphere is protected but balanced against the employer's right to run its business…

Lesson · CIPP/E

Works councils

Works councils represent employees and have rights under local law over how employee data is used; they often must safeguard employees' data protection…

Guide · CIPP/E

What is location data under the GDPR?

A practical GDPR guide to GPS, IP-address, mobile-network and inferred location data, with Article 4, legal-basis and DPIA exam points.

Looking for AI governance? Explore the AIGP study guide.