The complete study library
Explore the CIPP/E study library
Search 257 free study resources for CIPP/E. Find a lesson, review a term or choose a practice session.
257 resources
No matching resources
Try a broader term or reset the search to see the complete library.
CIPP/E exam format and blueprint
Current CIPP/E format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.
Guide · CIPP/ECIPP/E exam questions
How to approach CIPP/E questions using scope, legal basis, rights, accountability and enforcement.
Guide · CIPP/ECIPP/E practice exam
Independent CIPP/E practice questions, a timed-study method and an evidence-led review routine.
Guide · CIPP/ECIPP/E study guide
A free CIPP/E study guide structured around the published IAPP outline and active recall.
Guide · CIPP/ECIPP/E study plan
A four-week CIPP/E study plan using the published outline, retrieval practice and scenario questions.
Practice · CIPP/ECIPP/E cram sheet
The complete CIPP/E memorisation sheet: key dates, fines and numbers, the principles, lawful bases, rights, transfers, cases and the classic exam traps.
Practice · CIPP/EFind the CIPP/E areas to study next.
Take a free 10-question CIPP/E diagnostic. Get an immediate domain score and a personalised study plan without creating an account.
Glossary · CIPP/ECIPP/E glossary
Plain-language definitions for recurring terms in the CIPP/E study guide.
Guide · CIPP/EHow to pass the CIPP/E
How to prepare for the IAPP CIPP/E exam using current format details, a flexible study plan, common mistakes and exam-style practice.
Guide · CIPP/EIs the CIPP/E exam hard?
Is the CIPP/E exam hard? Format, pass mark, domain weights, where candidates struggle and a practical way to prepare.
Practice · CIPP/EFree CIPP/E mini mock
Try 25 exam-style CIPP/E practice questions free, with explanations and a domain score. No account or payment required.
Practice · CIPP/EWhich of these is NOT a data-protection consideration for CCTV under the training?
Which of these is NOT a data-protection consideration for CCTV under the training? Answer with a worked explanation and related free lesson.
Lesson · CIPP/EAccountability and telling the principles apart
The GDPR reinforces every principle by adding accountability: it places the burden of proof on organisations to demonstrate proper implementation, and…
Lesson · CIPP/EAccuracy
The accuracy principle requires controllers to take reasonable measures to keep personal data accurate and, where necessary, up to date. This means…
Lesson · CIPP/EAdministrative fines: the two tiers and how they are set (Article 83)
The fines regime (Article 83) has two tiers. The lower tier (Art 83(4)) caps fines at €10 million or 2% of total worldwide annual turnover, whichever is…
Lesson · CIPP/EAdtech legal basis and automated decisions
Adtech relies on either consent or legitimate interest. Consent is hard: it must be informed and demonstrable, and firms without a direct relationship…
Lesson · CIPP/EApplications on mobile devices
Mobile apps collect large volumes of often intimate data via sensors (location, audio, video) and stored data (contacts, photos). Devices are rarely…
Lesson · CIPP/EArticle 13 vs Article 14 - what must be provided
The primary information duties sit in Article 13 (data collected directly from the data subject) and Article 14 (data obtained from another source). Both…
Lesson · CIPP/EArticle 3(1): EU-established controllers and processors
Under Article 3(1) the GDPR applies to processing 'in the context of the activities of an establishment of a controller or a processor in the Union'…
Lesson · CIPP/EArticle 3(2): the targeting and monitoring tests
Article 3(2) is the long-arm rule for organisations not established in the EU. It catches their processing of personal data of data subjects who are in…
Lesson · CIPP/EArticle 33 - notifying the supervisory authority
Article 33 requires the controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours…
Lesson · CIPP/EArticle 33 vs Article 34 - side-by-side comparison
Both Article 33 and Article 34 are risk-reporting duties on the controller, but they differ on who is told, the threshold , the deadline and the content …
Lesson · CIPP/EArticle 34 - communicating the breach to data subjects
Article 34 requires controllers to inform affected individuals without undue delay where a breach is likely to result in a high risk to their rights and…
Lesson · CIPP/EArticle 9 exceptions - the ten conditions
Article 9's prohibition is lifted by ten conditions. The headline ones: explicit consent (more than ordinary consent); employment/social-security law…
Lesson · CIPP/EArtificial Intelligence and the EU AI Act
AI systems may process personal data during design, training, testing and deployment, so the GDPR can apply throughout the lifecycle. Articles 13 and 14…
Lesson · CIPP/EBackground - Lisbon Treaty and institutional reform
The Treaty of Lisbon reformed the EU's institutional structure to cut bureaucracy and speed up decision-making after enlargement. Article 13 of the EU…
Lesson · CIPP/EBackground - the rights and their Articles
European data protection law has always given individuals enforceable rights, but the GDPR is far more extensive than the old Data Protection Directive…
Lesson · CIPP/EBackground & the role of consent
The GDPR requires controllers to process personal data lawfully, fairly and in a transparent manner. Article 6 and Article 9 set out the criteria for…
Lesson · CIPP/EBackground to European data protection law
European data protection law grew out of fears that new technologies - phone-tapping, surveillance, large mainframe computers - threatened individual…
Lesson · CIPP/EBackground - why security is an A-list principle
Security is not just one principle among many; it underpins compliance with all the others. Insecurity can trigger unlawful transfers, inaccuracy, data…
Lesson · CIPP/EBinding corporate rules and conclusion
Binding corporate rules (BCRs) can support an accountability framework. Sometimes called the gold standard of global data protection, they are a single…
Lesson · CIPP/EBinding corporate rules (BCRs) for intra-group transfers
BCRs are a global set of internal rules based on European privacy standards that a multinational group adopts voluntarily and a regulator approves, to…
Lesson · CIPP/EBinding corporate rules for processors
Binding corporate rules (BCRs) are internal, legally binding data protection rules adopted by multinationals. The original BCR model applied only where a…
Lesson · CIPP/EBiometric data as special-category data
Biometric data is defined in Article 4(14) as personal data from specific technical processing of physical, physiological or behavioural characteristics…
Lesson · CIPP/EBlueprint Check, Domain coverage map (I–III)
A cross-check of the CIPP/E Exam Blueprint against this guide. Every competency in Domains I, II and III is covered by both this guide chapters and the…
Lesson · CIPP/EBlueprint Check, Domain coverage map (IV–V) & gap analysis
The cross-check for Domains IV (Scope & Accountability) and V (Compliance), plus the short list of items the official training reinforced on top of this…
Lesson · CIPP/EBrexit and UK data protection
After Brexit, withdrawal legislation repealed the European Communities Act 1972, converted the GDPR into the UK GDPR (retained EU law, amended by the 2019…
Lesson · CIPP/EBring your own device (BYOD)
Under BYOD, employees use personal devices for work. The employer remains the controller for work-related personal data processed on the device, yet the…
Lesson · CIPP/EChannel-by-channel rules: the consent matrix
This is the heart of the chapter for exam purposes. Post is GDPR-only (no ePrivacy), usually consent or legitimate interests. Live phone calls are left to…
Lesson · CIPP/ECloud computing: models and applicable law
Cloud computing is IT services delivered over the internet, split into IaaS, PaaS and SaaS by how much the supplier provides. Cloud infrastructure is…
Lesson · CIPP/ECloud: controllership issues
In most supply-of-services cases the customer is the controller (it decides purposes and means) and the supplier is a processor. But in cloud this can't…
Lesson · CIPP/ECloud: international data transfers
Cloud almost always involves international transfers, and the cloud customer (exporter) is responsible for compliance. Options to provide appropriate…
Lesson · CIPP/ECloud service contracts (Article 28)
A GDPR-subject customer must put an Article 28 contract in place with its cloud provider. The GDPR lists mandatory processor terms: processing only on…
Lesson · CIPP/ECommunications data: content, metadata and retention
Electronic communications generate two categories of data: content and metadata (data about data). Metadata splits into traffic data, location data and…
Lesson · CIPP/EComparing the transfer mechanisms & the future of restrictions
This pulls the four main routes together - adequacy decision, standard contractual clauses|SCCs, BCRs, and Article 49 derogation|derogations - and this…
Lesson · CIPP/ECompetence, the one-stop shop and the lead supervisory authority
Each DPA is competent in its own territory (Article 55). For cross-border processing, the lead supervisory authority - the DPA of the…
Lesson · CIPP/EConclusion: recalibrating responsibilities
The GDPR's biggest change to outsourcing is the recalibration of responsibilities between controllers and processors. Controllers remain primarily…
Lesson · CIPP/EConsent - definition and the four conditions
Consent is the first Article 6 basis. It is defined as any freely given, specific, informed and unambiguous indication of the data subject's wishes, by a…
Lesson · CIPP/EConsent vs legitimate interests - choosing correctly
Exam scenarios frequently turn on consent vs legitimate interests. Consent gives the subject control but can be withdrawn at any time, forcing the…
Lesson · CIPP/EController vs Processor - Roles and Liability
A controller is the person or body that alone or jointly determines the purposes and means of processing - the key decision-maker, who carries most GDPR…
Lesson · CIPP/EConvention 108+
A modernisation protocol - colloquially Convention 108+ - was signed by 21 states on 10 October 2018 after more than seven years of work begun in January…
Lesson · CIPP/EConvention 108
Convention 108 was opened for signature on 28 January 1981 by the Council of Europe. It was the first legally binding international instrument in data…
Lesson · CIPP/ECookies and similar technologies
A cookie is a small text file placed on a device that 'remembers' it. Other tracking tech includes device fingerprinting, tags, pixels, web beacons…
Lesson · CIPP/ECooperation, consistency and the EDPB (Articles 60–66, 68–71)
Cross-border cases run through the cooperation procedure (Article 60): the lead authority circulates a draft decision; other concerned DPAs may agree or…
Lesson · CIPP/ECouncil of Europe Convention 108
Opened for signature on 28 January 1981, Convention 108 was the first legally binding international instrument in data protection. It rests on data…
Lesson · CIPP/ECouncil of the European Union
The Council of the European Union (Council of Ministers) is the EU's main decision-making body and the co-legislator with the Parliament. Do not confuse…
Lesson · CIPP/ECourt of Justice of the European Union (CJEU)
The Court of Justice of the European Union|CJEU, based in Luxembourg, is the EU's judicial body, deciding issues of EU law and enforcing EU decisions. It…
Lesson · CIPP/ECriminal convictions data (Article 10) & processing without identification (Article 11)
Article 10 data - criminal convictions, offences and related security measures - needs greater protection but is NOT a special category under Article 9…
Lesson · CIPP/EData minimisation
Data minimisation means collecting and processing only data that is relevant, necessary and adequate for the purpose - collect only what you really need…
Lesson · CIPP/EData protection and direct marketing
Direct marketing is one of the hardest areas of data protection law because it triggers both DP rules and other consumer-protection rules that vary by…
Lesson · CIPP/EData protection by design and by default
Article 25 requires data protection by design and data protection by default - the technical and organisational measures a controller builds in to protect…
Lesson · CIPP/EData Protection Directive 95/46/EC
Adopted on 24 October 1995, Directive 95/46 was the EU's flagship data protection law, set up as an internal market harmonisation measure under the Treaty…
Lesson · CIPP/EData protection impact assessment (DPIA)
A DPIA (also called a PIA) systematically identifies and addresses the data protection impacts of new products, services or activities. Under Article 35…
Lesson · CIPP/EData Retention Directive
Directive 2006/24/EC (the Data Retention Directive) aligned national rules on retaining traffic and location data for serious crime and anti-terrorism. In…
Lesson · CIPP/EDelivering on security - programmes, people, paperwork
A strong security programme is board-endorsed, multidisciplinary, and connects security professionals with data protection and legal staff. Practitioners…
Lesson · CIPP/EDocumentation and records of processing (Article 30)
The GDPR abolished the Directive's notify/register requirement: controllers no longer file processing activities with a DPA. Instead they must keep…
Lesson · CIPP/EEmployee data
Employers process personal data on employees past, present and potential for recruitment, salary, benefits, personnel files, sickness records, monitoring…
Lesson · CIPP/EEmployees, the insider threat, and the controller-processor relationship
Article 32(4) covers employees and other workers acting under the controller's or processor's authority - read with Article 5(1)(f) and Article 28(3)(b)…
Lesson · CIPP/EEnforcement and conclusion
Enforcement of direct-marketing rules - especially cookies and unsolicited communications - is rising: class actions (Lloyd v Google in the UK…
Lesson · CIPP/EePrivacy consent and cookie controllership
Cookie consent must meet GDPR standards. Planet49 confirmed consent is not valid via a pre-ticked box, and users must be told the cookie's duration and…
Lesson · CIPP/EePrivacy laws: unsolicited messages and cookies
The ePrivacy Directive adds consent/information rules to digital marketing by phone, fax and electronic mail (incl. SMS, IM, push). The general rule: most…
Lesson · CIPP/EEU Cloud Code of Conduct
The EU Cloud Code was approved by Belgium's DPA in May 2021 after a positive EDPB opinion. It sets requirements for B2B cloud services where the provider…
Lesson · CIPP/EEuropean Commission
The European Commission is the EU's executive body but also far more: it holds the right to initiate legislation ('Union legislative acts may only be…
Lesson · CIPP/EEuropean Council
The European Council gives the EU its political impetus and direction but does not exercise legislative functions. It began as an informal body in 1974…
Lesson · CIPP/EEuropean Court of Human Rights (ECtHR)
The European Court of Human Rights|ECtHR is not an EU institution. It sits in Strasbourg as part of the Council of Europe, which has 46 member states…
Lesson · CIPP/EEuropean Parliament
The European Parliament is the only EU institution directly elected by EU citizens, giving it democratic weight. It has four roles: legislative…
Lesson · CIPP/EExam Prep, A study plan that actually works
The IAPP advises a minimum of 30 hours of study. But hours alone don't pass exams - active recall and spaced retrieval do. Re-reading and highlighting…
Lesson · CIPP/EExam Prep, After the course - next steps to certify
Completing the training is a step, not the finish line. To convert it into a pass, layer on this guide, the blueprint, practice questions and spaced…
Lesson · CIPP/EExam Prep, How the questions are written (Bloom's taxonomy)
Not every question is a definition. The IAPP writes questions at different Bloom's taxonomy levels. The verb in a performance indicator (define, identify…
Lesson · CIPP/EExam Prep, Test-day strategy & the classic traps
On the day, technique matters. Read the full stem, watch for absolutes ("always", "never"), and pick the best answer, not merely a true one. Most lost…
Lesson · CIPP/EExam Prep, The CIPP/E exam at a glance
The CIPP/E exam tests the IAPP Body of Knowledge across five domains. Knowing the weighting tells you where to spend your time: Domain II is the single…
Lesson · CIPP/EExemptions to the obligation to provide information
The GDPR has its own exemptions (no national law needed) and permits member states to create more. For Article 13 (direct collection) there is essentially…
Lesson · CIPP/EFair processing notices and best practice
Unlike the Directive, the GDPR specifies methods for informing data subjects, so fair processing notices (privacy notices) remain the convenient way to…
Lesson · CIPP/EFreely given consent - bundling, imbalance, cookie walls
Freely given means a genuine choice and the ability to refuse or withdraw. Consent bundled with other matters (e.g. buying a service) is invalid; under…
Lesson · CIPP/EHow information must be provided (manner and format)
Article 12 governs the manner: information must be concise, transparent, intelligible and easily accessible, using clear and plain language, and language…
Lesson · CIPP/EHuman rights law foundations
European data protection rests on human rights law. The Universal Declaration of Human Rights (1948) set the values: Article 12 protects privacy, Article…
Lesson · CIPP/EIdentifiability, Anonymisation and Pseudonymisation
A person is identifiable when, though not yet identified, it is possible to identify them - directly (by name) or indirectly (by an identifier, or by…
Lesson · CIPP/EImpact on member states - implementation, enforcement, direct effect
Directives are not directly applicable: states transpose them, so approaches vary - the great challenge of EU privacy law. The Commission can take…
Lesson · CIPP/EIncident response
Putting in place incident response is an implicit requirement of the security principle and the breach rules. A good incident response plan needs senior…
Lesson · CIPP/EIndependent national regulators and their tasks (Articles 51–57, 59)
Only the DPA|DPAs hold administrative supervisory and enforcement powers under the GDPR. They must be independent public authorities (Articles 51–52) with…
Lesson · CIPP/EIntegrity and confidentiality
Article 5(1)(f) - integrity and confidentiality (the 'security principle') - requires processing in a manner that ensures appropriate security, including…
Lesson · CIPP/EInternet of Things (IoT)
The IoT is physical objects ('connected objects') that connect, sense and transmit data - wearables, smart meters, connected vehicles, and VVA-paired…
Lesson · CIPP/EIntroduction and background to accountability
The GDPR formally embeds accountability into EU data protection law. Accountability means the obligations an organisation must meet to show and evidence…
Lesson · CIPP/EIntroduction and overview of scope
Chapter 5 sets out two filters that decide whether the GDPR applies at all: territorial scope (which organisations, by location or by who they target) and…
Lesson · CIPP/EIntroduction and scope
Chapter 17 maps how European data protection concepts apply to a range of internet technologies - cloud, cookies, IP addresses, search engines, social…
Lesson · CIPP/EIntroduction and surveillance technology
Surveillance means observing an individual or group, and it is getting cheaper, more capable and more pervasive. The classic concern is the nation state…
Lesson · CIPP/EIntroduction: the toolkit of supervision and enforcement
A regulatory system is only as good as the means by which it is supervised and enforced. The GDPR spreads enforcement firepower across many actors, not…
Lesson · CIPP/EIntroduction to Data Protection Concepts
The core data protection concepts pre-date the GDPR: they were set by the 1995 Data Protection Directive and remain essentially unchanged in the GDPR…
Lesson · CIPP/EIntroduction to outsourcing
Data protection law was born in the early 1970s as computers spread, and early service bureaux (also called computer bureaux) processed data on behalf of…
Lesson · CIPP/EIP addresses as personal data (Breyer)
An IP address is a numerical label assigned to a device. It can be static IP address|static (always the same) or dynamic IP address|dynamic (changes each…
Lesson · CIPP/EJoint Controllership
Joint controllership arises where two or more entities jointly determine the purposes and means of processing - either by a common decision or through…
Lesson · CIPP/ELaw Enforcement Directive (LED)
Agreed alongside the GDPR, the Law Enforcement Directive (Directive (EU) 2016/680) governs personal data processed by criminal law enforcement…
Lesson · CIPP/ELaw enforcement, EU institutions, ePrivacy and E-Commerce
Article 2(2)(d) exempts processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences (and…
Lesson · CIPP/ELawfulness, fairness and transparency
The first principle bundles three ideas. Lawfulness means there must be a legal ground (and the processing must comply with all applicable laws). Fairness…
Lesson · CIPP/ELegal basis for processing employee personal data
Employers usually rely on one of four grounds: consent, necessity for the employment contract, compliance with a legal obligation, or legitimate…
Lesson · CIPP/ELegal obligation & public interest - extra detail; documenting the basis
For both the legal obligation and public task bases, Recital 45 says the processing must have a basis in EU or member-state law, which may specify the…
Lesson · CIPP/ELegitimacy and proportionality of monitoring
Monitoring needs a lawful basis - usually the legitimate-interests balancing test, not consent, whose use the WP29 said is very limited for monitoring…
Lesson · CIPP/ELegitimate interests & the balancing test
Legitimate interests (6(1)(f)) is the most flexible basis and the one on which most processing relies, but public authorities cannot use it for their…
Lesson · CIPP/ELocation-based marketing
Using location data from devices for marketing engages both the GDPR and ePrivacy. ePrivacy Art 9 requires opt-in consent to use location data for a…
Lesson · CIPP/ELocation data and contact tracing
Location-based services (LBS) use location to deliver navigation, advertising, gaming, payments and more, drawn from satellite (GPS/Galileo), cell-based…
Lesson · CIPP/EMandatory Article 28(3) contract terms
Processing by a processor must be governed by a written contract (or other binding legal act). Article 28(3) sets out the mandatory terms. From the…
Lesson · CIPP/EMarketing by electronic mail and the soft opt-in
Email/SMS/MMS marketing needs prior opt-in consent (ePrivacy Art 13(1)) - typically a tick box at data capture. The exception is the soft opt-in…
Lesson · CIPP/EMaterial scope: matters outside EU law and the household exemption
Even an in-scope organisation has some processing carved out of the GDPR by Article 2. Article 2(2)(a) excludes activities outside the scope of Union law…
Lesson · CIPP/EMeaning of an 'adequate level of protection'
Under Article 45(1), the Commission can decide a third country, a territory, a sector, or an international organisation ensures an adequate level of…
Lesson · CIPP/EModalities - to whom, how, and when
Article 12(2) requires controllers to facilitate the exercise of rights. Unlike the Directive, the GDPR requires the controller to use all reasonable…
Lesson · CIPP/EModule 1, Council of Europe vs the EU
A critical exam distinction. The European Union (EU) is an economic and political union of 27 Member States; the Council of Europe (CoE) is an…
Lesson · CIPP/EModule 1, Directive vs Regulation, the EDPB and ePrivacy
A Directive obliges Member States to implement it in local law; a Regulation is directly applicable with no local implementation needed - the GDPR is a…
Lesson · CIPP/EModule 1, EU institutions and the legislative process
The EU's institutions split into legislative, policy and judicial roles. The European Commission proposes legislation; the European Parliament (MEPs) and…
Lesson · CIPP/EModule 1, European data protection timeline
The road to the GDPR: the OECD Guidelines (1980) set harmonised data-flow principles; Convention 108 (1981) was the first binding data protection treaty…
Lesson · CIPP/EModule 1, Foundations: UDHR and ECHR
European data protection grows from two human-rights instruments. The Universal Declaration of Human Rights (UDHR) was adopted on 10 December 1948 and is…
Lesson · CIPP/EModule 10, Accountability defined (Article 24)
Article 24(1) makes the controller responsible for implementing appropriate technical and organisational measures to ensure and be able to demonstrate…
Lesson · CIPP/EModule 10, Data protection by design and by default (Article 25)
Article 25 sets two linked duties. Data protection by design begins before processing and bakes data protection into the planning/design phase. Data…
Lesson · CIPP/EModule 10, Data protection impact assessment (DPIA, Articles 35 and 36)
A DPIA has two values: incorporate data protection into planning and demonstrate compliance to SAs. A PIA is broader and lighter and can run on any…
Lesson · CIPP/EModule 10, Data protection policy (Article 24(2))
A data protection policy (Article 24(2)) is an internal tool to train employees and set out what may and may not be done, plus the consequences of breach…
Lesson · CIPP/EModule 10, Records of processing (Article 30)
Records of processing (Article 30) apply to organisations with 250+ employees, OR - regardless of size - where processing is likely to result in a risk…
Lesson · CIPP/EModule 10, The data protection officer (DPO, Articles 37–39)
The DPO (formerly the Personal Data Protection Official) advises on and monitors compliance and must be an expert in data protection law and practices…
Lesson · CIPP/EModule 10, The EU representative (Article 27)
Under Article 27, controllers/processors caught by Article 3(2) - those offering goods/services to, or monitoring, people in the EU while not established…
Lesson · CIPP/EModule 11, Lead SA, one-stop-shop & cooperation/consistency
For cross-border processing a single lead supervisory authority (LSA) coordinates the concerned supervisory authorities through the one-stop-shop. The LSA…
Lesson · CIPP/EModule 11, Remedies, liabilities & administrative fines
The GDPR sets two fine tiers: up to €10 million or 2% of worldwide annual turnover (lower) and up to €20 million or 4% (higher), whichever is higher…
Lesson · CIPP/EModule 11, Supervisory authorities & Article 58 powers
Supervisory authorities (a.k.a. data protection authorities) are the bodies the GDPR tasks with promoting, monitoring and enforcing the regulation. Their…
Lesson · CIPP/EModule 11, The EDPB & the EDPS
The European Data Protection Board (EDPB) replaced the Article 29 Working Party and ensures consistent application of the GDPR. The 30 EEA SAs each send a…
Lesson · CIPP/EModule 2, Anonymous vs pseudonymous data
Anonymous data is rendered unidentifiable and is NOT protected by the GDPR, but true anonymisation is hard. Pseudonymous data is NOT fully anonymous -…
Lesson · CIPP/EModule 2, Defining and identifying personal data
Article 4(1) GDPR defines personal data as "any information relating to an identified or identifiable natural person." The course uses a four-step test…
Lesson · CIPP/EModule 2, Special categories of personal data (Article 9)
Article 9(1) prohibits processing of special-category data unless an exception applies. The categories cover racial/ethnic origin, political opinions…
Lesson · CIPP/EModule 3, Controller vs processor
Who decides the purposes and means of processing? Whoever determines the "why" and the "how" is the controller (Article 4(7)); whoever processes on the…
Lesson · CIPP/EModule 3, Sub-processors and Opinion 22/2024
A sub-processor is an entity engaged by a processor to help carry out the processing. EDPB Opinion 22/2024 makes three things clear: the controller must…
Lesson · CIPP/EModule 3, Vendor management and the Article 28 contract
Choosing a good processor is part of the controller's accountability - there is a pre-contractual due-diligence duty, and failing it leaves the controller…
Lesson · CIPP/EModule 4, Consent - the four conditions and children
Valid consent must be freely given, specific, informed and unambiguous - a clear affirmative act, clearly distinguishable and in plain language, with…
Lesson · CIPP/EModule 4, Data processing principles (OECD + Article 5)
The GDPR's Article 5 principles - lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity…
Lesson · CIPP/EModule 4, Legitimate interests and the balancing test
Legitimate interests (Art 6(1)(f)) is a flexible "safety net," but it demands a Legitimate Interest Assessment (LIA). EDPB Guidelines 1/2024 set three…
Lesson · CIPP/EModule 4, Special-category data and Article 9 exceptions
Processing special-category data is prohibited by default. To do it lawfully you need BOTH an Article 6 basis AND an Article 9 exception. The exceptions…
Lesson · CIPP/EModule 4, Territorial and material scope
Article 3 sets territorial scope - and only one criterion need be met: the establishment criterion (Art 3(1)), the targeting/monitoring criterion (Art…
Lesson · CIPP/EModule 4, The data processing life cycle
Processing is defined sweepingly in Article 4(2): any operation performed on personal data, automated or not - from collection and storage right through…
Lesson · CIPP/EModule 4, The six Article 6 lawful bases
Processing personal data needs a lawful basis. Article 6 offers six, and only one is needed: consent, contract, legal obligation, vital interests, public…
Lesson · CIPP/EModule 5, Access and rectification (Articles 15 & 16)
Two foundational data subject rights. The right of access (Article 15) lets a person obtain confirmation that their data is processed, a copy of their…
Lesson · CIPP/EModule 5, Automated decision-making and profiling (Article 22)
Article 22 gives the data subject the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal…
Lesson · CIPP/EModule 5, Data portability (Article 20)
Data portability (Article 20) extends the right of access: the data subject can receive their data in a structured, commonly used, machine-readable format…
Lesson · CIPP/EModule 5, Erasure / right to be forgotten (Article 17)
Right to erasure (Article 17), also called the right to be forgotten, lets a data subject have their data deleted in defined cases - e.g. data no longer…
Lesson · CIPP/EModule 5, Restriction of processing (Article 18)
Restriction of processing (Article 18) means marking stored personal data to limit future processing - a kind of legal hold. Per Article 4(3), the data is…
Lesson · CIPP/EModule 5, Right to object (Article 21)
Right to object (Article 21) applies where processing is for direct marketing (an absolute right - processing must cease, including profiling for…
Lesson · CIPP/EModule 6, Article 13 vs Article 14 (direct vs indirect collection)
Article 13 governs data collected directly from the data subject - provide the information at the time of collection. Article 14 governs data obtained…
Lesson · CIPP/EModule 6, Privacy notices and formats
A privacy notice describes how an organisation collects, uses, retains and discloses personal data (a.k.a. privacy statement / fair processing statement /…
Lesson · CIPP/EModule 6, Transparency (Article 12)
Transparency (Article 12) requires controllers to communicate concisely, transparently, intelligibly and in clear and plain language (adapted for…
Lesson · CIPP/EModule 7, Adequacy decisions & the Schrems/DPF saga
An adequacy decision is a European Commission finding that a third country's laws provide essentially equivalent protection - so transfers there need no…
Lesson · CIPP/EModule 7, Appropriate safeguards: SCCs, BCRs & codes
Used when there is no adequacy decision, appropriate safeguards bind the recipient to an EU standard. Standard Contractual Clauses (SCCs) are the most…
Lesson · CIPP/EModule 7, Derogations & restrictions (Article 49)
Derogations under Article 49 are last-resort exemptions, narrowly interpreted, that allow a transfer in specific situations only when neither adequacy nor…
Lesson · CIPP/EModule 7, The landscape: three options in order
When personal data leaves the EEA (the EU plus Iceland, Liechtenstein and Norway) it must stay protected to an EU-equivalent standard, and this applies to…
Lesson · CIPP/EModule 8, CCTV / video surveillance & Guidelines 3/2019
CCTV footage contains personal data and images may be biometric data. Compliance turns on lawfulness (often legitimate interest; consent is usually not…
Lesson · CIPP/EModule 8, Dark patterns (Guidelines 03/2022), AI & the EU AI Act
Dark patterns are deceptive interface designs that manipulate users about their personal data; EDPB Guidelines 03/2022 set out six categories. AI can make…
Lesson · CIPP/EModule 8, Direct marketing channel rules & the soft opt-in
Channel rules differ sharply. Postal marketing is outside ePrivacy and can often rely on legitimate interests. Person-to-person phone calls need no…
Lesson · CIPP/EModule 8, Direct marketing - GDPR vs ePrivacy & the absolute right to object
Direct marketing is a communication, by any advertising means, directed towards specific individuals. It is regulated by both the GDPR and the ePrivacy…
Lesson · CIPP/EModule 8, Employee data - legal layers, works councils & legal bases
Employee data sits under more than the GDPR: local data-protection AND employment law also apply, and these are not fully harmonised. Article 88 lets…
Lesson · CIPP/EModule 8, ePrivacy Directive, location data & biometric data
The ePrivacy Directive (2002/58) governs data from terminal equipment over public electronic communications networks - its main basis is consent and it…
Lesson · CIPP/EModule 8, Lawful employee monitoring & whistleblowing
Lawful employee monitoring must pass four tests - it must be necessary, have a legitimate, lawful basis, be proportionate and be transparent. Monitoring…
Lesson · CIPP/EModule 8, Online behavioural advertising (OBA) & cloud computing
OBA targets website ads on observed behaviour over time, often via third-party ad networks placing cookies with unique identifiers. OBA data is personal…
Lesson · CIPP/EModule 8, Search engines, Google Spain & social media targeting
Search engines determine purposes/means, so they are controllers. Google Spain (2014, CJEU) established the right to be forgotten and held search engines…
Lesson · CIPP/EModule 8, Sensitive employee data, record retention & BYOD
Sensitive employee data needs an Article 9 condition; the employment/social-security exception is the usual route, with explicit consent only as a last…
Lesson · CIPP/EModule 8, Surveillance framework - Article 23, content vs metadata
Surveillance is observation of individuals - covert or overt, real-time or stored. Article 23 lets EU/Member State law restrict data-subject rights, but…
Lesson · CIPP/EModule 8, Web cookies, Article 5(3) & the Planet49 ruling
A cookie is a text file on a device; cookie data is personal data (Recital 30) and processing is subject to the GDPR. ePrivacy Article 5(3) requires…
Lesson · CIPP/EModule 9, Appropriate technical and organisational measures (Article 32)
Security of processing is a prerequisite for compliance - most EU enforcement relates to security incidents, and failures can attract fines up to €20…
Lesson · CIPP/EModule 9, Data breach notification (Articles 33 and 34)
Article 4(12) defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised…
Lesson · CIPP/EModule 9, Security controls - the CIAR attributes
Security has four attributes - CIAR: Confidentiality, Integrity, Availability and Resilience. Resilience is new to EU data-protection law via the GDPR…
Lesson · CIPP/EModule 9, The NIS and NIS2 Directives
The original NIS Directive was the first EU-wide cybersecurity law. The NIS2 Directive entered into force on 16 January 2023. Member States had to…
Lesson · CIPP/ENatural Person, Deceased Persons and PII
Personal data protects natural persons (living humans) universally, regardless of nationality or residence (subject to Article 3 territorial scope). The…
Lesson · CIPP/ENecessity and the DPIA
Before monitoring, the employer must be confident it is really necessary and consider less-intrusive methods first. A DPIA is required where monitoring is…
Lesson · CIPP/ENecessity & the contract, legal obligation and vital interests bases
Every Article 6 basis except consent requires the processing to be necessary. 'Necessary' has an objective meaning - a close and substantial connection…
Lesson · CIPP/ENeed for a harmonised approach & the Data Protection Directive
Leaving implementation of Convention 108 and the OECD Guidelines to member states produced a diverse, fragmented set of regimes, threatening both…
Lesson · CIPP/ENIS Directive and NIS 2
The original NIS Directive, adopted on 6 July 2016, was the first EU-wide cybersecurity law. The NIS2 Directive, Directive (EU) 2022/2555, replaced it…
Lesson · CIPP/EOBA, cookies and ePrivacy (Article 5(3))
The key cookie rule is Article 5(3) ePrivacy Directive: storing or accessing information on a user's device (a cookie) needs the user's consent after…
Lesson · CIPP/EOECD Guidelines
In 1980 the OECD issued Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. They are not legally binding but set out eight…
Lesson · CIPP/EOffshoring and international transfers
Article 44 limits transfers of personal data outside the EEA unless the transfer meets a Chapter V condition. Available routes include an adequacy…
Lesson · CIPP/EOnline behavioural advertising (OBA)
OBA targets ads at people based on their behaviour observed over time. First-party OBA is run by the publisher itself; the trickier case is third-party ad…
Lesson · CIPP/EPersonal Data and Its Four Building Blocks
Personal data is any information relating to an identified or identifiable natural person (the 'data subject'). The definition is intentionally broad. The…
Lesson · CIPP/EPostal marketing
Postal marketing is not digital, so the ePrivacy Directive does not apply - only the GDPR. There is no express GDPR requirement to obtain consent for…
Lesson · CIPP/EPrivacy and Electronic Communications (ePrivacy) Directive
Directive 2002/58/EC (the ePrivacy Directive) adds specific rules for electronic communications. It applies to publicly available electronic…
Lesson · CIPP/EProcedure to designate adequate countries
The Commission designates adequacy by implementing act, guided by the WP29 Adequacy Referential (6 February 2018) on essential equivalence. Each decision…
Lesson · CIPP/EProcessing and Data Subject
Processing is defined extremely broadly: any operation or set of operations on personal data, whether or not automated - collection, recording, storage…
Lesson · CIPP/EProcessing sensitive employee data
Special-category (sensitive) employee data - racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic…
Lesson · CIPP/EEU Artificial Intelligence Act
The Commission proposed an AI regulation on 21 April 2021. The adopted EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and…
Lesson · CIPP/EProviding adequate safeguards - SCCs and the transfer impact assessment
Where there is no adequacy decision, controllers/processors must use appropriate safeguards. The GDPR lists several: binding instruments between public…
Lesson · CIPP/EProviding notice
Whatever lawful basis is used, employers must still give employees a clear notice about how their data is used. It can sit in an employee handbook or a…
Lesson · CIPP/EPublic international law, EU representatives and Brexit
Article 3(3) applies the GDPR where a controller not established in the Union processes in a place where member state law applies by virtue of public…
Lesson · CIPP/EPublic task / official authority basis
Basis 6(1)(e) covers processing necessary for a task carried out in the public interest or in the exercise of official authority vested in the controller…
Lesson · CIPP/EPurpose limitation
Purpose limitation means data must be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those…
Lesson · CIPP/ERationale for data protection
In the early 1970s, the spread of mainframe computers and telecommunications let governments and large firms build huge data banks, while trade through…
Lesson · CIPP/EReference, EDPB & WP29 guidelines and opinions (must-knows)
The Exam Blueprint repeatedly asks you to know "EDPB guidelines and opinions" on a topic. You don't need to memorise document numbers, but you SHOULD…
Lesson · CIPP/EReference, Key Articles, thresholds & timeframes cheat-sheet
The single highest-yield recall sheet for the exam: the article numbers, thresholds and timeframes that scenario questions hinge on. Drill these until…
Lesson · CIPP/EReference, Landmark CJEU/ECtHR cases & major fines
A handful of cases and fines come up again and again. Know what each one decided and the principle it established - examiners use them as scenario anchors.
Lesson · CIPP/EReform of the EU framework and the road to the GDPR
Divergent national measures and new technology pushed the Commission to reform the Directive. In January 2012 it published two proposals: a regulation…
Lesson · CIPP/ERegulating surveillance: the legal framework
Surveillance by public and state agencies for national security or law enforcement is mostly legislated by member states, with compliance with the Charter…
Lesson · CIPP/ERegulation by the citizen: rights, remedies, representation and compensation
Citizens are the 'second line of defence' - and the ~500 million citizens across the EU and UK are massive enforcement firepower. The GDPR gives…
Lesson · CIPP/ERegulators' powers under Article 58: investigatory, corrective, authorisation/advisory
Article 58 grants the DPAs three types of power: investigatory (Art 58(1)), corrective (Art 58(2)), and authorisation and advisory (Art 58(3))…
Lesson · CIPP/ERelated legislation: LED & ePrivacy
Alongside the GDPR, the EU adopted the Law Enforcement Directive for processing by criminal-law authorities. The ePrivacy Directive governs…
Lesson · CIPP/E'Relating to' - Content, Purpose and Result
For information to be personal data it must be about an individual, but the link is not always obvious. WP29 says one of three elements must apply (they…
Lesson · CIPP/ERelying on the Article 49 derogations
Where there is neither adequacy nor appropriate safeguards, a transfer may still rely on an Article 49 derogation. The EDPB says these must be interpreted…
Lesson · CIPP/ERequirements of the ePrivacy Directive
The ePrivacy Directive (2002/58/EC, as amended) adds information requirements for cookies and similar technologies on websites, apps and connected…
Lesson · CIPP/EResponsibility of the controller
Accountability is first introduced in Article 5: Article 5(1) lists the six principles, and Article 5(2) adds the new duty that the controller must be…
Lesson · CIPP/ERestrictions of data subject rights
Despite the GDPR's prescriptive nature, Union or member-state law may restrict the scope of the obligations and rights in Articles 12 to 22 (and the…
Lesson · CIPP/ERight not to be subject to solely automated decision-making
Despite its title, Article 22 is a general prohibition, not a right to be invoked - it applies regardless of the data subject's actions. It is narrow: it…
Lesson · CIPP/ERight of access (DSAR)
Article 15 is the active counterpart to the passive right to information: on request, a data subject must be told whether their data are processed and, if…
Lesson · CIPP/ERight to data portability
Article 20 is entirely new to EU data protection law. It lets data subjects receive their own data, which they provided to a controller, in a structured…
Lesson · CIPP/ERight to erasure ('right to be forgotten')
Article 17 lets a data subject have personal data erased - verbally or in writing - on specified grounds (data no longer needed, consent withdrawn…
Lesson · CIPP/ERight to object
Article 21(1) lets a data subject object to processing based on the controller's legitimate interests. The objection shifts the burden of proof to the…
Lesson · CIPP/ERight to opt out of direct marketing
Whatever the lawful basis, the GDPR gives individuals an absolute right to object to direct marketing. On consent, they withdraw consent; on legitimate…
Lesson · CIPP/ERight to rectification
Article 16 lets data subjects have inaccurate personal data corrected and incomplete data completed. Its scope is largely unchanged from the Directive…
Lesson · CIPP/ERight to restriction of processing
Article 18 is the GDPR's successor to the Directive's right to 'blocking' - a temporary freezing of data. On listed grounds (accuracy contested, unlawful…
Lesson · CIPP/ERisk reporting and the meaning of 'personal data breach'
Article 33 requires notifying the regulator and Article 34 requires communicating to data subjects - both only where there is risk (or high risk) to…
Lesson · CIPP/ERoles of the parties: controller and processor
In a typical outsourcing deal the customer is the controller and the supplier is the processor. A controller determines the purposes and means of…
Lesson · CIPP/EScope of data transfers - what counts as a transfer
The GDPR does not define 'transfer'. A key distinction is that a transfer is not the same as mere transit: it is the processing in the third country that…
Lesson · CIPP/ESearch engines and the right to be forgotten
Search engines process IP addresses, cookies, user log files and third-party webpages (which they crawl and index). In Google Spain, the CJEU held a…
Lesson · CIPP/ESecurity principle and the risk-based approach (Article 32)
Article 5(1)(f) sets the security principle ('integrity and confidentiality'); Article 32 expands on it, requiring appropriate technical and…
Lesson · CIPP/ESelf-regulation: accountability, DPOs, codes and certification
Self-regulation is arguably the most effective tool because controllers and processors directly control the measures protecting data. The GDPR advances it…
Lesson · CIPP/ESensitive data - Article 9 framework
Article 9 prohibits processing of special-category data unless an exception applies. The categories are: racial/ethnic origin, political opinions…
Lesson · CIPP/ESetting fines, guidelines and the Law Enforcement Directive
The WP29 (adopted by the EDPB) and the EDPB's 2022 guidelines steer how fines are calculated. A fine is not a mere mathematical exercise. Minor…
Lesson · CIPP/ESituations requiring additional information
Beyond Articles 13/14, the GDPR triggers extra information duties in specific situations, whether or not the data came from the subject: data subject…
Lesson · CIPP/ESocial media: legal basis, special category data, children
SMP processing needs an Article 6 basis, and Article 9 applies to special category data. One Art 9 route is data manifestly made public by the data…
Lesson · CIPP/ESocial media: roles, joint controllership, transparency
Social media platforms (SMPs) collect data users provide, observe, and infer/predict. The SMP is a controller. The pivotal case is Wirtschaftsakademie…
Lesson · CIPP/ESpecial Categories of Personal Data
Article 9 identifies special categories (sensitive) of personal data needing extra protection because their processing risks individuals' fundamental…
Lesson · CIPP/ESpecific, informed & unambiguous consent
Consent must be specific to the operation (purpose specification guards against function creep), informed (language the average person understands, not…
Lesson · CIPP/EStorage limitation
Storage limitation (Article 5(1)(e)) means personal data must not be kept longer than necessary for the purpose; once no longer needed, it must be…
Lesson · CIPP/EStorage of personnel records
Personnel records span recruitment, sick leave, medical insurance, salary, appraisals, evaluations and severance. They must not be kept longer than…
Lesson · CIPP/ESubcontracting conditions
Where outsourcing forms a chain, Articles 28(2) and (4) set conditions on engaging a sub-processor. The customer must give prior specific or general…
Lesson · CIPP/ESuppliers as controllers, AI, and chains of processors
A supplier that goes beyond its mandate and acquires a real role in determining the purposes or essential means of processing becomes a controller in its…
Lesson · CIPP/ETargeted online advertising: ecosystem and law
Most free internet services are funded by targeted online advertising, which builds profiles and routes ads to people who meet criteria. The adtech…
Lesson · CIPP/ETelephone marketing
Telemarketing is digital marketing, so both the GDPR and ePrivacy apply. For live person-to-person calls, Art 13(3) lets member states choose opt-in or…
Lesson · CIPP/EThe Article 5 principles overview
Chapter 6 covers the data processing principles now expressly listed in Article 5 of the GDPR. These principles did not start with the GDPR: they were…
Lesson · CIPP/EThe data protection officer (DPO)
Not every company needs a DPO, but Article 37 makes one mandatory in three cases: a public authority; where core activities consist of regular and…
Lesson · CIPP/EThe Five Building Blocks of 'Controller'
EDPB Guidelines 07/2020 break 'controller' into five building blocks: the person/body; 'determines'; 'alone or jointly with others'; 'the purposes and…
Lesson · CIPP/EThe General Data Protection Regulation (GDPR)
The GDPR is a directly applicable regulation with 173 recitals and 99 articles in eleven chapters. Unlike the Directive it binds processors directly…
Lesson · CIPP/EThe General Data Protection Regulation
The Directive could not keep pace with technology and globalisation, so the Commission proposed the GDPR in January 2012. It entered into force May 2016…
Lesson · CIPP/EThe general restriction on transfers outside the EEA
The GDPR lets personal data flow freely between member states, but transfers to any country outside the EEA are restricted. A transfer to a third country…
Lesson · CIPP/EThe NIS Directive (and NIS 2)
The original NIS Directive advanced EU cybersecurity and complemented the GDPR. NIS2, Directive (EU) 2022/2555, replaced that regime from 18 October 2024…
Lesson · CIPP/EThe Processor and the Article 28 Contract
A processor is a separate legal entity that processes personal data on behalf of a controller. Two building blocks: (1) separate legal entity, (2)…
Lesson · CIPP/EThe under-250-employees records exemption
There is an exemption from the Article 30 record-keeping duty for companies with fewer than 250 people. But it is heavily caveated and the chapter says it…
Lesson · CIPP/EThe United States - Privacy Shield, Schrems II and the Data Privacy Framework
Privacy Shield replaced Safe Harbor (adequacy decision 12 July 2016, in force 1 August 2016) with seven strengthened principles and extra safeguards. The…
Lesson · CIPP/EThe United States - Safe Harbor, Snowden and Schrems I
Safe Harbor (Commission decision 26 July 2000) was a self-certification framework treated as adequate for EU-US transfers. Criticised for weak…
Lesson · CIPP/ETransparency, AUPs and covert monitoring
Transparency both meets the notice requirement and sets expectations: employees told in advance that use is monitored have less scope to claim they didn't…
Lesson · CIPP/ETransparency principle
The first GDPR processing principle is that personal data must be processed lawfully, fairly and in a transparent manner. Transparency means being open…
Lesson · CIPP/ETransparent communication and the right to information
Transparency underpins the whole system: individuals cannot protect their privacy if they are not properly informed. Article 12(1) requires information to…
Lesson · CIPP/ETreaty of Lisbon
The Treaty of Lisbon was signed 13 December 2007 and took effect 1 December 2009. It amends the EU's two core treaties, renaming one the TFEU. Article…
Lesson · CIPP/EVideo surveillance (CCTV): lawful basis and proportionality
CCTV that captures images identifying people is processing personal data and must comply with the GDPR and, if applicable, the LED. The usual lawful basis…
Lesson · CIPP/EWhen information must be provided (timing)
Timing is one of the key practical differences between the two Articles. Under Article 13 the information must be given at the time the personal data are…
Lesson · CIPP/EWhistleblowing schemes
Whistleblowing lets employees report illegal or improper activity with privacy safeguards. SOX (2002) drove their prominence and reaches EU subsidiaries…
Lesson · CIPP/EWhy consent is problematic at work
Consent looks easy but should be a measure of last resort. Valid consent must be freely given, specific, informed and unambiguous - and the imbalance of…
Lesson · CIPP/EWorkplace monitoring: principles, background checks, DLP
An employee does not lose their right to privacy at work; their private sphere is protected but balanced against the employer's right to run its business…
Lesson · CIPP/EWorks councils
Works councils represent employees and have rights under local law over how employee data is used; they often must safeguard employees' data protection…
Guide · CIPP/EWhat is location data under the GDPR?
A practical GDPR guide to GPS, IP-address, mobile-network and inferred location data, with Article 4, legal-basis and DPIA exam points.
Looking for AI governance? Explore the AIGP study guide.