← All exams
Home · Certified Information Privacy Professional/Europe (CIPP/E)

Certified Information Privacy Professional/Europe (CIPP/E)

This certification is designed for professionals who use, process, and manage personal data within Europe and must understand and apply GDPR regulations. It validates a comprehensive understanding of pan-European and national data protection laws, key privacy terminology, and practical concepts concerning the protection of personal data and trans-border data flows.

Pass mark 63/90 150 minutes Real test fee approx $550 USD International Association of Privacy Professionals (IAPP) How many can I get wrong?
Don't cram it, drill it. Ten questions a topic beats an hour re-reading.
Free practice questions
Try 3 real Certified Information Privacy Professional/Europe (CIPP/E) questions
Have a go, then reveal the worked explanation. A taster from a bank of 206 original questions — unlock for unlimited drills and full timed mocks.
Q1. Under Article 3 of the GDPR (Territorial Scope), the regulation applies to a data controller that is not established in the Union, but is processing the personal data of data subjects who are in the Union. Which condition must be met for this to apply?
  • A.  The processing relates to offering goods or services to data subjects in the Union.
  • B.  The controller is a citizen of a Member State.
  • C.  The data is stored on servers located within the EU.
  • D.  The processing activity is for more than 5,000 data subjects.
Show answer & explanation
✓ Answer: A. The processing relates to offering goods or services to data subjects in the Union.
Article 3(2) establishes extraterritorial scope, applying the GDPR to non-EU controllers when their processing activities are related to offering goods/services to or monitoring the behavior of individuals in the EU.
Q2. A company collected customer data for processing online orders. It now wants to use this data for marketing new products. According to the 'purpose limitation' principle, what is the primary consideration before proceeding?
  • A.  Whether the new purpose is compatible with the original purpose of processing orders
  • B.  Whether the data is still accurate and up-to-date for marketing
  • C.  Whether the data is stored in an encrypted format
  • D.  Whether the original data was collected less than one year ago
Show answer & explanation
✓ Answer: A. Whether the new purpose is compatible with the original purpose of processing orders
The purpose limitation principle (Art. 5(1)(b)) requires that data is not further processed in a manner incompatible with the original purpose. The compatibility of the new purpose must be assessed.
Q3. A controller is processing data based on 'legitimate interests'. What information related to this legal basis must be provided in the privacy notice under Articles 13 and 14?
  • A.  A full copy of the Legitimate Interests Assessment (LIA).
  • B.  The name of the person who approved the LIA.
  • C.  The legitimate interests pursued by the controller or by a third party.
  • D.  A declaration that the legitimate interests outweigh the data subject's rights.
Show answer & explanation
✓ Answer: C. The legitimate interests pursued by the controller or by a third party.
Articles 13(1)(d) and 14(2)(b) require that where processing is based on legitimate interests, the controller must specify what those legitimate interests are in the information provided.
Start here
Ten questions to see where you stand
Two minutes, no timer, marked the moment you finish with every answer explained. Then you'll know which topics need the work before you sit a full mock.
Exam mode
Full mock exam
90 random questions, real timing, marked against the official pass mark. Different every time.
Create a free account for a full mock
No card needed. A free account unlocks a full timed mock and 3 drills on every exam.
Practice material only. This is revision practice, not official training, assessment or certification, and not a substitute for the required course or supervised experience. Always confirm the current requirements with the official awarding body or test provider before relying on it.
Try it free
Topic drills
Ten quick questions on one topic, marked instantly with explanations.
1 free drill left — then a free account unlocks 3 + a full mock.
European Data Protection Law and Regulation · 30
Principles and Lawful Bases for Processing · 30
Transparency and Information Provision to Data Subjects · 28
Data Subjects' Rights · 30
Accountability · 30
International Data Transfers · 19
Security of Processing and Data Breach Notification · 20
Supervision and Enforcement · 19
Certified Information Privacy Professional/Europe (CIPP/E) — common questions
Frequently asked
How many questions are in the Certified Information Privacy Professional/Europe (CIPP/E)?
The exam has 90 questions. Every Revision Robin mock uses the same 90-question format so your practice matches the real thing.
What is the pass mark for the Certified Information Privacy Professional/Europe (CIPP/E)?
You need 63 out of 90 correct to pass, which is about 70%. Our mocks mark you against this exact threshold.
How long do you get?
The test is timed at 150 minutes. Our full mock runs on the same clock so you can practise your pacing.
Are these the real exam questions?
No. Our questions are original and written to match the current syllabus, so they give realistic practice without copying the official paper. Every answer comes with a plain-English explanation. Always confirm current rules and content with International Association of Privacy Professionals (IAPP).
How much does the official test cost?
The official International Association of Privacy Professionals (IAPP) fee is approx $550 USD. Revision Robin practice is separate and helps you pass first time so you only pay that fee once.