Quick answer

Four GDPR areas cause a disproportionate share of CIPP/E failures: lawful basis selection (especially legitimate interest vs. consent), controller/processor vs. joint controller classification, Article 22 automated decision-making, and the international transfer mechanism hierarchy. These are not the hardest topics to learn — but they require applied reasoning, not memorization, and most study materials don't give them enough scenario practice.

The CIPP/E exam does not ask you to recite the GDPR. It gives you a situation and asks what the GDPR requires. That distinction matters most for the concepts where candidates most often pick a plausible wrong answer — not because they don't know the rule, but because they apply it incorrectly when the facts get specific.

This article focuses on the four GDPR mechanics that generate the most exam errors, with worked scenarios showing how the exam frames each concept and why the wrong answers are wrong.

1. Lawful Basis Selection — The Most Tested Concept on the Exam

The six lawful bases under Article 6(1) are not interchangeable. Each has specific conditions, and the exam tests whether you can select the correct one for a given scenario — and whether you know when a claimed basis does not actually apply.

Lawful BasisWhen It AppliesKey Constraint
Consent (a)Freely given, specific, informed, unambiguous indication of agreementCannot be bundled, pre-ticked, or made a condition of service unless processing is necessary for that service
Contract (b)Processing necessary to perform a contract with the data subject, or pre-contractual steps at their request"Necessary" is strict — processing must be genuinely required, not merely convenient
Legal obligation (c)Processing necessary to comply with a law the controller is subject toMust be an actual legal obligation — internal policies don't count
Vital interests (d)Protecting life where the data subject cannot consentNarrow — can't be used when the subject can consent
Public task (e)Official authority or public interest task established in lawPrimarily for public sector bodies
Legitimate interests (f)Genuine interest of controller or third party that isn't overridden by subject's rightsRequires Legitimate Interests Assessment; unavailable for special category data; cannot be used by public authorities for public functions

The most common exam error: choosing legitimate interest as the answer when contract or consent would actually be more appropriate — or vice versa, claiming consent is needed when legitimate interest would suffice. The exam exploits the fact that multiple bases can seem applicable to the same scenario.

Scenario — Lawful Basis

An e-commerce company processes customers' purchase history to send personalised product recommendations. The company argues this is necessary to perform the purchase contract. The marketing team also wants to use the same data for broader behavioural profiling to improve ad targeting across the site.

For purchase history used in the original checkout and order fulfilment:

Correct: Article 6(1)(b) — Contract

Processing purchase history to fulfil the order is genuinely necessary for the contract.

For using purchase history in broad ad-targeting behavioural profiling:

Wrong: Article 6(1)(b) — Contract

Ad targeting is not necessary to perform the purchase contract. The company must identify a separate basis — either consent (for intrusive profiling) or a legitimate interests assessment (for less intrusive analytics, if it passes the balancing test).

The legitimate interest trap. Legitimate interest under Article 6(1)(f) is not a fallback for when consent would be inconvenient. It requires a genuine Legitimate Interests Assessment (LIA) with three components: purpose test (is the interest legitimate?), necessity test (is the processing necessary for that purpose?), and balancing test (does the interest override the subject's rights and freedoms?). The exam will give you scenarios where a company claims legitimate interest and you must assess whether the balancing test actually holds — and it often doesn't.

High-frequency exam point

Legitimate interest can never be used as a lawful basis for processing special category data (Article 9 data). Special categories require both an Article 6(1) lawful basis and an Article 9(2) condition. A question that asks for the lawful basis for processing health data and offers "legitimate interest" as an option is testing whether you know this — and legitimate interest is always wrong there.

2. Controller vs. Processor vs. Joint Controller

Article 4 defines the controller as the entity that determines the purposes and means of processing. The processor processes personal data on behalf of and under the instructions of a controller. The joint controller arrangement under Article 26 applies when two or more controllers jointly determine the purposes and means.

The exam tests the boundary between these roles in scenarios where the relationship is not obvious — and it particularly loves joint controller scenarios, which most candidates underprep.

RoleKey IndicatorRequired Agreement
ControllerDecides why and how data is processedNone required (single controller)
ProcessorProcesses only on documented instructions; cannot decide purposesData Processing Agreement (Art. 28)
Joint ControllerTwo+ entities together decide purposes and/or meansArticle 26 arrangement defining each party's responsibilities
Scenario — Controller Classification

A recruiting platform allows employers to post jobs and review candidate applications. Candidates upload CVs and apply through the platform. The platform stores CV data and provides employers access to applications. The platform also uses aggregated application data to improve its recommendation algorithm.

The employer's relationship to the platform:

Correct: Joint Controllers (Art. 26)

Both the employer and the platform determine the purposes of processing the candidate's application data — the employer to evaluate candidates, the platform to facilitate recruitment. They jointly determine purpose, making them joint controllers for that processing activity.

The platform's use of aggregated data for its algorithm:

Correct: Platform is sole Controller

When the platform uses data for its own algorithm improvement — a purpose the employer does not determine — the platform acts as a sole controller for that specific processing activity.

The processor boundary. A cloud storage vendor that processes data exclusively on the client company's instructions, with no independent access to the data for its own purposes, is a processor. The moment that vendor starts using the data for its own analytics, training, or business purposes — even in aggregate — it has stepped outside the processor role and become a (joint) controller for those purposes. This is a common exam trap.

3. Article 22 — Automated Decision-Making and Profiling

Article 22 is one of the most tested and most misunderstood provisions on the CIPP/E. The core right: data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.

The key word is solely. If a human meaningfully reviews and can override the automated output before a decision is made, Article 22 does not apply. The exam tests whether candidates understand this boundary.

ScenarioArticle 22 Applies?Reason
Bank's algorithm auto-rejects loan application; no human review possibleYesSolely automated, legal effect (credit denial)
HR system scores CVs; recruiter reviews top 20 and makes final selectionNoHuman meaningfully involved in final decision
Insurance pricing algorithm sets premium; agent can override with justificationBorderlineDepends on whether human review is meaningful or rubber-stamp; exam will specify
Ad platform profiles users for targeted adsNoNot a "decision" with legal or similarly significant effects on the user

Where Article 22 does apply, the controller must either rely on one of three narrow lawful bases (explicit consent, contractual necessity, or Union/Member State law authorisation) and provide specific safeguards: the right to obtain human intervention, to express a point of view, and to contest the decision.

Exam distinction

Article 22 and Article 21 (right to object to processing, including profiling) are related but distinct. Article 21 lets subjects object to profiling based on legitimate interest or public task. Article 22 applies to automated decisions with legal or similarly significant effects. A question asking which right applies when someone objects to a scoring algorithm used (but not solely relied upon) for credit decisions is testing this distinction — Article 21, not Article 22.

4. International Transfer Mechanisms — The Hierarchy Matters

Chapter V GDPR restricts transfers of personal data to third countries. The exam tests both what each mechanism requires and which mechanism is appropriate in a given scenario — and critically, the hierarchy in which they apply.

MechanismWhen AvailableKey Condition
Adequacy decision (Art. 45)Country has EU adequacy status (UK, Japan, South Korea, Canada (commercial), others)No additional safeguards needed — transfer is treated as intra-EEA
Standard Contractual Clauses (Art. 46)No adequacy decision; parties can enter SCCsMust use current EC-approved SCCs (2021 version); Transfer Impact Assessment (TIA) recommended
Binding Corporate Rules (Art. 47)Intra-group transfers only; approved by competent DPALengthy approval process; only available to multinationals
Article 49 derogationsNo adequacy, no SCCs possible — narrow specific situationsExplicit consent, contractual necessity, vital interests, public interest — strictly limited, not a general fallback
Scenario — Transfer Mechanisms

A German company uses a US-based cloud services vendor to process employee HR data. No adequacy decision covers the US for this type of data. The vendor is willing to sign any contractual documents the company requires. A data protection officer advises that the company should use an Article 49 derogation based on the employees' consent.

Is the DPO's advice correct?

Wrong — SCCs are available and must be used first

Article 49 derogations are a last resort when no other mechanism is available. Since the vendor is willing to enter into contractual arrangements, SCCs under Article 46 are the appropriate mechanism. Article 49 consent derogations are also problematic for employee data because employment relationships make freely given consent structurally difficult. The exam tests this hierarchy: adequacy → SCCs/BCRs → derogations (narrow and exceptional).

The TIA requirement. Post-Schrems II, simply signing SCCs is not sufficient if the destination country's surveillance laws could undermine the protection the SCCs provide. A Transfer Impact Assessment (TIA) evaluates whether the third country's legal framework allows authorities to access the data in ways that conflict with GDPR standards. While not formally required by GDPR text, EDPB guidance makes TIAs effectively mandatory alongside SCCs for high-risk transfers. The exam references this as contextual knowledge rather than testing TIA mechanics in depth.

How to Practice These Concepts Effectively

Reading about lawful basis and joint controllers builds familiarity but does not build the applied judgment the CIPP/E tests. The practice that actually moves the needle is working through scenario questions — ones where the fact pattern is realistic, the wrong answers are plausible, and the explanation traces exactly why the correct answer is correct.

For each of the four areas above, the specific practice discipline:

  • Lawful basis: Practice identifying which basis applies AND which bases are unavailable. Questions that give you a scenario and ask you to rule out wrong bases are more diagnostic than questions asking you to pick the right one.
  • Controller/processor: For any entity in a processing scenario, ask: does this entity determine purposes? If yes, it is a (joint) controller. If it only processes on another entity's instructions, it is a processor — unless it also processes data for its own purposes, in which case it wears both hats for different processing activities.
  • Article 22: The trigger is always "solely automated" AND "legal or similarly significant effect." If a human meaningfully participates in the decision, the right does not attach — regardless of how much automation is involved in the pipeline.
  • Transfers: Always apply the hierarchy. Is there an adequacy decision? If not, can SCCs or BCRs be used? Only if neither is available or applicable do Article 49 derogations enter the picture — and they are narrow exceptions, not fallback options.

Everything you need to prep for the 2026 CIPP/E, in one place.

Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.

Get the Complete Pack →

What Else Shows Up on the CIPP/E

The four concepts above are the highest-failure areas, but they are not the complete exam. The CIPP/E also tests:

  • Special category data (Article 9): The 10 conditions under Article 9(2), which categories are included (and notably, which are not — criminal conviction data is Article 10, not Article 9), and what processing special categories requires beyond an Article 6 lawful basis.
  • Data subject rights in context: Not just what each right is, but when it does not apply. The right to erasure has six grounds and six exceptions under Article 17(3). The right to portability applies only to automated processing based on consent or contract — not to all personal data. The exam tests the conditions and the limits.
  • DPO appointment: Which organisations must appoint a DPO (Article 37), what the DPO does (Article 38–39), and the independence requirements — the DPO cannot be dismissed for performing their tasks and must have direct access to the highest management level.
  • Breach notification: Article 33 (72-hour DPA notification when there is a risk to rights and freedoms) vs. Article 34 (individual notification when the risk is high). The exam tests the thresholds and the documentation obligation that exists even when notification is not required.

For the full domain-weighted breakdown of exam topics and how to allocate your study time, see the CIPP/E 2026 exam format guide and the CIPP/E pass rate and difficulty assessment.