For CIPP/E preparation, you need a minimum of 200–300 practice questions calibrated to actual exam domain weights: ~30% in Domain 3 (compliance), ~26% in Domain 1 (law and regulation), ~18% in Domain 2 (institutions), ~16% in Domain 4 (processing activities), and ~10% in Domain 5 (security). Question quality matters more than volume — a bank that only marks right/wrong without explaining why wrong options were wrong teaches you the right answer to that question, not the reasoning pattern for similar questions on the actual exam.
Most CIPP/E candidates studying in 2026 will encounter some version of this question: "How many practice questions do I need, and how do I know if they're actually representative of the exam?" This guide answers that — including what the actual exam tests at domain level, what makes a question bank genuinely useful for preparation vs. merely reassuring, and 7 example questions that demonstrate the format and difficulty of real exam scenarios.
Figure 1 — CIPP/E domain weights. Your question bank should reflect these proportions.
What the CIPP/E Actually Tests — Domain by Domain
The CIPP/E (Certified Information Privacy Professional / Europe) is the IAPP's EU privacy law certification. It tests knowledge of European data protection law and the ability to apply it to real organizational scenarios. The exam is 90 questions, 150 minutes, scored 100–500 (passing: 300).
Domain 1: European Data Protection Law and Regulation (~26%)
Domain 1 covers the legal and regulatory framework: the history and development of EU data protection law, GDPR structure and key provisions, ePrivacy Directive (and proposed Regulation), and the interaction between data protection and other EU legal frameworks.
Key exam topics:
- GDPR scope: material scope (Article 2) — what processing activities are covered; territorial scope (Article 3) — when GDPR applies to non-EU organizations (the establishment criterion vs. the targeting/monitoring criterion)
- Core definitions: personal data (any information relating to an identified or identifiable natural person — know what makes data identifiable); processing (broad — covers collection, storage, retrieval, disclosure, erasure, and more); controller (determines purposes and means); processor (processes on behalf of controller); data subject (the natural person the data relates to)
- The 6 lawful bases for processing (Article 6): consent; contract performance; legal obligation; vital interests; public task; legitimate interests — know the conditions and limitations of each
- Special categories of data (Article 9): racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic data, biometric data (for ID purposes), health data, sex life or sexual orientation data — know the 10 processing conditions that can override the general prohibition
- ePrivacy Directive: cookies and consent; electronic direct marketing; confidentiality of communications — frequently tested alongside GDPR in multi-layer scenarios
Domain 2: European Data Protection Institutions (~18%)
Domain 2 covers the supervisory architecture: national Data Protection Authorities (DPAs), the European Data Protection Board (EDPB), the European Data Protection Supervisor (EDPS), and enforcement mechanisms.
Key exam topics:
- DPA powers under GDPR Article 58: investigative powers (access to premises, access to data); corrective powers (warnings, reprimands, bans on processing, fines); advisory powers (opinions, consultations). Know which power applies in which scenario.
- One-stop-shop mechanism: a controller with an EU main establishment is supervised primarily by the DPA in the member state of its main establishment. Other DPAs can be "concerned supervisory authorities" in cross-border cases.
- EDPB: composed of one representative of each national DPA and the EDPS. Issues binding decisions in cross-border disputes; publishes non-binding guidelines and recommendations; issues consistency opinions.
- EDPS: supervises EU institutions and bodies. Not a DPA for private organizations. Advises EU institutions on privacy implications of proposed legislation.
- GDPR fines: two tiers. Lower tier (up to €10M or 2% of global annual turnover, whichever higher): procedural violations, controller/processor obligations, certification body obligations. Higher tier (up to €20M or 4% of global annual turnover): violations of basic principles (Article 5), lawful bases (Article 6), special category conditions (Article 9), data subject rights (Chapter III), international transfers (Chapter V).
Domain 3: European Data Protection Law Compliance (~30% — Largest Domain)
Domain 3 is the most heavily tested domain and the one where operational knowledge matters most. It covers how organizations comply with GDPR requirements in practice: data subject rights, DPIAs, records of processing, international transfers, and data security obligations.
Everything you need to prep for the 2026 CIPP/E, in one place.
Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.
Get the Complete Pack →Key exam topics:
- Data subject rights (Articles 15–22): Right of access (Art. 15); Right to rectification (Art. 16); Right to erasure / right to be forgotten (Art. 17) — know the conditions and exceptions; Right to restriction of processing (Art. 18) — when it applies; Right to data portability (Art. 20) — only applies to consent or contract lawful bases, only to data provided by the data subject; Right to object (Art. 21) — applies to legitimate interest and public task processing; Rights related to automated decision-making (Art. 22).
- International transfers: adequacy decisions (GDPR Article 45); Standard Contractual Clauses (SCCs) — the 2021 modules; Binding Corporate Rules (BCRs) — controller BCRs vs. processor BCRs; derogations (Article 49).
- DPO obligations: when required (Article 37); tasks (Article 39); position and independence (Article 38).
- Security obligations: Article 32 — appropriate technical and organizational measures, risk-based, considering state of the art. Pseudonymization and encryption as examples, not prescriptions.
- Breach notification: Article 33 (to supervisory authority, 72-hour rule); Article 34 (to data subjects, where likely to result in high risk).
Domain 4: Data Processing Activities (~16%)
Domain 4 covers specific high-risk data processing contexts: employee monitoring, direct marketing, CCTV, cloud computing, and big data/AI analytics — applying GDPR principles to each.
Domain 5: Information Security (~10%)
Domain 5 covers security concepts relevant to privacy: encryption, access controls, pseudonymization vs. anonymization, breach detection, and security incident response. This is an overview domain — not an information security certification.
Figure 2 — Quality markers that distinguish a preparation-grade question bank from a low-value one
What Makes a Question Bank Genuinely Useful for CIPP/E Prep
Not all question banks are built equally. The difference between a question bank that prepares you for the exam and one that gives you false confidence comes down to five factors:
1. Scenario-Based Question Format (Not Factual Recall)
The actual CIPP/E exam is scenario-based. A typical question stem describes a real organizational situation — "A UK-based company processes the personal data of EU residents to provide them with subscription services..." — and then asks you to identify the most appropriate lawful basis, or what the company's disclosure obligation is, or whether a DPIA is required. A question bank that asks "What is the GDPR definition of personal data?" tests your ability to read a definition, not your ability to apply it. Real exam questions force application, not recitation.
2. Explanations for Wrong Answers, Not Just Right Ones
The most valuable learning in question bank review happens when you read why the wrong options were wrong — not just why the correct option was correct. A question bank that only tells you "Correct! The answer is C" teaches you the answer to that question. A question bank that explains "Option A is incorrect because Article 6(1)(b) applies to processing necessary for a contract the data subject is a party to — processing for internal analytics is not necessary for contract performance" teaches you the reasoning pattern that applies across dozens of similar questions.
3. Domain Weight Calibration
The actual exam distributes questions roughly in proportion to domain weights. A question bank over-weighted toward Domain 1 (legal provisions) while underweighting Domain 3 (compliance scenarios) will leave you under-practiced on the question types that appear most frequently. Before committing to a question bank, check whether the domain distribution is explicitly disclosed.
4. Updated for Current Enforcement Reality
GDPR has been enforced actively since 2018. Questions about international transfer mechanisms must reflect the 2021 SCCs (the old 2010 SCCs are no longer valid). Questions about fines should reflect actual enforcement precedent. A question bank written in 2019 that has not been updated will have outdated transfer mechanism questions and may not reflect the current EDPB guidance on legitimate interest balancing tests.
5. Plausible Distractors (The Wrong Options Must Feel Plausible)
On the actual CIPP/E, wrong answer choices are designed to look correct if you haven't understood the precise distinction the question is testing. A question about whether right to data portability applies to a given scenario should have distractors that test your understanding of portability's specific conditions (consent or contract basis; data provided by the data subject; technically feasible) — not obviously wrong options that anyone with basic knowledge would eliminate. A question bank with obviously wrong distractors builds false confidence.
How Many Practice Questions Do You Need?
| Preparation stage | Questions needed | How to use them |
|---|---|---|
| Early-phase diagnostic (first 2 weeks) | 50–75 questions | One domain-specific set per domain to identify knowledge gaps. Don't worry about scores — this is diagnostic. Read every explanation regardless of whether you got it right. |
| Mid-phase domain practice (weeks 3–6) | 150–200 questions | Targeted domain-by-domain practice, weighted toward D3 and D1. Focus on explanation quality over raw score. Track your hit rate per domain. |
| Late-phase full mock exams (weeks 7–8) | 2–3 full 90-question mock exams | Timed, full exam conditions. Review every wrong answer in detail. Use your domain breakdown to identify final-week priorities. |
| Final week cram | 40–60 targeted questions on weak domains | Targeted on the 1–2 domains where your mock exam score was lowest. Full explanation review. Not volume — precision. |
| Total (minimum) | 250–330 questions | With full explanation review — not just score tracking |
7 Exam-Style CIPP/E Practice Questions
These questions reflect the format, difficulty, and application-focus of actual CIPP/E exam questions.
A company incorporated in the United States operates a mobile app used by consumers in France, Germany, and Poland. The app tracks users' location data and purchase behaviour to deliver targeted advertising. The company has no office, subsidiary, or employees in the EU. Does GDPR apply to this company's processing of EU residents' data?
An e-commerce company wants to send promotional emails about similar products to existing customers who have previously purchased from them and have not opted out of marketing. The company's legal team argues that legitimate interests (Article 6(1)(f)) is the appropriate lawful basis. Which additional rule must the company satisfy for this email marketing to be lawful under EU law?
An individual requests erasure of all their personal data from a financial services company under GDPR Article 17. The company has processed their data to fulfil a loan agreement that is now complete. The company argues it must retain certain transaction records for 7 years under financial services regulatory obligations. Which of the following most accurately describes the company's position?
Everything you need to prep for the 2026 CIPP/E, in one place.
Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.
Get the Complete Pack →A German company (Controller) wants to transfer personal data to its US-based parent company for HR management purposes. The US parent will act as a processor. Which of the 2021 Standard Contractual Clause (SCC) modules applies to this transfer?
A private employer in France wants to process employees' health data to manage a sick leave programme — specifically to verify sick leave claims by requesting doctor's certificates. The processing is necessary to administer employment contracts. Which of the following represents the most appropriate legal basis for this processing?
A national DPA investigates a controller and determines that the controller has been collecting more personal data than is necessary for the stated purpose (data minimisation violation). The DPA wants to stop the over-collection immediately while the full investigation continues. Which DPA power under GDPR Article 58 should the DPA exercise?
An individual requests that a fitness app transmit their historical workout data directly to a competing fitness service in a machine-readable format. The fitness app processes the workout data on the basis of legitimate interests (Article 6(1)(f)). Which of the following is correct regarding this portability request?
The Single Biggest Question Bank Mistake CIPP/E Candidates Make
Tracking their score instead of studying the explanations. A candidate who does 400 questions and checks right/wrong without reading explanations will plateau. A candidate who does 200 questions and reads every explanation — including for the questions they got right — will continue improving. The question bank is not a testing tool. It's a teaching tool. Use it that way.
Frequently Asked Questions
How many questions are on the actual CIPP/E exam?
90 multiple-choice questions, 4 options each, one correct answer. 150 minutes. No partial credit. Passing score: 300 on a 100–500 scaled score (roughly 65–70% correct, though scaled scoring means this isn't a fixed percentage).
Are there free CIPP/E practice questions available?
Yes — IAPP provides a small number of sample questions in its exam preparation resources. However, the free samples are limited in number and don't provide full explanation coverage. They're useful for understanding exam format but not sufficient for full preparation. Third-party providers like Archuz offer full question banks (300+) with detailed explanations calibrated to current domain weights.
Do CIPP/E practice questions expire when GDPR changes?
The GDPR text itself has not been substantially amended since it became applicable in May 2018 — the core provisions tested on the exam are stable. However, the enforcement environment evolves: EDPB guidance, CJEU rulings (especially Schrems II and its aftermath), and DPA enforcement priorities can affect exam content. A question bank that was last updated in 2019 may have outdated international transfer questions (reflecting the old SCCs rather than the 2021 replacement). Check when a question bank was last updated before purchasing.
What score should I aim for on practice exams before sitting the CIPP/E?
Consistently scoring 72–75% or above on full mock exams under timed conditions is generally considered a reliable indicator of readiness. Candidates who enter the exam consistently scoring below 65% on mocks are at elevated risk of failure. Note that practice exam scores aren't directly comparable to the scaled exam score — use mock scores as directional indicators, not precise predictions.