Quick Answer

For CIPP/E preparation, you need a minimum of 200–300 practice questions calibrated to actual exam domain weights: ~30% in Domain 3 (compliance), ~26% in Domain 1 (law and regulation), ~18% in Domain 2 (institutions), ~16% in Domain 4 (processing activities), and ~10% in Domain 5 (security). Question quality matters more than volume — a bank that only marks right/wrong without explaining why wrong options were wrong teaches you the right answer to that question, not the reasoning pattern for similar questions on the actual exam.

Most CIPP/E candidates studying in 2026 will encounter some version of this question: "How many practice questions do I need, and how do I know if they're actually representative of the exam?" This guide answers that — including what the actual exam tests at domain level, what makes a question bank genuinely useful for preparation vs. merely reassuring, and 7 example questions that demonstrate the format and difficulty of real exam scenarios.

CIPP/E Domain Weights — Question Bank Distribution D1 European Data Protection Law & Regulation ~26% D2 European Data Protection Institutions ~18% D3 European Data Protection Law Compliance ~30% ★ D4 Data Processing Activities ~16% D5 Information Security ~10% 0% 10% 20% 30%

Figure 1 — CIPP/E domain weights. Your question bank should reflect these proportions.

What the CIPP/E Actually Tests — Domain by Domain

The CIPP/E (Certified Information Privacy Professional / Europe) is the IAPP's EU privacy law certification. It tests knowledge of European data protection law and the ability to apply it to real organizational scenarios. The exam is 90 questions, 150 minutes, scored 100–500 (passing: 300).

Domain 1: European Data Protection Law and Regulation (~26%)

Domain 1 covers the legal and regulatory framework: the history and development of EU data protection law, GDPR structure and key provisions, ePrivacy Directive (and proposed Regulation), and the interaction between data protection and other EU legal frameworks.

Key exam topics:

  • GDPR scope: material scope (Article 2) — what processing activities are covered; territorial scope (Article 3) — when GDPR applies to non-EU organizations (the establishment criterion vs. the targeting/monitoring criterion)
  • Core definitions: personal data (any information relating to an identified or identifiable natural person — know what makes data identifiable); processing (broad — covers collection, storage, retrieval, disclosure, erasure, and more); controller (determines purposes and means); processor (processes on behalf of controller); data subject (the natural person the data relates to)
  • The 6 lawful bases for processing (Article 6): consent; contract performance; legal obligation; vital interests; public task; legitimate interests — know the conditions and limitations of each
  • Special categories of data (Article 9): racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic data, biometric data (for ID purposes), health data, sex life or sexual orientation data — know the 10 processing conditions that can override the general prohibition
  • ePrivacy Directive: cookies and consent; electronic direct marketing; confidentiality of communications — frequently tested alongside GDPR in multi-layer scenarios

Domain 2: European Data Protection Institutions (~18%)

Domain 2 covers the supervisory architecture: national Data Protection Authorities (DPAs), the European Data Protection Board (EDPB), the European Data Protection Supervisor (EDPS), and enforcement mechanisms.

Key exam topics:

  • DPA powers under GDPR Article 58: investigative powers (access to premises, access to data); corrective powers (warnings, reprimands, bans on processing, fines); advisory powers (opinions, consultations). Know which power applies in which scenario.
  • One-stop-shop mechanism: a controller with an EU main establishment is supervised primarily by the DPA in the member state of its main establishment. Other DPAs can be "concerned supervisory authorities" in cross-border cases.
  • EDPB: composed of one representative of each national DPA and the EDPS. Issues binding decisions in cross-border disputes; publishes non-binding guidelines and recommendations; issues consistency opinions.
  • EDPS: supervises EU institutions and bodies. Not a DPA for private organizations. Advises EU institutions on privacy implications of proposed legislation.
  • GDPR fines: two tiers. Lower tier (up to €10M or 2% of global annual turnover, whichever higher): procedural violations, controller/processor obligations, certification body obligations. Higher tier (up to €20M or 4% of global annual turnover): violations of basic principles (Article 5), lawful bases (Article 6), special category conditions (Article 9), data subject rights (Chapter III), international transfers (Chapter V).

Domain 3: European Data Protection Law Compliance (~30% — Largest Domain)

Domain 3 is the most heavily tested domain and the one where operational knowledge matters most. It covers how organizations comply with GDPR requirements in practice: data subject rights, DPIAs, records of processing, international transfers, and data security obligations.

Everything you need to prep for the 2026 CIPP/E, in one place.

Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.

Get the Complete Pack →

Key exam topics:

  • Data subject rights (Articles 15–22): Right of access (Art. 15); Right to rectification (Art. 16); Right to erasure / right to be forgotten (Art. 17) — know the conditions and exceptions; Right to restriction of processing (Art. 18) — when it applies; Right to data portability (Art. 20) — only applies to consent or contract lawful bases, only to data provided by the data subject; Right to object (Art. 21) — applies to legitimate interest and public task processing; Rights related to automated decision-making (Art. 22).
  • International transfers: adequacy decisions (GDPR Article 45); Standard Contractual Clauses (SCCs) — the 2021 modules; Binding Corporate Rules (BCRs) — controller BCRs vs. processor BCRs; derogations (Article 49).
  • DPO obligations: when required (Article 37); tasks (Article 39); position and independence (Article 38).
  • Security obligations: Article 32 — appropriate technical and organizational measures, risk-based, considering state of the art. Pseudonymization and encryption as examples, not prescriptions.
  • Breach notification: Article 33 (to supervisory authority, 72-hour rule); Article 34 (to data subjects, where likely to result in high risk).

Domain 4: Data Processing Activities (~16%)

Domain 4 covers specific high-risk data processing contexts: employee monitoring, direct marketing, CCTV, cloud computing, and big data/AI analytics — applying GDPR principles to each.

Domain 5: Information Security (~10%)

Domain 5 covers security concepts relevant to privacy: encryption, access controls, pseudonymization vs. anonymization, breach detection, and security incident response. This is an overview domain — not an information security certification.

What Separates Good vs. Poor CIPP/E Question Banks ✓ High-Quality Question Bank ✗ Low-Quality Question Bank • Scenario-based stems (not true/false) • Explains WHY wrong answers are wrong • Updated for GDPR 2024+ enforcement • Domain weight proportions match exam • Tests application, not definition recall • Plausible distractors (not obvious traps) • Cites GDPR article in explanation • Factual recall questions only • Only marks right/wrong — no explanation • Based on pre-2022 exam format • Over-weighted toward one domain • Tests whether you can find the article • Obviously wrong distractors • No article citation in explanation

Figure 2 — Quality markers that distinguish a preparation-grade question bank from a low-value one

What Makes a Question Bank Genuinely Useful for CIPP/E Prep

Not all question banks are built equally. The difference between a question bank that prepares you for the exam and one that gives you false confidence comes down to five factors:

1. Scenario-Based Question Format (Not Factual Recall)

The actual CIPP/E exam is scenario-based. A typical question stem describes a real organizational situation — "A UK-based company processes the personal data of EU residents to provide them with subscription services..." — and then asks you to identify the most appropriate lawful basis, or what the company's disclosure obligation is, or whether a DPIA is required. A question bank that asks "What is the GDPR definition of personal data?" tests your ability to read a definition, not your ability to apply it. Real exam questions force application, not recitation.

2. Explanations for Wrong Answers, Not Just Right Ones

The most valuable learning in question bank review happens when you read why the wrong options were wrong — not just why the correct option was correct. A question bank that only tells you "Correct! The answer is C" teaches you the answer to that question. A question bank that explains "Option A is incorrect because Article 6(1)(b) applies to processing necessary for a contract the data subject is a party to — processing for internal analytics is not necessary for contract performance" teaches you the reasoning pattern that applies across dozens of similar questions.

3. Domain Weight Calibration

The actual exam distributes questions roughly in proportion to domain weights. A question bank over-weighted toward Domain 1 (legal provisions) while underweighting Domain 3 (compliance scenarios) will leave you under-practiced on the question types that appear most frequently. Before committing to a question bank, check whether the domain distribution is explicitly disclosed.

4. Updated for Current Enforcement Reality

GDPR has been enforced actively since 2018. Questions about international transfer mechanisms must reflect the 2021 SCCs (the old 2010 SCCs are no longer valid). Questions about fines should reflect actual enforcement precedent. A question bank written in 2019 that has not been updated will have outdated transfer mechanism questions and may not reflect the current EDPB guidance on legitimate interest balancing tests.

5. Plausible Distractors (The Wrong Options Must Feel Plausible)

On the actual CIPP/E, wrong answer choices are designed to look correct if you haven't understood the precise distinction the question is testing. A question about whether right to data portability applies to a given scenario should have distractors that test your understanding of portability's specific conditions (consent or contract basis; data provided by the data subject; technically feasible) — not obviously wrong options that anyone with basic knowledge would eliminate. A question bank with obviously wrong distractors builds false confidence.

How Many Practice Questions Do You Need?

Preparation stageQuestions neededHow to use them
Early-phase diagnostic (first 2 weeks)50–75 questionsOne domain-specific set per domain to identify knowledge gaps. Don't worry about scores — this is diagnostic. Read every explanation regardless of whether you got it right.
Mid-phase domain practice (weeks 3–6)150–200 questionsTargeted domain-by-domain practice, weighted toward D3 and D1. Focus on explanation quality over raw score. Track your hit rate per domain.
Late-phase full mock exams (weeks 7–8)2–3 full 90-question mock examsTimed, full exam conditions. Review every wrong answer in detail. Use your domain breakdown to identify final-week priorities.
Final week cram40–60 targeted questions on weak domainsTargeted on the 1–2 domains where your mock exam score was lowest. Full explanation review. Not volume — precision.
Total (minimum)250–330 questionsWith full explanation review — not just score tracking

7 Exam-Style CIPP/E Practice Questions

These questions reflect the format, difficulty, and application-focus of actual CIPP/E exam questions.

Practice Question 1 — Territorial Scope / GDPR Article 3

A company incorporated in the United States operates a mobile app used by consumers in France, Germany, and Poland. The app tracks users' location data and purchase behaviour to deliver targeted advertising. The company has no office, subsidiary, or employees in the EU. Does GDPR apply to this company's processing of EU residents' data?

  • A. No — GDPR only applies to companies with a legal establishment in the EU
  • B. Yes — GDPR applies because the company is targeting data subjects in the EU (Article 3(2)(a))
  • C. Yes — GDPR applies because the data is stored on servers located in the EU
  • D. No — GDPR only applies to data collected within EU member state borders
Answer: B. Article 3(2) extends GDPR's territorial scope to non-EU controllers that offer goods or services to data subjects in the EU (targeting criterion). The app is available to, and tracks, consumers in France, Germany, and Poland — this is squarely the targeting scenario Article 3(2)(a) was designed to capture. A is wrong because Article 3(2) expressly covers non-EU establishments. C is wrong — data storage location is not the basis for GDPR's territorial scope. D is incorrect — there is no geographic restriction on where data must be collected; it's about where the data subjects are located.
Practice Question 2 — Lawful Basis / Legitimate Interests

An e-commerce company wants to send promotional emails about similar products to existing customers who have previously purchased from them and have not opted out of marketing. The company's legal team argues that legitimate interests (Article 6(1)(f)) is the appropriate lawful basis. Which additional rule must the company satisfy for this email marketing to be lawful under EU law?

  • A. Explicit consent from each customer is required before sending the emails
  • B. Every email must include a clear and easy opt-out mechanism
  • C. A legitimate interests assessment (LIA) is required — and the interest must not be overridden by data subjects' rights
  • D. Registration of the processing activity with the national DPA is required before proceeding
Answer: B — but this question tests two layers. For the email marketing itself, the ePrivacy Directive (soft opt-in rule) requires: (1) the customer's email was collected in the context of a sale; (2) the marketing is for similar products/services; (3) the customer was given the opportunity to opt out at the time of collection and in every subsequent message. If those conditions are met, consent is not required for the email channel. C is also technically required for a valid legitimate interests basis under GDPR — but the more immediate rule in this direct marketing context is the soft opt-in under ePrivacy. In exam scenarios involving email marketing to existing customers, the ePrivacy soft opt-in rule and the opt-out mechanism in every message (B) are the testable operational requirements. A is wrong — soft opt-in does not require explicit consent. D is wrong — most GDPR processing does not require DPA registration.
Practice Question 3 — Data Subject Rights / Right to Erasure

An individual requests erasure of all their personal data from a financial services company under GDPR Article 17. The company has processed their data to fulfil a loan agreement that is now complete. The company argues it must retain certain transaction records for 7 years under financial services regulatory obligations. Which of the following most accurately describes the company's position?

  • A. Immediate erasure of all data is required — the right to erasure is absolute with no exceptions
  • B. Data required for legal compliance obligations may be retained; any data beyond that must be erased
  • C. All data can be retained — completing a contract is a permanent override of the erasure right
  • D. Explicit consent from the individual is needed to retain data beyond the original loan term
Answer: B. The right to erasure under Article 17 is not absolute. Article 17(3) lists exceptions — including where processing is necessary for compliance with a legal obligation (Article 17(3)(b)). A 7-year regulatory retention obligation is a valid legal obligation exception. However, the exception only covers the data that is actually required for regulatory compliance — data held beyond what the legal obligation requires must still be erased. The company cannot use the retention obligation as a blanket shield for all data. A is wrong — the right is not absolute. C is wrong — contract completion does not create a permanent right to retain data indefinitely. D is wrong — consent is not the mechanism for retention under a legal obligation.

Everything you need to prep for the 2026 CIPP/E, in one place.

Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.

Get the Complete Pack →
Practice Question 4 — International Transfers / SCCs

A German company (Controller) wants to transfer personal data to its US-based parent company for HR management purposes. The US parent will act as a processor. Which of the 2021 Standard Contractual Clause (SCC) modules applies to this transfer?

  • A. Module 1 — Controller to Controller
  • B. Module 2 — Controller to Processor
  • C. Module 3 — Processor to Processor
  • D. Module 4 — Processor to Controller
Answer: B — Module 2, Controller to Processor. The German company determines the purposes and means of the HR data processing (it is the controller). The US parent processes the data on behalf of the German company (it is the processor). A cross-border transfer from an EU controller to a non-EU processor uses Module 2. Module 1 (A) would apply if both entities are controllers — e.g., sharing data for each entity's own purposes. Module 3 (C) would apply if an EU processor transfers to a non-EU sub-processor. Module 4 (D) would apply if a non-EU processor sends data back to an EU controller.
Practice Question 5 — Special Categories / Article 9

A private employer in France wants to process employees' health data to manage a sick leave programme — specifically to verify sick leave claims by requesting doctor's certificates. The processing is necessary to administer employment contracts. Which of the following represents the most appropriate legal basis for this processing?

  • A. Article 6(1)(b) (contract performance) + Article 9(2)(b) (employment law obligation)
  • B. Article 6(1)(a) (consent) + Article 9(2)(a) (explicit consent)
  • C. Article 6(1)(c) (legal obligation) alone — GDPR Article 6 is sufficient for health data in employment contexts
  • D. Article 6(1)(f) (legitimate interests) + Article 9(2)(g) (substantial public interest)
Answer: A. Processing health data requires two legal bases simultaneously: an Article 6 lawful basis AND an Article 9(2) exception to the general prohibition on special category processing. For employment-related health data processing, Article 9(2)(b) — "processing is necessary for the purposes of carrying out obligations and exercising specific rights in the field of employment and social security and social protection law" — is typically the appropriate Article 9 exception, combined with Article 6(1)(b) (necessary for contract performance) or Article 6(1)(c) (legal obligation, if sick leave verification is required by national law). B is wrong because consent is generally not appropriate in employment contexts due to the power imbalance between employer and employee — consent cannot be freely given. C is wrong because Article 6 alone never suffices for special category processing. D is wrong because legitimate interest (Article 6(1)(f)) cannot be used by public authorities and is a poor fit for mandatory employment obligations; Article 9(2)(g) applies to substantial public interest contexts, not routine employment administration.
Practice Question 6 — DPA Powers / Corrective Measures

A national DPA investigates a controller and determines that the controller has been collecting more personal data than is necessary for the stated purpose (data minimisation violation). The DPA wants to stop the over-collection immediately while the full investigation continues. Which DPA power under GDPR Article 58 should the DPA exercise?

  • A. Issue a warning that future processing may infringe GDPR
  • B. Impose a temporary or permanent ban on the specific processing operation
  • C. Conduct an on-site audit of the controller's data processing facilities
  • D. Instruct the controller to communicate a personal data breach to affected data subjects
Answer: B. Article 58(2)(f) gives DPAs the corrective power to impose a temporary or permanent limitation including a ban on processing. This is the appropriate tool when the DPA needs to stop an ongoing violation immediately — in this case, ongoing over-collection. A (warning — Article 58(2)(a)) is a milder corrective measure appropriate before a violation is confirmed, not to stop an ongoing confirmed violation. C (audit — Article 58(1)(b)) is an investigative power, not a corrective one — it doesn't stop the processing. D concerns breach communication obligations, which is unrelated to a data minimisation enforcement action.
Practice Question 7 — Data Portability / Article 20 Conditions

An individual requests that a fitness app transmit their historical workout data directly to a competing fitness service in a machine-readable format. The fitness app processes the workout data on the basis of legitimate interests (Article 6(1)(f)). Which of the following is correct regarding this portability request?

  • A. Data portability applies — the fitness app must transmit the full dataset to the new service
  • B. Data portability does not apply here — the lawful basis is legitimate interests, not consent or contract
  • C. Portability applies but is limited to data the individual actively provided; app-generated data about them is excluded
  • D. Portability must be complied with, but a reasonable fee may be charged for the data transmission
Answer: B. Article 20(1) limits the right to data portability to processing carried out by automated means where the lawful basis is consent (Article 6(1)(a) or 9(2)(a)) or contract (Article 6(1)(b)). Processing based on legitimate interests (Article 6(1)(f)) does not give rise to the right to portability. If this fitness app uses legitimate interests as its lawful basis for processing workout data, the portability right does not apply to that processing. A is wrong — the lawful basis is the disqualifying factor. C would be a correct partial statement if portability applied (portability covers data provided by the data subject, not inferred data), but it doesn't apply here at all. D is wrong — GDPR Article 12(5) requires response to data subject requests free of charge (with narrow exceptions for manifestly unfounded or excessive requests).

The Single Biggest Question Bank Mistake CIPP/E Candidates Make

Tracking their score instead of studying the explanations. A candidate who does 400 questions and checks right/wrong without reading explanations will plateau. A candidate who does 200 questions and reads every explanation — including for the questions they got right — will continue improving. The question bank is not a testing tool. It's a teaching tool. Use it that way.

Frequently Asked Questions

How many questions are on the actual CIPP/E exam?

90 multiple-choice questions, 4 options each, one correct answer. 150 minutes. No partial credit. Passing score: 300 on a 100–500 scaled score (roughly 65–70% correct, though scaled scoring means this isn't a fixed percentage).

Are there free CIPP/E practice questions available?

Yes — IAPP provides a small number of sample questions in its exam preparation resources. However, the free samples are limited in number and don't provide full explanation coverage. They're useful for understanding exam format but not sufficient for full preparation. Third-party providers like Archuz offer full question banks (300+) with detailed explanations calibrated to current domain weights.

Do CIPP/E practice questions expire when GDPR changes?

The GDPR text itself has not been substantially amended since it became applicable in May 2018 — the core provisions tested on the exam are stable. However, the enforcement environment evolves: EDPB guidance, CJEU rulings (especially Schrems II and its aftermath), and DPA enforcement priorities can affect exam content. A question bank that was last updated in 2019 may have outdated international transfer questions (reflecting the old SCCs rather than the 2021 replacement). Check when a question bank was last updated before purchasing.

What score should I aim for on practice exams before sitting the CIPP/E?

Consistently scoring 72–75% or above on full mock exams under timed conditions is generally considered a reliable indicator of readiness. Candidates who enter the exam consistently scoring below 65% on mocks are at elevated risk of failure. Note that practice exam scores aren't directly comparable to the scaled exam score — use mock scores as directional indicators, not precise predictions.