The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 50 |
| 2 | Domain training | 50 |
| 3 | Domain training | 50 |
| 4 | Domain training | 50 |
| 5 | Timed simulation | 80 |
| 6 | Timed simulation | 80 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
General data protection regulation
A company based in Singapore operates a French-language e-commerce site that regularly delivers to customers residing in France and Belgium. Is this company subject to the GDPR?
- No, because its head office is outside the European Union and it has no establishment in the EU
- Yes, because of the offering of goods or services to individuals located in the EU
- Only if its EU turnover exceeds 10 million euros per year
- Only for transactions made with a bank card issued by a European bank
-
Technical and organizational measures for security
A marketing team wishes to collect, when registering for a loyalty programme, the name, email address, date of birth, postal address, telephone number, occupation, income and hobbies of customers. Which GDPR principle is primarily at stake if some of these fields are not justified by the declared purposes of the programme?
- The lawfulness principle (Article 5(1)(a))
- The minimisation principle (Article 5(1)(c))
- The accuracy principle (Article 5(1)(d))
- The integrity and confidentiality principle (Article 5(1)(f))
-
Accountability
The accountability principle enshrined in Article 5(2) of the GDPR requires the controller to be able to demonstrate compliance with the principles set out in Article 5(1). Among the following practices, which is the least effective for demonstrating accountability?
- Keeping a detailed and up-to-date record of processing activities (Article 30)
- Relying on verbal commitments and an internal climate of trust, without written formalisation
- Documenting data protection impact assessments (DPIAs) and legal basis analyses
- Putting in place written procedures for handling rights requests and breach notification
-
General data protection regulation
Among the following processing operations, which one is excluded from the material scope of the GDPR under Article 2?
- The processing of personal data by an EU-based SME for its customer management
- Processing carried out by a public authority in the performance of its public service tasks
- The processing of data by a non-profit association to manage its members
- Processing carried out by a natural person exclusively in the course of a purely personal or household activity
-
Technical and organizational measures for security
An organisation keeps full backups of its customer databases for 3 years for technical restoration reasons. How is this practice framed by the GDPR?
- Any retention beyond the active use periods of the main processing is strictly prohibited by the limitation principle of Article 5(1)(e)
- Backups are excluded from the scope of the GDPR because they serve a technical business continuity purpose only
- The periods must be proportionate to the technical continuity purpose and documented; in the case of Article 17, the data is deleted
- Backups may be kept indefinitely as long as they are encrypted with a robust algorithm and stored offline
-
Accountability
A person sends a controller an access request under Article 15 of the GDPR. Within what time limit and by what means must the controller respond?
- Within 72 hours of receiving the request, like the notification of a data breach
- Within one month, extendable by up to two further months in case of complexity or a high number of requests
- Within strictly 30 days, without any possibility of extension, regardless of the complexity of the request
- No time limit imposed by the GDPR as long as the controller response occurs before the end of the current calendar year
-
General data protection regulation
A US company with no establishment in the EU processes the data of its own US employees, some of whom carry out occasional assignments of a few days in Spain. Does the GDPR apply to this HR processing?
- No, because the HR processing does not aim to offer goods or services to individuals in the EU
- Yes, as soon as an employee sets foot on EU territory, the entire HR processing falls under the GDPR
- Yes, but only for data collected physically during the employee's presence on European territory
- The GDPR applies only if the company has a designated representative in the EU within the meaning of Article 27
-
Technical and organizational measures for security
According to Article 4(5) of the GDPR, what is pseudonymisation and what is its legal regime?
- A transformation technique that renders data fully anonymous and definitively removes it from the scope of the GDPR
- A simple change of variable or column name in a database, without any other associated technical measure
- A processing preventing attribution without additional information kept separately
- A mandatory and systematic measure for all automated processing involving personal data
-
Accountability
Article 22 of the GDPR governs the data subject right not to be subject to a decision based solely on automated processing. In which cases does this protection apply?
- To any automated decision, whatever its nature, consequences, or degree of human intervention
- To any decision involving an algorithm, even where a human operator manually validates the result before execution
- To solely automated decisions (including profiling) producing legal effects or significantly affecting the person (Art. 22(1))
- Only to decisions taken by public authorities in the exercise of their public service missions
-
General data protection regulation
According to Article 4(1) of the GDPR, which of the following elements does NOT, in itself and out of context, constitute personal data?
- A static IP address assigned to an individual subscriber of an internet access provider
- A vehicle registration plate number linked to the national vehicle register
- The aggregate annual turnover of a commercial company, with no reference to a natural person
- A photograph of an employee's face stored in an HR database with their name and staff number
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the GDPR, Data Protection Officer training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.