Exam Mode

GDPR, Data Protection Officer

The data protection officer role

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
General data protection regulation78%
Accountability64%
Technical and organizational measures for security55%

The domains assessed

Actual distribution of this product questions.

General data protection regulation135
Accountability122
Technical and organizational measures for security103

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. General data protection regulation

    A company based in Singapore operates a French-language e-commerce site that regularly delivers to customers residing in France and Belgium. Is this company subject to the GDPR?

    1. No, because its head office is outside the European Union and it has no establishment in the EU
    2. Yes, because of the offering of goods or services to individuals located in the EU
    3. Only if its EU turnover exceeds 10 million euros per year
    4. Only for transactions made with a bank card issued by a European bank
  2. Technical and organizational measures for security

    A marketing team wishes to collect, when registering for a loyalty programme, the name, email address, date of birth, postal address, telephone number, occupation, income and hobbies of customers. Which GDPR principle is primarily at stake if some of these fields are not justified by the declared purposes of the programme?

    1. The lawfulness principle (Article 5(1)(a))
    2. The minimisation principle (Article 5(1)(c))
    3. The accuracy principle (Article 5(1)(d))
    4. The integrity and confidentiality principle (Article 5(1)(f))
  3. Accountability

    The accountability principle enshrined in Article 5(2) of the GDPR requires the controller to be able to demonstrate compliance with the principles set out in Article 5(1). Among the following practices, which is the least effective for demonstrating accountability?

    1. Keeping a detailed and up-to-date record of processing activities (Article 30)
    2. Relying on verbal commitments and an internal climate of trust, without written formalisation
    3. Documenting data protection impact assessments (DPIAs) and legal basis analyses
    4. Putting in place written procedures for handling rights requests and breach notification
  4. General data protection regulation

    Among the following processing operations, which one is excluded from the material scope of the GDPR under Article 2?

    1. The processing of personal data by an EU-based SME for its customer management
    2. Processing carried out by a public authority in the performance of its public service tasks
    3. The processing of data by a non-profit association to manage its members
    4. Processing carried out by a natural person exclusively in the course of a purely personal or household activity
  5. Technical and organizational measures for security

    An organisation keeps full backups of its customer databases for 3 years for technical restoration reasons. How is this practice framed by the GDPR?

    1. Any retention beyond the active use periods of the main processing is strictly prohibited by the limitation principle of Article 5(1)(e)
    2. Backups are excluded from the scope of the GDPR because they serve a technical business continuity purpose only
    3. The periods must be proportionate to the technical continuity purpose and documented; in the case of Article 17, the data is deleted
    4. Backups may be kept indefinitely as long as they are encrypted with a robust algorithm and stored offline
  6. Accountability

    A person sends a controller an access request under Article 15 of the GDPR. Within what time limit and by what means must the controller respond?

    1. Within 72 hours of receiving the request, like the notification of a data breach
    2. Within one month, extendable by up to two further months in case of complexity or a high number of requests
    3. Within strictly 30 days, without any possibility of extension, regardless of the complexity of the request
    4. No time limit imposed by the GDPR as long as the controller response occurs before the end of the current calendar year
  7. General data protection regulation

    A US company with no establishment in the EU processes the data of its own US employees, some of whom carry out occasional assignments of a few days in Spain. Does the GDPR apply to this HR processing?

    1. No, because the HR processing does not aim to offer goods or services to individuals in the EU
    2. Yes, as soon as an employee sets foot on EU territory, the entire HR processing falls under the GDPR
    3. Yes, but only for data collected physically during the employee's presence on European territory
    4. The GDPR applies only if the company has a designated representative in the EU within the meaning of Article 27
  8. Technical and organizational measures for security

    According to Article 4(5) of the GDPR, what is pseudonymisation and what is its legal regime?

    1. A transformation technique that renders data fully anonymous and definitively removes it from the scope of the GDPR
    2. A simple change of variable or column name in a database, without any other associated technical measure
    3. A processing preventing attribution without additional information kept separately
    4. A mandatory and systematic measure for all automated processing involving personal data
  9. Accountability

    Article 22 of the GDPR governs the data subject right not to be subject to a decision based solely on automated processing. In which cases does this protection apply?

    1. To any automated decision, whatever its nature, consequences, or degree of human intervention
    2. To any decision involving an algorithm, even where a human operator manually validates the result before execution
    3. To solely automated decisions (including profiling) producing legal effects or significantly affecting the person (Art. 22(1))
    4. Only to decisions taken by public authorities in the exercise of their public service missions
  10. General data protection regulation

    According to Article 4(1) of the GDPR, which of the following elements does NOT, in itself and out of context, constitute personal data?

    1. A static IP address assigned to an individual subscriber of an internet access provider
    2. A vehicle registration plate number linked to the national vehicle register
    3. The aggregate annual turnover of a commercial company, with no reference to a natural person
    4. A photograph of an employee's face stored in an HR database with their name and staff number

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the GDPR, Data Protection Officer training.

See the training

All exams