Free CIPP/US Practice Questions
Last reviewed: · By Victor Humenhuk (CIPP/US certified)
Sharpen your CIPP/US exam readiness with 22 free scenario-based practice questions covering the U.S. privacy environment, state laws, sectoral regulation, workplace privacy, and government access. Every question includes a full explanation of the correct answer and why each distractor fails. No signup required.
All 22 questions are original and free - no signup. Work through them, then check each answer. When you are ready for more, the full question bank has every topic covered, or start with the complete study guide.
The U.S. Privacy Environment and FTC Enforcement
Q1. A European colleague asks a U.S. privacy officer why her company must track HIPAA, GLBA, COPPA, and a patchwork of state statutes instead of complying with one national privacy law overseen by a single data protection authority. What best explains the U.S. approach?
- The U.S. follows a comprehensive model but delegates enforcement to each industry's trade association
- The U.S. Constitution prohibits Congress from enacting a comprehensive privacy law, leaving regulation to the states
- The U.S. follows a sectoral model, regulating privacy through industry-specific laws with no single national data protection authority
- The U.S. follows a co-regulatory model in which Congress ratifies industry codes of conduct as binding national law
Show answer & explanation
Answer: C. The United States uses the sectoral model: privacy is protected through laws targeting specific industries or data types (health, financial, children's data), which produces tailored rules but also gaps, overlaps, and no single data protection authority. Option A is wrong because the U.S. has no comprehensive national law, and trade associations are not statutory enforcers. Option B is wrong because nothing in the Constitution bars a federal comprehensive privacy law; Congress simply has not passed one. Option D misstates the co-regulatory approach, which is not the dominant U.S. model and does not involve Congress ratifying industry codes as national law.
Q2. A privacy analyst is classifying the consent standards behind several company practices: obtaining parental permission before collecting a 10-year-old's data online, sharing customer data with nonaffiliated third parties under GLBA, and using a customer's address to ship the product she ordered. Which classification is correct?
- All three require opt-in consent under the FTC's fair information practices
- COPPA requires opt-in consent, GLBA third-party sharing works on an opt-out basis, and order fulfillment requires no choice at all
- COPPA works on an opt-out basis, GLBA requires opt-in, and order fulfillment requires opt-out
- COPPA and GLBA both require opt-in, while order fulfillment requires opt-out notice
Show answer & explanation
Answer: B. U.S. laws take three approaches to choice: opt-in (COPPA verifiable parental consent, HIPAA disclosures, releasing credit reports under FCRA), opt-out (GLBA sharing with nonaffiliated third parties, CAN-SPAM, Do Not Call), and no option for commonly accepted practices like fulfilling the customer's own order. Option A is wrong because there is no universal opt-in requirement in U.S. law. Option C reverses the COPPA and GLBA standards. Option D is wrong on both GLBA (opt-out, not opt-in) and fulfillment (no consumer choice is required to process a transaction the consumer initiated).
Q3. A fitness app's privacy notice promises that workout data 'is never shared with third parties.' In fact, the company routinely sells the data to advertising networks. The company argues the FTC cannot act because no privacy statute specifically governs fitness apps. Is the company correct?
- Yes - the FTC may only enforce sector-specific statutes like HIPAA and GLBA
- No - but the FTC must first prove consumers suffered substantial financial injury
- Yes - privacy notices are voluntary disclosures and cannot create enforceable obligations
- No - breaking a material privacy promise is a deceptive practice under Section 5 of the FTC Act, regardless of any sector-specific statute
Show answer & explanation
Answer: D. A deceptive practice under FTC Act Section 5 is a material statement or omission likely to mislead reasonable consumers, and breaking a promise made in a privacy notice is a classic example - no sector-specific statute is needed. Option A is wrong because Section 5 gives the FTC broad authority over unfair or deceptive practices across most of the economy. Option B confuses deception with unfairness; the substantial-injury test belongs to the unfairness prong, not deception. Option C is wrong because once a company makes a privacy promise, failing to keep it is actionable deception even though publishing the notice was voluntary.
Related note: Deceptive Trade Practices and Broken Privacy Promises →
Q4. PlatePilot, a meal-planning app, states clearly on its signup screen - directly above the Subscribe button - that recipe-browsing history is shared with grocery advertising partners, and every account includes a one-tap toggle that stops the sharing. An advocacy group petitions the FTC to charge the practice as unfair under Section 5. An FTC staff attorney evaluates the claim against the elements of unfairness. What is the most accurate assessment?
- The claim is weak: with a clear up-front disclosure and a working opt-out, any injury is reasonably avoidable by consumers - and mere irritation at disclosed ad-sharing is unlikely to count as substantial injury
- The claim is weak, but only because unfairness always requires an accompanying false or deceptive statement, which PlatePilot never made
- The claim is strong: sharing any browsing data with advertisers without opt-in consent is per se unfair under Section 5
- The claim is strong: the countervailing-benefits element applies only to brick-and-mortar businesses, so PlatePilot cannot invoke it
Show answer & explanation
Answer: A. An unfair practice must (1) cause or be likely to cause substantial injury, (2) that consumers cannot reasonably avoid, and (3) that is not outweighed by countervailing benefits to consumers or competition. When a practice is conspicuously disclosed before purchase and consumers hold an easy, functioning opt-out, they can reasonably avoid any injury - and speculative annoyance is not substantial injury - so the unfairness theory collapses on its own elements. Option B is wrong in its reasoning: unfairness requires no deceptive statement at all (inadequate security or disclosures can be unfair on their own); the claim here fails on the elements, not for lack of deception. Option C is wrong because Section 5 contains no per se opt-in rule for ad-sharing. Option D is wrong because the three-part test applies across the economy, online and off.
State Comprehensive Privacy and Breach Notification Laws
Q5. A national wellness company operating in California, Colorado, and Virginia is mapping which data elements require heightened treatment under all three comprehensive state privacy laws. Which category can it treat as sensitive in every one of those states?
- Data revealing a consumer's racial or ethnic origin
- Union membership information
- A consumer's ZIP code
- Employment history
Show answer & explanation
Answer: A. All five comprehensive state laws align on a core set of sensitive data categories: citizenship/immigration status, genetic and biometric data, health information, racial or ethnic origin, religious beliefs, and sexual orientation - so race/ethnicity qualifies everywhere. Option B is wrong because union membership is a California addition (along with philosophical beliefs and contents of communications), not a universal category. Options C and D are wrong because ZIP codes and employment history are ordinary personal information at most, not sensitive data in any of the five states' definitions.
Q6. A retailer suffers a breach affecting 600,000 consumers spread across all 50 states. The incident response team knows affected individuals must be told, but asks who else may have to be notified under state breach notification laws. What is the most accurate answer?
- Only the affected individuals - no state requires notice to anyone else
- Only the FTC, which coordinates all state breach responses
- The local police department in every affected consumer's jurisdiction
- In many states, the company must also notify the state attorney general or a state agency, and nationwide consumer reporting agencies
Show answer & explanation
Answer: D. State breach laws commonly require notice to three audiences: affected residents (in all 50 states), state attorneys general or designated agencies (in roughly two-thirds of states), and the nationwide consumer reporting agencies when a threshold number of residents is affected (also about two-thirds of states). Option A understates the obligations - regulator and CRA notice are widespread requirements. Option B is wrong because there is no federal role coordinating state breach notice, and the FTC is not a general recipient of state-law breach notifications. Option C is wrong because notifying local police everywhere is not a state-law requirement; law enforcement's role is typically limited to permitting delayed notice during an investigation.
Q7. LlanoGraph, an Austin ad-tech boutique with eight employees and $4 million in annual gross revenue, builds interest profiles on about 30,000 California residents and earns roughly 60 percent of its revenue by selling those profiles to advertisers and sharing them with partner networks for targeted advertising. The founder assumes California's comprehensive privacy law 'can't possibly reach a company this small.' Is LlanoGraph a covered business?
- No - coverage always requires at least $25 million in annual gross revenue
- No - it handles data on fewer than 100,000 California consumers or households
- Yes, but only if it also maintains a physical office located inside California
- Yes - deriving 50 percent or more of annual revenue from selling or sharing California consumers' personal information independently triggers coverage, regardless of company size or consumer count
Show answer & explanation
Answer: D. California's law reaches a company doing business in the state that meets any one of three alternative thresholds: $25 million in annual gross revenue, buying/selling/sharing personal information of a large volume of consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. LlanoGraph's 60 percent figure satisfies the third prong on its own - and California is notable for counting both selling and sharing in that test, while Colorado, Connecticut, and Virginia look only at selling. Option A wrongly treats one alternative threshold as a universal requirement; revenue is sufficient when met but never necessary. Option B makes the same mistake with the consumer-volume prong. Option C is wrong because 'doing business in California' does not require a physical in-state office; serving and profiling California consumers suffices.
Related note: Defining Business - Applicability Thresholds →
Q8. In March 2026, SummitCrate, a Denver-based outdoor-gear e-tailer, receives violation notices on the same day from the Virginia and Colorado attorneys general over the same defective opt-out mechanism. The general counsel asks whether the company is entitled to fix the problem before either state can bring an enforcement action. What is the accurate answer?
- Both states must give a 30-day cure window before any enforcement action
- Virginia must still allow a 30-day cure - its cure provision has no end date - but Colorado's cure period sunset at the end of 2024, so the Colorado attorney general may proceed without offering one
- Neither state has ever provided a cure period; only California did
- Cure periods protect businesses only against consumer class actions, not attorney general enforcement
Show answer & explanation
Answer: B. The cure landscape splits three ways: Utah and Virginia give a 30-day cure with no sunset; Colorado's and Connecticut's cure periods sunset on December 31, 2024; and California's cure period has expired. So in 2026 SummitCrate retains a right to cure in Virginia but cannot demand one in Colorado. Option A assumes uniformity that no longer exists after the sunsets. Option C is backwards - Virginia, Colorado, Connecticut, and Utah all enacted cure provisions, and it is California's that lapsed. Option D misunderstands what cure periods do: they condition regulator enforcement, and there is no wave of consumer class actions to shield against because none of the five state laws grants a traditional private right of action over these consumer rights.
Related note: Cure Periods and the Private Right of Action →
Q9. After a breach exposes California members' unencrypted personal information, Vintner's Exchange, a wine-club retailer, receives the required pre-suit notice from affected consumers who intend to seek statutory damages. Within the 30-day window, the company hires a security firm, deploys encryption and monitoring across its systems, and sends the consumers a letter declaring the violation 'fully cured.' Can the consumers still pursue statutory damages?
- No - any security improvements completed within the 30-day window operate as a complete cure
- No - statutory damages are available only to consumers who can prove out-of-pocket losses from the breach
- Yes, but only if at least 100 affected consumers join the same lawsuit
- Yes - implementing reasonable security after the breach does not count as a cure, so the statutory damages claim may proceed
Show answer & explanation
Answer: D. California's private right of action lets consumers whose personal information is breached because a business failed to implement and maintain reasonable security recover statutory damages of $100 to $750 per consumer per incident. A business that successfully cures within 30 days of the pre-suit notice can cut off statutory damages - but the law is explicit that merely adopting reasonable security after the breach does not qualify as a cure, because it does nothing to undo the exposure the consumers already suffered. Option A states exactly the misconception the rule rejects. Option B defeats the purpose of statutory damages, which exist precisely because actual losses are hard to prove in breach cases; no out-of-pocket showing is required. Option C invents a numerosity threshold that appears nowhere in the statute.
Medical, Financial, and Education Privacy
Q10. A landlord rejects a rental application based in part on a tenant-screening report from a consumer reporting agency. The applicant is told only 'you didn't qualify.' What did the landlord fail to do under the FCRA?
- Provide an adverse action notice identifying the CRA, stating the CRA did not make the decision, and explaining the rights to a free report within 60 days and to dispute
- Nothing - adverse action notices apply only to credit card denials
- Obtain a court order before using the report
- Give the applicant 30 days' advance notice before requesting the report
Show answer & explanation
Answer: A. When a user takes adverse action - any negative credit, employment, insurance, or business decision such as denying a rental - based even in part on a consumer report, the FCRA requires notice identifying the CRA that supplied the report, stating that the CRA did not make the decision and cannot explain it, and informing the consumer of the rights to a free file disclosure within 60 days and to dispute inaccurate information. Option B is wrong because adverse action extends well beyond credit cards to housing, insurance, and employment decisions. Option C is wrong because a court order is not required; the landlord needs a permissible purpose, which tenant screening provides. Option D invents a waiting period that the FCRA does not impose for tenant screening.
Q11. A university wants to publish an online athletics roster listing student-athletes' names, majors, heights, and hometowns. One student objects to appearing. The registrar also suggests adding student ID numbers 'for convenience.' What does FERPA require?
- Nothing may be published without each student's written consent
- The roster data may be published as directory information if students were given a chance to opt out - and this student's objection must be honored - but Social Security and student ID numbers may not be treated as directory information
- Everything, including ID numbers, may be published because rosters are public records
- The roster may be published only with parental consent for every student
Show answer & explanation
Answer: B. Directory information is data not generally considered harmful if disclosed - each institution defines its list (names, majors, athletic data commonly qualify) - but the school must give students the opportunity to opt out before releasing it, so the objecting student must be excluded, and Social Security numbers and student ID numbers may not be designated as directory information. Option A is wrong because the directory-information exception exists precisely so routine data can be released without individual consent. Option C is wrong because FERPA's directory rules, not public-records logic, govern, and ID numbers are excluded. Option D is wrong because at the postsecondary level the rights belong to the student, not the parents.
Q12. The procurement lead at St. Odilia Medical Center is reviewing four proposed vendor contracts and must flag which vendor requires a business associate agreement: (1) an outside law firm that will receive patient charts to defend malpractice claims, (2) an electrician rewiring the ICU who may incidentally pass display screens, (3) a landscaping company, and (4) a beverage distributor supplying the cafeteria. Which vendor needs a BAA?
- Only the law firm - it performs a service for the hospital that involves the use or disclosure of PHI, which is what makes a vendor a business associate; incidental physical proximity to PHI does not
- All four vendors, because anyone who enters a hospital may encounter PHI
- The law firm and the electrician, because both may see patient information during their work
- None of them - business associate agreements are required only between hospitals and health insurance plans
Show answer & explanation
Answer: A. A business associate is a person or company that performs services for a covered entity involving the use or disclosure of PHI - classic examples include claims processing, data analysis, billing, legal, actuarial, accounting, consulting, and data aggregation services, as well as cloud storage providers handling PHI. The law firm will receive and use patient charts to deliver its legal services, so a written BAA is required (an electronic signature is acceptable if valid under state law). Option B sweeps in vendors whose services have nothing to do with PHI; hospitals manage incidental exposure through safeguards like screen placement and access controls, not BAAs. Option C fails for the same reason - the electrician's job does not involve using or disclosing PHI, so a possible glimpse of a screen does not create BA status. Option D is wrong because health plans are covered entities in their own right, and business associates span a wide range of service providers, not insurers.
Q13. Cascade Federal Credit Union signs a written agreement with a nonaffiliated home-insurance carrier to jointly market a bundled home-plus-loan product, and provides the carrier with members' names, addresses, and contact details for the campaign. A member complains that she was never given an opportunity to opt out of the sharing. Did the credit union violate the GLBA Privacy Rule?
- Yes - sharing nonpublic personal information with any nonaffiliated company requires an opt-out opportunity, without exception
- Yes - using member information for marketing requires prior opt-in consent under GLBA
- Not necessarily - sharing under a joint marketing agreement is an exception to the opt-out requirement, provided the arrangement is disclosed in the institution's privacy notice and the partner is contractually bound to confidentiality
- No - GLBA imposes no limits of any kind on how financial institutions share customer information
Show answer & explanation
Answer: C. The GLBA Privacy Rule requires initial and annual privacy notices and, as a general rule, notice plus an opt-out before nonpublic personal information is shared with nonaffiliated third parties - with opt-outs processed within 30 days. But the rule carves out sharing with affiliates and with joint marketing partners: a financial institution may share customer information with a nonaffiliated company under a joint marketing agreement without offering an opt-out, so long as the practice is described in its privacy notice and the partner is bound to keep the data confidential and use it only for the arrangement. Option A ignores these exceptions. Option B misstates the statute's architecture - GLBA is an opt-out regime, not opt-in. Option D swings to the opposite extreme; the Privacy Rule imposes real notice, choice, and processing obligations even though this particular sharing fits an exception.
Telecommunications, Marketing, and Workplace Privacy
Q14. An e-commerce company sends promotional emails that use the recipient's name in a truthful subject line, include an unsubscribe link, and honor opt-outs within 15 business days. The messages omit the company's postal address. Which two elements violate CAN-SPAM?
- Using the recipient's name in a subject line and the unsubscribe link
- Nothing - CAN-SPAM only prohibits false email headers
- The 15-day opt-out processing time and the missing physical postal address
- Sending any commercial email without prior opt-in consent
Show answer & explanation
Answer: C. CAN-SPAM requires senders of commercial email to avoid false headers and deceptive subject lines, provide a functioning opt-out mechanism honored within 10 business days, and include a valid physical postal address - so processing opt-outs in 15 days and omitting the address are both violations. Option A is wrong because personalization and unsubscribe links are compliant features, not violations. Option B understates the statute, which imposes several affirmative content and processing requirements beyond header accuracy. Option D is wrong because CAN-SPAM is an opt-out regime; no prior consent is needed to send commercial email.
Q15. A city audits pager message logs of an officer who repeatedly exceeded his character allowance, to determine whether the usage limits were too low for work needs. The officer, who sent many personal messages, claims the review violated his rights. Based on City of Ontario v. Quon, how should this resolve?
- The review was permissible because it was motivated by a legitimate, work-related purpose and was reasonable in scope
- The review was unlawful because employees always have an absolute expectation of privacy in messages
- The review was unlawful because the SCA bars employers from ever accessing employee communications
- The review was permissible only because the officer signed a union waiver
Show answer & explanation
Answer: A. In City of Ontario v. Quon, the Supreme Court upheld the employer's review of an employee's texts on an employer-provided device because the search was justified by a legitimate, work-related rationale (checking whether the character limit met operational needs) and was not excessive in scope; more broadly, the SCA's service-provider and authorized-user exceptions generally allow employers to review work communications for reasonable, work-related reasons. Option B is wrong because employee privacy expectations in employer systems are limited, not absolute. Option C misreads the SCA, which contains an exception that often covers the employer as the provider of the service. Option D invents a waiver requirement that played no role in the decision.
Related note: Stored Communications Act and City of Ontario v. Quon →
Q16. After discovering $40,000 in inventory missing from one warehouse, a private logistics company wants to polygraph its entire national workforce to find the thief. It also polygraphs one clerk who had exclusive access to the storage cage during the loss period. How does the Employee Polygraph Protection Act treat these two plans?
- Both are lawful because the company suffered an actual financial loss
- Both are prohibited because private employers may never administer polygraphs
- Mass testing is prohibited, but testing the clerk may fall within the ongoing-investigation exception because there is reasonable suspicion tied to an economic loss
- Both are lawful if employees consent in writing
Show answer & explanation
Answer: C. The EPPA, enforced by the Department of Labor, generally bars private employers from using lie detector tests on employees and applicants, but an exception permits testing during an ongoing investigation of economic loss where the employer has reasonable suspicion of the specific employee's involvement - dragnet testing of an entire workforce cannot satisfy that individualized-suspicion requirement, while the clerk with exclusive access plausibly can. Option A is wrong because economic loss alone does not authorize blanket testing. Option B overstates the ban, ignoring the statutory exceptions for certain occupations and investigations. Option D is wrong because employee consent does not override the EPPA's prohibitions.
Q17. HireLens, a startup, scrapes public social media posts, court dockets, and news articles to generate 'workplace risk scores' on job candidates, which it sells to corporate HR departments on a subscription basis. Its founder insists the FCRA is irrelevant: 'That law regulates credit bureaus, and we're a tech company that never touches credit data.' How would a regulator most likely analyze HireLens?
- It is unregulated, because the FCRA reaches only the three nationwide credit bureaus
- By regularly assembling information on consumers and furnishing it to employers for hiring decisions, HireLens is acting as a consumer reporting agency and its scores are consumer reports - bringing it within the FCRA even though no credit data is involved
- It is exempt because everything it collects is publicly available online
- It is governed only by state law, because algorithmically generated scores fall outside the FCRA
Show answer & explanation
Answer: B. FCRA coverage turns on function, not on what a company calls itself: a firm that assembles information bearing on a consumer's character, general reputation, personal characteristics, or mode of living and furnishes it to third parties for eligibility decisions - including employment purposes like preemployment screening, promotion, reassignment, and retention - is a consumer reporting agency, and the FTC has aggressively pursued exactly these nontraditional CRAs that collect data online and report it to employers. HireLens therefore faces the full FCRA framework: permissible purpose, employer certifications, accuracy duties, and exposure to civil and criminal penalties plus a private right of action. Option A is wrong because the CRA definition extends far beyond the big three bureaus, and consumer reports include criminal, driving, and reputational data, not just credit. Option C is wrong because assembling even publicly available information into reports sold for eligibility decisions triggers the statute. Option D invents an algorithmic carve-out that does not exist.
Government Access, Litigation, and International Privacy
Q18. Police suspect a man of fraud. Without a warrant, they (1) photograph him meeting associates in a public park and (2) obtain from his bank the deposit records he shared with the bank. He moves to suppress both under the Fourth Amendment. What result under traditional doctrine?
- Both motions succeed - all warrantless evidence gathering is unconstitutional
- Both motions fail - there is no reasonable expectation of privacy in public activities or in records voluntarily shared with a third party
- Only the photographs are suppressed, because public surveillance always requires a warrant
- Only the bank records are suppressed, because financial data is categorically protected by the Fourth Amendment
Show answer & explanation
Answer: B. Under Katz, Fourth Amendment protection turns on a reasonable expectation of privacy, and two doctrines limit it: activities knowingly exposed in public receive no protection, and under the third-party doctrine, information voluntarily conveyed to a third party (like bank records) traditionally loses protection - so neither suppression motion succeeds. Option A is wrong because the warrant requirement applies only where a protected privacy interest exists. Option C inverts the in-public doctrine. Option D is wrong because bank records are the classic third-party doctrine example (United States v. Miller); statutory protections like the RFPA exist precisely because the Constitution does not cover them.
Related note: Fourth Amendment Limits on Law Enforcement Searches →
Q19. A journalist in a state requiring all-party consent secretly records a phone call with a source, relying on the fact that federal law permits recording with one party's consent. She is charged under the state statute and argues federal law overrides it. Is she right?
- Yes - federal one-party consent always displaces stricter state recording laws
- Yes - the First Amendment exempts journalists from recording statutes
- No - but only because she recorded a phone call rather than an in-person conversation
- No - the federal Wiretap Act's one-party consent rule is not preemptive, so states may require all-party consent
Show answer & explanation
Answer: D. The Wiretap Act (Title III), extended to electronic communications by ECPA, permits interception with one party's consent, but the federal statute is not preemptive - many states require all-party consent, and those stricter state laws remain fully enforceable. Option A states the opposite of the actual preemption position. Option B is wrong because no general First Amendment exemption shields journalists from generally applicable recording statutes. Option C is wrong because the all-party consent requirement in such states applies to intercepted communications generally, and the phone/in-person distinction does not rescue her.
Related note: Wiretap Act, ECPA, and Stored Communications Act →
Q20. A U.S. company acting as a GDPR controller for its EU operations discovers on Monday morning that an attacker exfiltrated EU customers' account data, creating a high risk to those individuals. Its EU processor detected the intrusion on Friday but said nothing all weekend. Which statement about GDPR breach duties is correct?
- Only the processor owes notification duties, since it suffered the intrusion
- The controller must notify the supervisory authority within 72 hours where feasible and tell affected individuals because the risk is high; the processor should have notified the controller without undue delay
- The controller has 30 days to notify the supervisory authority and need never inform individuals
- Notification is required only if the data was unencrypted financial information
Show answer & explanation
Answer: B. The GDPR defines a breach broadly (destruction, loss, alteration, or unauthorized disclosure or access) and allocates duties by role: processors must notify their controller without undue delay after becoming aware - so the weekend silence was itself a failure - while controllers must notify the supervisory authority within 72 hours where feasible and communicate to data subjects when the breach poses a high risk to them. Option A is wrong because the regulator- and individual-facing duties belong to the controller. Option C invents a 30-day deadline and ignores the high-risk communication duty. Option D is wrong because GDPR breach duties are not limited to any particular data category; risk drives the individual-notification analysis.
Q21. A German subsidiary wants to send employee personal data to its parent company in a country that has no EU adequacy decision. The parent's counsel suggests the transfer is fine 'because the data stays within the corporate family.' Under the GDPR, is that sufficient?
- Yes - intra-group transfers are automatically exempt from transfer restrictions
- Yes - as long as the data is encrypted in transit
- No - personal data may never leave the EEA under any circumstances
- No - transfers outside the EEA are prohibited unless supported by an adequacy decision, an appropriate safeguard, or a derogation; common corporate ownership alone is none of these
Show answer & explanation
Answer: D. The GDPR prohibits transfers of personal data from the EEA to third countries unless the destination benefits from an adequacy decision (protections essentially equivalent to the GDPR), the transfer is covered by an appropriate safeguard (such as standard contractual clauses or binding corporate rules), or a derogation applies - being part of the same corporate group is not, by itself, a lawful transfer mechanism, though binding corporate rules exist precisely for such groups. Option A is wrong because no automatic intra-group exemption exists. Option B is wrong because encryption is a security measure, not a legal transfer basis. Option C overcorrects - transfers are permitted through the recognized mechanisms.
Related note: International Transfers and Adequate Countries →
Q22. An EU supervisory authority finds that a multinational with €2 billion in worldwide annual turnover committed two violations: it failed to maintain adequate records of processing activities, and it ignored data subjects' access requests. What is the maximum fine exposure for each violation under the GDPR's two-tier structure?
- Both violations carry the same flat maximum of €20 million
- Recordkeeping is the higher-tier violation, and rights violations are lower-tier
- Recordkeeping falls in the lower tier (up to €10 million or 2% of global turnover), while violating data subject rights falls in the higher tier (up to €20 million or 4%), whichever is greater
- Fines are capped at 4% of EU-only revenue for all violations
Show answer & explanation
Answer: C. The GDPR sets two tiers of administrative fines: lower-tier violations - administrative and organizational duties such as records of processing - carry a maximum of €10 million or 2% of total worldwide annual turnover, whichever is greater; higher-tier violations - core processing principles, data subject rights, and transfer rules - carry up to €20 million or 4%. Ignoring access requests is a data subject rights violation and sits in the higher tier. Option A is wrong because the tiers set different ceilings, and the percentage alternative can exceed €20 million for large companies. Option B reverses the tiers. Option D is wrong because the percentage is calculated on total worldwide turnover, not EU-only revenue.
Unlock the full 722-question practice bank → See the full study guide