18 free MCQs

GDPR Exam Practice Questions

18 questions across 6 chapters, every answer cited to its GDPR article · Last reviewed 08/2026

Use this free set of GDPR exam practice questions to test yourself across the topics that regularly appear in DPO and GDPR certification exams. Unlike a prose guide, this page is a standalone bank of 18 realistic multiple-choice questions spanning principles, lawful bases, consent, data subject rights and deadlines, records of processing, breach notification, DPIAs, DPO rules, and fines. Each answer includes a concise explanation that cites the exact GDPR article or paragraph, so you can revise the rule and the exam trap at the same time. Answer each question before revealing the explanation, mark your score, then review every explanation carefully — including why the tempting wrong option fails under the GDPR wording.

Key facts at a glance

Questions
18 multiple-choice questions
Categories
6 core GDPR topic areas
Coverage
Articles 5, 6, 7, 8, 9, 12, 15, 17, 19, 21, 30, 33, 34, 35, 37, 38, 39, 83
Format
4 options per question
Explanations
Every answer cites the exact article/paragraph
Best use
Mixed-topic exam revision and self-testing

On this page

  1. Principles and lawful bases (Articles 5-9)
  2. Data subject rights and deadlines (Articles 12, 15, 17, 19, 21)
  3. Records and accountability (Article 30)
  4. Breach notification (Articles 33-34)
  5. DPIA and DPO (Articles 35, 37, 38, 39)
  6. Fines and enforcement (Article 83)
  7. FAQ

Principles and lawful bases (Articles 5-9)

These questions test core foundations that often appear early in GDPR exams.

Q1. Which statement best describes the accountability principle?
  • A. The controller is responsible for, and must be able to demonstrate, compliance with the other six principles ✓ Correct
  • B. The controller must always appoint a DPO to prove compliance
  • C. The processor is solely responsible for demonstrating compliance with all principles
  • D. Accountability is a separate lawful basis for processing

Why: Article 5 lists seven principles, and the seventh is accountability: the controller is responsible for, and must be able to demonstrate, compliance with the other six principles. The tempting wrong option is the DPO answer, but Article 5 does not say a DPO is always required, and accountability is a principle, not a lawful basis.

Q2. A controller is choosing a lawful basis under Article 6(1). Which answer is correct?
  • A. Consent must always be used if it is available
  • B. There is a hierarchy, with contract always preferred over legitimate interests
  • C. The controller should choose whichever of the six lawful bases genuinely fits; there is no ranking among them ✓ Correct
  • D. Public authorities may freely rely on legitimate interests when exercising their tasks

Why: Article 6(1) provides six lawful bases, and there is no ranking or hierarchy among them; the controller picks whichever genuinely fits. The tempting wrong option is the consent answer, but Article 6(1) does not make consent automatically superior to the other lawful bases, and legitimate interests is not available to public authorities exercising their tasks.

Q3. Which statement about consent is correct under the GDPR?
  • A. Silence can count as consent if the privacy notice is clear
  • B. Pre-ticked boxes are acceptable if the user later receives a confirmation email
  • C. Consent must be freely given, specific, informed and unambiguous, and it must be as easy to withdraw as to give ✓ Correct
  • D. Once given, consent cannot be withdrawn if processing has already started

Why: Article 7 requires consent to be freely given, specific, informed and unambiguous, and it must be as easy to withdraw as to give. The tempting wrong option is the silence answer, but Article 7 expressly says silence, pre-ticked boxes or inactivity do not constitute consent.

Data subject rights and deadlines (Articles 12, 15, 17, 19, 21)

These questions focus on common exam scenarios involving requests, objections and erasure.

Q1. A controller receives a valid subject access request. What is the standard response deadline?
  • A. Within 72 hours of receipt
  • B. Without undue delay and in any event within one month of receipt ✓ Correct
  • C. Within one month, with no possibility of extension
  • D. Within two months of receipt unless the request is simple

Why: Article 12(3) says controllers must respond to data-subject-rights requests without undue delay and in any event within one month of receipt. The tempting wrong option is the 72-hour answer, but that timing belongs to breach notification to the supervisory authority under Article 33, not rights requests.

Q2. Which statement about copies provided under a subject access request is correct?
  • A. The controller may always charge a reasonable fee for the first copy
  • B. The first copy must be free, but a reasonable fee based on administrative cost may be charged for further copies ✓ Correct
  • C. The controller must provide unlimited free copies on request
  • D. A fee may be charged for the first copy whenever the request is time-consuming

Why: Article 15(3) states that the first copy must be free, while a reasonable fee based on administrative cost may be charged for further copies. The tempting wrong option is the fee-for-first-copy answer, but that conflicts with Article 15(3); refusal or charging in other cases depends on Article 12(5) and requires the controller to demonstrate the request is manifestly unfounded or excessive.

Q3. A person objects to processing used for direct marketing. What is the controller required to do?
  • A. Continue if it can show compelling legitimate grounds
  • B. Continue for 30 days while reviewing the objection
  • C. Stop the direct marketing processing because the objection is unconditional ✓ Correct
  • D. Ignore the objection if the original lawful basis was consent

Why: Article 21(2)-(3) makes the right to object to direct marketing unconditional, so the controller must stop. The tempting wrong option is the balancing-test answer, but the "compelling legitimate grounds" test belongs to Article 21(1) objections to Article 6(1)(e) or 6(1)(f) processing generally, not direct marketing.

Records and accountability (Article 30)

These questions test what a RoPA is, who needs one, and what it must contain.

Q1. Which statement about Records of Processing Activities (RoPA) is correct?
  • A. Only controllers must maintain a RoPA
  • B. Only processors must maintain a RoPA
  • C. Both controllers and processors must maintain a RoPA, in writing including electronic form ✓ Correct
  • D. A RoPA is optional if an organisation has a privacy notice

Why: Article 30 requires both controllers under Article 30(1) and processors under Article 30(2) to maintain a Record of Processing Activities, in writing including electronic form. The tempting wrong option is the controllers-only answer, but Article 30 expressly covers processors too.

Q2. A company has fewer than 250 employees and processes employee and customer data on a regular basis. Which answer best reflects the Article 30(5) position?
  • A. It is automatically exempt from keeping a RoPA because it has under 250 employees
  • B. It is exempt unless it transfers data outside the EU
  • C. The under-250 exception does not apply if the processing is not occasional, so in practice it will often still need a RoPA ✓ Correct
  • D. It only needs a RoPA if it has appointed a DPO

Why: Article 30(5) contains an exception for organisations under 250 employees, but that exception does not apply where processing is not occasional, is likely to result in a risk to rights and freedoms, or includes Article 9 or Article 10 data. The tempting wrong option is the automatic-exemption answer, but regular employee and customer processing is not occasional, which is why many small businesses still need a RoPA.

Q3. Which item is part of a controller's RoPA content under Article 30(1)?
  • A. A mandatory copy of every data protection impact assessment
  • B. The categories of data subjects and categories of personal data ✓ Correct
  • C. A list of all data subject complaints ever received
  • D. A record of every consent withdrawal

Why: Article 30(1) includes, among other items, the purposes of processing and the categories of data subjects and categories of personal data. The tempting wrong option is the DPIA answer, but Article 30's content list does not require every DPIA to be included in the RoPA.

Breach notification (Articles 33-34)

These questions distinguish authority notification, data-subject notification, and exemptions.

Q1. When must a controller notify the competent supervisory authority of a personal data breach?
  • A. Always within 24 hours of discovery
  • B. Without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to rights and freedoms ✓ Correct
  • C. Only if the breach is likely to result in a high risk to rights and freedoms
  • D. Only after affected data subjects have been informed

Why: Article 33 requires notification to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after the controller becomes aware of the breach, unless it is unlikely to result in a risk to rights and freedoms. The tempting wrong option is the high-risk answer, but high risk is the threshold for notifying data subjects under Article 34, not the authority under Article 33.

Q2. A breach is unlikely to result in a risk to the rights and freedoms of natural persons. What still applies?
  • A. No action is required at all
  • B. The controller must still internally log or document the breach ✓ Correct
  • C. The controller must still notify all affected data subjects
  • D. The controller must still notify the authority within one month

Why: Even where authority notification is not required because the breach is unlikely to result in a risk, Article 33(5) still requires internal logging or documentation. The tempting wrong option is "no action is required," but Article 33(5) specifically keeps the documentation duty.

Q3. Which statement correctly describes when affected data subjects must be informed of a breach?
  • A. Whenever any personal data breach occurs, regardless of severity
  • B. Only where the breach is likely to result in a high risk to their rights and freedoms, subject to the Article 34(3) exemptions ✓ Correct
  • C. Only after the supervisory authority orders the controller to do so
  • D. Only if the breach involves special-category data

Why: Article 34 requires communication to affected data subjects only where the breach is likely to result in a high risk to their rights and freedoms, a higher threshold than Article 33. The tempting wrong option is the "any breach" answer, but that confuses Article 34 with Article 33's lower risk threshold for authority notification.

DPIA and DPO (Articles 35, 37, 38, 39)

These questions cover when a DPIA or DPO is mandatory and what the DPO role actually means.

Q1. When is a Data Protection Impact Assessment (DPIA) required?
  • A. Whenever personal data is processed for any purpose
  • B. Only when special-category data is processed
  • C. Where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons ✓ Correct
  • D. Only after a personal data breach has occurred

Why: Article 35(1) requires a DPIA where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. The tempting wrong option is the special-category answer, but the general trigger is high risk, not special-category data alone.

Q2. Which of the following is one of the minimum required contents of a DPIA under Article 35(7)?
  • A. A necessity and proportionality assessment ✓ Correct
  • B. A mandatory approval letter from the supervisory authority
  • C. A list of all employees who can access the data
  • D. A copy of the organisation's latest RoPA

Why: Article 35(7) says a DPIA must contain at least a systematic description of the processing, a necessity and proportionality assessment, a risk assessment, and the mitigating measures. The tempting wrong option is the authority-approval answer, but that is not one of the minimum contents listed in Article 35(7).

Q3. Which statement about the DPO role is correct?
  • A. The DPO is personally liable for administrative fines under Article 83
  • B. The DPO must personally guarantee the organisation's compliance
  • C. A DPO may have other tasks, but the controller must ensure there is no conflict of interest ✓ Correct
  • D. The controller may instruct the DPO how to exercise DPO tasks

Why: Article 38(6) allows a DPO to have other tasks, but the controller must ensure no conflict of interest results. The tempting wrong option is the personal-liability answer, but Article 83 fines are levied against the controller or processor only, not the DPO personally; Article 39(1) also says the DPO's minimum tasks are to inform, advise and monitor, not personally guarantee compliance.

Fines and enforcement (Article 83)

These questions test the two fine tiers and the role of aggravating and mitigating factors.

Q1. Which statement correctly describes the lower tier of GDPR administrative fines?
  • A. Up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher ✓ Correct
  • B. Up to €10 million or 2% of total worldwide annual turnover, whichever is lower
  • C. Up to €20 million or 4% of turnover, whichever is higher
  • D. A fixed fine of €10 million for every Article 30 breach

Why: Article 83(4) sets the lower tier at up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher — for example, RoPA/Article 30 failures. The tempting wrong option is the "whichever is lower" answer, but the rule expressly says whichever is higher.

Q2. Which type of infringement sits in the higher fine tier?
  • A. Failures relating to RoPA under Article 30
  • B. Breaching core processing principles or data subject rights ✓ Correct
  • C. Any breach that is documented internally under Article 33(5)
  • D. Appointing a DPO who has other tasks

Why: Article 83(5) is the upper tier (up to €20 million or 4% of turnover, whichever is higher), and its examples include breaches of core processing principles or data subject rights. The tempting wrong option is the RoPA answer, but Article 30 failures are an example of the lower Article 83(4) tier.

Q3. Which factor is specifically listed among the aggravating or mitigating factors used when assessing fines?
  • A. Whether the organisation has more than 250 employees
  • B. Whether the controller used cloud software
  • C. Intent or negligence, mitigation steps taken, prior infringements, and cooperation with the authority ✓ Correct
  • D. Whether the organisation has a marketing team

Why: Article 83(2) lists factors such as intent or negligence, mitigation steps taken, prior infringements, and cooperation with the supervisory authority — used in the EDPB's 5-step fining methodology (Guidelines 04/2022). The tempting wrong option is the employee-count answer, but organisation size alone is not one of the Article 83(2) factors.

Frequently asked questions

How many GDPR practice questions are on this page?

This page contains 18 multiple-choice questions split across 6 categories, with 3 questions in each category.

Are the explanations tied to specific GDPR articles?

Yes. Each explanation cites the exact article or paragraph used for the answer, so you can revise the rule directly from the question.

Is this page enough on its own to pass a GDPR or DPO exam?

No single question set can guarantee a pass. Use these questions as mixed-topic revision, then revisit the underlying articles and your wider study materials for any weak areas.

Do these questions match real exam formats exactly?

They are designed to feel realistic for GDPR and DPO certification study, but different providers use different wording, difficulty levels and exam structures.

Want hundreds more questions like these?

GDPR Exam Trainer turns the full syllabus into hundreds of practice questions, chapter training and a timed exam simulation, with AI explanations for every answer.

Create your free accountTry 30 questions free · No credit card required.

Primary sources

Every question and explanation on this page is grounded in the articles already fact-checked and cited in this site's own guides, linked above. This page is study material, not legal advice; for a binding interpretation, consult the official text on EUR-Lex, the EDPB, your competent supervisory authority, or a qualified data protection lawyer.