Principles and lawful bases (Articles 5-9)
These questions test core foundations that often appear early in GDPR exams.
Q1. Which statement best describes the accountability principle?
Why: Article 5 lists seven principles, and the seventh is accountability: the controller is responsible for, and must be able to demonstrate, compliance with the other six principles. The tempting wrong option is the DPO answer, but Article 5 does not say a DPO is always required, and accountability is a principle, not a lawful basis.
Q2. A controller is choosing a lawful basis under Article 6(1). Which answer is correct?
Why: Article 6(1) provides six lawful bases, and there is no ranking or hierarchy among them; the controller picks whichever genuinely fits. The tempting wrong option is the consent answer, but Article 6(1) does not make consent automatically superior to the other lawful bases, and legitimate interests is not available to public authorities exercising their tasks.
Q3. Which statement about consent is correct under the GDPR?
Why: Article 7 requires consent to be freely given, specific, informed and unambiguous, and it must be as easy to withdraw as to give. The tempting wrong option is the silence answer, but Article 7 expressly says silence, pre-ticked boxes or inactivity do not constitute consent.
Data subject rights and deadlines (Articles 12, 15, 17, 19, 21)
These questions focus on common exam scenarios involving requests, objections and erasure.
Q1. A controller receives a valid subject access request. What is the standard response deadline?
Why: Article 12(3) says controllers must respond to data-subject-rights requests without undue delay and in any event within one month of receipt. The tempting wrong option is the 72-hour answer, but that timing belongs to breach notification to the supervisory authority under Article 33, not rights requests.
Q2. Which statement about copies provided under a subject access request is correct?
Why: Article 15(3) states that the first copy must be free, while a reasonable fee based on administrative cost may be charged for further copies. The tempting wrong option is the fee-for-first-copy answer, but that conflicts with Article 15(3); refusal or charging in other cases depends on Article 12(5) and requires the controller to demonstrate the request is manifestly unfounded or excessive.
Q3. A person objects to processing used for direct marketing. What is the controller required to do?
Why: Article 21(2)-(3) makes the right to object to direct marketing unconditional, so the controller must stop. The tempting wrong option is the balancing-test answer, but the "compelling legitimate grounds" test belongs to Article 21(1) objections to Article 6(1)(e) or 6(1)(f) processing generally, not direct marketing.
Records and accountability (Article 30)
These questions test what a RoPA is, who needs one, and what it must contain.
Q1. Which statement about Records of Processing Activities (RoPA) is correct?
Why: Article 30 requires both controllers under Article 30(1) and processors under Article 30(2) to maintain a Record of Processing Activities, in writing including electronic form. The tempting wrong option is the controllers-only answer, but Article 30 expressly covers processors too.
Q2. A company has fewer than 250 employees and processes employee and customer data on a regular basis. Which answer best reflects the Article 30(5) position?
Why: Article 30(5) contains an exception for organisations under 250 employees, but that exception does not apply where processing is not occasional, is likely to result in a risk to rights and freedoms, or includes Article 9 or Article 10 data. The tempting wrong option is the automatic-exemption answer, but regular employee and customer processing is not occasional, which is why many small businesses still need a RoPA.
Q3. Which item is part of a controller's RoPA content under Article 30(1)?
Why: Article 30(1) includes, among other items, the purposes of processing and the categories of data subjects and categories of personal data. The tempting wrong option is the DPIA answer, but Article 30's content list does not require every DPIA to be included in the RoPA.
Breach notification (Articles 33-34)
These questions distinguish authority notification, data-subject notification, and exemptions.
Q1. When must a controller notify the competent supervisory authority of a personal data breach?
Why: Article 33 requires notification to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after the controller becomes aware of the breach, unless it is unlikely to result in a risk to rights and freedoms. The tempting wrong option is the high-risk answer, but high risk is the threshold for notifying data subjects under Article 34, not the authority under Article 33.
Q2. A breach is unlikely to result in a risk to the rights and freedoms of natural persons. What still applies?
Why: Even where authority notification is not required because the breach is unlikely to result in a risk, Article 33(5) still requires internal logging or documentation. The tempting wrong option is "no action is required," but Article 33(5) specifically keeps the documentation duty.
Q3. Which statement correctly describes when affected data subjects must be informed of a breach?
Why: Article 34 requires communication to affected data subjects only where the breach is likely to result in a high risk to their rights and freedoms, a higher threshold than Article 33. The tempting wrong option is the "any breach" answer, but that confuses Article 34 with Article 33's lower risk threshold for authority notification.
DPIA and DPO (Articles 35, 37, 38, 39)
These questions cover when a DPIA or DPO is mandatory and what the DPO role actually means.
Q1. When is a Data Protection Impact Assessment (DPIA) required?
Why: Article 35(1) requires a DPIA where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. The tempting wrong option is the special-category answer, but the general trigger is high risk, not special-category data alone.
Q2. Which of the following is one of the minimum required contents of a DPIA under Article 35(7)?
Why: Article 35(7) says a DPIA must contain at least a systematic description of the processing, a necessity and proportionality assessment, a risk assessment, and the mitigating measures. The tempting wrong option is the authority-approval answer, but that is not one of the minimum contents listed in Article 35(7).
Q3. Which statement about the DPO role is correct?
Why: Article 38(6) allows a DPO to have other tasks, but the controller must ensure no conflict of interest results. The tempting wrong option is the personal-liability answer, but Article 83 fines are levied against the controller or processor only, not the DPO personally; Article 39(1) also says the DPO's minimum tasks are to inform, advise and monitor, not personally guarantee compliance.
Fines and enforcement (Article 83)
These questions test the two fine tiers and the role of aggravating and mitigating factors.
Q1. Which statement correctly describes the lower tier of GDPR administrative fines?
Why: Article 83(4) sets the lower tier at up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher — for example, RoPA/Article 30 failures. The tempting wrong option is the "whichever is lower" answer, but the rule expressly says whichever is higher.
Q2. Which type of infringement sits in the higher fine tier?
Why: Article 83(5) is the upper tier (up to €20 million or 4% of turnover, whichever is higher), and its examples include breaches of core processing principles or data subject rights. The tempting wrong option is the RoPA answer, but Article 30 failures are an example of the lower Article 83(4) tier.
Q3. Which factor is specifically listed among the aggravating or mitigating factors used when assessing fines?
Why: Article 83(2) lists factors such as intent or negligence, mitigation steps taken, prior infringements, and cooperation with the supervisory authority — used in the EDPB's 5-step fining methodology (Guidelines 04/2022). The tempting wrong option is the employee-count answer, but organisation size alone is not one of the Article 83(2) factors.
Frequently asked questions
How many GDPR practice questions are on this page?
This page contains 18 multiple-choice questions split across 6 categories, with 3 questions in each category.
Are the explanations tied to specific GDPR articles?
Yes. Each explanation cites the exact article or paragraph used for the answer, so you can revise the rule directly from the question.
Is this page enough on its own to pass a GDPR or DPO exam?
No single question set can guarantee a pass. Use these questions as mixed-topic revision, then revisit the underlying articles and your wider study materials for any weak areas.
Do these questions match real exam formats exactly?
They are designed to feel realistic for GDPR and DPO certification study, but different providers use different wording, difficulty levels and exam structures.
Want hundreds more questions like these?
GDPR Exam Trainer turns the full syllabus into hundreds of practice questions, chapter training and a timed exam simulation, with AI explanations for every answer.
Create your free accountTry 30 questions free · No credit card required.