CIPP/E
What should you ask in a CIPP/E interview, and how should candidates answer?
A CIPP/E says someone knows European data protection law. These questions test whether they can apply it: lawful bases, rights requests, breaches, transfers and accountability, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask a CIPP/E candidate?
Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
When is pseudonymized data still personal data?
Listen for: When it can be attributed to a person using additional information. Only truly anonymous data falls outside the GDPR.
II.A: basic GDPR concepts
We have a personal data breach. What happens in the first 72 hours?
Listen for: Contain, assess the risk, notify the supervisory authority within 72 hours unless the breach is unlikely to result in a risk, tell individuals if the risk is high, and record every breach.
II.B: security of personal data
A customer asks for all the data we hold on them. Walk me through it.
Listen for: Verify identity, answer within one month (extendable), give a copy plus the required information, and apply exemptions narrowly.
II.C: data subjects' rights
How do you choose a lawful basis for a new processing activity?
Listen for: Purpose first, then one of the six bases in Article 6; consent only where it can be freely given and withdrawn; a written balancing test for legitimate interests.
III.B: lawful processing bases
How do we send personal data to a vendor outside the EU lawfully?
Listen for: An adequacy decision covering the recipient, or appropriate safeguards such as standard contractual clauses with a transfer assessment.
III.D: international data transfers
What does accountability look like day to day?
Listen for: Records of processing, DPIAs where risk is high, data protection by design and default, contracts with processors, training and evidence.
IV.B: accountability
What can we monitor of our employees?
Listen for: Only what is necessary and proportionate, with transparency, a DPIA where needed, and national employment law in mind.
V.A: the workplace
Can marketing email our existing customers?
Listen for: ePrivacy rules set by national law apply alongside the GDPR, and the right to object to direct marketing is absolute.
V.C: direct marketing
CIPP/E interview scorecard
CIPP/E interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | When is pseudonymized data still personal data? | When it can be attributed to a person using additional information. Only truly anonymous data falls outside the GDPR. | |
| 2 | We have a personal data breach. What happens in the first 72 hours? | Contain, assess the risk, notify the supervisory authority within 72 hours unless the breach is unlikely to result in a risk, tell individuals if the risk is high, and record every breach. | |
| 3 | A customer asks for all the data we hold on them. Walk me through it. | Verify identity, answer within one month (extendable), give a copy plus the required information, and apply exemptions narrowly. | |
| 4 | How do you choose a lawful basis for a new processing activity? | Purpose first, then one of the six bases in Article 6; consent only where it can be freely given and withdrawn; a written balancing test for legitimate interests. | |
| 5 | How do we send personal data to a vendor outside the EU lawfully? | An adequacy decision covering the recipient, or appropriate safeguards such as standard contractual clauses with a transfer assessment. | |
| 6 | What does accountability look like day to day? | Records of processing, DPIAs where risk is high, data protection by design and default, contracts with processors, training and evidence. | |
| 7 | What can we monitor of our employees? | Only what is necessary and proportionate, with transparency, a DPIA where needed, and national employment law in mind. | |
| 8 | Can marketing email our existing customers? | ePrivacy rules set by national law apply alongside the GDPR, and the right to object to direct marketing is absolute. |
Source: https://credentialpress.com/guides/cipp-e-interview-questions
Which questions should a CIPP/E candidate prepare for?
Why CIPP/E?
How to answer: It shows you know the GDPR and the European framework around it. Say where you have applied it.
Which domain do you know best?
How to answer: Name one, give a real example, then name the weakest and how you are closing it.
Tell me about a DPIA you worked on.
How to answer: The processing, the risks found, the measures taken, and whether the supervisory authority had to be consulted.
How do you keep up with EDPB guidance?
How to answer: Name your sources and one recent guideline that changed how you work.
What should a candidate ask the employer?
- Do you have a DPO, and who do they report to?
- How current is your record of processing activities?
- Which data transfers worry you most?
Where next?
Also free: the CIPP/E mind map and the CIPP/E 10-question quiz, plus every other credential on our study tools page. For the full syllabus, the CIPP/E Exam Guide and the CIPP/E Practice Questions go domain by domain.
Frequently asked questions
What should an employer ask a CIPP/E candidate?
Questions that test each exam domain in practice, for example: When is pseudonymized data still personal data? We have a personal data breach. What happens in the first 72 hours? A customer asks for all the data we hold on them. Walk me through it.
What should a CIPP/E candidate ask the employer?
Do you have a DPO, and who do they report to? How current is your record of processing activities? Which data transfers worry you most?
How should a candidate prepare for a CIPP/E interview?
It shows you know the GDPR and the European framework around it. Say where you have applied it.
Which books go deeper on CIPP/E?

Certified Information Privacy Professional, Europe. 18 chapters, 441 pages.

Sources
- IAPP, CIPP/E Body of Knowledge, version 1.3.3, effective 1 September 2025, read 3 October 2026
- IAPP, CIPP/E certification page, read 2 October 2026
- IAPP, certification FAQs, read 2 October 2026
- GDPR, Regulation (EU) 2016/679
Credential Press is independent of the IAPP.