# CIPP/E interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | When is pseudonymized data still personal data? | When it can be attributed to a person using additional information. Only truly anonymous data falls outside the GDPR. | |
| 2 | We have a personal data breach. What happens in the first 72 hours? | Contain, assess the risk, notify the supervisory authority within 72 hours unless the breach is unlikely to result in a risk, tell individuals if the risk is high, and record every breach. | |
| 3 | A customer asks for all the data we hold on them. Walk me through it. | Verify identity, answer within one month (extendable), give a copy plus the required information, and apply exemptions narrowly. | |
| 4 | How do you choose a lawful basis for a new processing activity? | Purpose first, then one of the six bases in Article 6; consent only where it can be freely given and withdrawn; a written balancing test for legitimate interests. | |
| 5 | How do we send personal data to a vendor outside the EU lawfully? | An adequacy decision covering the recipient, or appropriate safeguards such as standard contractual clauses with a transfer assessment. | |
| 6 | What does accountability look like day to day? | Records of processing, DPIAs where risk is high, data protection by design and default, contracts with processors, training and evidence. | |
| 7 | What can we monitor of our employees? | Only what is necessary and proportionate, with transparency, a DPIA where needed, and national employment law in mind. | |
| 8 | Can marketing email our existing customers? | ePrivacy rules set by national law apply alongside the GDPR, and the right to object to direct marketing is absolute. | |

Source: https://credentialpress.com/guides/cipp-e-interview-questions
