By Fatskills Exam Guides Team — the exam nerds behind 28,500+ quizzes and 2.1M practice questions across 500+ global exams.
CIPP/E – Lawful Bases for Processing (Study Guide – Exam?Ready, Practical, Plain?Language)
Lawful bases are the “legal justifications” that allow a data controller (or processor) to handle personal data under the GDPR. Without a valid basis, any collection, use, or transfer is illegal and can trigger fines of up to?€20?million or?4?% of global turnover. Real?world example: A multinational retailer wants to move its European employee payroll data to a cloud provider in the United?States. The retailer must first decide whether the transfer is covered by a legitimate?interest assessment, a contract?based necessity, or a consent?based approach before the data can legally leave the EU.
Scenario: A German SaaS provider wants to send a monthly newsletter to EU customers who have never purchased anything. Which lawful basis is appropriate? Answer: Consent (Art.?6(1)(a)). Explanation: The newsletter is a direct?marketing activity not required for a contract; therefore, an opt?in consent is needed.
Scenario: An EU?based hospital shares a patient’s medical record with a specialist in another EU country for emergency treatment. Which basis applies? Answer: Vital Interests (Art.?6(1)(d)). Explanation: The processing is necessary to protect the patient’s life; consent is not required in an emergency.
Scenario: A UK e?commerce site uses cookies to remember a shopper’s cart contents for 30?days. The site also profiles the shopper for personalised offers. Which basis covers the profiling? Answer: Legitimate Interest (Art.?6(1)(f)) – provided a proper LIA is performed and the shopper is given an easy right?to?object.
Good luck – you’ve got the core concepts, the exam traps, and the practical steps you need to ace the CIPP/E!
Join 4M+ learners. Unlock unlimited quizzes, wrong-answer tracking, flashcards + reminders, study guides, and 1-on-1 challenges.