The BCS Practitioner Certificate in Data Protection (PDP9) validates your ability to apply data protection legislation in real-world scenarios. This exam is designed for professionals working in compliance, IT security, legal, or operational roles who need to demonstrate practical knowledge of GDPR, UK GDPR, and related regulations. This page maps the exam syllabus, explains question formats, and guides your preparation strategy so you can study efficiently and confidently. Whether you're new to data protection or building on existing knowledge, understanding the PDP9 structure helps you focus on what matters most within the Information security and data protection certifications pathway.
Use this topic map to guide your study for BCS PDP9 (BCS Practitioner Certificate in Data Protection) within the Information security and data protection certifications path.
PDP9 assesses both foundational knowledge and the ability to apply data protection concepts to realistic business situations. Questions are designed to test whether you can interpret legislation, make compliant decisions, and advise on practical implementation.
Questions progress in difficulty and reflect real-world complexity, ensuring that passing candidates can confidently handle data protection responsibilities in their roles.
Effective preparation combines structured topic review with regular practice and self-assessment. Map each syllabus domain to weekly study goals, practice applying concepts to scenarios, and use timed drills to build exam pacing. This approach prevents last-minute cramming and reinforces the practical reasoning skills the exam measures.
Explore other BCS certifications: view all BCS exams.
Strengthen your preparation with up-to-date resources from validexamdumps.com. These materials align to PDP9 and cover practical scenarios with clear explanations.
Visit the exam page to download the PDF, Online Practice Test, or get a Bundle Discount offer for both formats: BCS Practitioner Certificate in Data Protection.
Lawful bases for processing, data subject rights, and controller obligations are core to most exam items because they directly impact how organizations operate. Principles and terminology also appear frequently because they underpin all other topics. Allocate roughly 30% of your study time to these three domains and distribute the remaining time across sector-specific applications, breaches, and emerging areas like AI.
The seven principles (lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, and storage limitation) form the foundation for every data protection process. In practice, they guide privacy impact assessments, data retention policies, consent forms, and breach response procedures. Understanding how each principle applies to specific workflows, such as customer onboarding, employee records, or marketing campaigns, helps you answer scenario questions confidently.
Confusing legal bases (e.g., mixing consent with legitimate interest) and misidentifying which regulation applies (GDPR vs. PECR vs. sector-specific rules) are frequent errors. Candidates also sometimes overlook exceptions and special cases, such as public task exemptions or the stricter rules for children's data. Careful reading of scenario details and practice with mixed-topic questions help avoid these pitfalls.
Direct experience with privacy impact assessments, breach handling, or data transfer documentation is valuable but not required. If you have access to real examples, review how your organization documents legal bases, manages consent, or responds to subject access requests. Prioritize understanding the practical steps behind each principle and obligation so that you can apply them to unfamiliar scenarios on the exam.
Shift from learning new topics to consolidation and practice. Complete at least one full-length timed practice test to identify remaining weak areas, then focus revision on those domains. Review key definitions and legal bases using flashcards or summary notes. On the day before the exam, do a light review of high-impact topics (lawful bases, rights, controller obligations) and get adequate sleep to maintain focus during the test.
Which one task are supervisory authorities NOT required to carry out under Article 57(1 )(f) of the UK GDPR? Select the CORRECT answer.
Article 57(1)(f) of the UK GDPR requires the supervisory authority (the ICO in the UK) to handle complaints lodged by a data subject, investigate the subject matter of the complaint, and inform the complainant of the progress and the outcome of the investigation. It also requires the supervisory authority to cooperate with other supervisory authorities if the complaint involves cross-border processing. However, it does not require the supervisory authority to mediate between the complainant and the controller or processor against which the complaint has been lodged, to resolve the complaint. This is not a task of the supervisory authority under the UK GDPR, although it may be possible in some cases as a way of achieving an amicable solution.Reference:
Article 57(1)(f) of the UK GDPR1
Under which circumstances can the 'domestic purposes' exemption be used to justify non-compliance with the Data Protection Act 2018?
A) An individual sells make up products for commission and uses social media to promote products to friends and family
B) A couple are planning their daughter's wedding and use excel to store contact details and dietary needs of the guests
C) An individual employs a babysitter and stores her bank details in an encrypted document in order to make payments
D) A pansh council keeps a spreadsheet to manage bookings of the village hall, it contains only contact information and time slots
E) A group of students are arranging a house party and using social media to invite people that they do and do not know
The domestic purposes exemption applies to personal data processed by an individual only for the purposes of their personal, family or household affairs. This means that the processing has no connection to any professional or commercial activity. Examples of such processing include writing to friends and family, taking pictures for personal enjoyment, or keeping an address book. However, the exemption does not apply if the individual processes personal data outside the reasonable expectations of the data subject, or if the processing causes unwarranted harm to the data subject's interests. Therefore, the exemption can be used to justify non-compliance with the Data Protection Act 2018 in scenarios B and C, where the processing is purely personal and does not affect the rights and freedoms of others. However, the exemption cannot be used in scenarios A, D and E, where the processing has a professional or commercial element, or involves sharing personal data with third parties without consent or legitimate interest.Reference:
Data Protection Act 2018, Schedule 2, Part 1, Paragraph 21
ICO Guide to Data Protection, Domestic Purposes2
ICO Guide to Data Protection, Exemptions3
Which of the following would NOT be a personal data breach'?
A personal data breach is defined in Article 4(12) of the UK GDPR as ''a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed''. Personal data means any information relating to an identified or identifiable natural person, such as a name, an identification number, location data, an online identifier or factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Therefore, a personal data breach only occurs when the security incident affects personal data, not any other type of information. In this case, the accidental deletion of an organisation's information security policy from the public facing website would not be a personal data breach, as the policy does not contain any personal data. However, the other scenarios would be considered personal data breaches, as they involve the loss, alteration, destruction or unauthorised access to personal data of customers, employees or students.Reference:
ICO Guide to Data Protection, Personal Data Breaches3
In the terms of their relevance under data protection legislation, how can CCTV images recorded in a supermarket BEST be described'?
CCTV images recorded in a supermarket are personal data as they can be used to identify living human beings, either directly or indirectly, by their physical appearance, clothing, accessories, or other distinctive features. Personal data is defined in Article 4(1) of the GDPR as ''any information relating to an identified or identifiable natural person''. The GDPR applies to the processing of personal data by automated means, such as CCTV cameras, or by non-automated means that form part of a filing system, such as paper records. The other options are incorrect because:
CCTV images are not special category data as they do not reveal any of the sensitive information listed in Article 9(1) of the GDPR, such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, or biometric or genetic data. Special category data is subject to stricter conditions and safeguards under the GDPR, as it poses a higher risk to the rights and freedoms of individuals.
CCTV images are not biometric data in the terms of the definition stipulated in the GDPR. Biometric data is defined in Article 4(14) of the GDPR as ''personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data''. CCTV images do not result from specific technical processing, nor do they allow or confirm the unique identification of a natural person, unless they are combined with other data or identifiers.
The GDPR is not only engaged where CCTV images are accompanied by text or other identifier. The GDPR applies to any information that relates to an identified or identifiable natural person, regardless of whether it is accompanied by text or other identifier. CCTV images can relate to an identifiable natural person even if they do not contain any text or other identifier, as long as there is a possibility to single out or link the person to other data or factors.Reference:
Where a processor engages another processor ("sub-processor") to carry out processing activities on behalf of a controller, which of the following statements is CORRECT?
Article 28(2) of UK GDPR states that where a processor engages another processor (''sub-processor'') for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor shall be imposed on that other processor by way of a contract or other legal act under domestic law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of UK GDPR. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes. The other options are incorrect, as they do not reflect the requirements of UK GDPR for using a sub-processor. The processor cannot use a sub-processor without the written authorisation of the controller, regardless of whether it adheres to an approved code of conduct, signs a contract with the same obligations as the controller, or deems the processing to be low risk.Reference:
ICO guidance on contracts and liabilities between controllers and processors3