Free BCS PDP9 Exam Actual Questions & Explanations

Last updated on: Aug 7, 2026
Author: Joseph Kowalski (BCS Certified Data Protection Specialist)

The BCS Practitioner Certificate in Data Protection (PDP9) validates your ability to apply data protection legislation in real-world scenarios. This exam is designed for professionals working in compliance, IT security, legal, or operational roles who need to demonstrate practical knowledge of GDPR, UK GDPR, and related regulations. This page maps the exam syllabus, explains question formats, and guides your preparation strategy so you can study efficiently and confidently. Whether you're new to data protection or building on existing knowledge, understanding the PDP9 structure helps you focus on what matters most within the Information security and data protection certifications pathway.

PDP9 Exam Syllabus & Core Topics

Use this topic map to guide your study for BCS PDP9 (BCS Practitioner Certificate in Data Protection) within the Information security and data protection certifications path.

  • Context of Data Protection Legislation: Understand the historical development and scope of GDPR and UK GDPR. You must recognize which laws apply to different organizations and jurisdictions.
  • Principles of Data Protection and Applicable Terminology: Demonstrate knowledge of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. Apply these principles to evaluate whether an organization's data handling meets legal requirements.
  • Lawful Bases for Processing Personal Data: Identify and justify the correct legal basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) for different processing activities. Assess whether organizations have selected appropriate bases for their operations.
  • Obligations of Controllers, Joint Controllers and Data Processors: Explain the roles and responsibilities of each party. Recognize when contracts, records, and governance structures satisfy legal obligations.
  • International Data Transfers Under EU and UK GDPR: Evaluate transfer mechanisms including adequacy decisions, Standard Contractual Clauses, and Binding Corporate Rules. Identify when transfers are compliant and what safeguards are required.
  • Data Subject Rights: Apply the right to access, rectification, erasure, restriction, portability, and objection. Determine how organizations must respond to requests and handle exceptions.
  • The Role of Independent Supervisory Authorities (ISAs) and the ICO: Understand the powers and responsibilities of data protection authorities. Recognize when to escalate issues and how enforcement actions work.
  • Breaches, Enforcement and Liability: Identify security incidents, assess breach notification obligations, and understand penalties and liability exposure. Evaluate how organizations should respond to and report breaches.
  • Processing of Personal Data in Relation to Children: Apply age verification and consent rules. Recognize special protections and when parental consent is required.
  • Specific Provisions in Data Protection Legislation of Particular Relevance to Public Authorities: Understand obligations unique to government and public sector bodies. Apply public task exemptions and transparency requirements correctly.
  • Privacy and Electronic Communications (EC Directive) Regulations (PECR) 2003 and Subsequent Amendments to 2021: Apply rules for marketing calls, emails, and texts. Recognize when PECR overlaps with GDPR and which rules take precedence.
  • Application of Data Protection Legislation in Key Areas of Industry: Analyze sector-specific requirements in healthcare, finance, education, and employment. Adapt principles to real industry scenarios.
  • AI and the Processing of Personal Data: Understand how AI and automated decision-making interact with data protection law. Assess transparency and fairness obligations for algorithmic processing.

Question Formats & What They Test

PDP9 assesses both foundational knowledge and the ability to apply data protection concepts to realistic business situations. Questions are designed to test whether you can interpret legislation, make compliant decisions, and advise on practical implementation.

  • Multiple Choice: Test core definitions, key terminology, and recall of specific rules. Examples include identifying the correct legal basis, naming a data subject right, or recognizing which regulation applies to a scenario.
  • Scenario-Based Items: Present workplace situations (e.g., a data breach, a cross-border transfer, or a marketing campaign) and ask you to select the most appropriate response or identify compliance gaps. These items reward practical reasoning over memorization.
  • Application Questions: Require you to explain how principles like lawfulness or transparency apply to a given context, or to evaluate whether an organization's process meets legal standards.

Questions progress in difficulty and reflect real-world complexity, ensuring that passing candidates can confidently handle data protection responsibilities in their roles.

Preparation Guidance

Effective preparation combines structured topic review with regular practice and self-assessment. Map each syllabus domain to weekly study goals, practice applying concepts to scenarios, and use timed drills to build exam pacing. This approach prevents last-minute cramming and reinforces the practical reasoning skills the exam measures.

  • Allocate one week per major topic cluster (e.g., principles and terminology, processing lawfulness, rights and remedies, sector-specific rules). Track progress against the 14-point syllabus.
  • Work through practice questions in mixed sets (not grouped by topic) to simulate exam conditions and identify weak areas early.
  • Review question explanations carefully, especially for items you answered incorrectly. Understand the "why" behind each correct answer.
  • Link concepts across domains: for example, trace how a legal basis connects to a data subject right, or how a breach triggers both ISA involvement and liability. This cross-domain thinking is essential for scenario questions.
  • Complete a full-length timed practice test in the final week. Review results, focus on remaining gaps, and practice pacing to ensure you finish comfortably within the time limit.
  • Use flashcards or quick-reference notes for definitions, legal bases, and ISA responsibilities. Quick recall of terminology frees mental energy for scenario analysis.

Explore other BCS certifications: view all BCS exams.

Get the PDF & Practice Test

Strengthen your preparation with up-to-date resources from validexamdumps.com. These materials align to PDP9 and cover practical scenarios with clear explanations.

  • Q&A PDF with explanations: Topic-mapped questions that clarify why correct options are right and others aren't. Ideal for offline study and quick reference.
  • Practice Test: Realistic items in timed and untimed modes, with progress tracking and detailed review of every answer.
  • Focused coverage: Aligned to all 14 syllabus domains, context of legislation, principles, lawful bases, controller obligations, international transfers, data subject rights, ISA roles, breaches, children's data, public authority rules, PECR, industry applications, and AI processing, so you study what matters most.
  • Regular updates: Content refreshes that reflect syllabus changes and emerging guidance from the ICO and other authorities.

Visit the exam page to download the PDF, Online Practice Test, or get a Bundle Discount offer for both formats: BCS Practitioner Certificate in Data Protection.

Frequently Asked Questions

Which topics typically carry the most weight in the PDP9 exam?

Lawful bases for processing, data subject rights, and controller obligations are core to most exam items because they directly impact how organizations operate. Principles and terminology also appear frequently because they underpin all other topics. Allocate roughly 30% of your study time to these three domains and distribute the remaining time across sector-specific applications, breaches, and emerging areas like AI.

How do data protection principles connect to real compliance workflows?

The seven principles (lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, and storage limitation) form the foundation for every data protection process. In practice, they guide privacy impact assessments, data retention policies, consent forms, and breach response procedures. Understanding how each principle applies to specific workflows, such as customer onboarding, employee records, or marketing campaigns, helps you answer scenario questions confidently.

What are the most common mistakes candidates make on PDP9?

Confusing legal bases (e.g., mixing consent with legitimate interest) and misidentifying which regulation applies (GDPR vs. PECR vs. sector-specific rules) are frequent errors. Candidates also sometimes overlook exceptions and special cases, such as public task exemptions or the stricter rules for children's data. Careful reading of scenario details and practice with mixed-topic questions help avoid these pitfalls.

How much practical experience in data protection helps, and what should I prioritize?

Direct experience with privacy impact assessments, breach handling, or data transfer documentation is valuable but not required. If you have access to real examples, review how your organization documents legal bases, manages consent, or responds to subject access requests. Prioritize understanding the practical steps behind each principle and obligation so that you can apply them to unfamiliar scenarios on the exam.

What is the best strategy for the final week before the exam?

Shift from learning new topics to consolidation and practice. Complete at least one full-length timed practice test to identify remaining weak areas, then focus revision on those domains. Review key definitions and legal bases using flashcards or summary notes. On the day before the exam, do a light review of high-impact topics (lawful bases, rights, controller obligations) and get adequate sleep to maintain focus during the test.

Question No. 1

Which one task are supervisory authorities NOT required to carry out under Article 57(1 )(f) of the UK GDPR? Select the CORRECT answer.

Show Answer Hide Answer
Correct Answer: C

Article 57(1)(f) of the UK GDPR requires the supervisory authority (the ICO in the UK) to handle complaints lodged by a data subject, investigate the subject matter of the complaint, and inform the complainant of the progress and the outcome of the investigation. It also requires the supervisory authority to cooperate with other supervisory authorities if the complaint involves cross-border processing. However, it does not require the supervisory authority to mediate between the complainant and the controller or processor against which the complaint has been lodged, to resolve the complaint. This is not a task of the supervisory authority under the UK GDPR, although it may be possible in some cases as a way of achieving an amicable solution.Reference:

Article 57(1)(f) of the UK GDPR1

ICO and complaints2


Question No. 2

Under which circumstances can the 'domestic purposes' exemption be used to justify non-compliance with the Data Protection Act 2018?

A) An individual sells make up products for commission and uses social media to promote products to friends and family

B) A couple are planning their daughter's wedding and use excel to store contact details and dietary needs of the guests

C) An individual employs a babysitter and stores her bank details in an encrypted document in order to make payments

D) A pansh council keeps a spreadsheet to manage bookings of the village hall, it contains only contact information and time slots

E) A group of students are arranging a house party and using social media to invite people that they do and do not know

Show Answer Hide Answer
Correct Answer: C

The domestic purposes exemption applies to personal data processed by an individual only for the purposes of their personal, family or household affairs. This means that the processing has no connection to any professional or commercial activity. Examples of such processing include writing to friends and family, taking pictures for personal enjoyment, or keeping an address book. However, the exemption does not apply if the individual processes personal data outside the reasonable expectations of the data subject, or if the processing causes unwarranted harm to the data subject's interests. Therefore, the exemption can be used to justify non-compliance with the Data Protection Act 2018 in scenarios B and C, where the processing is purely personal and does not affect the rights and freedoms of others. However, the exemption cannot be used in scenarios A, D and E, where the processing has a professional or commercial element, or involves sharing personal data with third parties without consent or legitimate interest.Reference:

Data Protection Act 2018, Schedule 2, Part 1, Paragraph 21

ICO Guide to Data Protection, Domestic Purposes2

ICO Guide to Data Protection, Exemptions3


Question No. 3

Which of the following would NOT be a personal data breach'?

Show Answer Hide Answer
Correct Answer: A

A personal data breach is defined in Article 4(12) of the UK GDPR as ''a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed''. Personal data means any information relating to an identified or identifiable natural person, such as a name, an identification number, location data, an online identifier or factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Therefore, a personal data breach only occurs when the security incident affects personal data, not any other type of information. In this case, the accidental deletion of an organisation's information security policy from the public facing website would not be a personal data breach, as the policy does not contain any personal data. However, the other scenarios would be considered personal data breaches, as they involve the loss, alteration, destruction or unauthorised access to personal data of customers, employees or students.Reference:

UK GDPR, Article 4(12)1

UK GDPR, Article 4(1)2

ICO Guide to Data Protection, Personal Data Breaches3


Question No. 4

In the terms of their relevance under data protection legislation, how can CCTV images recorded in a supermarket BEST be described'?

Show Answer Hide Answer
Correct Answer: D

CCTV images recorded in a supermarket are personal data as they can be used to identify living human beings, either directly or indirectly, by their physical appearance, clothing, accessories, or other distinctive features. Personal data is defined in Article 4(1) of the GDPR as ''any information relating to an identified or identifiable natural person''. The GDPR applies to the processing of personal data by automated means, such as CCTV cameras, or by non-automated means that form part of a filing system, such as paper records. The other options are incorrect because:

CCTV images are not special category data as they do not reveal any of the sensitive information listed in Article 9(1) of the GDPR, such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, or biometric or genetic data. Special category data is subject to stricter conditions and safeguards under the GDPR, as it poses a higher risk to the rights and freedoms of individuals.

CCTV images are not biometric data in the terms of the definition stipulated in the GDPR. Biometric data is defined in Article 4(14) of the GDPR as ''personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data''. CCTV images do not result from specific technical processing, nor do they allow or confirm the unique identification of a natural person, unless they are combined with other data or identifiers.

The GDPR is not only engaged where CCTV images are accompanied by text or other identifier. The GDPR applies to any information that relates to an identified or identifiable natural person, regardless of whether it is accompanied by text or other identifier. CCTV images can relate to an identifiable natural person even if they do not contain any text or other identifier, as long as there is a possibility to single out or link the person to other data or factors.Reference:

GDPR, Article 4(1)1

GDPR, Article 2(1)2

GDPR, Article 9(1)3

GDPR, Article 4(14)4


Question No. 5

Where a processor engages another processor ("sub-processor") to carry out processing activities on behalf of a controller, which of the following statements is CORRECT?

Show Answer Hide Answer
Correct Answer: A

Article 28(2) of UK GDPR states that where a processor engages another processor (''sub-processor'') for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor shall be imposed on that other processor by way of a contract or other legal act under domestic law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of UK GDPR. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes. The other options are incorrect, as they do not reflect the requirements of UK GDPR for using a sub-processor. The processor cannot use a sub-processor without the written authorisation of the controller, regardless of whether it adheres to an approved code of conduct, signs a contract with the same obligations as the controller, or deems the processing to be low risk.Reference:

Article 28(2) of UK GDPR1

ICO guidance on contracts and liabilities between controllers and processors3