Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Article 57 of the UK GDPR states that the tasks of the Commissioner include -Select the INCORRECT answer
Article 57 of the UK GDPR states that the tasks of the Commissioner include handling complaints raised by individuals/data subjects, providing general guidance to clarify the law, and advising UK Parliament on issues related to the protection of personal data, among other tasks. However, adopting consistency findings in cross-border data protection cases is not a task of the Commissioner, but of the European Data Protection Board (EDPB), which is an independent body composed of the heads of the supervisory authorities of the EU and EEA member states and the European Data Protection Supervisor. The EDPB is responsible for ensuring the consistent application of the EU GDPR across the EU and EEA, and for issuing opinions and decisions on matters of general application or affecting more than one member state. The UK is no longer part of the EU or the EEA, and therefore the EDPB does not have jurisdiction over the UK GDPR or the Commissioner. The UK has its own mechanism for ensuring consistency and cooperation with other countries, which involves the Commissioner and the Secretary of State.Reference:
Describe the act of processing under the authority of a controller or processor as stipulated in UK GDPR Article 29.
Article 29 of UK GDPR states that the processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by domestic law. This means that the processor must follow the controller's directions on how to handle the personal data, and cannot use it for its own purposes or deviate from the agreed terms. The only exception is when the processor is obliged by law to process the data in a different way, for example, to comply with a court order or a legal obligation. The other options are not related to Article 29, but to other articles of UK GDPR, such as Article 25 (data protection by design and by default), Article 30 (records of processing activities), and Article 36 (prior consultation).Reference:
An individual applies for a job as a security guard The employer has had significant issues with the sickness record of past recruits They therefore decide to offer the position to the individual on the basis they request a copy of their medical record so that the employer can be assured that they are in a good state of health.
The Data Protection Officer has been asked to advise. What advice is MOST appropriate?
The Data Protection Act 2018 (DPA 2018) makes it a criminal offence for a person to require another person to make a subject access request for information about their health, convictions or cautions, or spent convictions, and to provide that information to the first person or a third person, as a condition of providing or offering to provide goods, facilities or services, or as a condition of entering into or continuing a contract. This is known as an enforced subject access request. The employer in this scenario is committing a criminal offence by offering the job to the individual on the condition that they request a copy of their medical record and provide it to the employer. The employer is also breaching the data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, and storage limitation, as they are processing health data, which is a special category of personal data, without a valid legal basis, without informing the individual of the purpose and legal basis of the processing, and without limiting the processing to what is necessary and relevant for the employment relationship. The employer should instead obtain the individual's explicit consent to request the health information directly from the relevant health professional, and only request the information that is necessary and proportionate for the specific role of a security guard.Reference:
Who is entitled to a private life by law in the UK?
The right to a private life is a fundamental human right that is protected by law in the UK. Article 8 of the European Convention on Human Rights (ECHR), which is incorporated into UK law by the Human Rights Act 1998, states that ''Everyone has the right to respect for his private and family life, his home and his correspondence''. This right applies to all individuals, regardless of their status, profession, or public exposure. The right to a private life covers aspects such as personal identity, personal relationships, physical and mental well-being, personal data, and correspondence. However, this right is not absolute and can be limited or interfered with by the state or other parties in certain circumstances, such as for the protection of national security, public safety, health, morals, or the rights and freedoms of others.Reference:
Which of the following is NOT a key requirement of independent supervisory authorities?
Independent supervisory authorities are public authorities that supervise, through investigative and corrective powers, the application of the data protection law. They provide expert advice on data protection issues and handle complaints lodged against violations of the UK GDPR and the relevant national laws. The UK GDPR sets out the key requirements for independent supervisory authorities in Chapter VI, which include the following:
They must operate independently and remain free from external influence, whether direct or indirect, and must neither seek nor take instructions from anybody.
They must have adequate human, technical and financial resources to perform their tasks and exercise their powers effectively.
They must review data protection impact assessments in cases of unmitigated high risk and provide prior consultation to controllers on such processing operations.
They must provide each other with mutual assistance and cooperate with each other and the European Data Protection Board to ensure the consistent application of the UK GDPR across the EU.
They must handle complaints lodged by data subjects or by bodies, organisations or associations representing them, and investigate the subject matter of the complaint to the extent appropriate.
They must adopt binding decisions on matters concerning the application of the UK GDPR and impose effective, proportionate and dissuasive administrative fines for infringements of the UK GDPR.
The UK GDPR does not specify any fixed term for the leadership of independent supervisory authorities, nor does it require their leadership to change every four years. However, it does require that the members of the supervisory authority must be appointed by means of a transparent procedure by the parliament, the government or the head of state of the Member State concerned, and that they must act with integrity, refrain from any action incompatible with their duties and not engage in any incompatible occupation during and after their term of office. The UK GDPR also allows Member States to provide for rules regarding the establishment, appointment, duration of the term and dismissal of the head or members of the supervisory authority.Reference:
40 questions covering all exam domains
Exam domains verified against: Official BCS PDP9 exam guide, last checked September 2026.
Understand the foundational concepts of data protection and privacy within the UK and EU legal framework. This area covers the historical development of data protection law and how GDPR applies across different territories and jurisdictions.
Master the core terminology and principles that underpin data protection regulations. Learn how these principles govern the lawful processing of personal data in practice.
Study the six lawful bases for processing under Article 6 of UK GDPR and the conditions for processing special category and criminal offence data. Understanding these forms the legal foundation for all data handling decisions.
Examine the distinct responsibilities of controllers and processors and the requirements for joint controller arrangements. Learn when data processing agreements are necessary and what they must contain.
Sample question from this domain above: Q2
Understand the principles governing transfers of personal data to third countries and the legal mechanisms available. Recognise the practical compliance challenges that arise from different transfer mechanisms.
Learn the comprehensive rights available to individuals under GDPR including access, rectification and erasure. Understand the restrictions and exemptions that may limit these rights in specific circumstances.
Explore the powers and responsibilities of data protection authorities across the EU and the specific role of the UK Information Commissioner's Office. Understand how these bodies enforce compliance and support organisations.
Sample question from this domain above: Q1
Analyse what constitutes a personal data breach and the mandatory reporting obligations and timescales. Learn about the potential sanctions, liabilities and the role of courts in enforcing data protection rights.
Understand the heightened protections that apply when organisations process the personal data of children. Learn the specific consent and parental involvement requirements that differ from adult data protection.
Study the distinct obligations that apply to public authorities under the Data Protection Act 2018 and UK GDPR. Learn about the mandatory appointment of Data Protection Officers and relevant exemptions for health and education.
Understand how PECR complements and extends GDPR to regulate electronic marketing and communications. Learn the relationship between PECR and GDPR and the specific rules that apply to direct marketing.
Apply data protection principles to employment, video surveillance and cookies in real business contexts. Learn how data sharing is governed and what ICO codes of practice require in these specific sectors.
Analyse the opportunities and risks that AI systems present for individuals and organisations under data protection law. Learn how to complete a Data Protection Impact Assessment when deploying AI technologies.
Sample question from this domain above: Q3
Common questions about the exam itself