BCS PDP9 Practice Exam Questions & Answers

5 Free Questions · Last reviewed: September 16, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

BCS PDP9 Exam Details

Key details for this exam, checked against the published exam outline

40 Practice Questions (Our Bank)
90 minutes Exam Duration
65% Passing Score
Exam Code
PDP9
Full Name
BCS Practitioner Certificate in Data Protection
Issuing Body
BCS, The Chartered Institute for IT
Question Format (Our Bank)
Multiple Choice
Eligibility
Experience in data protection or completion of BCS Foundation Certificate in Data Protection
Practice Questions

Free PDP9 Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our PDP9 exam preparation team, who also write the explanation shown with each one. How we research and review these pages

Article 57 of the UK GDPR states that the tasks of the Commissioner include -Select the INCORRECT answer

Correct Answer: C
Explanation

Article 57 of the UK GDPR states that the tasks of the Commissioner include handling complaints raised by individuals/data subjects, providing general guidance to clarify the law, and advising UK Parliament on issues related to the protection of personal data, among other tasks. However, adopting consistency findings in cross-border data protection cases is not a task of the Commissioner, but of the European Data Protection Board (EDPB), which is an independent body composed of the heads of the supervisory authorities of the EU and EEA member states and the European Data Protection Supervisor. The EDPB is responsible for ensuring the consistent application of the EU GDPR across the EU and EEA, and for issuing opinions and decisions on matters of general application or affecting more than one member state. The UK is no longer part of the EU or the EEA, and therefore the EDPB does not have jurisdiction over the UK GDPR or the Commissioner. The UK has its own mechanism for ensuring consistency and cooperation with other countries, which involves the Commissioner and the Secretary of State.Reference:

Article 57 of the UK GDPR1

Article 63 and 64 of the EU GDPR4

ICO guidance on the UK GDPR and the EU GDPR5

Describe the act of processing under the authority of a controller or processor as stipulated in UK GDPR Article 29.

Correct Answer: B
Explanation

Article 29 of UK GDPR states that the processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by domestic law. This means that the processor must follow the controller's directions on how to handle the personal data, and cannot use it for its own purposes or deviate from the agreed terms. The only exception is when the processor is obliged by law to process the data in a different way, for example, to comply with a court order or a legal obligation. The other options are not related to Article 29, but to other articles of UK GDPR, such as Article 25 (data protection by design and by default), Article 30 (records of processing activities), and Article 36 (prior consultation).Reference:

Article 29 of UK GDPR1

ICO guidance on controllers and processors2

An individual applies for a job as a security guard The employer has had significant issues with the sickness record of past recruits They therefore decide to offer the position to the individual on the basis they request a copy of their medical record so that the employer can be assured that they are in a good state of health.

The Data Protection Officer has been asked to advise. What advice is MOST appropriate?

Correct Answer: D
Explanation

The Data Protection Act 2018 (DPA 2018) makes it a criminal offence for a person to require another person to make a subject access request for information about their health, convictions or cautions, or spent convictions, and to provide that information to the first person or a third person, as a condition of providing or offering to provide goods, facilities or services, or as a condition of entering into or continuing a contract. This is known as an enforced subject access request. The employer in this scenario is committing a criminal offence by offering the job to the individual on the condition that they request a copy of their medical record and provide it to the employer. The employer is also breaching the data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, and storage limitation, as they are processing health data, which is a special category of personal data, without a valid legal basis, without informing the individual of the purpose and legal basis of the processing, and without limiting the processing to what is necessary and relevant for the employment relationship. The employer should instead obtain the individual's explicit consent to request the health information directly from the relevant health professional, and only request the information that is necessary and proportionate for the specific role of a security guard.Reference:

Section 184 of the DPA 20183

ICO guidance on enforced subject access requests4

ICO guidance on special category data5

Who is entitled to a private life by law in the UK?

Correct Answer: A
Explanation

The right to a private life is a fundamental human right that is protected by law in the UK. Article 8 of the European Convention on Human Rights (ECHR), which is incorporated into UK law by the Human Rights Act 1998, states that ''Everyone has the right to respect for his private and family life, his home and his correspondence''. This right applies to all individuals, regardless of their status, profession, or public exposure. The right to a private life covers aspects such as personal identity, personal relationships, physical and mental well-being, personal data, and correspondence. However, this right is not absolute and can be limited or interfered with by the state or other parties in certain circumstances, such as for the protection of national security, public safety, health, morals, or the rights and freedoms of others.Reference:

Article 8 of the ECHR1

Human Rights Act 19982

ICO Guide to Data Protection3

Which of the following is NOT a key requirement of independent supervisory authorities?

Correct Answer: A
Explanation

Independent supervisory authorities are public authorities that supervise, through investigative and corrective powers, the application of the data protection law. They provide expert advice on data protection issues and handle complaints lodged against violations of the UK GDPR and the relevant national laws. The UK GDPR sets out the key requirements for independent supervisory authorities in Chapter VI, which include the following:

They must operate independently and remain free from external influence, whether direct or indirect, and must neither seek nor take instructions from anybody.

They must have adequate human, technical and financial resources to perform their tasks and exercise their powers effectively.

They must review data protection impact assessments in cases of unmitigated high risk and provide prior consultation to controllers on such processing operations.

They must provide each other with mutual assistance and cooperate with each other and the European Data Protection Board to ensure the consistent application of the UK GDPR across the EU.

They must handle complaints lodged by data subjects or by bodies, organisations or associations representing them, and investigate the subject matter of the complaint to the extent appropriate.

They must adopt binding decisions on matters concerning the application of the UK GDPR and impose effective, proportionate and dissuasive administrative fines for infringements of the UK GDPR.

The UK GDPR does not specify any fixed term for the leadership of independent supervisory authorities, nor does it require their leadership to change every four years. However, it does require that the members of the supervisory authority must be appointed by means of a transparent procedure by the parliament, the government or the head of state of the Member State concerned, and that they must act with integrity, refrain from any action incompatible with their duties and not engage in any incompatible occupation during and after their term of office. The UK GDPR also allows Member States to provide for rules regarding the establishment, appointment, duration of the term and dismissal of the head or members of the supervisory authority.Reference:

UK GDPR, Chapter VI7

ICO website, About the ICO8

Get Full Access

40 questions covering all exam domains

Study Guide

What the BCS PDP9 Exam Covers

Exam domains verified against: Official BCS PDP9 exam guide, last checked September 2026.

Domain 1: CONTEXT OF DATA PROTECTION LEGISLATION 7.5%

Understand the foundational concepts of data protection and privacy within the UK and EU legal framework. This area covers the historical development of data protection law and how GDPR applies across different territories and jurisdictions.

Domain 2: PRINCIPLES OF DATA PROTECTION AND APPLICABLE TERMINOLOGY 5%

Master the core terminology and principles that underpin data protection regulations. Learn how these principles govern the lawful processing of personal data in practice.

Domain 3: LAWFUL BASES FOR PROCESSING PERSONAL DATA 5%

Study the six lawful bases for processing under Article 6 of UK GDPR and the conditions for processing special category and criminal offence data. Understanding these forms the legal foundation for all data handling decisions.

Domain 4: OBLIGATIONS OF CONTROLLERS, JOINT CONTROLLERS AND DATA PROCESSORS 10%

Examine the distinct responsibilities of controllers and processors and the requirements for joint controller arrangements. Learn when data processing agreements are necessary and what they must contain.

Sample question from this domain above: Q2

Domain 5: INTERNATIONAL DATA TRANSFERS UNDER EU AND UK GDPR 2.5%

Understand the principles governing transfers of personal data to third countries and the legal mechanisms available. Recognise the practical compliance challenges that arise from different transfer mechanisms.

Domain 6: DATA SUBJECT RIGHTS 5%

Learn the comprehensive rights available to individuals under GDPR including access, rectification and erasure. Understand the restrictions and exemptions that may limit these rights in specific circumstances.

Domain 7: THE ROLE OF INDEPENDENT SUPERVISORY AUTHORITIES (ISAS) AND THE ICO 7.5%

Explore the powers and responsibilities of data protection authorities across the EU and the specific role of the UK Information Commissioner's Office. Understand how these bodies enforce compliance and support organisations.

Sample question from this domain above: Q1

Domain 8: BREACHES, ENFORCEMENT AND LIABILITY 12.5%

Analyse what constitutes a personal data breach and the mandatory reporting obligations and timescales. Learn about the potential sanctions, liabilities and the role of courts in enforcing data protection rights.

Domain 9: PROCESSING OF PERSONAL DATA IN RELATION TO CHILDREN 2.5%

Understand the heightened protections that apply when organisations process the personal data of children. Learn the specific consent and parental involvement requirements that differ from adult data protection.

Domain 10: SPECIFIC PROVISIONS IN DATA PROTECTION LEGISLATION OF PARTICULAR RELEVANCE TO PUBLIC AUTHORITIES 7.5%

Study the distinct obligations that apply to public authorities under the Data Protection Act 2018 and UK GDPR. Learn about the mandatory appointment of Data Protection Officers and relevant exemptions for health and education.

Domain 11: PRIVACY AND ELECTRONIC COMMUNICATIONS (EC DIRECTIVE) REGULATIONS (PECR) 2003 AND SUBSEQUENT AMENDMENTS TO 2021 5%

Understand how PECR complements and extends GDPR to regulate electronic marketing and communications. Learn the relationship between PECR and GDPR and the specific rules that apply to direct marketing.

Domain 12: APPLICATION OF DATA PROTECTION LEGISLATION IN KEY AREAS OF INDUSTRY 10%

Apply data protection principles to employment, video surveillance and cookies in real business contexts. Learn how data sharing is governed and what ICO codes of practice require in these specific sectors.

Sample questions from this domain above: Q4Q5

Domain 13: AI AND THE PROCESSING OF PERSONAL DATA 5%

Analyse the opportunities and risks that AI systems present for individuals and organisations under data protection law. Learn how to complete a Data Protection Impact Assessment when deploying AI technologies.

Sample question from this domain above: Q3

FAQ

PDP9 Exam FAQ

Common questions about the exam itself

What prior experience do I need for the PDP9 exam?
The PDP9 is designed for experienced data protection professionals. Most candidates either hold the BCS Foundation Certificate in Data Protection or have practical responsibility for data protection within their organisation. You should already understand basic GDPR concepts before taking this exam.
How many questions are on the PDP9 exam and how long do I have?
The PDP9 consists of 40 multiple-choice questions that you must complete in 90 minutes. This works out to roughly two minutes per question on average, though some may require longer analysis than others.
What score do I need to pass the PDP9 exam?
You need to achieve a minimum score of 65% to pass the PDP9 exam. This means you need to answer at least 26 out of 40 questions correctly.
Which objective area of PDP9 is the most difficult and how should I study it?
Breaches, Enforcement and Liability is the heaviest weighted domain at 12.5% and covers complex material about reporting obligations, sanctions and court procedures. Focus on understanding the specific timescales for breach notification and the different types of penalties that apply.
How long does it realistically take to prepare for PDP9?
Most candidates with data protection background experience need 40 to 60 hours of study time to prepare. This includes studying the syllabus, working through case studies, and practising with sample questions to build confidence in application.
Can I retake the PDP9 exam if I fail and how does rescheduling work?
You can retake the exam if you do not pass on your first attempt. Rescheduling policies depend on your exam delivery provider. Contact the centre where you are scheduled to sit the exam for their specific rules on retakes and rebooking.
Is the PDP9 certification permanent or does it need renewal?
The BCS Practitioner Certificate in Data Protection does not expire and requires no renewal. Once you pass the exam, your certification remains valid for life.
What job roles does the PDP9 certification lead to?
This certification is suited for data protection officers, data protection specialists, privacy managers and compliance officers. It demonstrates operational capability to work on complex data protection activities within organisations of any size.
How does PDP9 relate to the BCS Foundation Certificate in Data Protection?
PDP9 is the practitioner level certification that builds on the Foundation level knowledge. Foundation is introductory and covers core GDPR principles. PDP9 requires deeper understanding and practical experience with how to apply data protection law in real business scenarios.
What topics in PDP9 are most relevant to my everyday work in data protection?
The lawful bases for processing, data subject rights, and international data transfers are immediately applicable to most organisations. Breaches and reporting obligations are also critical because they require swift action when incidents occur. These four areas together cover roughly 35% of the exam weight.