FC-DP Sample Questions

FC-DP Sample Questions & Answers

The accountability principle, including DPIAs, carries the biggest share, ahead of data subject rights, terminology and lawful bases for processing, controller obligations, breaches and enforcement, and smaller topics like UK history, international transfers and PECR.

Launch the full FC-DP simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    Principles of Data Protection and Applicable Terminology · Key terminology definitions

    An e-commerce enterprise replaces direct customer identifiers (like names and emails) in its analytics database with randomly generated reference numbers. The mapping table linking these numbers back to the original identities is stored securely on a separate, heavily encrypted server with strict access controls. How does the UK GDPR classify the data in the analytics database?

    Show answer & explanation

    Correct answer: B

    Pseudonymisation is a security measure where identifiers are replaced with pseudonyms. Because the mapping key still exists (even if kept separately and securely), the data can be re-identified. Therefore, under Article 4 and Recital 26, pseudonymised data remains personal data and is fully subject to the UK GDPR.

  2. Question 2Intermediate

    Principles of Data Protection and Applicable Terminology · Key terminology definitions

    "HealthTech Solutions" provides a cloud-based patient management system to "City General Hospital". The Hospital decides what patient data is collected, sets the retention periods, and uses the system to manage daily appointments. HealthTech Solutions decides which cloud infrastructure to use (Microsoft Azure), handles routine software maintenance, and applies security patches without altering the data's purpose. Under the UK GDPR, what are the respective roles of these entities?

    Show answer & explanation

    Correct answer: D

    The Controller (City General Hospital) determines the "purposes and essential means" of processing (why the data is collected and what it is used for). The Processor (HealthTech Solutions) processes data on behalf of the controller and can decide on "non-essential means" like the specific hardware or software architecture. Microsoft Azure, engaged by the processor, acts as a sub-processor.

    graph TD A[City General Hospital] -->|Determines Purpose & Essential Means| B(Controller) C[HealthTech Solutions] -->|Processes on behalf of Controller| D(Processor) E[Microsoft Azure] -->|Engaged by Processor| F(Sub-processor) B -. Written Contract Art 28 .-> D D -. Prior Authorization .-> F

  3. Question 3Beginner

    Principles of Data Protection and Applicable Terminology · Key terminology definitions

    Which of the following data points collected by a fitness tracking mobile application is explicitly classified as "special category data" under Article 9 of the UK GDPR?

    Show answer & explanation

    Correct answer: B

    Under Article 9, data concerning health is classified as special category data. Heart rate and blood pressure readings are clear indicators of a person's physical health status. General tracking like step counts, without revealing specific health conditions, is generally not considered special category unless combined with other data to infer health status.

  4. Question 4Intermediate

    Principles of Data Protection and Applicable Terminology · Six data protection principles (Article 5)

    A retail bank originally collected customer email addresses exclusively for the purpose of sending monthly digital account statements. Two years later, the bank's marketing department decides to use this existing email database to send promotional offers for a new credit card product, without obtaining new consent or updating their privacy notice. Which data protection principle has the bank most directly violated?

    Show answer & explanation

    Correct answer: C

    Article 5(1)(b) dictates that personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Using data collected for administrative account updates for direct marketing is an incompatible further processing.

  5. Question 5Intermediate

    Principles of Data Protection and Applicable Terminology · Six data protection principles (Article 5)

    A local authority implements an automated script that permanently deletes all unsuccessful job applicant CVs exactly six months after the recruitment campaign concludes, aligning with the timeframe during which an applicant could bring an employment tribunal claim. Which UK GDPR principle is this technical measure primarily designed to satisfy?

    Show answer & explanation

    Correct answer: D

    Article 5(1)(e) (Storage limitation) requires that personal data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Implementing automated deletion at the end of a justified retention period directly satisfies this principle.

  6. Question 6AdvancedSelect 2

    Principles of Data Protection and Applicable Terminology · Six data protection principles (Article 5)

    A technology firm is developing an AI-driven recruitment screening tool. To comply with the "Data Minimisation" principle (Article 5(1)(c)), which TWO actions should the development team take? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    Removing irrelevant attributes before processing ensures the system does not ingest or analyze data that isn't necessary for the purpose, directly satisfying the data minimisation principle.

    Data minimisation requires data to be adequate, relevant, and limited to what is necessary. Ensuring the AI only processes necessary fields fulfills this.

Ready for the real thing?

The full FC-DP simulator has every exam-style question, timed mode, and instant scoring.

Go to the FC-DP simulator →