All Practice Exams

100+ Free BCS Practitioner Certificate in Data Protection Practice Questions

Pass your BCS Practitioner Certificate in Data Protection (PDP9, BCS, UK) exam on the first try — instant access, no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: BCS Practitioner Certificate in Data Protection Exam

40 Qs

Exam Questions

65% (26/40 marks)

Passing Score

£195.00

Exam Fee

Master the 40 scenario-based questions on the BCS Practitioner Data Protection exam with 100 free practice questions covering DPIAs, breach response, and international transfers.

Sample BCS Practitioner Certificate in Data Protection Practice Questions

Try these sample questions to test your BCS Practitioner Certificate in Data Protection exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Under Article 2(1) of the UK GDPR, which processing activity falls WITHIN the material scope of the legislation?
A.Processing of personal data by an individual strictly in the course of a purely personal or household activity
B.Automated processing of personal data stored in an electronic customer relationship management (CRM) database
C.Processing of anonymous statistical data that cannot identify any living individual
D.Processing of personal data concerning deceased individuals
Explanation: Article 2(1) specifies that UK GDPR applies to the processing of personal data wholly or partly by automated means, such as an electronic CRM database. Purely household activities are excluded under Article 2(2)(c). Anonymous data and data of deceased persons fall outside the scope of UK GDPR.
2A US-based e-commerce platform with no office or servers in the UK intentionally targets UK consumers by offering prices in GBP and providing local UK customer support. Under Article 3(2) of the UK GDPR, does the UK GDPR apply to this processing?
A.No, because the organisation has no physical establishment or servers within the United Kingdom
B.Yes, under the territorial scope provisions of Article 3(2)(a) because it offers goods or services to data subjects in the UK
C.No, because US companies are automatically subject only to US federal data privacy laws
D.Yes, but only if the US organisation registers directly with the Information Commissioner's Office (ICO) first
Explanation: Article 3(2)(a) establishes extraterritorial jurisdiction. UK GDPR applies to non-UK controllers or processors who process personal data of data subjects located in the UK where processing activities relate to offering goods or services to them, regardless of physical establishment.
3Which entity is defined under UK GDPR Article 4(7) as the natural or legal person that determines the purposes and means of processing personal data?
A.Data Processor
B.Data Controller
C.Data Protection Officer
D.Third Party
Explanation: Article 4(7) defines the Data Controller as the body that determines the essential 'why' (purposes) and 'how' (means) of processing. Processors only process data on behalf of and under instructions from the controller.
4A retail company collects customer contact details solely to deliver purchased products. Six months later, the marketing team uses these details to send unsolicited promotional newsletters without prior notification. Which Article 5 principle is directly breached?
A.Integrity and confidentiality (security)
B.Purpose limitation (Article 5(1)(b))
C.Data minimisation (Article 5(1)(c))
D.Storage limitation (Article 5(1)(e))
Explanation: The Purpose Limitation principle under Article 5(1)(b) dictates that personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those initial purposes.
5An online loan application form mandates that applicants submit their full medical history, even though creditworthiness is calculated solely from income and debt history. Which data protection principle is violated?
A.Accuracy (Article 5(1)(d))
B.Data minimisation (Article 5(1)(c))
C.Lawfulness, fairness and transparency (Article 5(1)(a))
D.Storage limitation (Article 5(1)(e))
Explanation: Article 5(1)(c) defines data minimisation: data collected must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Collecting irrelevant medical history violates this principle.
6Which statement accurately describes the Storage Limitation principle under Article 5(1)(e) of the UK GDPR?
A.Personal data must be stored on servers located exclusively inside the United Kingdom
B.Personal data must be kept in a form permitting identification of data subjects for no longer than is necessary for the processing purposes
C.All customer records must be permanently erased after exactly 30 days regardless of statutory retention duties
D.Data controllers must limit cloud storage capacity to prevent environmental waste
Explanation: Article 5(1)(e) requires personal data to be kept in identifiable form no longer than necessary. Controllers must set explicit retention periods or review criteria, allowing longer storage only for archiving in the public interest, scientific, or statistical purposes under Article 89.
7What is the primary responsibility of a Data Controller under the Accountability principle (Article 5(2))?
A.To publish all internal database passwords on a public website for transparency
B.To take responsibility for complying with the principles and be able to demonstrate that compliance
C.To report every routine internal email to the Information Commissioner's Office on a daily basis
D.To guarantee that zero security incidents or software bugs will ever occur
Explanation: Article 5(2) states that the controller shall be responsible for, and be able to demonstrate compliance with, the core principles of Article 5(1). This requires documentation, policies, audits, DPIAs, and records of processing activities.
8Which of the following describes 'pseudonymised' data under UK GDPR Article 4(5)?
A.Data that can no longer be attributed to a specific data subject without the use of additional information kept separately and securely
B.Data where all identifiers have been permanently removed such that re-identification is impossible under any circumstances
C.Public domain data published in local telephone directories
D.Data encrypted with a key that has been permanently destroyed
Explanation: Article 4(5) defines pseudonymisation as processing personal data in such a way that it can no longer be attributed to a specific data subject without additional information, provided that such additional information is kept separately and securely.
9A clinical research organisation replaces patient names with unique code numbers in a trial database. The master key linking codes to names is held in a locked safe by the Lead Investigator. How is this clinical dataset classified under UK GDPR?
A.Anonymised data, which is completely exempt from UK GDPR
B.Pseudonymised personal data, which remains subject to UK GDPR requirements
C.Public statistical data, requiring no legal basis
D.Commercial trade secret data, governed solely by intellectual property law
Explanation: Because the master key exists to link codes to identities, the coded data is pseudonymised personal data. Recital 26 clarifies that personal data which has undergone pseudonymisation is still personal data and falls under UK GDPR.
10How does the UK Data Protection Act 2018 (DPA 2018) interact with the UK GDPR?
A.The DPA 2018 completely repealed and replaced the UK GDPR in 2021
B.The DPA 2018 sits alongside the UK GDPR, setting out national derogations, exemptions, and provisions for law enforcement and intelligence processing
C.The UK GDPR applies only to private companies, while the DPA 2018 applies exclusively to local government councils
D.The DPA 2018 applies only to data transfers to EU member states
Explanation: The UK data protection regime comprises both the UK GDPR (which contains main principles, rights, and obligations) and the DPA 2018 (which supplements UK GDPR with domestic exemptions, Schedule 1 conditions, Part 3 law enforcement processing, and Part 4 intelligence services processing).

About the BCS Practitioner Certificate in Data Protection Exam

The BCS Practitioner Certificate in Data Protection (PDP9) tests advanced scenario-based application of UK GDPR, DPA 2018, DPIAs, DSAR management, and ICO regulatory compliance.

Questions

40 scored questions

Time Limit

90 minutes

Passing Score

65% (26/40 marks)

Exam Fee

£195.00 (BCS, The Chartered Institute for IT)

BCS Practitioner Certificate in Data Protection Exam Content Outline

25%

Lawful Bases & Complex Processing

Legitimate interest assessments, special category data, and consent management.

25%

DPIAs & Privacy by Design

Conducting DPIAs, risk threshold determination, and technical safeguards.

25%

Rights Management & DSARs

Handling complex DSAR exemptions, redaction, restriction, and erasure requests.

25%

Breach Incident & ICO Enforcement

72-hour ICO reporting, high-risk notifications, TRA assessments, and fine calculations.

How to Pass the BCS Practitioner Certificate in Data Protection Exam

What You Need to Know

  • Passing score: 65% (26/40 marks)
  • Exam length: 40 questions
  • Time limit: 90 minutes
  • Exam fee: £195.00

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

BCS Practitioner Certificate in Data Protection Study Tips from Top Performers

1Review all official BCS, The Chartered Institute for IT syllabus domain weightings and key terms before testing.
2Practice timed mock questions to build pace for the 90 minutes exam limit.
3Study answer explanations carefully to understand why incorrect distractors are wrong.

Frequently Asked Questions

How many questions are on the official BCS Data Protection Practitioner exam?

The official BCS Data Protection Practitioner exam consists of 40 questions to be completed within 90 minutes.

What is the passing score for the BCS Data Protection Practitioner exam?

The passing score for the BCS Data Protection Practitioner exam is 65% (26/40 marks).

How much does the BCS Data Protection Practitioner exam cost?

The official exam fee for the BCS Data Protection Practitioner is £195.00.