Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

PDP9 Exam Questions & Answers

BCS Practitioner Certificate in Data Protection  •  BCS

40 Questions Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample PDP9 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Article 57 of the UK GDPR states that the tasks of the Commissioner include -Select the INCORRECT answer

Correct Answer: C
Explanation:

Article 57 of the UK GDPR states that the tasks of the Commissioner include handling complaints raised by individuals/data subjects, providing general guidance to clarify the law, and advising UK Parliament on issues related to the protection of personal data, among other tasks. However, adopting consistency findings in cross-border data protection cases is not a task of the Commissioner, but of the European Data Protection Board (EDPB), which is an independent body composed of the heads of the supervisory authorities of the EU and EEA member states and the European Data Protection Supervisor. The EDPB is responsible for ensuring the consistent application of the EU GDPR across the EU and EEA, and for issuing opinions and decisions on matters of general application or affecting more than one member state. The UK is no longer part of the EU or the EEA, and therefore the EDPB does not have jurisdiction over the UK GDPR or the Commissioner. The UK has its own mechanism for ensuring consistency and cooperation with other countries, which involves the Commissioner and the Secretary of State.Reference:

Article 57 of the UK GDPR1

Article 63 and 64 of the EU GDPR4

ICO guidance on the UK GDPR and the EU GDPR5

Q2 MultipleChoice

Article 9(2)(c) of UK GDPR condition of processing special category data in the vital interests of the data subject is only applicable in which of the following circumstances:

Correct Answer: B
Explanation:

Article 9(2) of UK GDPR allows the processing of special category data when it is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent. This means that the data subject is unable to exercise their right to consent or object to the processing, either because they are unconscious, in a coma, suffering from a severe mental disorder, or otherwise unable to communicate their wishes. This condition is intended to cover emergency situations, such as life-threatening medical interventions, where the data subject's consent cannot be obtained in time. It does not apply when another lawful basis applies, when the data subject is physically absent but still capable of giving consent, or when the data subject refuses to consent.Reference:

Article 9(2) of UK GDPR1

ICO guidance on special category data2

Q3 MultipleChoice

Which of the following is NOT a key requirement of independent supervisory authorities?

Correct Answer: A
Explanation:

Independent supervisory authorities are public authorities that supervise, through investigative and corrective powers, the application of the data protection law. They provide expert advice on data protection issues and handle complaints lodged against violations of the UK GDPR and the relevant national laws. The UK GDPR sets out the key requirements for independent supervisory authorities in Chapter VI, which include the following:

They must operate independently and remain free from external influence, whether direct or indirect, and must neither seek nor take instructions from anybody.

They must have adequate human, technical and financial resources to perform their tasks and exercise their powers effectively.

They must review data protection impact assessments in cases of unmitigated high risk and provide prior consultation to controllers on such processing operations.

They must provide each other with mutual assistance and cooperate with each other and the European Data Protection Board to ensure the consistent application of the UK GDPR across the EU.

They must handle complaints lodged by data subjects or by bodies, organisations or associations representing them, and investigate the subject matter of the complaint to the extent appropriate.

They must adopt binding decisions on matters concerning the application of the UK GDPR and impose effective, proportionate and dissuasive administrative fines for infringements of the UK GDPR.

The UK GDPR does not specify any fixed term for the leadership of independent supervisory authorities, nor does it require their leadership to change every four years. However, it does require that the members of the supervisory authority must be appointed by means of a transparent procedure by the parliament, the government or the head of state of the Member State concerned, and that they must act with integrity, refrain from any action incompatible with their duties and not engage in any incompatible occupation during and after their term of office. The UK GDPR also allows Member States to provide for rules regarding the establishment, appointment, duration of the term and dismissal of the head or members of the supervisory authority.Reference:

UK GDPR, Chapter VI7

ICO website, About the ICO8

Q4 MultipleChoice

When were data protection rights first introduced into UK law'?

Correct Answer: C
Explanation:

Data protection rights were first introduced into UK law by the Data Protection Act 1984, which was enacted to implement the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data of 1981. The Data Protection Act 1984 established a set of principles for the processing of personal data by data users, such as obtaining consent, ensuring accuracy, and limiting retention. It also created a system of registration for data users and a Data Protection Registrar (later renamed as the Information Commissioner) to oversee and enforce the law. The Data Protection Act 1984 was replaced by the Data Protection Act 1998, which transposed the EU Data Protection Directive 1995 into UK law and extended the scope of data protection to cover manual as well as automated processing of personal data. The Data Protection Act 1998 was further amended by the Data Protection Act 2018, which incorporated the EU General Data Protection Regulation (GDPR) and the Law Enforcement Directive into UK law and made provisions for specific processing situations, such as national security, immigration, and journalism.Reference:

Data Protection Act 19844

Council of Europe Convention 1085

Data Protection Act 19986

Data Protection Act 20187

Q5 MultipleChoice

What does NOT have an exemption prescribed under schedule 3 of the Data Protection Act 2018?

Correct Answer: B
Explanation:

Schedule 3 of the Data Protection Act 2018 (DPA 2018) provides exemptions from some of the UK GDPR provisions for certain types of personal data processing, such as health data, social work data, education data, and child abuse data. These exemptions are intended to balance the rights and freedoms of data subjects with the public interest or the legitimate interests of data controllers in specific contexts. For example, the exemptions may allow data controllers to restrict the data subjects' access to their personal data, or to process their personal data without their consent, if complying with the UK GDPR would be likely to prejudice the purposes of the processing, such as the provision of health care, social work, education, or child protection. However, Schedule 3 of the DPA 2018 does not provide any exemption for credit checking agency data, which is personal data processed by credit reference agencies for the purposes of assessing the creditworthiness of individuals or organisations, or preventing fraud or money laundering. Credit checking agency data is subject to the UK GDPR provisions as normal, unless another exemption applies. For example, credit reference agencies may rely on the crime and taxation exemption in Schedule 2, Part 1, Paragraph 2 of the DPA 2018 if disclosing personal data to a data subject would be likely to prejudice the prevention or detection of crime, or the apprehension or prosecution of offenders.Reference:

Data Protection Act 2018, Schedule 31

ICO Guide to Data Protection, Exemptions2

ICO Guide to Data Protection, Credit3

Get access to all 40 verified questions with detailed answers.

Unlock All PDP9 Questions

Frequently Asked Questions

The PDP9 is the BCS Practitioner Certificate in Data Protection, designed for professionals who work with data protection and privacy in their organizations. It's ideal for data protection officers, compliance managers, IT professionals, and anyone responsible for implementing data protection practices within their organization.

The PDP9 exam covers key data protection principles, legal frameworks including GDPR and UK data protection law, data subject rights, security measures, international data transfers, and practical implementation of data protection policies. It also includes organizational accountability and breach notification requirements.

The PDP9 exam typically consists of 60 multiple-choice questions that must be completed within 90 minutes. A pass mark of 70% (42 out of 60 questions) is required to achieve certification.

Candidates should study the official BCS PDP9 syllabus and recommended textbooks, take practice exams to familiarize themselves with question formats, and consider enrolling in accredited training courses. Practical experience in data protection roles combined with structured study is highly beneficial for success.

The PDP9 certification is typically valid for three years from the date of achievement. To maintain certification, practitioners must either retake the exam or complete specified continuing professional development activities before the certification expires.
Exam Details
  • Exam CodePDP9
  • VendorBCS
  • Total Questions40
  • LanguageEnglish
  • Last UpdatedSep 3, 2026
4.9/5

Pass PDP9 First Time

Get all 40 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals