1. Lawful Basis & Purpose Limitation beginner Multiple choice

    A European travel marketplace of Booking.com's shape holds the same guest email twice: once captured at checkout so the booking confirmation can be sent, once captured at newsletter sign-up. The data team wants a single golden customer record and cannot see the objection. Which data model keeps the merge lawful?

    3 min answer purpose-limitationgolden-recordmdmconsent
  2. Privacy by Design beginner Multiple choice

    A food-delivery app of Zomato's shape must refuse alcohol orders to under-18s. The sign-up form asks for a full date of birth and the team is about to store it on the user row alongside the address. What should the account record hold instead, and what does the full date of birth cost you later?

    3 min answer data-minimisationderived-attributesgdpr-article-25age-verification
  3. Records Retention & Legal Hold beginner

    A policy says customer records are deleted seven years after the relationship ends. A team implements it literally and still fails the audit. What actually starts the clock, and what does that force into the design?

    2 min answer retentiondeletionobject-lockcrypto-shredding
  4. Regulatory & Data Protection Architecture beginner

    Marketing has signed with an analytics vendor and the vendor's SDK is due in next week's mobile release. Legal asks whether you are the controller or the processor for what that SDK collects. Why does the answer change the architecture rather than only the paperwork?

    2 min answer controllerprocessorsub-processorssdk
  5. Third-Party Risk beginner

    A supplier provides an ISO 27001 certificate in response to your security assessment. What does the certificate actually tell you, and what does it not?

    3 min answer certificationthird-party-riskassurancescope