Skip to content

FC-DP BCS Foundation Certificate in Data Protection Practice Questions

Prepare for FC-DP with more than an answer.

135 questions in the full set12 sample questionsUpdated Mar 12, 2026
Level
Foundation
Valid for
No formal expiry, but staying current with legislation changes is recommended
Domains covered on the exam 10
  1. An Introduction to the History of Data Protection in the UK6%
  2. Principles of Data Protection and Applicable Terminology15%
  3. Lawful Bases for Processing of Personal Data10%
  4. Accountability Principle21.5%
  5. Obligations of Controllers, Joint Controllers and Data Processors7.5%
  6. International Data Transfers under UK GDPR7.5%
  7. Data Subject Rights12.5%
  8. Independent Supervisory Authorities (ISAs) and the Information Commissioner's Office (ICO)7.5%
  9. Breaches, Enforcement and Liability7.5%
  10. Privacy and Electronic Communications (EC Directive) Regulations (PECR) 2003 and Subsequent Amendments5%
  1. 1

    During a regulatory audit, a company is found to have stored unencrypted backups of its customer database on unsecured, portable external hard drives that are kept in an unlocked supply closet. Which specific UK GDPR principle is the company failing to uphold?

    Show answer details

    Correct answer: A

    Article 5(1)(f) (Integrity and confidentiality) requires data to be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Unencrypted drives in an unlocked closet represent a severe failure of both technical and organizational security measures.

  2. 2

    A marketing agency wishes to rely on 'Consent' as the lawful basis for sending promotional emails to newly registered website users. They design their signup form with a pre-ticked checkbox that says, "I agree to receive promotional emails." Which requirement of valid consent under Article 6 of the UK GDPR does this approach violate?

    Show answer details

    Correct answer: C

    Recital 32 of the UK GDPR explicitly states that silence, pre-ticked boxes, or inactivity do not constitute consent. Consent must be given by a clear affirmative act establishing a freely given, specific, informed, and unambiguous indication of the data subject's agreement.

  3. 3

    A manufacturing company processes records detailing which of its employees are members of a national trade union in order to facilitate payroll deduction of union dues as required by their collective bargaining agreement. What lawful bases are required for this processing?

    Show answer details

    Correct answer: A

    Trade union membership is special category data. Under UK law, processing special category data always requires identifying a lawful basis under Article 6 AND a separate condition under Article 9. Furthermore, most Article 9 conditions (like employment law) require meeting a specific condition in Schedule 1 of the DPA 2018.

  4. 4

    A UK-based healthcare research organization is evaluating its compliance framework in light of the Data (Use and Access) Act 2025 (DUA Act). They want to understand how this new legislation interacts with the existing UK GDPR and DPA 2018. Which of the following statements most accurately describes the legal mechanism by which the DUA Act 2025 alters the UK's data protection landscape?

    Show answer details

    Correct answer: D

    The Data (Use and Access) Act 2025 does not repeal the UK GDPR or the DPA 2018. Instead, it amends these existing pieces of legislation (as well as PECR) to reform specific areas of data protection, such as subject access request timelines and legitimate interests, while maintaining the core framework.

  5. 5

    True or False: Under Article 3 of the UK GDPR, a software company headquartered exclusively in Singapore that actively targets and sells its project management application in GBP to consumers residing in the UK is subject to the UK GDPR, despite having no physical establishment or servers within the UK.

    Show answer details

    Correct answer: A

    Under Article 3(2) of the UK GDPR, the regulation applies extraterritorially to controllers and processors not established in the UK if their processing activities are related to offering goods or services to data subjects who are in the UK. Targeting UK consumers and accepting GBP clearly indicates an intention to offer services to individuals in the UK.

  6. 6

    Select TWO statements that correctly reflect the UK's data protection framework following its exit from the European Union. (Select TWO)

    Show answer details

    Correct answer: A, B

    The UK GDPR was created by retaining the EU GDPR in domestic law under the European Union (Withdrawal) Act 2018, as amended by subsequent data protection regulations.

    The DPA 2018 sits alongside the UK GDPR. It fills in the gaps left to member states/domestic law, such as establishing the ICO's powers, defining exemptions, and outlining conditions for processing special category and criminal offence data.

Create an account to continue.