CDPO Diagnostic: Open-Access Sample Exam Questions for the IIM-Africa Credential
These open-access CDPO questions are original Vantrel questions written in the scenario-led style candidates should be prepared to handle for the IIM-Africa credential. They are mapped across D1-D5...
These open-access CDPO questions are original Vantrel questions written in the scenario-led style candidates should be prepared to handle for the IIM-Africa credential. They are mapped across D1-D5 and include worked explanations. They are not copied IIM exam items, and this short set is not large enough to produce a valid readiness signal.
The sample questions below are drawn from the same CDPO mock exam style Vantrel uses for full-length practice.
A useful CDPO question should do more than ask whether you remember a definition.
It should force you to decide what matters in a realistic situation, choose the rule that controls and reject an answer that sounds reasonable but does not fit the facts.
That is what the set below is designed to do.
Before you start, two boundaries matter.
First, these are original exam-preparation questions. They are not live, recalled or reproduced IIM examination questions.
Second, ten questions cannot tell you whether you are ready to sit a 60-question, 150-minute professional exam. Treat the result as a small sample of your reasoning, not as a Vantage Score.
How should you use these CDPO questions?
Answer all ten before reading the explanations.
Give yourself roughly 25 minutes. That mirrors the real exam's average time budget of about two and a half minutes per question without pretending this short set reproduces full exam pressure.
Record three things for every error:
- what answer you chose;
- why you chose it; and
- what fact you missed or misapplied.
The third point is the most valuable.
Question 1 — Lawful basis for required identity processing
A Nigerian financial institution is required by applicable regulation to collect and verify specified customer identity information before opening an account. A customer says, "I do not consent to you processing my ID data." Which lawful basis is most directly relevant to the processing that the institution is legally required to perform?
A. Consent
B. Legal obligation
C. Legitimate interests
D. Vital interests
Correct answer: B — Legal obligation
Where processing is necessary for compliance with a legal obligation to which the controller or processor is subject, Section 25 of the NDPA recognises legal obligation as a lawful basis.
Consent is not automatically the correct basis simply because personal data is involved. If the processing is legally required, asking for consent can create the false impression that the individual can withdraw permission and thereby remove the legal requirement.
Practice map: D1 — Legal and Regulatory Frameworks.
Question 2 — Pre-ticked consent
An e-commerce company adds a pre-selected box to its checkout page stating: "I agree to receive marketing messages from selected partners." Customers can untick the box, but most do not notice it. Which statement best reflects the NDPA position?
A. The consent is valid because customers could untick the box.
B. The consent is valid if the privacy notice explains the marketing.
C. The consent is not valid because consent must be affirmative and not based on a pre-selected confirmation.
D. The consent is valid where the company has a legitimate commercial reason for marketing.
Correct answer: C — The consent is not valid
Section 26 states that consent must be affirmative and not based on a pre-selected confirmation. Silence or inactivity does not constitute consent either.
The fact that a customer could find and change the default does not turn the default itself into affirmative consent.
Practice map: D1 — Legal and Regulatory Frameworks.
Question 3 — Data minimisation
A professional association asks people signing up for a monthly regulatory newsletter to provide their full name, email address, passport number, marital status and next-of-kin details. The association says the extra information "may be useful for future services." What is the clearest compliance issue?
A. Data portability
B. Data minimisation and purpose limitation
C. Cross-border transfer
D. Automated decision-making
Correct answer: B — Data minimisation and purpose limitation
The stated purpose is newsletter delivery. Passport, marital-status and next-of-kin information are difficult to justify as necessary for that purpose.
Section 24 requires personal data to be adequate, relevant and limited to what is necessary, and to be collected for specified, explicit and legitimate purposes.
Practice map: D2 — Data Protection Principles and Compliance.
Question 4 — Processor agreement
A Nigerian retailer outsources its customer-support platform to a software vendor that processes customer names, email addresses and complaint records on the retailer's instructions. Which control is specifically contemplated by Section 29 of the NDPA?
A. A written agreement governing the processing relationship
B. A separate consent form signed by every customer for the vendor
C. Transfer of all accountability to the vendor
D. Automatic deletion of all complaint data after seven days
Correct answer: A — A written agreement governing the processing relationship
Section 29 requires the party engaging a processor to ensure that the processor meets applicable obligations, supports data-subject rights, implements appropriate security and provides information required to demonstrate compliance. The measures include a written agreement.
Outsourcing processing does not outsource the controller's accountability.
Practice map: D2 — Data Protection Principles and Compliance.
Question 5 — High-risk product launch
A health platform plans to launch a new feature that analyses large volumes of sensitive patient information to predict treatment adherence. The privacy team believes the processing may create high risk to individuals. What should happen before the feature begins processing personal data?
A. Launch first and conduct a DPIA after 30 days of live data
B. Conduct a DPIA before the processing begins
C. Obtain employee consent because staff designed the feature
D. Notify every customer of a personal data breach
Correct answer: B — Conduct a DPIA before the processing begins
Section 28 requires a DPIA where proposed processing is likely to result in high risk to a data subject's rights and freedoms because of its nature, scope, context and purposes.
The timing is part of the rule: the assessment comes before the high-risk processing.
Practice map: D3 — Risk Management and DPIA.
Question 6 — Residual high risk after a DPIA
A controller completes a DPIA for a new biometric monitoring system. After proposed controls are applied, the assessment still indicates high risk to data subjects. Which action is most consistent with Section 28?
A. Proceed because a DPIA has already been completed
B. Consult the NDPC before the processing begins
C. Replace the DPO
D. Convert the lawful basis to consent and proceed immediately
Correct answer: B — Consult the NDPC before the processing begins
Section 28 provides for prior consultation with the Commission where the DPIA indicates that high risk remains notwithstanding the measures envisaged by the controller.
A DPIA is not a permission slip. Its purpose is to identify whether the proposed processing can proceed with acceptable risk.
Practice map: D3 — Risk Management and DPIA.
Question 7 — Processor discovers a breach
A cloud provider processing personal data for a Nigerian company discovers unauthorised access to a database containing the company's customer records. What is the provider's first statutory notification responsibility under Section 40?
A. Notify every affected customer directly within 72 hours
B. Notify the NDPC directly in every case
C. Notify the controller or engaging processor and provide relevant breach information
D. Wait until the full forensic investigation is complete
Correct answer: C — Notify the controller or engaging processor
Section 40 places a processor-to-controller notification duty on the processor that becomes aware of a breach involving personal data it stores or processes.
The controller then has its own regulatory obligations, including NDPC notification within 72 hours where the breach is likely to result in risk to individuals.
Practice map: D4 — Incident Response and Data Breaches.
Question 8 — When must the NDPC be notified?
A controller becomes aware of a personal data breach. Its initial assessment concludes that the incident is likely to result in a risk to the rights and freedoms of individuals. What is the relevant NDPC notification timeframe under the NDPA?
A. Within 24 hours
B. Within 48 hours
C. Within 72 hours of becoming aware
D. Only after the controller confirms actual financial loss
Correct answer: C — Within 72 hours of becoming aware
Section 40 requires a controller to notify the NDPC within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals.
The threshold is risk, not proof that harm has already occurred.
Practice map: D4 — Incident Response and Data Breaches.
Question 9 — Cross-border transfer safeguard
A Nigerian company wants to send personal data to a service provider in another country. The recipient is bound by contractual clauses that provide an adequate level of protection consistent with the NDPA. Which statement best reflects Section 41?
A. Cross-border transfers are prohibited in all circumstances
B. The transfer may proceed where the statutory basis and adequate protection requirements are satisfied and documented
C. The transfer is lawful only if every data subject gives consent
D. The transfer is automatically lawful because the service provider is outside Nigeria
Correct answer: B — The transfer may proceed with a valid basis and adequate protection
Section 41 allows transfers where the recipient is subject to safeguards such as applicable law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism that affords adequate protection, or where another statutory condition applies.
The controller or processor must also record the basis for transfer and the adequacy of protection.
Practice map: D1/D5 — Legal framework and governance.
Question 10 — DPO responsibility
A data controller of major importance appoints a DPO. Senior management then tells the DPO: "You now own all privacy compliance. If a business unit breaches the NDPA, responsibility sits with you." Which response best reflects the statutory role?
A. Correct, because the DPO replaces management accountability for data protection
B. Correct, but only where the DPO is an employee rather than an external service provider
C. Incorrect, because the DPO advises, monitors compliance and acts as a contact point, while organisational accountability remains with the controller
D. Incorrect, because DPOs are only required for data processors
Correct answer: C — The DPO does not replace organisational accountability
Section 32 describes the DPO's tasks as advising, monitoring compliance and acting as a contact point for the Commission. Appointing a DPO does not transfer the controller's statutory accountability to one individual.
Practice map: D5 — Governance, Policies and Ethics.
How should you interpret your score on these ten questions?
Carefully.
A score of 8/10 is 80 percent on this set. It does not mean your CDPO readiness is 80 percent.
Why not?
Because this set is:
- only ten questions;
- not a full representation of the five-domain blueprint;
- not long enough to test 150-minute endurance;
- not calibrated as a complete mock exam; and
- visible on a public article, which means future attempts are no longer independent.
The useful output is your error pattern.
If you missed both breach questions, review Section 40. If you chose consent in Question 1 or accepted the pre-ticked box in Question 2, lawful basis and consent deserve more work. If the DPIA questions felt uncertain, D3 should move up your study plan.
That is what a diagnostic is supposed to do: identify the gap before the real exam does.
What does a full CDPO diagnostic need to measure?
A proper diagnostic should do more than count correct answers.
It should cover the full D1-D5 blueprint, include enough new questions to reduce noise, use scenario difficulty that exposes application errors and report performance by domain.
On Vantrel, the Signal Engine uses your answer history and blueprint coverage to select questions, while the Vantage Score converts the broader performance pattern into a readiness signal.
The important distinction is between a score from a set and evidence that you are ready to sit.
Those are not the same product.
For the study structure that follows a diagnostic, read How to Prepare for the CDPO Exam. For the real exam mechanics, see IIM CDPO Exam Format.
Take the open-access CDPO diagnostic.
Continue in this guide
- the complete guide to the IIM CDPO certification
- how to prepare for the CDPO exam
- IIM CDPO exam format
Frequently Asked Questions
Are these real IIM CDPO exam questions?
No. They are original Vantrel exam-preparation questions written from the public IIM blueprint and Nigerian data protection law. They are not copied, recalled or represented as live IIM examination items.
How many questions are in the real IIM CDPO exam?
IIM publishes a 60-question exam with a 150-minute duration and a 70 percent pass threshold.
Does getting 7 out of 10 here mean I would pass the real CDPO exam?
No. A ten-question public set is too small and too narrow to provide a valid readiness prediction.
What topics should a CDPO diagnostic cover?
It should cover all five IIM domains: Legal and Regulatory Frameworks; Data Protection Principles and Compliance; Risk Management and DPIA; Incident Response and Data Breaches; and Governance, Policies and Ethics.
What should I do after getting a question wrong?
Review the correct rule, explain why your selected answer fails and identify the fact in the scenario that should have changed your reasoning. Then test the same concept in a different scenario.
Sources checked
- Institute of Information Management, IIM CDPO Certification.
- Nigeria Data Protection Commission, Nigeria Data Protection Act 2023.
- Nigeria Data Protection Commission, NDP Act — GAID 2025.
All questions in this article are original Vantrel editorial content. They are designed for learning and diagnosis, not to reproduce confidential certification examination material.
Frequently Asked Questions
Are these real IIM CDPO exam questions?
No. They are original Vantrel exam-preparation questions written from the public IIM blueprint and Nigerian data protection law. They are not copied, recalled or represented as live IIM examination items.
How many questions are in the real IIM CDPO exam?
IIM publishes a 60-question exam with a 150-minute duration and a 70 percent pass threshold.
Does getting 7 out of 10 here mean I would pass the real CDPO exam?
No. A ten-question public set is too small and too narrow to provide a valid readiness prediction.
What topics should a CDPO diagnostic cover?
It should cover all five IIM domains: Legal and Regulatory Frameworks; Data Protection Principles and Compliance; Risk Management and DPIA; Incident Response and Data Breaches; and Governance, Policies and Ethics.
What should I do after getting a question wrong?
Review the correct rule, explain why your selected answer fails and identify the fact in the scenario that should have changed your reasoning. Then test the same concept in a different scenario.
Keep building exam readiness
If this article helped clarify the path, the next step is to turn insight into practice. Explore the platform, choose your exam track, and start preparing with structure.
