Practice the legal vocabulary of GDPR data transfers: SCCs, adequacy decisions, data controller vs processor, and lawful bases.
0 / 10 completed
1 / 10
Your company uses a US-based analytics SaaS. The DPA references Standard Contractual Clauses (SCCs). What are these?
SCCs (also called model clauses) are the most common mechanism for lawful EU-to-third-country data transfers when no adequacy decision exists. The 2021 EU SCCs replaced the old versions and require a Transfer Impact Assessment.
2 / 10
A vendor contract classifies your company as the data controller and them as the data processor. What is the key legal difference?
Controller vs processor is a fundamental GDPR distinction. Controllers decide why and how data is processed; processors only act on instructions. Both have obligations, but controllers carry primary liability.
3 / 10
A DPA states that the lawful basis for processing is legitimate interests. What does this mean for an engineering team?
Legitimate interests is one of six GDPR lawful bases. It requires a three-part test: identify the interest, necessity assessment, and balancing test. Engineering teams must understand this when designing data flows.
4 / 10
A contract requires you to honour data subject access requests (DSARs) within one month. A user submits a DSAR. What must you provide?
Article 15 GDPR DSARs require a full data export plus processing metadata within one month (extendable by two months for complex requests). Engineers must design systems that can fulfil this efficiently.
5 / 10
The contract includes a Data Breach Notification clause requiring notification within 72 hours of discovery. Who must be notified under GDPR?
GDPR Article 33 requires controller notification to the supervisory authority within 72 hours. Article 34 requires individual notification for high-risk breaches. Encryption reduces risk but does not always eliminate notification obligations.
6 / 10
Code Review Comment: During a review of the new user onboarding flow, Sarah points out that you're logging IP addresses for analytics. She asks, 'Are we explicitly stating our use of this data under GDPR? We should include a brief note about the Standard Contractual Clauses (SCCs) referenced in the DPA.' Which of the following responses best demonstrates an understanding of the situation and Sarah's concern?
Sarah's comment highlights a critical aspect of GDPR compliance: transparency. Simply collecting data isn't enough; you need to document how the data is being used and which lawful basis (like SCCs) is applied. Option 1 directly addresses this by acknowledging the DPA reference and explaining its importance, while the other options either dismiss the concern or introduce unnecessary complexity.
7 / 10
Slack Message: David (Product) sends a message to the team: 'Just noticed we're pulling user data from our EU servers into our US-based analytics dashboard. We need to ensure we're compliant with GDPR, especially regarding data transfers. Any thoughts?' Which of the following responses best reflects an appropriate response?
David's message correctly identifies a key GDPR concern: international data transfers. The DPA is crucial because it establishes the legal framework for transferring data between jurisdictions and outlines how compliance requirements are met. Option 1 is passive and doesn't address the core issue, while options 2, 3 and 4 offer insufficient or incorrect responses.
8 / 10
PR Description: You're updating the release notes for a new feature that integrates with a third-party CRM. The integration requires collecting user email addresses and names. The PR description should include a statement about GDPR compliance. Which of the following is the MOST appropriate inclusion?
A good PR description needs to proactively address data protection concerns. While 'enhanced security' is positive, stating the specific GDPR foundation (legitimate interest in this case) and acknowledging compliance demonstrates a clear understanding of the legal requirements. The other options are too vague or simply announce the release without any context regarding user rights.
9 / 10
Standup Update: During the daily stand-up, Mark says, 'I'm working on implementing the DSAR process. Users can now request to have their data deleted.' What is the *primary* legal responsibility Mark needs to be aware of in this situation?
While Mark is implementing the technical process, the core legal responsibility related to DSARs is adhering to the response time defined within the contract. GDPR mandates specific timelines for handling these requests (typically one month), and failing to meet this deadline can result in significant penalties. The other options represent supporting tasks but don't address the fundamental legal requirement.
10 / 10
API Response: The API endpoint /users/{user_id} returns user data including email address and location. The system's documentation states that the company is subject to GDPR. Which of the following actions would be *most* appropriate regarding this API endpoint?
Given the API returns sensitive user data and subject to GDPR, a proactive approach is needed. A CMP allows users control over their location data, aligning with GDPR's principles of consent and transparency. While documenting legitimate interests and disabling the endpoint are potentially relevant steps, implementing a CMP directly addresses the core concern of user choice and data protection.
What will I practise in "GDPR & Data Transfer Vocabulary for Engineers"?
Practice the legal vocabulary of GDPR data transfers: SCCs, adequacy decisions, data controller vs processor, and lawful bases.
How many exercises are in this module?
This module has 10 multiple-choice exercises, each with instant feedback and a full explanation of the correct answer.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall.
Do I need to create an account to do these exercises?
No account is required. Just click an option to answer — your score for this session is tracked automatically in the progress bar above.
What happens if I choose the wrong answer?
You'll immediately see which answer was correct, plus a full explanation covering the vocabulary and reasoning behind it — mistakes are where most of the learning happens.
Can I retry the exercises if I want a higher score?
Yes — use the "Try again" button on the results screen to reset and go through all the questions again.
Is my progress saved if I close the page?
No. Progress is tracked only for your current visit; reloading or leaving the page resets the counter. This keeps the exercise simple and account-free.
Where can I find more Legal Contracts exercises?
Browse the full Legal Contracts hub for related drills, or check the "Next up" link below to continue with a connected topic.
How is this different from reading an article on the same topic?
Articles explain vocabulary and concepts in prose; this exercise tests and reinforces that vocabulary through active recall with immediate feedback — the two work best together.
Who writes these exercises?
Every exercise is written by the CoderSlingo team, drawing on real workplace English used in IT roles, then reviewed for accuracy and clarity.