CISSP Security and Risk Management Practice Question
Under GDPR, which TWO of the following are valid lawful bases for processing personal data?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Consent
GDPR Article 6 lists lawful bases including consent, contract, legal obligation, vital interests, public task, and legitimate interests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data subject's employment
Why it's wrong here
The data subject's employment status is not, in itself, a standalone lawful basis for processing personal data under GDPR Article 6. While data processing related to employment is common, it must be justified by one of the six specified lawful bases. Typically, employment-related data processing falls under the 'performance of a contract' (the employment contract), 'legal obligation' (e.g., tax, social security), or sometimes 'legitimate interest' for specific HR functions, rather than employment being a basis itself.
- ✗
Data processor's request
Why it's wrong here
A data processor's request does not constitute a lawful basis for processing personal data under GDPR. The data processor acts strictly on the instructions of the data controller, as defined in Article 28, and is not responsible for determining the purpose or means of processing. It is the data controller's sole responsibility to identify and establish a valid lawful basis for any personal data processing activity before instructing a processor.
- ✓
Consent
Why this is correct
Consent is a valid lawful basis under GDPR Article 6(1)(a) when the data subject has given their explicit agreement to the processing of their personal data for one or more specific purposes. For consent to be valid, it must be freely given, specific, informed, and unambiguous, signified by a clear affirmative action. Furthermore, the data subject must be able to withdraw their consent as easily as they gave it, and the controller must be able to demonstrate that consent was obtained.
- ✓
Legitimate interest
Why this is correct
Legitimate interest serves as a lawful basis under GDPR Article 6(1)(f) when processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. This basis requires a careful three-part test: identifying a legitimate interest, demonstrating the necessity of the processing, and conducting a balancing test to weigh the controller's interests against the data subject's rights.
- ✗
Data controller's profit
Why it's wrong here
A data controller's profit motive alone is not a lawful basis for processing personal data under GDPR. While many commercial activities are undertaken with the aim of generating profit, the processing of personal data to achieve that profit must still be justified by one of the six specific lawful bases outlined in Article 6. Profit is a business objective, not a legal ground; therefore, controllers must ensure their profit-driven processing aligns with bases like 'contract,' 'legitimate interest' (following a strict balancing test), or 'consent'.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.