CCM Data Privacy and Information Security Compliance — Questions and Answers
Question 1: Under the EU General Data Protection Regulation (GDPR), a data breach that is likely to result in high risk to individuals' rights must be reported to:
- The supervisory authority within 72 hours and to affected individuals without undue delay (Correct answer)
- Only the affected individuals within 30 days of discovery
- The European Commission within 24 hours of discovery
- The data processor within 48 hours, who then notifies the supervisory authority
Correct answer: The supervisory authority within 72 hours and to affected individuals without undue delay
GDPR Article 33 requires notification to the relevant supervisory authority within 72 hours of becoming aware of a breach (when feasible). Article 34 additionally requires notifying affected individuals 'without undue delay' when the breach is likely to result in high risk to their rights and freedoms.
Question 2: A company collects customer email addresses for a newsletter. Under a privacy-by-design framework, which approach best reflects this principle?
- Collect all available customer data and delete it annually during a scheduled purge
- Build data minimization and consent mechanisms into the system before launch, not as an afterthought (Correct answer)
- Encrypt customer data only when a breach has been detected
- Obtain consent once at signup, then assume it covers all future data uses
Correct answer: Build data minimization and consent mechanisms into the system before launch, not as an afterthought
Privacy by design requires embedding privacy protections into systems and processes from the start — not retrofitting them. This includes data minimization (collecting only what's needed), purpose limitation, and building consent mechanisms proactively. Retroactive encryption or annual purges do not satisfy the proactive standard.
Question 3: Under HIPAA, a 'business associate' is best defined as:
- Any employee of a covered entity who handles protected health information
- A person or entity that performs functions involving the use or disclosure of PHI on behalf of a covered entity (Correct answer)
- A government agency that regulates the covered entity's health plan
- A patient who has authorized release of their medical records to a third party
Correct answer: A person or entity that performs functions involving the use or disclosure of PHI on behalf of a covered entity
Under HIPAA, a business associate is a third-party vendor or contractor (not a workforce member) who creates, receives, maintains, or transmits PHI while performing services for a covered entity. Business associates must sign a Business Associate Agreement (BAA) and are directly subject to HIPAA's Security Rule.
Question 4: The California Consumer Privacy Act (CCPA) grants California residents the right to:
- Demand that a company never collect their data under any circumstances
- Know what personal information is collected about them and opt out of its sale (Correct answer)
- Sue companies for any data collection without prior court approval
- Access only the data collected in the past 30 days
Correct answer: Know what personal information is collected about them and opt out of its sale
CCPA grants California residents the right to know what personal information a business collects, the right to delete that information (with exceptions), and the right to opt out of the sale of their personal information. It does not prohibit collection outright or require court approval for data collection.
Question 5: A compliance manager is building a data inventory as part of a privacy compliance program. What is the primary compliance purpose of maintaining such an inventory?
- To calculate the company's total data storage costs for the IT budget
- To identify what personal data is collected, where it is stored, how it is used, and who has access — enabling compliance with subject access and deletion requests (Correct answer)
- To satisfy SEC disclosure requirements for publicly traded companies
- To provide a list of all employees who have accessed the HR database
Correct answer: To identify what personal data is collected, where it is stored, how it is used, and who has access — enabling compliance with subject access and deletion requests
A data inventory (or data map) is foundational to privacy compliance. It enables organizations to respond to data subject rights requests (access, deletion, portability), demonstrate lawful bases for processing under GDPR, manage data retention, and identify risks. Without it, organizations cannot reliably comply with modern privacy laws.
Question 6: Which of the following is an example of a 'legitimate interest' as a lawful basis for processing personal data under GDPR?
- Selling customer email addresses to third-party advertisers to generate revenue
- Processing employee contact details for payroll and benefits administration (Correct answer)
- Collecting browsing history from website visitors without their knowledge to build advertising profiles
- Sharing customer medical records with marketing partners without consent
Correct answer: Processing employee contact details for payroll and benefits administration
Processing employee data for payroll and HR administration is a recognized legitimate interest (and often necessary for contract performance) under GDPR. Selling data to advertisers, covert tracking for ad profiling, and sharing medical records without consent are not legitimate interests and likely require explicit consent or other lawful bases.
Under the EU General Data Protection Regulation (GDPR), a data breach that is likely to result in high risk to individuals' rights must be reported to: