CCO Data Privacy and Information Security Compliance 2 — Questions and Answers
Question 1: What is the principle of data minimization under GDPR?
- Storing data in the smallest possible file format
- Collecting only the personal data that is necessary for the specified purpose (Correct answer)
- Limiting data to a single database
- Reducing the number of employees with data access
Correct answer: Collecting only the personal data that is necessary for the specified purpose
Data minimization requires that organizations collect and process only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
Question 2: What is the right to erasure ('right to be forgotten') under GDPR?
- The right to delete a company's data storage systems
- An individual's right to request deletion of their personal data under certain circumstances (Correct answer)
- The right to remove negative reviews online
- A company's right to delete inactive accounts
Correct answer: An individual's right to request deletion of their personal data under certain circumstances
The right to erasure allows individuals to request that their personal data be deleted when it is no longer necessary, consent is withdrawn, or processing is unlawful.
Question 3: What is HIPAA and what type of data does it protect?
- A cybersecurity law protecting financial data
- The Health Insurance Portability and Accountability Act, which protects protected health information (PHI) in the US (Correct answer)
- An international standard for hospital records
- A privacy law specific to Medicare and Medicaid
Correct answer: The Health Insurance Portability and Accountability Act, which protects protected health information (PHI) in the US
HIPAA establishes national standards for protecting sensitive patient health information from disclosure without the patient's consent or knowledge.
Question 4: What is the role of a Data Protection Officer (DPO)?
- To manage the company's IT infrastructure
- To oversee data protection strategy and ensure compliance with GDPR and related privacy laws (Correct answer)
- To process customer data requests only
- To serve as the company's legal counsel for all matters
Correct answer: To oversee data protection strategy and ensure compliance with GDPR and related privacy laws
A DPO advises on data protection obligations, monitors compliance with GDPR, and acts as the contact point for supervisory authorities and data subjects.
Question 5: What is 'privacy by design'?
- Designing aesthetically pleasing privacy notices
- Embedding privacy protections into the design of systems, processes, and products from the outset rather than adding them later (Correct answer)
- A method for encrypting databases
- A customer-facing transparency tool
Correct answer: Embedding privacy protections into the design of systems, processes, and products from the outset rather than adding them later
Privacy by design integrates data protection into the development of technologies, processes, and business practices before they go live, rather than retrofitting protections afterward.
Question 6: What is a lawful basis for processing personal data under GDPR?
- The company's desire to improve its services
- One of six legal grounds such as consent, contract performance, legal obligation, vital interests, public task, or legitimate interests (Correct answer)
- The existence of a privacy policy
- The company's internal data governance policy
Correct answer: One of six legal grounds such as consent, contract performance, legal obligation, vital interests, public task, or legitimate interests
GDPR requires every processing activity to be grounded in one of six lawful bases to ensure data is not processed arbitrarily or without justification.
What is the principle of data minimization under GDPR?