CDPSE Governance Frameworks 2 — Questions and Answers
Question 1: Which governance principle requires that individuals responsible for privacy decisions be held answerable for their actions and outcomes?
- Transparency
- Accountability (Correct answer)
- Data minimization
- Purpose limitation
Correct answer: Accountability
Accountability is the governance principle requiring that decision-makers are answerable for how personal data is handled.
Question 2: A privacy governance framework should include which of the following as a primary component for managing third-party data processors?
- Annual security audits of all vendors
- Data Processing Agreements (DPAs) with contractual privacy obligations (Correct answer)
- Prohibition of all data sharing with third parties
- On-site inspections of all processor facilities
Correct answer: Data Processing Agreements (DPAs) with contractual privacy obligations
DPAs are the contractual mechanism requiring third-party processors to uphold the controller's privacy obligations.
Question 3: In a multinational organization, which governance structure best ensures consistent privacy practices across all jurisdictions?
- Decentralized teams applying local rules independently
- A federated model with global standards and local compliance adaptations (Correct answer)
- A single centralized team managing all regions identically
- Outsourcing all privacy decisions to local legal counsel
Correct answer: A federated model with global standards and local compliance adaptations
A federated model balances global consistency with the flexibility to meet jurisdiction-specific requirements.
Question 4: Which element of privacy governance ensures that personal data is only used for the purposes for which it was originally collected?
- Data integrity
- Purpose limitation (Correct answer)
- Storage limitation
- Confidentiality
Correct answer: Purpose limitation
Purpose limitation restricts the use of personal data to the specific, stated purposes communicated at collection.
Question 5: A company's privacy governance framework lacks defined escalation paths for privacy incidents. What risk does this create?
- Increased marketing costs
- Delayed breach response and regulatory notification failures (Correct answer)
- Reduced employee productivity
- Overly broad data retention policies
Correct answer: Delayed breach response and regulatory notification failures
Without escalation paths, incidents may not reach decision-makers in time to meet regulatory breach notification deadlines.
Question 6: Which governance document typically defines an organization's high-level commitment to data privacy and sets the tone for all subordinate policies?
- Data inventory spreadsheet
- Privacy impact assessment template
- Privacy policy statement (Correct answer)
- Incident response runbook
Correct answer: Privacy policy statement
A privacy policy statement expresses the organization's overarching commitment and principles, driving all subordinate privacy policies.
Question 7: Under a mature privacy governance framework, who is ultimately accountable for organizational privacy risk?
- The IT security team
- Individual department managers
- The Board of Directors or senior executive leadership (Correct answer)
- The Data Protection Officer exclusively
Correct answer: The Board of Directors or senior executive leadership
Ultimate accountability for privacy risk rests with the Board or senior leadership, who set strategy and oversee compliance.
Which governance principle requires that individuals responsible for privacy decisions be held answerable for their actions and outcomes?