CDPSE Risk Management 2 — Questions and Answers
Question 1: A CDPSE is evaluating a third-party vendor that processes personal health information on behalf of the organization. Which risk management step should be performed FIRST?
- Sign a data processing agreement immediately
- Conduct a vendor privacy risk assessment (Correct answer)
- Audit the vendor's security controls
- Terminate the relationship if any risk is found
Correct answer: Conduct a vendor privacy risk assessment
A vendor privacy risk assessment identifies the scope and nature of risk before decisions about agreements or audits can be meaningfully made.
Question 2: Which of the following BEST describes residual risk in a data privacy context?
- Risk that exists before any controls are applied
- Risk that remains after privacy controls have been implemented (Correct answer)
- Risk transferred to a third-party processor
- Risk accepted by senior management without mitigation
Correct answer: Risk that remains after privacy controls have been implemented
Residual risk is what remains after controls are applied; it must be evaluated to determine if it falls within the organization's risk appetite.
Question 3: An organization's risk appetite for data privacy is defined as low. A proposed marketing analytics project carries moderate privacy risk. What is the MOST appropriate response?
- Proceed with the project and monitor it quarterly
- Reject the project outright without further review
- Implement additional privacy controls to reduce risk to an acceptable level (Correct answer)
- Transfer the risk to a cyber insurance provider
Correct answer: Implement additional privacy controls to reduce risk to an acceptable level
When risk exceeds risk appetite, the appropriate response is to implement controls that bring residual risk within acceptable bounds before proceeding.
Question 4: Which metric is MOST useful when quantifying the likelihood component of a privacy risk?
- Number of records exposed in past breaches industry-wide
- The organization's current data breach insurance premium
- Historical frequency of similar threat events within the organization (Correct answer)
- The cost of replacing compromised personal data
Correct answer: Historical frequency of similar threat events within the organization
Internal historical frequency of similar events provides the most relevant and organization-specific input for likelihood estimation.
Question 5: A CDPSE discovers that an automated profiling system makes decisions about loan eligibility using personal data without human review. Which privacy risk category BEST describes this situation?
- Data minimization risk
- Automated decision-making risk (Correct answer)
- Cross-border transfer risk
- Data retention risk
Correct answer: Automated decision-making risk
Automated decision-making risk arises when systems make significant decisions about individuals without human oversight, a concern addressed by regulations like GDPR Article 22.
Question 6: When performing a Data Protection Impact Assessment (DPIA), what is the primary purpose of identifying risk owners?
- To assign blame in case of a data breach
- To ensure accountability for treating or accepting identified privacy risks (Correct answer)
- To satisfy regulatory documentation requirements only
- To delegate all privacy decisions to departmental managers
Correct answer: To ensure accountability for treating or accepting identified privacy risks
Risk owners are accountable for taking action on identified risks, ensuring that treatment plans are executed and residual risk is monitored.
Question 7: An organization operates in a jurisdiction that has enacted a new data privacy law. How should this be reflected in the privacy risk register?
- Create a new risk entry for regulatory non-compliance exposure (Correct answer)
- Wait until the regulator issues enforcement actions before updating the register
- Remove existing risks that the new law renders irrelevant
- Classify the regulatory change as an opportunity, not a risk
Correct answer: Create a new risk entry for regulatory non-compliance exposure
New regulatory requirements introduce compliance risk that must be formally documented and tracked in the risk register.
A CDPSE is evaluating a third-party vendor that processes personal health information on behalf of the organization.
Which risk management step should be performed FIRST?