Technology & Data Compliance Flashcards
7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Technology & Data Compliance flashcards as text
Under the California Consumer Privacy Act (CCPA), what right allows consumers to direct businesses to stop selling their personal information?
Answer: Right to opt-out
The CCPA's right to opt-out allows California consumers to direct businesses not to sell their personal information to third parties.
A company experiences a ransomware attack that encrypts employee PII. Under HIPAA, when must breach notification to HHS be submitted if fewer than 500 individuals are affected?
Answer: Within 60 days after the end of the calendar year
HIPAA requires covered entities to notify HHS of breaches affecting fewer than 500 individuals within 60 days after the end of the calendar year in which the breach occurred.
Which framework provides a risk-based approach to managing cybersecurity risk and was developed by NIST?
Answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach organized around five core functions: Identify, Protect, Detect, Respond, and Recover.
An organization's third-party vendor suffers a data breach exposing customer data held on behalf of the organization. Under GDPR, the organization is classified as which role?
Answer: Data controller
The organization that determines the purposes and means of processing personal data is the data controller, even when a vendor (processor) handles the data on its behalf.
Which U.S. law specifically governs the privacy of children's online data and requires verifiable parental consent for users under 13?
Answer: COPPA
The Children's Online Privacy Protection Act (COPPA) requires operators of websites directed at children under 13 to obtain verifiable parental consent before collecting personal information.
A compliance officer is reviewing vendor contracts for data processing agreements. Under GDPR Article 28, which element is NOT required in a data processing agreement?
Answer: The processor's right to subcontract without controller notice
GDPR Article 28 requires processors to obtain prior written authorization from the controller before engaging sub-processors, not a unilateral right to subcontract.
What is the primary purpose of data minimization as a principle in privacy compliance?
Answer: Collecting only the data necessary for specified, legitimate purposes
Data minimization requires organizations to limit personal data collection to what is adequate, relevant, and necessary for the stated purpose.