Technology & Data Compliance Flashcards
7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Technology & Data Compliance flashcards as text
Which element is required in a GDPR-compliant privacy notice but is NOT typically required under the original U.S. HIPAA Privacy Rule's Notice of Privacy Practices?
Answer: Lawful basis for each processing activity
GDPR requires organizations to specify the lawful basis (e.g., consent, legitimate interest, contract) for each processing activity, a requirement that does not have a direct equivalent in HIPAA's Notice of Privacy Practices.
A compliance officer is assessing the risk of a new AI-powered HR screening tool. Which privacy regulation requires a Data Protection Impact Assessment (DPIA) before deploying such high-risk processing?
Answer: GDPR Article 35
GDPR Article 35 mandates a Data Protection Impact Assessment for processing activities likely to result in high risk, including systematic evaluation of individuals using automated processing.
An employee at a healthcare provider accesses patient records out of curiosity without clinical need. This violates which HIPAA rule and concept?
Answer: Minimum Necessary standard under the Privacy Rule
HIPAA's Minimum Necessary standard requires workforce members to access only the protected health information needed to perform their job functions, prohibiting curiosity browsing.
Under the SEC's cybersecurity disclosure rules effective December 2023, public companies must report material cybersecurity incidents within how many business days on Form 8-K?
Answer: 4 business days
The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material.
A company's privacy policy states it will not share data with third parties, but its website embeds third-party analytics pixels that collect visitor data. This situation most likely constitutes:
Answer: A deceptive trade practice under FTC Act Section 5
Collecting and transmitting user data to third parties contrary to promises made in a privacy policy constitutes a deceptive act or practice enforceable by the FTC under Section 5 of the FTC Act.
Which PCI DSS requirement mandates that organizations restrict physical access to cardholder data environments and maintain visitor logs?
Answer: Requirement 9 – Restrict physical access to cardholder data
PCI DSS Requirement 9 addresses physical security controls including restricting access to systems storing cardholder data, maintaining visitor logs, and securing physical media.
A compliance officer discovers that the company's mobile app collects precise geolocation data but the privacy policy only mentions 'location data.' Under multiple U.S. state privacy laws, what compliance gap does this represent?
Answer: Insufficient specificity in disclosure of sensitive data category collection
Multiple state privacy laws (CCPA, VCDPA, CPA) classify precise geolocation as sensitive personal information requiring explicit disclosure and often enhanced consent beyond generic 'location data' references.