Data Privacy Compliance Flashcards
7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Data Privacy Compliance flashcards as text
Which GDPR role has primary accountability for compliance with data protection obligations, even when using third-party processors?
Answer: Data Controller
The data controller determines the purposes and means of processing and retains primary accountability for GDPR compliance, including when processors are engaged.
A hospital's business associate suffers a breach of 600 individuals' protected health information. Under HIPAA, what is the notification timeline to the Secretary of HHS?
Answer: Within 60 days of the calendar year end
For breaches affecting fewer than 500 individuals, HIPAA requires covered entities to notify HHS within 60 days of the end of the calendar year in which the breach occurred.
Under Virginia's Consumer Data Protection Act (VCDPA), which of the following is NOT a right granted to Virginia consumers?
Answer: Right to private lawsuit for violations
The VCDPA does not include a private right of action; enforcement is handled exclusively by the Virginia Attorney General.
Which concept in privacy law holds that individuals should be notified about data collection practices and have a choice about how their information is used?
Answer: Notice and choice
Notice and choice is a foundational privacy principle requiring that individuals be informed about data practices and given meaningful options about the use of their personal information.
An organization subject to GDPR appoints a Data Protection Officer (DPO). Which of the following actions by the organization would violate GDPR Article 38?
Answer: Dismissing the DPO for providing advice that conflicts with business objectives
GDPR Article 38(3) protects DPOs from dismissal or penalty for performing their tasks, ensuring independence; penalizing a DPO for providing unfavorable advice violates this protection.
What is the primary purpose of conducting a privacy risk assessment before launching a new product?
Answer: To identify and mitigate privacy risks before they materialize and harm individuals
Privacy risk assessments proactively identify and mitigate potential harms to individuals before a product launches, embodying the Privacy by Design principle.
A company's third-party vendor is involved in a ransomware attack that exposes customer PII. From a compliance perspective, who bears responsibility for ensuring the vendor had adequate security controls?
Answer: The company (data controller) bears accountability for vendor due diligence and contractual safeguards
Controllers are accountable for selecting processors that provide sufficient security guarantees and must verify this through contracts and due diligence under GDPR Article 28.