By Design Principles Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 By Design Principles flashcards as text
A Privacy Impact Assessment (PIA) conducted before a system is built rather than after deployment best reflects which Privacy by Design principle?
Answer: Proactive not Reactive; Preventative not Remedial
Conducting a PIA before building the system exemplifies the proactive principle — identifying and mitigating privacy risks before they are built into the product.
An organization's API returns full user objects including fields the calling service doesn't need. Which Privacy by Design concept should the architect apply?
Answer: Data Minimization at the API response level
Data minimization requires that only the data actually needed by the consuming service is returned, reducing unnecessary exposure in transit and at rest.
Which Privacy by Design principle is MOST concerned with ensuring individuals can access, correct, and delete their own data?
Answer: Respect for User Privacy — Keep it User-Centric
Respect for User Privacy (Keep it User-Centric) centers the design on empowering individuals with rights over their own data including access, correction, and erasure.
A CDPSE candidate finds that an application stores passwords in plaintext in the database. This violates which Privacy by Design principle most directly?
Answer: Full Lifecycle Protection — End-to-End Security
End-to-End Security as part of Full Lifecycle Protection requires that credentials are stored using strong hashing, not plaintext, throughout the data's lifecycle.
An organization publishes its data processing algorithms and allows independent third-party audits of its privacy controls. This most directly demonstrates which principle?
Answer: Visibility and Transparency — Keep it Open
Visibility and Transparency requires that organizations open their practices to independent verification, going beyond self-attestation.
Which approach to user consent design best aligns with the 'Privacy as the Default' and 'Respect for User Privacy' principles combined?
Answer: Granular opt-in consent with plain language and easy withdrawal
Granular opt-in consent with clear language and easy withdrawal respects autonomy (user-centric) and ensures the default state is non-consented (privacy as default).
A healthcare app architect proposes storing patient data on the device only, never uploading it to servers, to minimize exposure. Which Privacy by Design principle does this most directly exemplify?
Answer: Privacy Embedded into Design through Data Minimization and Locality
Keeping data local by design eliminates server-side exposure risks entirely, embedding privacy protection into the core architecture through minimization of data movement.