โ† All CDPSE Flashcard Decks

CDPSE Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CDPSE flashcards as text
  1. An organization wants to implement data minimization. Which approach BEST achieves this principle?

    Answer: Collect only the data strictly necessary for the specified purpose

    Data minimization means collecting only what is necessary for the defined purpose, reducing privacy risk at the source.

  2. Which technical control BEST enforces purpose limitation for personal data stored in a database?

    Answer: Role-based access control tied to processing purposes

    RBAC tied to processing purposes ensures users and systems can only access personal data for authorized, defined purposes.

  3. A company processes health data under a research exemption. What privacy control is MOST critical to implement?

    Answer: Pseudonymization of the health data before analysis

    Pseudonymization reduces re-identification risk while still enabling legitimate research under many privacy frameworks.

  4. Under GDPR, a Data Protection Officer (DPO) reports a data breach to the supervisory authority 80 hours after discovery. What is the consequence?

    Answer: The notification is late since GDPR requires 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a breach.

  5. Which Privacy Enhancing Technology (PET) allows computations on encrypted data without decrypting it?

    Answer: Homomorphic encryption

    Homomorphic encryption enables mathematical operations on ciphertext, so sensitive data never needs to be decrypted for processing.

  6. A Privacy Impact Assessment (PIA) reveals high residual risk after controls are applied. What is the NEXT appropriate step?

    Answer: Consult with the supervisory authority before proceeding

    Under GDPR, when residual risk remains high after mitigation, a Data Protection Impact Assessment (DPIA) consultation with the supervisory authority is required before processing.

  7. An organization transfers personal data from the EU to a country without an adequacy decision. Which mechanism is MOST commonly used?

    Answer: Standard Contractual Clauses (SCCs)

    Standard Contractual Clauses are the most widely used transfer mechanism for EU data exports to non-adequate third countries.