CDPSE Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 CDPSE flashcards as text
Which element is MOST important when designing a consent management platform?
Answer: Granular consent per purpose with easy withdrawal
Valid consent under GDPR must be granular, freely given, and as easy to withdraw as to give.
A CDPSE is reviewing a vendor contract for cloud data processing. What privacy clause is MOST critical to include?
Answer: A Data Processing Agreement (DPA) specifying controller obligations
A Data Processing Agreement is legally required under GDPR when a controller engages a processor, defining each party's data protection obligations.
What does the concept of 'privacy by default' require?
Answer: Applying maximum privacy settings automatically without user action
Privacy by default means the most privacy-protective settings are applied automatically, so individuals don't need to take action to protect their privacy.
An organization processes data based on legitimate interests. Which step is REQUIRED before relying on this lawful basis?
Answer: Conduct a Legitimate Interests Assessment (LIA)
A Legitimate Interests Assessment balances the organization's interests against data subjects' rights and must be documented before relying on legitimate interests.
Which data lifecycle phase presents the HIGHEST privacy risk if not properly managed?
Answer: Data retention beyond stated purpose
Retaining data longer than necessary violates storage limitation principles and increases exposure to breaches, legal liability, and unauthorized use.
A mobile app sends user location data to a third-party analytics SDK by default. What privacy principle does this MOST likely violate?
Answer: Privacy by design and by default
Sharing sensitive data with third parties by default without user knowledge violates privacy by default, which requires the most protective settings to be on by default.
Which framework provides a structured approach to managing privacy risk using a five-function core: Identify, Govern, Control, Communicate, Protect?
Answer: NIST Privacy Framework
The NIST Privacy Framework uses the five core functions—Identify, Govern, Control, Communicate, and Protect—to manage privacy risk.