โ† All CDPSE Flashcard Decks

CDPSE Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CDPSE flashcards as text
  1. A CDPSE is asked to implement a records of processing activities (RoPA). Which element is REQUIRED under GDPR Article 30?

    Answer: Categories of personal data and recipients

    GDPR Article 30 requires RoPA to document categories of data, purposes, recipients, retention periods, and security measures, among other elements.

  2. What is the PRIMARY purpose of data pseudonymization compared to anonymization?

    Answer: Pseudonymization is reversible and still subject to data protection laws

    Pseudonymized data can be re-identified with additional information and therefore remains personal data subject to privacy regulations, unlike truly anonymized data.

  3. Which technique adds statistical noise to query results to prevent inference of individual records in a dataset?

    Answer: Differential privacy

    Differential privacy adds calibrated noise to outputs so that the presence or absence of any individual's data cannot be determined from the results.

  4. Under CCPA, which right allows California consumers to obtain a copy of the personal information a business has collected about them?

    Answer: Right to know

    The CCPA Right to Know allows consumers to request disclosure of what personal information a business has collected, used, disclosed, or sold about them.

  5. A CDPSE is assessing a biometric authentication system. Which privacy risk is UNIQUE to biometric data compared to passwords?

    Answer: Biometric identifiers cannot be changed if compromised

    Unlike passwords, biometric identifiers such as fingerprints or iris scans cannot be reset if exposed, making a breach permanently harmful to the individual.

  6. Which control BEST addresses the privacy risk of employees accessing more personal data than their role requires?

    Answer: Attribute-based access control with least privilege

    Attribute-based access control with least privilege ensures employees can access only the personal data their specific role and purpose require.

  7. An organization receives a Data Subject Access Request (DSAR). Under GDPR, what is the standard response deadline?

    Answer: One month, extendable by two months where complex

    GDPR Article 12 requires response to DSARs within one month, extendable by two additional months for complex or numerous requests.