CDPSE Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CDPSE flashcards as text
A company uses an AI model trained on customer data to make credit decisions. Which privacy principle is MOST relevant to ensure fairness and transparency?
Answer: Right to explanation for automated decisions
GDPR Article 22 grants individuals the right not to be subject to solely automated decisions and entitles them to an explanation of the logic involved.
Which privacy architecture pattern separates the identity of a data subject from their transactional records using a mapping table stored separately?
Answer: Pseudonymization with a key vault
Pseudonymization with a separate key vault replaces direct identifiers with pseudonyms and stores the mapping securely, allowing re-identification only under controlled conditions.
A multinational organization wants a single privacy framework to apply globally. Which standard BEST extends ISO 27001 with privacy-specific controls?
Answer: ISO/IEC 27701
ISO/IEC 27701 extends ISO 27001 and ISO 27002 with privacy-specific requirements for PII controllers and processors, providing a global privacy management framework.
What is the PRIMARY difference between a Data Controller and a Data Processor under GDPR?
Answer: Controllers determine purposes and means; processors act on controller instructions
A controller decides why and how personal data is processed; a processor handles data only on the controller's documented instructions.
During a DPIA, which factor MOST increases the likelihood that prior consultation with a supervisory authority is required?
Answer: Processing involves systematic profiling of public spaces
Systematic monitoring of public areas is listed in GDPR Article 35 as a high-risk processing type triggering mandatory DPIA and potential supervisory authority consultation.
A breach exposes hashed passwords with bcrypt. The organization concludes notification to data subjects is NOT required. What is the BEST justification?
Answer: Bcrypt hashing makes it unlikely that individuals face high risk
If the compromised data is rendered unintelligible (e.g., via strong hashing), GDPR allows controllers to conclude the breach is unlikely to result in high risk, waiving individual notification.
Which privacy governance role is PRIMARILY responsible for ensuring data processing activities comply with applicable privacy laws on a day-to-day basis?
Answer: Data Protection Officer (DPO)
The DPO is the formal role under GDPR with specific independence and advisory responsibilities for monitoring compliance with data protection obligations.