← All CDPSE Flashcard Decks

By Design Principles Flashcards

6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 By Design Principles flashcards as text
  1. A software development team is building a new e-commerce platform using an Agile methodology. To properly implement the 'Privacy Embedded into Design' principle, when should the privacy engineer introduce privacy requirements and controls?

    Answer: During the initial sprint planning and user story creation phases.

    The 'Privacy Embedded into Design' principle states that privacy should be an essential component of the core functionality being delivered. It must be integrated into the project from the very beginning, alongside other functional requirements. Introducing privacy during initial planning ensures it is a foundational part of the architecture, not an afterthought.

  2. Which of the following scenarios best illustrates a failure of the 'Full Functionality – Positive-Sum, not Zero-Sum' principle of Privacy by Design?

    Answer: A system architect disables a popular personalization feature because the engineering team believes it is impossible to implement without collecting excessive user data.

    The 'Full Functionality – Positive-Sum, not Zero-Sum' principle avoids false dichotomies, such as pitting privacy against functionality. It encourages finding solutions that allow for both privacy and the desired functionality ('win-win'). Disabling a feature entirely because of privacy challenges represents a zero-sum trade-off, which this principle seeks to avoid.

  3. A privacy engineer is tasked with ensuring 'End-to-End Security – Full Lifecycle Protection' for customer data. Beyond implementing strong encryption for data in transit and at rest, which of the following is MOST critical to fulfilling this principle?

    Answer: Implementing a robust and automated process for the secure destruction of data once its retention period has expired.

    The 'End-to-End Security' principle requires that data be protected throughout its entire lifecycle, from creation to secure destruction. While encryption is vital for protection during the 'use' phase, a secure data destruction process is equally critical to protect the data at the 'end' of its life, ensuring it is not retained indefinitely or disposed of improperly.

  4. Which of the following technical controls is the best implementation of the 'Visibility and Transparency – Keep it Open' principle?

    Answer: Providing users with a clear, interactive privacy dashboard that shows them what data is collected, why it is collected, and with whom it is shared.

    The 'Visibility and Transparency' principle requires that stakeholders can see and understand how their data is being processed. A privacy dashboard directly serves this principle by providing users with clear, accessible, and auditable information and controls over their personal data. The other options are valid privacy controls but relate more to security and data minimization.

  5. A mobile app developer is designing the onboarding process for new users. To align with the 'Respect for User Privacy – Keep it User-Centric' principle, which design choice should the privacy engineer recommend?

    Answer: Implementing granular consent options with clear, just-in-time notices that explain why each piece of data is needed before it is requested.

    The 'Respect for User Privacy' principle puts the individual's interests at the forefront. A user-centric design empowers users by giving them control and making informed choices. Granular consent with just-in-time notices is a prime example of this, as it provides context and respects the user's autonomy. The other options are considered 'dark patterns' that undermine user control.

  6. Which of the following activities is the clearest example of the 'Proactive not Reactive; Preventative not Remedial' principle in practice?

    Answer: Conducting a Data Protection Impact Assessment (DPIA) during the design phase of a new system that will process sensitive personal information.

    The 'Proactive not Reactive' principle emphasizes anticipating and preventing privacy risks before they occur. A DPIA is a systematic process to identify and mitigate privacy risks inherent in a new project *before* it is launched. The other options are all reactive measures taken *after* a negative privacy event has already happened.