Privacy Compliance and Auditing Flashcards
6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Privacy Compliance and Auditing flashcards as text
A privacy auditor reviews an organization's consent management system and finds that consent is bundled with terms of service. Which privacy principle is MOST likely violated?
Answer: Freely given consent
Valid consent under GDPR and similar frameworks must be freely given, meaning it cannot be bundled with terms of service in a way that makes it conditional on accepting unrelated terms.
Which type of audit evaluates both the design and operating effectiveness of privacy controls?
Answer: Control effectiveness audit
A control effectiveness audit tests whether controls are both properly designed to address risks and actually operating as intended in practice over time.
What is the MAIN purpose of a data protection audit trail?
Answer: To provide an immutable record of data access, modifications, and deletions for accountability and incident investigation
Audit trails record who accessed or modified personal data and when, supporting breach investigations, regulatory inquiries, and accountability requirements.
An organization is preparing for a GDPR supervisory authority audit. Which document is MOST important to have readily available?
Answer: Record of Processing Activities (RoPA)
The RoPA is a mandatory GDPR document that supervisory authorities commonly request first, as it provides a comprehensive overview of all personal data processing activities.
Which of the following is a key indicator of a mature privacy compliance program?
Answer: Regular privacy training, documented policies, and evidence of continuous monitoring and improvement
Maturity in privacy programs is characterized by systematic training, documented policies, ongoing monitoring, and a culture of continuous improvement rather than point-in-time efforts.
Under the CCPA, what must an organization provide to a consumer who submits a verifiable request to know about their personal information?
Answer: The categories and specific pieces of personal information collected, the purposes, and any third parties it was shared with
The CCPA's right to know requires businesses to disclose the categories, specific pieces, sources, purposes, and third-party disclosures of a consumer's personal information.