โ† All CDPSE Flashcard Decks

Governance Frameworks Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance Frameworks flashcards as text
  1. An organization is building a privacy governance committee. Which representation is MOST critical for effective privacy decision-making?

    Answer: Cross-functional representation including legal, IT, HR, marketing, and operations

    Cross-functional representation ensures privacy decisions account for all business functions that process personal data.

  2. Which approach to privacy governance treats privacy as a competitive differentiator and business enabler rather than just a compliance obligation?

    Answer: Privacy as a business value and trust driver

    Treating privacy as a business value positions it as a trust-building asset that can differentiate products and attract privacy-conscious customers.

  3. Under the GDPR accountability principle, which of the following BEST demonstrates that an organization has embedded governance?

    Answer: Maintaining records of processing activities and documented evidence of compliance measures

    Records of processing activities (Article 30) and documented compliance measures are the primary evidence of embedded accountability under GDPR.

  4. A privacy governance framework's scope statement should define which of the following?

    Answer: The types of personal data, processing activities, and organizational units covered by the framework

    A scope statement delimits what data, activities, and units fall under the governance framework, preventing ambiguity and gaps.

  5. Which privacy governance concept requires organizations to limit the collection of personal data to what is directly relevant and necessary for the stated purpose?

    Answer: Data minimization

    Data minimization requires collecting only the personal data that is adequate, relevant, and limited to what is necessary for the specified purpose.

  6. When integrating a newly acquired company into an existing privacy governance framework, the FIRST step should be:

    Answer: Conducting a privacy gap assessment of the acquired company's data practices

    A gap assessment identifies how the acquired company's practices differ from existing governance standards, enabling a structured integration plan.

  7. A privacy governance policy requires employees to report suspected privacy violations. What governance element BEST supports this requirement?

    Answer: A non-retaliation clause and accessible reporting channels

    Non-retaliation protections and accessible reporting channels encourage employees to surface privacy concerns without fear of consequences.