Risk Management Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management flashcards as text
Which of the following BEST describes the difference between a privacy risk assessment and a Data Protection Impact Assessment (DPIA)?
Answer: A DPIA is legally mandated for high-risk processing under GDPR, while a privacy risk assessment is a general best-practice tool
Under GDPR Article 35, a DPIA is legally required for high-risk processing activities, whereas a privacy risk assessment is a broader, framework-agnostic practice.
An organization processes personal data in Country A and transfers it to a processor in Country B, which lacks an adequacy decision. What privacy risk does this introduce?
Answer: Risk of non-compliance with data transfer restrictions and inadequate protection standards
Transferring data to a country without an adequacy decision creates legal and protection-level risk, requiring additional safeguards such as Standard Contractual Clauses.
A CDPSE is evaluating privacy risks associated with a biometric authentication system. Which risk is MOST specific to biometric data?
Answer: Risk of irreversible harm since biometric data cannot be changed if compromised
Unlike passwords, biometric identifiers (fingerprints, facial features) are permanent; a compromise creates lifelong risk because they cannot be reset.
Which of the following scenarios BEST demonstrates the concept of 'data minimization' as a risk control?
Answer: Collecting only the personal data fields strictly necessary for the stated purpose
Data minimization reduces privacy risk by limiting the volume and sensitivity of personal data held, thereby reducing the potential impact of a breach or misuse.
A CDPSE is performing a risk assessment on an employee monitoring program. Which factor is MOST critical to evaluate for privacy risk?
Answer: The proportionality of monitoring scope relative to its stated business purpose
Proportionality—whether the intrusiveness of monitoring is justified by the business purpose—is the central privacy risk factor in employee monitoring programs.
During a risk workshop, a stakeholder argues that encrypting personal data eliminates privacy risk entirely. How should the CDPSE respond?
Answer: Explain that encryption reduces confidentiality risk but does not address risks like unauthorized disclosure, consent violations, or data misuse by authorized parties
Encryption is a control for unauthorized access, but privacy risks such as misuse by authorized users, lack of consent, or purpose limitation violations remain unaddressed.
What is the PRIMARY purpose of a privacy risk heat map?
Answer: To provide a visual representation of risks by likelihood and impact to prioritize treatment
A heat map visually plots risks on a likelihood-versus-impact grid, enabling stakeholders to quickly identify which risks require the most urgent treatment.