Privacy by Design & Technology Compliance Flashcards
6 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Privacy by Design & Technology Compliance flashcards as text
What is a 'Data Protection Impact Assessment' (DPIA), and when is it required under GDPR?
Answer: A systematic risk assessment required before high-risk processing activities
A DPIA is a systematic process to identify and minimize data protection risks, required under GDPR Article 35 before engaging in processing likely to result in high risk to individuals.
Which technique involves replacing direct identifiers (like names or SSNs) with artificial identifiers while retaining the ability to re-identify the data?
Answer: Pseudonymization
Pseudonymization replaces identifying fields with artificial identifiers while keeping a separate key that enables re-identification, unlike full anonymization which is irreversible.
Under the Children's Online Privacy Protection Act (COPPA), websites and apps directed to children under 13 must obtain verifiable parental consent before:
Answer: Collecting, using, or disclosing personal information from children
COPPA requires verifiable parental consent before collecting, using, or sharing personal information from children under 13, as enforced by the FTC.
What is the primary privacy concern with 'cookie walls' — requiring users to accept all cookies or be denied access to a website?
Answer: They undermine the freely given nature of consent required by GDPR and state laws
Regulators have found that cookie walls coerce consent, making it not 'freely given' as required by GDPR and similar state privacy laws, because users have no real choice.
Which privacy-enhancing technology (PET) allows organizations to perform computations on encrypted data without decrypting it?
Answer: Homomorphic encryption
Homomorphic encryption enables computations to be performed directly on encrypted data, producing encrypted results that, when decrypted, match the result of operations on plaintext.
A company's mobile app collects location data continuously in the background. Under the principle of 'purpose limitation,' this practice is problematic because:
Answer: The data may be used for purposes beyond what users were told at collection
Purpose limitation requires that personal data be collected for specified, explicit purposes and not further processed in ways incompatible with those original purposes.