โ† All RCMS Flashcard Decks

Data Privacy & Protection Compliance Flashcards

7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Privacy & Protection Compliance flashcards as text
  1. FERPA protects the educational records of students at institutions receiving federal funding. At what age do FERPA rights transfer from parents to the student?

    Answer: 18

    FERPA rights transfer to the eligible student at age 18 or upon enrollment in a postsecondary institution.

  2. A Data Protection Impact Assessment (DPIA) under GDPR is mandatory when processing is likely to result in:

    Answer: High risk to the rights and freedoms of natural persons

    GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to individuals' rights and freedoms, especially with new technologies.

  3. Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers a privacy notice:

    Answer: At account opening and annually thereafter

    GLBA requires financial institutions to provide an initial privacy notice at the time of establishing a customer relationship and annually thereafter.

  4. Which principle from the OECD Privacy Guidelines requires that personal data should only be collected for specified, explicit purposes?

    Answer: Purpose Specification Principle

    The Purpose Specification Principle requires that the purposes for data collection be specified no later than at the time of collection.

  5. A compliance officer discovers that a third-party vendor is processing personal data beyond the scope of the signed data processing agreement. The FIRST corrective action should be:

    Answer: Issue a formal cure notice and suspend processing pending remediation

    The immediate step is to halt unauthorized processing and provide the vendor an opportunity to cure the breach per the contract terms.

  6. Under NIST Privacy Framework, which core function focuses on developing organizational understanding to manage privacy risk?

    Answer: Identify-P

    The Identify-P function in the NIST Privacy Framework focuses on developing an organizational understanding of privacy risk to individuals.

  7. Virginia's Consumer Data Protection Act (VCDPA) excludes which of the following from its definition of 'personal data'?

    Answer: De-identified data and publicly available information

    VCDPA explicitly excludes de-identified data and publicly available information from its definition of personal data.