ATP Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: The Privacy Shield framework between the U.S. and EU was invalidated by which ruling, requiring alternative data transfer mechanisms?
- Schrems I (2015)
- Schrems II (2020) (Correct answer)
- GDPR Article 45 ruling (2018)
- CJEU Opinion 2/13
Correct answer: Schrems II (2020)
Schrems II (Data Protection Commissioner v. Facebook Ireland, 2020) invalidated Privacy Shield, requiring Standard Contractual Clauses or other transfer mechanisms.
Question 2: A test publisher must retain candidate score records to support a validity study five years later. Which principle governs how long this data may be kept?
- Data minimization
- Data retention policy aligned with legitimate purpose (Correct answer)
- Immediate deletion after score release
- Indefinite storage for audit purposes
Correct answer: Data retention policy aligned with legitimate purpose
Data should be retained only as long as necessary for the stated legitimate purpose; a documented retention policy aligns storage with validity research needs.
Question 3: Under the Standards for Educational and Psychological Testing Standard 9, what must a test publisher demonstrate when claiming a test is valid for a specific use?
- The test has high internal consistency only
- Appropriate validity evidence for that specific intended use (Correct answer)
- The test is used by a majority of practitioners
- State or federal approval of the instrument
Correct answer: Appropriate validity evidence for that specific intended use
Standard 9 requires that validity evidence be specific to the intended use; validity for one purpose does not automatically apply to other uses.
Question 4: A publisher operating an online proctoring service must comply with GDPR's data protection by design principle by:
- Adding privacy controls as an afterthought after launch
- Building privacy safeguards into the system architecture from the outset (Correct answer)
- Relying solely on user consent after collection
- Documenting violations only when discovered
Correct answer: Building privacy safeguards into the system architecture from the outset
GDPR Article 25 requires that data protection be integrated into the design of systems from the beginning, not added retroactively.
Question 5: Which ATP practice guideline specifically addresses the use of artificial intelligence and automated scoring in assessments?
- Guidelines for Constructed Response Scoring
- ATP Guidelines for Technology-Based Assessment (Correct answer)
- NCME Automated Scoring Appendix
- APA Ethics Code Section 9
Correct answer: ATP Guidelines for Technology-Based Assessment
ATP's Guidelines for Technology-Based Assessment include provisions for AI-driven and automated scoring systems used in modern testing environments.
Question 6: A test developer discovers that an item contains culturally biased language that disadvantages a protected class. Under EEOC guidelines, the BEST course of action is to:
- Keep the item and note it in technical documentation
- Remove or revise the item based on expert bias review findings (Correct answer)
- Administer the item only to the affected group
- Report the item to the DOJ without internal review
Correct answer: Remove or revise the item based on expert bias review findings
EEOC guidelines and professional standards require that items identified as biased through sensitivity review be revised or removed before operational use.
Question 7: When a credentialing organization's exam is used across multiple jurisdictions with different regulations, the organization must:
- Apply the most lenient regulation to reduce burden
- Identify the applicable jurisdiction for each candidate and comply accordingly (Correct answer)
- Use only federal standards and ignore state laws
- Publish one universal policy that supersedes all local laws
Correct answer: Identify the applicable jurisdiction for each candidate and comply accordingly
Multi-jurisdictional testing requires identifying applicable regulations for each candidate's location and ensuring compliance with the most stringent relevant requirements.
The Privacy Shield framework between the U.S. and EU was invalidated by which ruling, requiring alternative data transfer mechanisms?