Technology & Data Compliance Flashcards
7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Technology & Data Compliance flashcards as text
A healthcare company implements a system where patient data is de-identified by replacing names with codes and storing the mapping key separately. This technique is best described as:
Answer: Pseudonymization
Pseudonymization replaces identifying information with artificial identifiers while retaining the ability to re-identify data using a separately stored key, unlike true anonymization.
Which data retention principle requires organizations to store personal data only as long as necessary for the original purpose of collection?
Answer: Storage limitation
The storage limitation principle under GDPR requires that personal data be kept only for as long as necessary to fulfill the specified, explicit purpose for which it was collected.
An e-commerce company wants to track website visitors across multiple sites using persistent identifiers. Under GDPR's ePrivacy rules and many state laws, this typically requires:
Answer: Explicit consent before placing non-essential tracking cookies
Non-essential cookies and tracking technologies used for advertising or analytics require prior, informed, and freely given consent under GDPR and similar privacy regulations.
A multinational company transfers EU personal data to its U.S. parent company. Following the invalidation of Privacy Shield, which mechanism is most commonly used to legitimize this transfer?
Answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are the most widely used mechanism for lawful data transfers from the EU to non-adequate third countries, providing contractual safeguards approved by the European Commission.
Under the Computer Fraud and Abuse Act (CFAA), which action could expose a compliance officer to criminal liability?
Answer: Accessing a computer system without authorization to investigate suspected fraud
The CFAA prohibits unauthorized access to protected computer systems, and even internal investigators can face liability if they access systems beyond the scope of their authorization.
Which governance framework specifically addresses the controls organizations should implement over IT systems that support financial reporting, relevant to Sarbanes-Oxley compliance?
Answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the most widely used framework for IT governance and control, specifically referenced for SOX IT general controls.
A compliance team discovers that a third-party SaaS vendor processes sensitive employee data but has not signed a data processing agreement. Under GDPR, what is the immediate compliance risk?
Answer: Violation of Article 28, exposing the controller to regulatory fines
GDPR Article 28 mandates that controllers only use processors that provide sufficient guarantees via a binding data processing agreement, and absence of such agreement constitutes a violation.