CCCP Technology & Data Compliance 2 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), what right allows consumers to direct businesses to stop selling their personal information?
- Right to deletion
- Right to opt-out (Correct answer)
- Right to portability
- Right to correction
Correct answer: Right to opt-out
The CCPA's right to opt-out allows California consumers to direct businesses not to sell their personal information to third parties.
Question 2: A company experiences a ransomware attack that encrypts employee PII. Under HIPAA, when must breach notification to HHS be submitted if fewer than 500 individuals are affected?
- Within 60 days of discovery
- Within 30 days of discovery
- Within 60 days after the end of the calendar year (Correct answer)
- Within 90 days of discovery
Correct answer: Within 60 days after the end of the calendar year
HIPAA requires covered entities to notify HHS of breaches affecting fewer than 500 individuals within 60 days after the end of the calendar year in which the breach occurred.
Question 3: Which framework provides a risk-based approach to managing cybersecurity risk and was developed by NIST?
- ISO 27001
- SOC 2 Type II
- NIST Cybersecurity Framework (CSF) (Correct answer)
- PCI DSS
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach organized around five core functions: Identify, Protect, Detect, Respond, and Recover.
Question 4: An organization's third-party vendor suffers a data breach exposing customer data held on behalf of the organization. Under GDPR, the organization is classified as which role?
- Data processor
- Data controller (Correct answer)
- Joint controller
- Data subject
Correct answer: Data controller
The organization that determines the purposes and means of processing personal data is the data controller, even when a vendor (processor) handles the data on its behalf.
Question 5: Which U.S. law specifically governs the privacy of children's online data and requires verifiable parental consent for users under 13?
- FERPA
- COPPA (Correct answer)
- CIPA
- TCPA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) requires operators of websites directed at children under 13 to obtain verifiable parental consent before collecting personal information.
Question 6: A compliance officer is reviewing vendor contracts for data processing agreements. Under GDPR Article 28, which element is NOT required in a data processing agreement?
- Subject matter and duration of processing
- The processor's right to subcontract without controller notice (Correct answer)
- Security measures the processor must implement
- Instructions for returning or deleting data after processing ends
Correct answer: The processor's right to subcontract without controller notice
GDPR Article 28 requires processors to obtain prior written authorization from the controller before engaging sub-processors, not a unilateral right to subcontract.
Question 7: What is the primary purpose of data minimization as a principle in privacy compliance?
- Encrypting data at rest to prevent unauthorized access
- Collecting only the data necessary for specified, legitimate purposes (Correct answer)
- Deleting all personal data after one year
- Anonymizing data before it is shared with third parties
Correct answer: Collecting only the data necessary for specified, legitimate purposes
Data minimization requires organizations to limit personal data collection to what is adequate, relevant, and necessary for the stated purpose.
Under the California Consumer Privacy Act (CCPA), what right allows consumers to direct businesses to stop selling their personal information?