CCCP Technology & Data Compliance 4 — Questions and Answers
Question 1: A healthcare company implements a system where patient data is de-identified by replacing names with codes and storing the mapping key separately. This technique is best described as:
- Anonymization
- Pseudonymization (Correct answer)
- Tokenization
- Masking
Correct answer: Pseudonymization
Pseudonymization replaces identifying information with artificial identifiers while retaining the ability to re-identify data using a separately stored key, unlike true anonymization.
Question 2: Which data retention principle requires organizations to store personal data only as long as necessary for the original purpose of collection?
- Purpose limitation
- Storage limitation (Correct answer)
- Integrity and confidentiality
- Accuracy
Correct answer: Storage limitation
The storage limitation principle under GDPR requires that personal data be kept only for as long as necessary to fulfill the specified, explicit purpose for which it was collected.
Question 3: An e-commerce company wants to track website visitors across multiple sites using persistent identifiers. Under GDPR's ePrivacy rules and many state laws, this typically requires:
- Only a privacy policy disclosure
- Explicit consent before placing non-essential tracking cookies (Correct answer)
- Opt-out mechanism within 30 days of first visit
- Annual renewal of terms of service agreement
Correct answer: Explicit consent before placing non-essential tracking cookies
Non-essential cookies and tracking technologies used for advertising or analytics require prior, informed, and freely given consent under GDPR and similar privacy regulations.
Question 4: A multinational company transfers EU personal data to its U.S. parent company. Following the invalidation of Privacy Shield, which mechanism is most commonly used to legitimize this transfer?
- Binding Corporate Rules (BCRs) only
- Standard Contractual Clauses (SCCs) (Correct answer)
- An adequacy decision from the EU Commission
- A written consent form from each data subject
Correct answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are the most widely used mechanism for lawful data transfers from the EU to non-adequate third countries, providing contractual safeguards approved by the European Commission.
Question 5: Under the Computer Fraud and Abuse Act (CFAA), which action could expose a compliance officer to criminal liability?
- Conducting authorized penetration testing with written permission
- Accessing a computer system without authorization to investigate suspected fraud (Correct answer)
- Reviewing employee emails pursuant to a documented retention policy
- Monitoring network traffic using company-owned equipment with disclosed policies
Correct answer: Accessing a computer system without authorization to investigate suspected fraud
The CFAA prohibits unauthorized access to protected computer systems, and even internal investigators can face liability if they access systems beyond the scope of their authorization.
Question 6: Which governance framework specifically addresses the controls organizations should implement over IT systems that support financial reporting, relevant to Sarbanes-Oxley compliance?
- COBIT (Correct answer)
- ITIL
- TOGAF
- PRINCE2
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the most widely used framework for IT governance and control, specifically referenced for SOX IT general controls.
Question 7: A compliance team discovers that a third-party SaaS vendor processes sensitive employee data but has not signed a data processing agreement. Under GDPR, what is the immediate compliance risk?
- No risk if the vendor is ISO 27001 certified
- Violation of Article 28, exposing the controller to regulatory fines (Correct answer)
- Only a reputational risk without legal consequences
- Risk only if the vendor is located outside the EU
Correct answer: Violation of Article 28, exposing the controller to regulatory fines
GDPR Article 28 mandates that controllers only use processors that provide sufficient guarantees via a binding data processing agreement, and absence of such agreement constitutes a violation.
A healthcare company implements a system where patient data is de-identified by replacing names with codes and storing the mapping key separately.
This technique is best described as: