CCCP Technology & Data Compliance 5 — Questions and Answers
Question 1: Which element is required in a GDPR-compliant privacy notice but is NOT typically required under the original U.S. HIPAA Privacy Rule's Notice of Privacy Practices?
- Description of how data may be used and disclosed
- Lawful basis for each processing activity (Correct answer)
- Contact information for the privacy officer
- Individual's right to access their health information
Correct answer: Lawful basis for each processing activity
GDPR requires organizations to specify the lawful basis (e.g., consent, legitimate interest, contract) for each processing activity, a requirement that does not have a direct equivalent in HIPAA's Notice of Privacy Practices.
Question 2: A compliance officer is assessing the risk of a new AI-powered HR screening tool. Which privacy regulation requires a Data Protection Impact Assessment (DPIA) before deploying such high-risk processing?
- HIPAA
- CCPA/CPRA
- GDPR Article 35 (Correct answer)
- Gramm-Leach-Bliley Act
Correct answer: GDPR Article 35
GDPR Article 35 mandates a Data Protection Impact Assessment for processing activities likely to result in high risk, including systematic evaluation of individuals using automated processing.
Question 3: An employee at a healthcare provider accesses patient records out of curiosity without clinical need. This violates which HIPAA rule and concept?
- Breach Notification Rule's safe harbor provision
- Minimum Necessary standard under the Privacy Rule (Correct answer)
- Encryption requirements under the Security Rule
- Transaction and Code Set requirements
Correct answer: Minimum Necessary standard under the Privacy Rule
HIPAA's Minimum Necessary standard requires workforce members to access only the protected health information needed to perform their job functions, prohibiting curiosity browsing.
Question 4: Under the SEC's cybersecurity disclosure rules effective December 2023, public companies must report material cybersecurity incidents within how many business days on Form 8-K?
- 72 hours
- 4 business days (Correct answer)
- 10 business days
- 30 calendar days
Correct answer: 4 business days
The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material.
Question 5: A company's privacy policy states it will not share data with third parties, but its website embeds third-party analytics pixels that collect visitor data. This situation most likely constitutes:
- Acceptable use under legitimate interest
- A deceptive trade practice under FTC Act Section 5 (Correct answer)
- A COPPA violation only if visitors are under 13
- A technical violation with no enforcement risk
Correct answer: A deceptive trade practice under FTC Act Section 5
Collecting and transmitting user data to third parties contrary to promises made in a privacy policy constitutes a deceptive act or practice enforceable by the FTC under Section 5 of the FTC Act.
Question 6: Which PCI DSS requirement mandates that organizations restrict physical access to cardholder data environments and maintain visitor logs?
- Requirement 6 – Develop secure systems
- Requirement 9 – Restrict physical access to cardholder data (Correct answer)
- Requirement 11 – Test security systems regularly
- Requirement 12 – Maintain an information security policy
Correct answer: Requirement 9 – Restrict physical access to cardholder data
PCI DSS Requirement 9 addresses physical security controls including restricting access to systems storing cardholder data, maintaining visitor logs, and securing physical media.
Question 7: A compliance officer discovers that the company's mobile app collects precise geolocation data but the privacy policy only mentions 'location data.' Under multiple U.S. state privacy laws, what compliance gap does this represent?
- No gap, as 'location data' is sufficiently descriptive
- Insufficient specificity in disclosure of sensitive data category collection (Correct answer)
- A gap only if the app is used by California residents
- A violation only if the data is sold to data brokers
Correct answer: Insufficient specificity in disclosure of sensitive data category collection
Multiple state privacy laws (CCPA, VCDPA, CPA) classify precise geolocation as sensitive personal information requiring explicit disclosure and often enhanced consent beyond generic 'location data' references.
Which element is required in a GDPR-compliant privacy notice but is NOT typically required under the original U.S.
HIPAA Privacy Rule's Notice of Privacy Practices?