Data Privacy Compliance Flashcards
7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Data Privacy Compliance flashcards as text
Under the California Consumer Privacy Act (CCPA), which category of information is explicitly excluded from the definition of 'personal information'?
Answer: Publicly available information from government records
The CCPA explicitly excludes publicly available information from government records from its definition of personal information.
A company experiences a data breach affecting 600 California residents' unencrypted Social Security numbers. Under CCPA, within how many days must it notify affected consumers?
Answer: Without unreasonable delay
California law (Civil Code § 1798.82) requires breach notification to affected consumers in 'the most expedient time possible and without unreasonable delay,' not a fixed number of days.
Which principle under GDPR requires organizations to only collect personal data that is necessary for a specified purpose?
Answer: Data minimization
Data minimization under GDPR Article 5(1)(c) requires that personal data be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
An organization wants to rely on 'legitimate interests' as its legal basis for processing personal data under GDPR. What test must it conduct first?
Answer: Legitimate Interests Assessment (LIA)
Organizations relying on legitimate interests must complete a Legitimate Interests Assessment (LIA) to balance their interests against the data subjects' rights and freedoms.
Which US federal law specifically governs the privacy of children's online personal information for children under the age of 13?
Answer: COPPA
The Children's Online Privacy Protection Act (COPPA) governs the collection of personal information from children under 13 by websites and online services.
A compliance officer discovers their company transfers EU personal data to a US vendor using Standard Contractual Clauses (SCCs). After the Schrems II ruling, what additional step is required?
Answer: Conduct a Transfer Impact Assessment (TIA)
After Schrems II, organizations must conduct a Transfer Impact Assessment (TIA) to evaluate whether the destination country's laws undermine the protection offered by SCCs.
Which of the following best describes 'pseudonymization' as defined under GDPR?
Answer: Replacing identifying fields with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces directly identifying information with artificial identifiers, but the data can still be re-linked using separately held additional information—it remains personal data under GDPR.