โ† All CCEP Flashcard Decks

Data Privacy Compliance Flashcards

7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Privacy Compliance flashcards as text
  1. Under HIPAA's Minimum Necessary Standard, when may a covered entity share an entire medical record with another covered entity?

    Answer: When the entire record is specifically justified as necessary for the purpose

    The Minimum Necessary Standard requires covered entities to limit disclosures to what is reasonably necessary, and sharing an entire record is only appropriate when specifically justified.

  2. A SaaS vendor processes HR data on behalf of a company subject to GDPR. What document must govern this relationship under GDPR Article 28?

    Answer: Data Processing Agreement (DPA)

    GDPR Article 28 requires a Data Processing Agreement (DPA) between a controller and any processor that processes personal data on its behalf.

  3. Which CCPA right allows a consumer to stop a business from selling or sharing their personal information to third parties?

    Answer: Right to opt-out of sale

    The CCPA grants consumers the right to opt-out of the sale or sharing of their personal information, which businesses must honor via a 'Do Not Sell or Share My Personal Information' link.

  4. Under GDPR, when is a Data Protection Impact Assessment (DPIA) mandatory?

    Answer: When processing is likely to result in high risk to individuals' rights and freedoms

    GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of natural persons, based on the nature, scope, context, and purposes of processing.

  5. An employee's GPS location is tracked continuously during work hours via a company vehicle. Under a privacy compliance framework, which principle is most at risk if tracking continues outside work hours?

    Answer: Purpose limitation

    Purpose limitation restricts data use to the specific purposes disclosed; tracking employees outside work hours exceeds the stated purpose of business-related fleet management.

  6. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to do which of the following?

    Answer: Develop, implement, and maintain a comprehensive information security program

    The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customers' nonpublic personal information.

  7. A company's privacy notice states it uses customer email addresses only for order confirmations. Six months later, it wants to use those same emails for marketing. Under privacy best practices, what must it do first?

    Answer: Obtain fresh consent or identify a new lawful basis before repurposing the data

    Repurposing data for a materially different use requires either obtaining new consent or establishing a compatible lawful basis before the new processing begins.

Data Privacy Compliance Flashcards โ€” CCEP Study Cards with Answers