โ† All CCEP Flashcard Decks

Data Privacy Compliance Flashcards

7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Privacy Compliance flashcards as text
  1. Under CCPA as amended by CPRA, which new category of data receives heightened 'sensitive personal information' protections?

    Answer: Social Security numbers and precise geolocation data

    CPRA created a 'sensitive personal information' category that includes Social Security numbers, precise geolocation, racial/ethnic origin, and similar high-risk data, granting consumers the right to limit its use.

  2. Which privacy principle requires organizations to be able to demonstrate their compliance with data protection rules, rather than just stating they comply?

    Answer: Accountability

    The accountability principle under GDPR Article 5(2) requires controllers to not only comply with data protection principles but to be able to demonstrate that compliance.

  3. An organization processes biometric data to authenticate employees at building entry points. Under GDPR, biometric data processed for unique identification is classified as which type of data?

    Answer: Special category data requiring explicit consent or another Art. 9 basis

    GDPR Article 9 classifies biometric data processed for the purpose of uniquely identifying a natural person as special category data requiring an explicit legal basis from Article 9(2).

  4. A US company receives a data subject access request (DSAR) from an EU customer under GDPR. What is the standard deadline for responding?

    Answer: One month, extendable by two additional months for complex requests

    GDPR Article 12(3) requires responding to DSARs within one month of receipt, with the possibility of extending by two additional months for complex or numerous requests after notifying the requester.

  5. Which of the following best describes 'Privacy by Design' as a compliance approach?

    Answer: Embedding privacy protections into systems and processes from the earliest design stage

    Privacy by Design, codified in GDPR Article 25, requires integrating data protection into the design of systems and business practices from the outset, not as an afterthought.

  6. Under FTC enforcement, which legal theory has the agency most commonly used to take action against companies with inadequate data security practices?

    Answer: Unfair or deceptive acts or practices under Section 5 of the FTC Act

    The FTC relies on Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, to bring enforcement actions against companies whose data security fails to meet their stated commitments or harms consumers.

  7. A multinational company's EU operations involve processing that requires a DPIA, but the DPO advises that the identified risks cannot be fully mitigated internally. What must the organization do before proceeding?

    Answer: Consult the competent supervisory authority prior to processing

    GDPR Article 36 requires organizations to consult their supervisory authority prior to processing when a DPIA indicates the processing would result in high risk that cannot be mitigated.