CCEP Data Privacy Compliance 2 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), which category of information is explicitly excluded from the definition of 'personal information'?
- Medical records held by healthcare providers
- Publicly available information from government records (Correct answer)
- Email addresses used for marketing
- Financial account numbers
Correct answer: Publicly available information from government records
The CCPA explicitly excludes publicly available information from government records from its definition of personal information.
Question 2: A company experiences a data breach affecting 600 California residents' unencrypted Social Security numbers. Under CCPA, within how many days must it notify affected consumers?
- 30 days
- 45 days
- 72 hours
- Without unreasonable delay (Correct answer)
Correct answer: Without unreasonable delay
California law (Civil Code § 1798.82) requires breach notification to affected consumers in 'the most expedient time possible and without unreasonable delay,' not a fixed number of days.
Question 3: Which principle under GDPR requires organizations to only collect personal data that is necessary for a specified purpose?
- Storage limitation
- Data minimization (Correct answer)
- Purpose limitation
- Integrity and confidentiality
Correct answer: Data minimization
Data minimization under GDPR Article 5(1)(c) requires that personal data be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
Question 4: An organization wants to rely on 'legitimate interests' as its legal basis for processing personal data under GDPR. What test must it conduct first?
- Data Protection Impact Assessment (DPIA)
- Legitimate Interests Assessment (LIA) (Correct answer)
- Records of Processing Activities review
- Privacy by Design audit
Correct answer: Legitimate Interests Assessment (LIA)
Organizations relying on legitimate interests must complete a Legitimate Interests Assessment (LIA) to balance their interests against the data subjects' rights and freedoms.
Question 5: Which US federal law specifically governs the privacy of children's online personal information for children under the age of 13?
- FERPA
- HIPAA
- COPPA (Correct answer)
- GLBA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) governs the collection of personal information from children under 13 by websites and online services.
Question 6: A compliance officer discovers their company transfers EU personal data to a US vendor using Standard Contractual Clauses (SCCs). After the Schrems II ruling, what additional step is required?
- Register the transfer with the EU data protection authority
- Conduct a Transfer Impact Assessment (TIA) (Correct answer)
- Obtain explicit consent from all data subjects
- Appoint an EU Data Protection Officer
Correct answer: Conduct a Transfer Impact Assessment (TIA)
After Schrems II, organizations must conduct a Transfer Impact Assessment (TIA) to evaluate whether the destination country's laws undermine the protection offered by SCCs.
Question 7: Which of the following best describes 'pseudonymization' as defined under GDPR?
- Permanently deleting all identifying information from a dataset
- Replacing identifying fields with artificial identifiers so data cannot be attributed to a specific person without additional information (Correct answer)
- Encrypting personal data using industry-standard algorithms
- Converting personal data into aggregate statistical form
Correct answer: Replacing identifying fields with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces directly identifying information with artificial identifiers, but the data can still be re-linked using separately held additional information—it remains personal data under GDPR.
Under the California Consumer Privacy Act (CCPA), which category of information is explicitly excluded from the definition of 'personal information'?