CCEP Data Privacy Compliance 3 — Questions and Answers
Question 1: Under HIPAA's Minimum Necessary Standard, when may a covered entity share an entire medical record with another covered entity?
- Whenever the patient has signed a general authorization form
- When the entire record is specifically justified as necessary for the purpose (Correct answer)
- Any time treatment is involved, without restriction
- Only when the receiving entity is a business associate
Correct answer: When the entire record is specifically justified as necessary for the purpose
The Minimum Necessary Standard requires covered entities to limit disclosures to what is reasonably necessary, and sharing an entire record is only appropriate when specifically justified.
Question 2: A SaaS vendor processes HR data on behalf of a company subject to GDPR. What document must govern this relationship under GDPR Article 28?
- Non-Disclosure Agreement (NDA)
- Data Processing Agreement (DPA) (Correct answer)
- Service Level Agreement (SLA)
- Joint Controller Agreement
Correct answer: Data Processing Agreement (DPA)
GDPR Article 28 requires a Data Processing Agreement (DPA) between a controller and any processor that processes personal data on its behalf.
Question 3: Which CCPA right allows a consumer to stop a business from selling or sharing their personal information to third parties?
- Right to deletion
- Right to opt-out of sale (Correct answer)
- Right to data portability
- Right to correct inaccurate information
Correct answer: Right to opt-out of sale
The CCPA grants consumers the right to opt-out of the sale or sharing of their personal information, which businesses must honor via a 'Do Not Sell or Share My Personal Information' link.
Question 4: Under GDPR, when is a Data Protection Impact Assessment (DPIA) mandatory?
- For all new data processing activities
- When processing is likely to result in high risk to individuals' rights and freedoms (Correct answer)
- Whenever personal data is transferred outside the EU
- Only when processing sensitive data categories
Correct answer: When processing is likely to result in high risk to individuals' rights and freedoms
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of natural persons, based on the nature, scope, context, and purposes of processing.
Question 5: An employee's GPS location is tracked continuously during work hours via a company vehicle. Under a privacy compliance framework, which principle is most at risk if tracking continues outside work hours?
- Accuracy
- Purpose limitation (Correct answer)
- Accountability
- Storage limitation
Correct answer: Purpose limitation
Purpose limitation restricts data use to the specific purposes disclosed; tracking employees outside work hours exceeds the stated purpose of business-related fleet management.
Question 6: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to do which of the following?
- Encrypt all customer data at rest and in transit at all times
- Develop, implement, and maintain a comprehensive information security program (Correct answer)
- Appoint a Chief Privacy Officer at the C-suite level
- Notify customers before collecting any nonpublic personal information
Correct answer: Develop, implement, and maintain a comprehensive information security program
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customers' nonpublic personal information.
Question 7: A company's privacy notice states it uses customer email addresses only for order confirmations. Six months later, it wants to use those same emails for marketing. Under privacy best practices, what must it do first?
- Update the privacy notice on its website
- Obtain fresh consent or identify a new lawful basis before repurposing the data (Correct answer)
- Send an opt-out notification and wait 30 days
- Conduct a DPIA for the new marketing campaign
Correct answer: Obtain fresh consent or identify a new lawful basis before repurposing the data
Repurposing data for a materially different use requires either obtaining new consent or establishing a compatible lawful basis before the new processing begins.
Under HIPAA's Minimum Necessary Standard, when may a covered entity share an entire medical record with another covered entity?