CCEP Data Privacy Compliance 4 — Questions and Answers
Question 1: Which GDPR role has primary accountability for compliance with data protection obligations, even when using third-party processors?
- Data Processor
- Data Controller (Correct answer)
- Data Protection Officer
- Supervisory Authority
Correct answer: Data Controller
The data controller determines the purposes and means of processing and retains primary accountability for GDPR compliance, including when processors are engaged.
Question 2: A hospital's business associate suffers a breach of 600 individuals' protected health information. Under HIPAA, what is the notification timeline to the Secretary of HHS?
- Immediately upon discovery
- Within 60 days of discovery
- Within 60 days of the calendar year end (Correct answer)
- Within 30 days of notifying affected individuals
Correct answer: Within 60 days of the calendar year end
For breaches affecting fewer than 500 individuals, HIPAA requires covered entities to notify HHS within 60 days of the end of the calendar year in which the breach occurred.
Question 3: Under Virginia's Consumer Data Protection Act (VCDPA), which of the following is NOT a right granted to Virginia consumers?
- Right to access their personal data
- Right to delete personal data they provided
- Right to private lawsuit for violations (Correct answer)
- Right to opt out of targeted advertising
Correct answer: Right to private lawsuit for violations
The VCDPA does not include a private right of action; enforcement is handled exclusively by the Virginia Attorney General.
Question 4: Which concept in privacy law holds that individuals should be notified about data collection practices and have a choice about how their information is used?
- Data minimization and storage limitation
- Notice and choice (Correct answer)
- Purpose specification and use limitation
- Security safeguards and accountability
Correct answer: Notice and choice
Notice and choice is a foundational privacy principle requiring that individuals be informed about data practices and given meaningful options about the use of their personal information.
Question 5: An organization subject to GDPR appoints a Data Protection Officer (DPO). Which of the following actions by the organization would violate GDPR Article 38?
- Involving the DPO in all matters relating to personal data protection
- Providing resources necessary for the DPO to carry out their tasks
- Dismissing the DPO for providing advice that conflicts with business objectives (Correct answer)
- Allowing the DPO to report directly to the highest management level
Correct answer: Dismissing the DPO for providing advice that conflicts with business objectives
GDPR Article 38(3) protects DPOs from dismissal or penalty for performing their tasks, ensuring independence; penalizing a DPO for providing unfavorable advice violates this protection.
Question 6: What is the primary purpose of conducting a privacy risk assessment before launching a new product?
- To satisfy a mandatory regulatory filing requirement
- To identify and mitigate privacy risks before they materialize and harm individuals (Correct answer)
- To determine the market value of the personal data being collected
- To establish a legal basis for processing under applicable law
Correct answer: To identify and mitigate privacy risks before they materialize and harm individuals
Privacy risk assessments proactively identify and mitigate potential harms to individuals before a product launches, embodying the Privacy by Design principle.
Question 7: A company's third-party vendor is involved in a ransomware attack that exposes customer PII. From a compliance perspective, who bears responsibility for ensuring the vendor had adequate security controls?
- The vendor bears sole responsibility as the data processor
- The company (data controller) bears accountability for vendor due diligence and contractual safeguards (Correct answer)
- Shared responsibility is automatic; no single party is accountable
- The cloud infrastructure provider hosting the vendor's systems
Correct answer: The company (data controller) bears accountability for vendor due diligence and contractual safeguards
Controllers are accountable for selecting processors that provide sufficient security guarantees and must verify this through contracts and due diligence under GDPR Article 28.
Which GDPR role has primary accountability for compliance with data protection obligations, even when using third-party processors?