CCEP Data Privacy Compliance 5 β Questions and Answers
Question 1: Under CCPA as amended by CPRA, which new category of data receives heightened 'sensitive personal information' protections?
- Home addresses and phone numbers
- Social Security numbers and precise geolocation data (Correct answer)
- Purchase histories and browsing data
- Employment information and educational records
Correct answer: Social Security numbers and precise geolocation data
CPRA created a 'sensitive personal information' category that includes Social Security numbers, precise geolocation, racial/ethnic origin, and similar high-risk data, granting consumers the right to limit its use.
Question 2: Which privacy principle requires organizations to be able to demonstrate their compliance with data protection rules, rather than just stating they comply?
- Transparency
- Fairness
- Accountability (Correct answer)
- Integrity and confidentiality
Correct answer: Accountability
The accountability principle under GDPR Article 5(2) requires controllers to not only comply with data protection principles but to be able to demonstrate that compliance.
Question 3: An organization processes biometric data to authenticate employees at building entry points. Under GDPR, biometric data processed for unique identification is classified as which type of data?
- General personal data requiring standard safeguards
- Special category data requiring explicit consent or another Art. 9 basis (Correct answer)
- Pseudonymized data exempt from most GDPR requirements
- Anonymized data outside the scope of GDPR
Correct answer: Special category data requiring explicit consent or another Art. 9 basis
GDPR Article 9 classifies biometric data processed for the purpose of uniquely identifying a natural person as special category data requiring an explicit legal basis from Article 9(2).
Question 4: A US company receives a data subject access request (DSAR) from an EU customer under GDPR. What is the standard deadline for responding?
- 30 calendar days
- One month, extendable by two additional months for complex requests (Correct answer)
- 45 business days
- 60 days with automatic extension available
Correct answer: One month, extendable by two additional months for complex requests
GDPR Article 12(3) requires responding to DSARs within one month of receipt, with the possibility of extending by two additional months for complex or numerous requests after notifying the requester.
Question 5: Which of the following best describes 'Privacy by Design' as a compliance approach?
- Adding privacy controls after a product is deployed to meet regulatory requirements
- Embedding privacy protections into systems and processes from the earliest design stage (Correct answer)
- Publishing a comprehensive privacy policy before product launch
- Conducting annual privacy audits of existing systems
Correct answer: Embedding privacy protections into systems and processes from the earliest design stage
Privacy by Design, codified in GDPR Article 25, requires integrating data protection into the design of systems and business practices from the outset, not as an afterthought.
Question 6: Under FTC enforcement, which legal theory has the agency most commonly used to take action against companies with inadequate data security practices?
- Negligence per se under the Privacy Act
- Unfair or deceptive acts or practices under Section 5 of the FTC Act (Correct answer)
- Strict liability under state consumer protection statutes
- Breach of fiduciary duty to data subjects
Correct answer: Unfair or deceptive acts or practices under Section 5 of the FTC Act
The FTC relies on Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, to bring enforcement actions against companies whose data security fails to meet their stated commitments or harms consumers.
Question 7: A multinational company's EU operations involve processing that requires a DPIA, but the DPO advises that the identified risks cannot be fully mitigated internally. What must the organization do before proceeding?
- Proceed with processing after documenting the residual risks
- Consult the competent supervisory authority prior to processing (Correct answer)
- Obtain explicit consent from all affected data subjects
- Transfer the data to a jurisdiction with less restrictive privacy laws
Correct answer: Consult the competent supervisory authority prior to processing
GDPR Article 36 requires organizations to consult their supervisory authority prior to processing when a DPIA indicates the processing would result in high risk that cannot be mitigated.
Under CCPA as amended by CPRA, which new category of data receives heightened 'sensitive personal information' protections?