Data Privacy and Information Security Compliance Flashcards
6 cards from real CCO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Privacy and Information Security Compliance flashcards as text
What is the principle of data minimization under GDPR?
Answer: Collecting only the personal data that is necessary for the specified purpose
Data minimization requires that organizations collect and process only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
What is the right to erasure ('right to be forgotten') under GDPR?
Answer: An individual's right to request deletion of their personal data under certain circumstances
The right to erasure allows individuals to request that their personal data be deleted when it is no longer necessary, consent is withdrawn, or processing is unlawful.
What is HIPAA and what type of data does it protect?
Answer: The Health Insurance Portability and Accountability Act, which protects protected health information (PHI) in the US
HIPAA establishes national standards for protecting sensitive patient health information from disclosure without the patient's consent or knowledge.
What is the role of a Data Protection Officer (DPO)?
Answer: To oversee data protection strategy and ensure compliance with GDPR and related privacy laws
A DPO advises on data protection obligations, monitors compliance with GDPR, and acts as the contact point for supervisory authorities and data subjects.
What is 'privacy by design'?
Answer: Embedding privacy protections into the design of systems, processes, and products from the outset rather than adding them later
Privacy by design integrates data protection into the development of technologies, processes, and business practices before they go live, rather than retrofitting protections afterward.
What is a lawful basis for processing personal data under GDPR?
Answer: One of six legal grounds such as consent, contract performance, legal obligation, vital interests, public task, or legitimate interests
GDPR requires every processing activity to be grounded in one of six lawful bases to ensure data is not processed arbitrarily or without justification.