Data Privacy and Information Security Compliance Flashcards
6 cards from real CCO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Data Privacy and Information Security Compliance flashcards as text
What is a data processing agreement (DPA) and when is it required?
Answer: A legally required agreement between a data controller and a data processor outlining how personal data will be handled
A DPA is required under GDPR whenever a controller engages a third-party processor, specifying the subject-matter, duration, and nature of the processing.
What does 'pseudonymization' mean in data privacy?
Answer: Replacing directly identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces identifying fields with artificial identifiers, reducing re-identification risk while still allowing data utility, though it differs from full anonymization.
What is the purpose of a Records of Processing Activities (RoPA) under GDPR?
Answer: To document all processing activities involving personal data, required for organizations with 250 or more employees or high-risk processing
A RoPA serves as the organization's inventory of data processing activities and is a key accountability tool under GDPR Article 30.
What is the significance of cross-border data transfer restrictions under GDPR?
Answer: They restrict transferring personal data to countries outside the EEA that do not have adequate data protection levels
GDPR restricts transfers of personal data to third countries unless the destination has an adequacy decision or appropriate safeguards like Standard Contractual Clauses are in place.
What is a security incident response plan in the context of data privacy compliance?
Answer: A documented process for detecting, containing, assessing, notifying, and recovering from data security incidents
An incident response plan ensures the organization can act quickly and methodically when a data breach occurs, meeting notification timelines and minimizing harm.
What is 'consent' as a lawful basis under GDPR?
Answer: Freely given, specific, informed, and unambiguous indication of the data subject's agreement to processing their personal data
GDPR consent must be an active, affirmative, specific, and informed act — pre-ticked boxes or bundled consent does not qualify.