Data Privacy and Information Security Compliance Flashcards
6 cards from real CCO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Data Privacy and Information Security Compliance flashcards as text
What does GDPR stand for and which organizations must comply with it?
Answer: General Data Protection Regulation; applies to any organization processing personal data of EU residents
GDPR is the EU's comprehensive data protection law that applies to any organization, regardless of location, that processes personal data of EU residents.
What is 'personal data' under GDPR?
Answer: Any information relating to an identified or identifiable natural person
Personal data under GDPR includes any information that can directly or indirectly identify a natural person, including names, email addresses, location data, and online identifiers.
What is the maximum fine for a serious GDPR violation?
Answer: €20 million or 4% of global annual turnover, whichever is higher
GDPR's highest tier of fines reaches €20 million or 4% of total worldwide annual revenue, whichever is greater.
What is the California Consumer Privacy Act (CCPA)?
Answer: California's state privacy law granting consumers rights over their personal data collected by businesses
The CCPA gives California consumers the right to know, delete, and opt out of the sale of their personal information held by qualifying businesses.
What is a Data Protection Impact Assessment (DPIA)?
Answer: A structured process to identify and minimize data protection risks in high-risk processing activities
DPIAs are required under GDPR for processing activities that pose high risks to individuals' rights, helping organizations identify and mitigate those risks before implementation.
What is the GDPR requirement for reporting a personal data breach to supervisory authorities?
Answer: Within 72 hours of becoming aware of the breach, unless it is unlikely to result in risk to individuals
GDPR requires notifying the relevant supervisory authority within 72 hours of discovering a personal data breach, unless the breach is low-risk.