CCP Compliance, Legal, & Ethical Issues 3 — Questions and Answers
Question 1: The EU-US Data Privacy Framework replaced which previous mechanism that was invalidated by the Schrems II ruling?
- GDPR Article 46 Standard Contractual Clauses
- Privacy Shield (Correct answer)
- Safe Harbor
- Binding Corporate Rules
Correct answer: Privacy Shield
The EU-US Privacy Shield was invalidated by the Court of Justice of the EU in the Schrems II decision due to US surveillance law concerns.
Question 2: Under HIPAA, a covered entity discovers a breach affecting 600 individuals. What is the notification deadline to the Secretary of HHS?
- Immediately upon discovery
- Within 30 days
- Within 60 days of discovery
- Within 60 days of year-end, or immediately if over 500 (Correct answer)
Correct answer: Within 60 days of year-end, or immediately if over 500
Breaches affecting 500+ individuals in a state must be reported to HHS within 60 days of discovery; smaller breaches are reported in annual logs within 60 days of year-end.
Question 3: Which concept in cybersecurity law holds that an organization may be liable for failing to implement reasonable security measures even without a specific breach occurring?
- Strict liability
- Negligence (Correct answer)
- Vicarious liability
- Contributory negligence
Correct answer: Negligence
Negligence in cybersecurity law means failing to exercise reasonable care in protecting systems and data, which can establish liability independent of an actual breach.
Question 4: A company collects children's data through a mobile app. Which US federal law imposes parental consent requirements?
- FERPA
- COPPA (Correct answer)
- CIPA
- SOPIPA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13.
Question 5: Which PCI DSS requirement specifically addresses the protection of stored cardholder data?
- Requirement 1 – Install and maintain firewalls
- Requirement 3 – Protect stored cardholder data (Correct answer)
- Requirement 6 – Maintain secure systems
- Requirement 10 – Track and monitor access
Correct answer: Requirement 3 – Protect stored cardholder data
PCI DSS Requirement 3 mandates that organizations protect stored cardholder data through encryption, masking, and data minimization practices.
Question 6: An employee uses company resources to run a personal cryptocurrency mining operation. Which ethical violation has primarily occurred?
- Breach of confidentiality
- Unauthorized use of resources (Correct answer)
- Failure to report a security incident
- Violation of need-to-know principle
Correct answer: Unauthorized use of resources
Using organizational resources for personal financial gain without authorization violates the ethical obligation to use employer resources only for authorized purposes.
Question 7: Which legal theory allows a plaintiff to sue for damages when a data breach results from a defendant's failure to meet an industry standard of care?
- Res ipsa loquitur
- Tortious interference
- Negligence per se (Correct answer)
- Unjust enrichment
Correct answer: Negligence per se
Negligence per se applies when a defendant violates a statute or regulation that establishes the standard of care, and that violation causes harm.
The EU-US Data Privacy Framework replaced which previous mechanism that was invalidated by the Schrems II ruling?