CDPSE Privacy Compliance and Auditing 2 — Questions and Answers
Question 1: A privacy auditor reviews an organization's consent management system and finds that consent is bundled with terms of service. Which privacy principle is MOST likely violated?
- Data accuracy
- Freely given consent (Correct answer)
- Storage limitation
- Data portability
Correct answer: Freely given consent
Valid consent under GDPR and similar frameworks must be freely given, meaning it cannot be bundled with terms of service in a way that makes it conditional on accepting unrelated terms.
Question 2: Which type of audit evaluates both the design and operating effectiveness of privacy controls?
- Desk review
- Control effectiveness audit (Correct answer)
- Penetration test
- Compliance checklist review
Correct answer: Control effectiveness audit
A control effectiveness audit tests whether controls are both properly designed to address risks and actually operating as intended in practice over time.
Question 3: What is the MAIN purpose of a data protection audit trail?
- To track employee internet usage
- To provide an immutable record of data access, modifications, and deletions for accountability and incident investigation (Correct answer)
- To monitor network traffic for malware
- To measure application performance over time
Correct answer: To provide an immutable record of data access, modifications, and deletions for accountability and incident investigation
Audit trails record who accessed or modified personal data and when, supporting breach investigations, regulatory inquiries, and accountability requirements.
Question 4: An organization is preparing for a GDPR supervisory authority audit. Which document is MOST important to have readily available?
- IT infrastructure diagram
- Record of Processing Activities (RoPA) (Correct answer)
- Marketing campaign performance reports
- Employee handbook
Correct answer: Record of Processing Activities (RoPA)
The RoPA is a mandatory GDPR document that supervisory authorities commonly request first, as it provides a comprehensive overview of all personal data processing activities.
Question 5: Which of the following is a key indicator of a mature privacy compliance program?
- Zero privacy incidents ever recorded
- Regular privacy training, documented policies, and evidence of continuous monitoring and improvement (Correct answer)
- Complete reliance on automated compliance tools without human oversight
- A single annual privacy review conducted by legal counsel
Correct answer: Regular privacy training, documented policies, and evidence of continuous monitoring and improvement
Maturity in privacy programs is characterized by systematic training, documented policies, ongoing monitoring, and a culture of continuous improvement rather than point-in-time efforts.
Question 6: Under the CCPA, what must an organization provide to a consumer who submits a verifiable request to know about their personal information?
- A list of all employees who handled their data
- The categories and specific pieces of personal information collected, the purposes, and any third parties it was shared with (Correct answer)
- A complete backup of all data stored in their account
- A financial estimate of the value of their personal data
Correct answer: The categories and specific pieces of personal information collected, the purposes, and any third parties it was shared with
The CCPA's right to know requires businesses to disclose the categories, specific pieces, sources, purposes, and third-party disclosures of a consumer's personal information.
A privacy auditor reviews an organization's consent management system and finds that consent is bundled with terms of service.
Which privacy principle is MOST likely violated?