CDPSE - Certified Data Privacy Solutions Engineer — Questions and Answers
Question 1: The epsilon (ε) parameter in differential privacy controls:
- The number of parties allowed to query the differentially private system
- The encryption strength of the noise-generation algorithm
- The number of records required for statistical significance
- The privacy-utility tradeoff, where lower epsilon means stronger privacy but less accurate results (Correct answer)
Correct answer: The privacy-utility tradeoff, where lower epsilon means stronger privacy but less accurate results
Epsilon (ε) is the privacy budget; a smaller epsilon adds more noise for stronger privacy guarantees but reduces the accuracy of aggregate query results.
Question 2: How does the US CCPA's consent approach for opt-out of data sale differ from GDPR's opt-in consent model?
- CCPA applies a blanket ban on selling consumer data, eliminating the need for a consent mechanism entirely
- CCPA and GDPR both require opt-in consent, but CCPA applies only to California residents over age 16
- CCPA gives consumers the right to opt out of the sale of their data via a 'Do Not Sell My Personal Information' link, whereas GDPR requires affirmative opt-in consent before processing (Correct answer)
- CCPA requires businesses to obtain opt-in consent before selling personal information from any adult consumer
Correct answer: CCPA gives consumers the right to opt out of the sale of their data via a 'Do Not Sell My Personal Information' link, whereas GDPR requires affirmative opt-in consent before processing
CCPA uses an opt-out model for data sales — processing is allowed by default and consumers must actively opt out — while GDPR's consent basis requires prior affirmative opt-in.
Question 3: What is the primary purpose of conducting a privacy maturity assessment within a governance program?
- To eliminate the need for future privacy audits
- To satisfy annual regulatory filing requirements
- To benchmark current capabilities against a defined model and identify gaps (Correct answer)
- To transfer privacy liability to assessment vendors
Correct answer: To benchmark current capabilities against a defined model and identify gaps
A privacy maturity assessment benchmarks existing practices against a capability model, revealing gaps and prioritizing improvements.
Question 4: A CDPSE candidate is designing a data retention schedule. Which factor is MOST critical to determine first?
- Legal and regulatory retention requirements (Correct answer)
- Cost of storage media
- User access frequency
- Available storage capacity
Correct answer: Legal and regulatory retention requirements
Legal and regulatory requirements set the minimum and maximum retention periods that override business convenience or cost considerations.
Question 5: Which of the following characteristics should be included in a company's technology stack in order to meet privacy standards relating to data subjects' rights to control their personal information?
- Establishing a data privacy customer service bot for individuals
- Allowing system administrators to manage data access
- Providing system engineers the ability to search and retrieve data
- Allowing individuals to have direct access to their data (Correct answer)
Correct answer: Allowing individuals to have direct access to their data
Privacy regulations like GDPR and CCPA grant data subjects the fundamental right to access their personal information held by organizations. Therefore, a company's technology stack must be designed to enable individuals to directly view, obtain, and potentially correct their data. This capability is crucial for demonstrating transparency and empowering individuals to exercise control over their personal information, which are core tenets of modern privacy standards.
Question 6: Under a privacy governance framework, what is the purpose of a data protection impact assessment (DPIA) trigger list?
- To replace the need for data processing agreements
- To define which data can be deleted without review
- To identify processing activities that automatically require a DPIA before commencement (Correct answer)
- To establish data retention schedules
Correct answer: To identify processing activities that automatically require a DPIA before commencement
A DPIA trigger list enumerates high-risk processing scenarios (e.g., large-scale profiling, biometric processing) that mandatorily require a DPIA.
Question 7: When managing privacy risks, it is crucial to distinguish them from security risks. Which of the following scenarios describes a privacy risk arising from authorized data processing, rather than a security risk from unauthorized access?
- An employee's login credentials are stolen and used to exfiltrate a client database.
- A hacker exploits a software vulnerability to access customer records.
- An unencrypted laptop containing personal data is lost or stolen.
- Customer data collected for marketing is used to make automated, adverse credit decisions without transparency. (Correct answer)
Correct answer: Customer data collected for marketing is used to make automated, adverse credit decisions without transparency.
Privacy risks can arise from authorized data processing activities that are problematic, while security risks typically stem from unauthorized access. Using data for a secondary purpose that is incompatible with the original purpose for which it was collected, and which has a significant negative impact on the individual (like an adverse credit decision), is a classic example of a privacy risk resulting from authorized, but inappropriate, data processing.
Question 8: An employee asks their employer to delete all personal data collected about them. Under GDPR, which exemption most likely allows the employer to retain employment records?
- Legitimate interest in retaining all HR data indefinitely
- Consent obtained during onboarding
- Legal obligation to maintain employment and payroll records under national law (Correct answer)
- Contractual necessity with the employee
Correct answer: Legal obligation to maintain employment and payroll records under national law
Employment records are typically subject to statutory retention requirements, qualifying as a legal obligation that overrides the erasure right under GDPR Article 17(3)(b).
Question 9: What is the primary purpose of consent management in data privacy?
- To define the retention period for all personal data assets
- To encrypt personal data before storing it in a database
- To document and enforce user agreements for the collection and processing of personal data (Correct answer)
- To authenticate users before they access a privacy portal
Correct answer: To document and enforce user agreements for the collection and processing of personal data
Consent management ensures organizations obtain, record, and honor individuals' explicit agreement regarding how their personal data is collected and used.
Question 10: When Privacy by Design says it should be 'embedded into design,' what does this primarily mean for software architects?
- Privacy features are added as plugins after development
- Privacy compliance is handled exclusively by legal teams
- Privacy controls are bolted on during the testing phase
- Privacy is integrated as a core component of the system architecture (Correct answer)
Correct answer: Privacy is integrated as a core component of the system architecture
Embedding privacy into design means it is a core architectural element, not an afterthought or add-on layer.
Question 11: Under GDPR, which mechanism allows a US company to legally receive personal data from the EU without an adequacy decision?
- APEC CBPR
- Standard Contractual Clauses (SCCs) (Correct answer)
- Privacy Shield
- Safe Harbor Agreement
Correct answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses are EU-approved contractual templates that provide a valid transfer mechanism after Privacy Shield was invalidated by Schrems II.
Question 12: An organization publishes its data processing algorithms and allows independent third-party audits of its privacy controls. This most directly demonstrates which principle?
- Privacy Embedded into Design
- Visibility and Transparency — Keep it Open (Correct answer)
- Proactive not Reactive
- Full Functionality
Correct answer: Visibility and Transparency — Keep it Open
Visibility and Transparency requires that organizations open their practices to independent verification, going beyond self-attestation.
Question 13: What is the BEST method for ensuring that personal data is irreversibly destroyed at the end of its retention period?
- Deleting the file from the folder
- Changing file permissions to restrict access
- Overwriting data with random bits multiple times (Correct answer)
- Moving data to an archive folder
Correct answer: Overwriting data with random bits multiple times
Cryptographic erasure or multi-pass overwriting renders data unrecoverable, meeting the standard for irreversible destruction under data protection regulations.
Question 14: Which metric is MOST useful when quantifying the likelihood component of a privacy risk?
- Number of records exposed in past breaches industry-wide
- Historical frequency of similar threat events within the organization (Correct answer)
- The organization's current data breach insurance premium
- The cost of replacing compromised personal data
Correct answer: Historical frequency of similar threat events within the organization
Internal historical frequency of similar events provides the most relevant and organization-specific input for likelihood estimation.
Question 15: An organization allows users to opt out of data sharing but sets opt-in as the default. Does this satisfy the 'Privacy as the Default' principle?
- Yes, because opt-out provides sufficient user control
- Yes, because users can always change their settings
- No, because privacy settings should not be configurable
- No, because the most privacy-protective option must be the default (Correct answer)
Correct answer: No, because the most privacy-protective option must be the default
Privacy as the Default requires that the strongest privacy protections apply automatically without any user action.
Question 16: A cloud vendor stores EU customer data on US servers. Which document MUST exist to make this transfer lawful under GDPR?
- A software license agreement
- An ISO 27001 certification from the cloud vendor
- A valid data transfer mechanism such as SCCs incorporated in the Data Processing Agreement (Correct answer)
- A bilateral trade agreement between the EU and US
Correct answer: A valid data transfer mechanism such as SCCs incorporated in the Data Processing Agreement
A valid transfer mechanism—most commonly SCCs incorporated into a DPA—is legally required for any transfer of EU personal data to a country lacking an adequacy decision.
Question 17: A CDPSE is advising on a new IoT product that collects continuous location data from users. Which privacy risk is MOST significant and should be prioritized?
- Risk of insufficient data volume for analytics
- Risk of inferred sensitive attributes from location patterns (Correct answer)
- Risk of data becoming outdated
- Risk of users opting out of data collection
Correct answer: Risk of inferred sensitive attributes from location patterns
Continuous location data can reveal sensitive inferences such as medical appointments, religious practices, or political activities, making inference risk the most significant concern.
Question 18: Which condition allows an organization to REFUSE a right-to-erasure request under GDPR?
- The data was collected more than two years ago
- The data is necessary for compliance with a legal obligation (Correct answer)
- The data subject is not an EU resident
- The data subject has not paid a fee
Correct answer: The data is necessary for compliance with a legal obligation
GDPR Article 17(3) permits refusal of erasure requests when retention is necessary to comply with a legal obligation.
Question 19: Which emerging privacy-enhancing technology uses cryptographic commitments to allow auditors to verify data processing compliance without accessing the underlying data?
- Synthetic data
- Zero-knowledge proofs (Correct answer)
- Differential privacy
- K-anonymity
Correct answer: Zero-knowledge proofs
Zero-knowledge proofs allow a party to prove that a computation was performed correctly or that data meets certain criteria without revealing the actual data to the verifier.
Question 20: Which of the following principles of Privacy by Design (PbD) is BEST demonstrated by configuring an application's data sharing settings to 'off' by default, requiring the user to actively enable sharing?
- Proactive not Reactive; Preventative not Remedial
- Privacy as the Default Setting (Correct answer)
- Visibility and Transparency – Keep it Open
- Full Functionality – Positive-Sum, not Zero-Sum
Correct answer: Privacy as the Default Setting
The principle of 'Privacy as the Default Setting' ensures that personal data is automatically protected in any given system or business practice. No action is required on the part of the individual to protect their privacy; it is built into the system by default. Setting data sharing to 'off' is a direct implementation of this principle.
Question 21: Which activity BEST supports the principle of data minimization during system design?
- Backing up data to multiple geographic regions
- Applying role-based access controls to all data
- Encrypting all collected fields
- Collecting only the data elements strictly required for the defined purpose (Correct answer)
Correct answer: Collecting only the data elements strictly required for the defined purpose
Data minimization means not collecting personal data beyond what is necessary, reducing the privacy risk surface from the outset.
Question 22: What does a privacy maturity model assess?
- The degree to which an organization's privacy practices have evolved toward a defined ideal state (Correct answer)
- The technical security level of an organization's IT infrastructure
- The number of privacy incidents reported in a given year
- The financial penalties an organization may face for non-compliance
Correct answer: The degree to which an organization's privacy practices have evolved toward a defined ideal state
A privacy maturity model benchmarks an organization's privacy program against defined capability levels, helping identify improvement priorities.
Question 23: A privacy officer receives a credible tip that an employee has been emailing customer personal data to a personal account. Which incident response step should occur FIRST?
- Preserve evidence by capturing email logs before the employee is confronted (Correct answer)
- Notify all affected customers immediately
- Issue a public press release disclosing the potential breach
- Delete the employee's account to prevent further exfiltration
Correct answer: Preserve evidence by capturing email logs before the employee is confronted
Preserving forensic evidence before taking containment or notification actions ensures the organization has an accurate record for investigation and legal purposes.
Question 24: A financial institution is launching a new AI-driven service to analyze customer spending habits and offer personalized loan products. This involves processing large volumes of sensitive financial data and making automated decisions. Within a robust privacy governance framework, what is the MOST critical activity to perform before launching this service?
- Performing a routine data backup.
- Training the marketing team on the new product features.
- Updating the public-facing privacy notice.
- Conducting a Data Protection Impact Assessment (DPIA). (Correct answer)
Correct answer: Conducting a Data Protection Impact Assessment (DPIA).
Given that the new service involves processing sensitive data on a large scale and uses new technology (AI) for profiling and automated decision-making, it is considered a high-risk processing activity. Under regulations like GDPR, conducting a Data Protection Impact Assessment (DPIA) is mandatory for such high-risk projects to identify and mitigate privacy risks before they materialize.
Question 25: Which element distinguishes a Privacy Impact Assessment (PIA) from a general risk assessment?
- A PIA specifically evaluates risks to individuals' privacy rights and freedoms (Correct answer)
- A PIA is only required for government agencies
- A PIA focuses exclusively on financial risks
- A PIA replaces the need for a security risk assessment
Correct answer: A PIA specifically evaluates risks to individuals' privacy rights and freedoms
A PIA specifically evaluates how a project or system affects the privacy rights and freedoms of individuals, not just organizational or financial risk.
Question 26: An organization collects customer email addresses for order confirmations but later uses them for marketing newsletters. This violates which data lifecycle principle?
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
- Data accuracy
Correct answer: Purpose limitation
Purpose limitation requires that personal data collected for a specific purpose must not be used for incompatible secondary purposes without a new legal basis.
Question 27: Format-preserving encryption (FPE) is preferred over standard encryption in some data systems because:
- It produces ciphertext in the same format as plaintext, minimizing application changes (Correct answer)
- It does not require key management infrastructure
- It is faster than all other encryption algorithms
- It provides stronger cryptographic guarantees than AES
Correct answer: It produces ciphertext in the same format as plaintext, minimizing application changes
FPE maintains the format (length, character set) of the original data, allowing encrypted values to pass validation rules and minimizing changes to downstream systems.
Question 28: Which risk treatment option involves purchasing cyber liability insurance to cover costs associated with a data breach?
- Risk transfer (Correct answer)
- Risk acceptance
- Risk avoidance
- Risk mitigation
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party, such as an insurer, though the underlying risk and liability may still remain.
Question 29: An organization processes personal data in Country A and transfers it to a processor in Country B, which lacks an adequacy decision. What privacy risk does this introduce?
- Risk of losing intellectual property rights to the data
- Increased risk of data corruption during transit
- Risk of the processor retaining data beyond the agreed retention period
- Risk of non-compliance with data transfer restrictions and inadequate protection standards (Correct answer)
Correct answer: Risk of non-compliance with data transfer restrictions and inadequate protection standards
Transferring data to a country without an adequacy decision creates legal and protection-level risk, requiring additional safeguards such as Standard Contractual Clauses.
Question 30: Which control BEST addresses the privacy risk of employees accessing more personal data than their role requires?
- Data loss prevention scanning on email
- Multi-factor authentication for all logins
- Full-disk encryption on workstations
- Attribute-based access control with least privilege (Correct answer)
Correct answer: Attribute-based access control with least privilege
Attribute-based access control with least privilege ensures employees can access only the personal data their specific role and purpose require.
Question 31: A CDPSE is reviewing a vendor contract for cloud data processing. What privacy clause is MOST critical to include?
- SLA guarantees for 99.9% uptime
- Insurance coverage for business interruption
- A non-disclosure agreement covering proprietary algorithms
- A Data Processing Agreement (DPA) specifying controller obligations (Correct answer)
Correct answer: A Data Processing Agreement (DPA) specifying controller obligations
A Data Processing Agreement is legally required under GDPR when a controller engages a processor, defining each party's data protection obligations.
Question 32: An organization is building a privacy governance committee. Which representation is MOST critical for effective privacy decision-making?
- The DPO and CISO exclusively
- External privacy consultants only
- Cross-functional representation including legal, IT, HR, marketing, and operations (Correct answer)
- Only legal and compliance personnel
Correct answer: Cross-functional representation including legal, IT, HR, marketing, and operations
Cross-functional representation ensures privacy decisions account for all business functions that process personal data.
Question 33: Which of the following BEST describes the difference between a privacy risk assessment and a Data Protection Impact Assessment (DPIA)?
- A DPIA is legally mandated for high-risk processing under GDPR, while a privacy risk assessment is a general best-practice tool (Correct answer)
- A DPIA focuses on technical controls while a privacy risk assessment focuses on legal compliance
- A DPIA is broader and covers all organizational risks, while a privacy risk assessment is narrower
- A privacy risk assessment replaces the need for a DPIA under all frameworks
Correct answer: A DPIA is legally mandated for high-risk processing under GDPR, while a privacy risk assessment is a general best-practice tool
Under GDPR Article 35, a DPIA is legally required for high-risk processing activities, whereas a privacy risk assessment is a broader, framework-agnostic practice.
Question 34: Which of the following should be documented in an incident response log to support regulatory accountability?
- Employee salaries of the response team
- Timestamps, actions taken, decisions made, and personnel involved (Correct answer)
- Names of competing organizations that were not affected
- Marketing campaign performance during the incident
Correct answer: Timestamps, actions taken, decisions made, and personnel involved
A detailed incident log with timestamps, actions, decisions, and personnel creates the audit trail required to demonstrate regulatory accountability.
Question 35: Under GDPR, a Data Protection Officer (DPO) reports a data breach to the supervisory authority 80 hours after discovery. What is the consequence?
- No consequence if the breach was minor
- The notification is late since GDPR requires 72 hours (Correct answer)
- The organization receives automatic immunity
- The 80-hour window is acceptable if justified
Correct answer: The notification is late since GDPR requires 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a breach.
Question 36: A financial services firm wants to analyze transaction patterns across multiple banks without any bank revealing its customers' individual transactions to the others. The most appropriate PET is:
- Federated learning on aggregated statistics
- Secure multi-party computation (SMPC) (Correct answer)
- Differential privacy applied independently at each bank
- Pseudonymization with a shared key
Correct answer: Secure multi-party computation (SMPC)
SMPC allows multiple banks to jointly compute analytics on their combined data without any party ever seeing another party's raw transaction records.
Question 37: During which data lifecycle phase is the Privacy Impact Assessment (PIA) MOST effectively initiated?
- Data analysis phase
- Data archiving phase
- Data collection phase (Correct answer)
- Data disposal phase
Correct answer: Data collection phase
Initiating a PIA during the data collection design phase allows privacy risks to be mitigated before personal data is ever gathered.
Question 38: An engineer recommends that a new payment system fail to a locked-out state rather than an open state if authentication fails. This is an example of which security principle aligned with Privacy by Design?
- Least Privilege
- Fail Secure (Fail Safe) (Correct answer)
- Defense in Depth
- Zero Trust
Correct answer: Fail Secure (Fail Safe)
Fail Secure ensures that when a system fails, it defaults to denying access rather than inadvertently granting it.
Question 39: Which incident response role is MOST responsible for determining whether a privacy breach notification obligation exists?
- Chief Privacy Officer or Privacy Counsel (Correct answer)
- System Administrator
- Marketing Director
- IT Security Analyst
Correct answer: Chief Privacy Officer or Privacy Counsel
The Chief Privacy Officer or Privacy Counsel interprets applicable privacy laws to determine whether a breach triggers mandatory notification obligations.
Question 40: An organization uses a cloud service provider to store personal data. The CSP experiences a breach. Under GDPR, which party must notify the supervisory authority?
- The organization (controller) must notify the supervisory authority (Correct answer)
- The CSP (processor) must notify the supervisory authority directly
- No notification is required when a processor causes the breach
- The data subject must notify the supervisory authority
Correct answer: The organization (controller) must notify the supervisory authority
The controller holds the notification obligation under GDPR; the processor must notify the controller without undue delay so the controller can meet its obligations.
Question 41: A CDPSE is evaluating privacy risks associated with a biometric authentication system. Which risk is MOST specific to biometric data?
- Risk of users forgetting their biometric credentials
- Risk of system downtime affecting user access
- Risk of the authentication system being slower than password-based alternatives
- Risk of irreversible harm since biometric data cannot be changed if compromised (Correct answer)
Correct answer: Risk of irreversible harm since biometric data cannot be changed if compromised
Unlike passwords, biometric identifiers (fingerprints, facial features) are permanent; a compromise creates lifelong risk because they cannot be reset.
Question 42: A CDPSE is reviewing a cloud migration project. Which privacy risk is introduced SPECIFICALLY by moving personal data to a cloud provider?
- Risk of employees accessing data without authorization
- Risk of data being subject to foreign government access laws (Correct answer)
- Risk of data loss due to hardware failure
- Risk of data becoming corrupted during migration
Correct answer: Risk of data being subject to foreign government access laws
Cloud providers may be subject to the laws of their home country (e.g., US CLOUD Act), allowing foreign governments to compel access to data stored by those providers.
Question 43: What does a data retention legal hold require an organization to do?
- Transfer data to a third-party escrow service
- Suspend normal retention schedules and preserve relevant data for legal proceedings (Correct answer)
- Encrypt all potentially relevant data in place
- Immediately delete all data related to ongoing litigation
Correct answer: Suspend normal retention schedules and preserve relevant data for legal proceedings
A legal hold overrides standard deletion schedules, requiring organizations to preserve all potentially relevant data until the legal matter is resolved.
Question 44: What is the function of 'threat modeling' within an impact assessment for a data-intensive system?
- Estimating software development costs for privacy features
- Auditing third-party contract compliance
- Systematically identifying potential adversaries, attack vectors, and privacy harms they could cause (Correct answer)
- Reviewing physical security of server facilities
Correct answer: Systematically identifying potential adversaries, attack vectors, and privacy harms they could cause
Threat modeling identifies who might seek to misuse data, how they could do so, and what privacy harms could result — informing the risk assessment phase of the DPIA.
Question 45: A company uses an AI model trained on customer data to make credit decisions. Which privacy principle is MOST relevant to ensure fairness and transparency?
- Purpose limitation
- Storage limitation
- Right to explanation for automated decisions (Correct answer)
- Data portability
Correct answer: Right to explanation for automated decisions
GDPR Article 22 grants individuals the right not to be subject to solely automated decisions and entitles them to an explanation of the logic involved.
Question 46: What is the key difference between a privacy audit and a security audit?
- Privacy audits focus on financial data; security audits focus on personal data
- Privacy audits are only performed by external parties; security audits can be internal
- Privacy audits evaluate compliance with personal data rights and regulations; security audits assess technical controls protecting data confidentiality and integrity (Correct answer)
- Security audits are legally required; privacy audits are voluntary
Correct answer: Privacy audits evaluate compliance with personal data rights and regulations; security audits assess technical controls protecting data confidentiality and integrity
While overlapping, privacy audits focus on regulatory compliance, individual rights, and data use legitimacy, whereas security audits focus on technical protections against unauthorized access.
Question 47: Which sanitization standard is MOST commonly referenced for the secure disposal of US government data on magnetic media?
- PCI DSS v4.0
- FIPS 140-3
- NIST SP 800-88 (Correct answer)
- ISO/IEC 27001
Correct answer: NIST SP 800-88
NIST SP 800-88 'Guidelines for Media Sanitization' provides the authoritative US standard for clearing, purging, and destroying data on various media types.
Question 48: An organization wants to use a risk scoring matrix for privacy risks. Which TWO dimensions are MOST commonly used in such a matrix?
- Impact and likelihood (Correct answer)
- Detectability and severity
- Cost and duration
- Complexity and urgency
Correct answer: Impact and likelihood
A standard risk matrix plots likelihood (probability of occurrence) against impact (magnitude of harm) to produce a risk score.
Question 49: A governance framework that requires business units to complete a privacy threshold assessment before launching new projects primarily serves to:
- Satisfy vendor onboarding requirements
- Replace the need for a full PIA/DPIA
- Identify privacy risks early enough to address them before deployment (Correct answer)
- Slow down project timelines unnecessarily
Correct answer: Identify privacy risks early enough to address them before deployment
Privacy threshold assessments are early-stage screening tools that flag high-risk projects requiring deeper privacy analysis before deployment.
Question 50: Under the GDPR accountability principle, which of the following BEST demonstrates that an organization has embedded governance?
- Publishing a privacy notice on the company website
- Subscribing to a legal update service
- Maintaining records of processing activities and documented evidence of compliance measures (Correct answer)
- Obtaining ISO 27001 certification
Correct answer: Maintaining records of processing activities and documented evidence of compliance measures
Records of processing activities (Article 30) and documented compliance measures are the primary evidence of embedded accountability under GDPR.
Question 51: How does the principle of 'purpose limitation' interact with consent management?
- Purpose limitation allows an organization to reuse consent for any future processing that benefits the user
- Purpose limitation requires deleting data after the initially consented purpose is fulfilled within 30 days
- Purpose limitation means consent obtained for one specific purpose cannot be used to justify processing for a different purpose without new consent (Correct answer)
- Purpose limitation is a financial regulation unrelated to privacy consent
Correct answer: Purpose limitation means consent obtained for one specific purpose cannot be used to justify processing for a different purpose without new consent
Purpose limitation (GDPR Article 5(1)(b)) requires that data collected under consent for purpose A cannot be repurposed for purpose B without obtaining fresh consent.
Question 52: A company's privacy notice fails to inform data subjects of their right to withdraw consent. Under GDPR, what is the consequence?
- The supervisory authority must be notified within 24 hours
- Processing is automatically lawful because other bases may apply
- The company must pay a fixed fine of €1,000
- Consent obtained without this information may be invalid, rendering the processing unlawful (Correct answer)
Correct answer: Consent obtained without this information may be invalid, rendering the processing unlawful
GDPR requires that privacy notices include the right to withdraw consent; failure to inform means consent may not have been freely given and could be deemed invalid.
Question 53: Which of the following BEST illustrates the concept of 'privacy harm' in risk assessment?
- An organization paying a regulatory fine for a breach
- A data subject losing employment after medical data is disclosed to their employer (Correct answer)
- An organization failing a third-party security audit
- An IT system experiencing downtime due to a ransomware attack
Correct answer: A data subject losing employment after medical data is disclosed to their employer
Privacy harm refers to real-world negative consequences suffered by individuals, such as economic loss, discrimination, or emotional distress resulting from misuse of their data.
Question 54: Which GDPR article establishes the right to erasure ('right to be forgotten')?
- Article 16
- Article 17 (Correct answer)
- Article 21
- Article 15
Correct answer: Article 17
GDPR Article 17 establishes the right to erasure, allowing data subjects to request deletion of their personal data under specific conditions.
Question 55: A privacy governance framework should ensure that privacy requirements are embedded into the system development lifecycle (SDLC) through which practice?
- Third-party code reviews only
- Post-launch penetration testing
- Privacy by Design integration at each SDLC phase (Correct answer)
- End-user training on new features
Correct answer: Privacy by Design integration at each SDLC phase
Privacy by Design embeds privacy controls and requirements at every SDLC phase rather than retrofitting them after development.
Question 56: A financial services company wants to leverage a third-party cloud service for complex data analytics. A key privacy requirement is that the cloud provider must be able to perform calculations (e.g., summations, multiplications) directly on the data while it remains encrypted, with only the company able to decrypt the final results. Which Privacy Enhancing Technology (PET) should a privacy engineer recommend?
- Data Masking
- Differential Privacy
- Homomorphic Encryption (Correct answer)
- Zero-Knowledge Proofs
Correct answer: Homomorphic Encryption
Homomorphic encryption is a specific form of encryption that allows computation on ciphertexts, generating an encrypted result which, when decrypted, matches the result of the operations as if they had been performed on the plaintext. This directly meets the requirement of performing calculations on encrypted data.
Question 57: Which approach to user consent design best aligns with the 'Privacy as the Default' and 'Respect for User Privacy' principles combined?
- Implied consent based on continued use of the service
- Bundling consent for all data uses into a single terms acceptance
- Pre-checked consent boxes with fine print explaining data uses
- Granular opt-in consent with plain language and easy withdrawal (Correct answer)
Correct answer: Granular opt-in consent with plain language and easy withdrawal
Granular opt-in consent with clear language and easy withdrawal respects autonomy (user-centric) and ensures the default state is non-consented (privacy as default).
Question 58: A privacy risk assessment reveals a HIGH inherent risk for a customer data analytics program. After applying controls, residual risk drops to LOW. What should the CDPSE do next?
- Discontinue the program since inherent risk was high
- Conduct a full audit before allowing the program to launch
- Escalate the residual risk to the board for approval
- Document the controls and obtain risk owner sign-off on residual risk (Correct answer)
Correct answer: Document the controls and obtain risk owner sign-off on residual risk
Once residual risk is reduced to an acceptable level, the CDPSE should document the controls applied and obtain formal acceptance from the risk owner.
Question 59: A social media platform wants to publish a report on user behavior trends without revealing information about any single individual. To accomplish this, their privacy engineering team implements a system that adds a precisely calculated amount of statistical noise to the aggregate query results before publication. This ensures that the presence or absence of any single user's data does not significantly affect the final output. This technique is known as:
- k-Anonymity
- Differential Privacy (Correct answer)
- t-Closeness
- l-Diversity
Correct answer: Differential Privacy
Differential Privacy is a mathematically rigorous framework designed to share aggregate information about a dataset while withholding information about the specific individuals within it. It achieves this by injecting carefully calibrated statistical noise into the results of database queries, providing a formal guarantee that an adversary cannot confidently determine whether any given individual's data was included in the computation.
Question 60: A company stores personal data on decommissioned server hard drives in a locked warehouse. What is the MAIN privacy risk?
- Increased regulatory audit frequency
- Data accuracy degradation over time
- Unauthorized physical access leading to data recovery (Correct answer)
- Loss of data availability for business use
Correct answer: Unauthorized physical access leading to data recovery
Retaining unwiped storage media creates a risk that data could be physically accessed and recovered using forensic tools.
Question 61: A privacy engineer is creating a screening questionnaire to help project managers determine if a full Privacy Impact Assessment is required for a new initiative. Which of the following questions would be MOST effective in identifying a trigger for a mandatory PIA?
- Is the project budget greater than the established departmental threshold?
- Will the personal data be stored for longer than one year?
- Does the project introduce a new technology or a novel use of existing technology for processing personal data? (Correct answer)
- Will the project involve processing data from more than 100 individuals?
Correct answer: Does the project introduce a new technology or a novel use of existing technology for processing personal data?
A primary trigger for conducting a PIA is when a project involves new or significantly changed ways of handling personal data, especially using new technologies. This creates uncertainty about the potential privacy impact, making a systematic assessment necessary. While the number of individuals or data retention periods are factors, the introduction of novel processing is a more direct and critical trigger.
Question 62: After resolving a privacy incident, what is the MOST important action for long-term privacy program improvement?
- Conducting a post-incident review and updating policies and controls (Correct answer)
- Immediately deleting all logs related to the incident
- Hiring new staff to handle future incidents
- Replacing all affected hardware regardless of cost
Correct answer: Conducting a post-incident review and updating policies and controls
A post-incident review identifies gaps, updates controls, and feeds lessons learned back into policies to strengthen the privacy program.
Question 63: A CDPSE is conducting a privacy risk assessment for a machine learning model trained on customer purchase history. Which risk is UNIQUE to this type of processing?
- Inference of sensitive attributes not explicitly provided by users (Correct answer)
- Failure to encrypt data at rest
- Unauthorized access by external attackers
- Improper data retention schedules
Correct answer: Inference of sensitive attributes not explicitly provided by users
ML models can infer sensitive attributes (e.g., health status, political views) from seemingly innocuous behavioral data, creating a unique re-identification or inference risk.
Question 64: In a trusted execution environment (TEE), data privacy is protected by:
- Processing sensitive data in an isolated hardware enclave inaccessible to the host OS (Correct answer)
- Applying differential privacy noise before any computation
- Encrypting data using the data subject's public key
- Storing data in a geographically distributed manner
Correct answer: Processing sensitive data in an isolated hardware enclave inaccessible to the host OS
A TEE (such as Intel SGX or ARM TrustZone) provides a hardware-isolated enclave where code and data are protected even from the operating system or hypervisor.
Question 65: A key principle within the GDPR is 'Accountability'. What does this principle require of an organization?
- To ensure all personal data collected is 100% accurate at all times.
- To be responsible for and able to demonstrate compliance with all GDPR principles. (Correct answer)
- To process data only when it is absolutely necessary for business operations.
- To respond to data subject access requests within 24 hours of receipt.
Correct answer: To be responsible for and able to demonstrate compliance with all GDPR principles.
The accountability principle, as defined in Article 5(2) of the GDPR, requires that data controllers are not only responsible for complying with the GDPR's principles but must also be able to demonstrate that compliance. This involves maintaining documentation, implementing data protection by design and default, and having appropriate policies and procedures in place.
Question 66: Which of the following BEST describes 'data provenance' in the context of privacy?
- The classification level assigned to sensitive data
- The origin and chain of custody of data throughout its lifecycle (Correct answer)
- The legal basis for processing personal data
- The geographic location where data is stored
Correct answer: The origin and chain of custody of data throughout its lifecycle
Data provenance tracks where data came from, how it was transformed, and who handled it, supporting accountability and auditability.
Question 67: Under the CDPSE framework, who bears primary accountability for defining data retention policies?
- Data owner or business unit responsible for the data (Correct answer)
- Cloud service provider
- External auditors
- IT security team
Correct answer: Data owner or business unit responsible for the data
The data owner is accountable for determining how long data must be retained to meet business and regulatory requirements.
Question 68: What did the Court of Justice of the EU (CJEU) determine in the Schrems II ruling regarding Privacy Shield?
- Privacy Shield was replaced by Standard Contractual Clauses automatically
- Privacy Shield was strengthened with additional safeguards
- Privacy Shield was limited to B2B transfers only
- Privacy Shield was invalidated due to inadequate US surveillance law protections (Correct answer)
Correct answer: Privacy Shield was invalidated due to inadequate US surveillance law protections
The CJEU invalidated Privacy Shield in 2020 because US surveillance laws did not provide EU residents with effective remedies equivalent to EU rights.
Question 69: What is 'dynamic consent' and how does it benefit data subjects in long-term research studies?
- Dynamic consent is a machine-learning model that predicts whether a user would consent to a new data use
- Dynamic consent is a one-time consent that automatically renews every year without user action
- Dynamic consent is consent granted by a data subject's attorney that adapts to regulatory changes
- Dynamic consent allows participants to continuously review, update, or withdraw their consent for specific uses of their data over time via an online platform (Correct answer)
Correct answer: Dynamic consent allows participants to continuously review, update, or withdraw their consent for specific uses of their data over time via an online platform
Dynamic consent frameworks give research participants ongoing control by providing an interface to manage and update their consent preferences as study purposes evolve.
Question 70: Which of the following is a key limitation of k-anonymity as a privacy-enhancing technique?
- It is vulnerable to homogeneity and background knowledge attacks (Correct answer)
- It requires homomorphic encryption to implement correctly
- It cannot be applied to datasets with more than 10 attributes
- It permanently destroys the utility of the dataset
Correct answer: It is vulnerable to homogeneity and background knowledge attacks
K-anonymity can be defeated by homogeneity attacks (when all records in a group share the same sensitive value) and background knowledge attacks using external information.
Question 71: Which principle requires that personal data be kept only as long as necessary for its original collection purpose?
- Data minimization
- Storage limitation (Correct answer)
- Purpose limitation
- Accuracy
Correct answer: Storage limitation
The storage limitation principle, recognized in GDPR and other frameworks, mandates that personal data must not be retained beyond the period necessary for its specified purpose.
Question 72: Which NIST privacy framework function focuses on developing organizational understanding to manage privacy risk to individuals?
- Identify-P (Correct answer)
- Protect-P
- Respond
- Communicate
Correct answer: Identify-P
The Identify-P function in the NIST Privacy Framework establishes understanding of data processing activities and associated privacy risks.
Question 73: What distinguishes l-diversity from k-anonymity as a privacy technique?
- L-diversity applies differential privacy noise to each group
- L-diversity ensures sensitive attribute values are sufficiently diverse within each anonymization group (Correct answer)
- L-diversity requires more records per equivalence class
- L-diversity removes all quasi-identifiers from the dataset
Correct answer: L-diversity ensures sensitive attribute values are sufficiently diverse within each anonymization group
L-diversity extends k-anonymity by requiring that each equivalence class contains at least l well-represented values for sensitive attributes, preventing homogeneity attacks.
Question 74: What is the privacy risk of keeping personal data in test and development environments?
- Difficulty in running automated tests
- Lower system performance
- Exposure of live personal data in less-controlled environments (Correct answer)
- Increased cloud storage costs
Correct answer: Exposure of live personal data in less-controlled environments
Dev and test environments typically have weaker security controls than production, so using real personal data risks unauthorized exposure.
Question 75: An organization deploys federated learning for a machine learning model trained on personal health data across multiple hospitals. What is the PRIMARY privacy advantage over centralized training?
- The trained model is automatically anonymized before deployment
- Model weights cannot be used to reconstruct training data
- Raw personal data never leaves each hospital's local environment (Correct answer)
- Federated models achieve higher accuracy than centrally trained models
Correct answer: Raw personal data never leaves each hospital's local environment
Federated learning trains on local data at each node and shares only model updates (gradients), so raw personal health records are never centralized.
Question 76: A CDPSE professional must conduct a Transfer Impact Assessment (TIA). What is the main purpose of this assessment?
- To determine the bandwidth requirements for the data transfer
- To evaluate whether the legal protections in the destination country adequately protect transferred data (Correct answer)
- To obtain board approval for international operations
- To calculate the financial cost of international data transfers
Correct answer: To evaluate whether the legal protections in the destination country adequately protect transferred data
A TIA assesses whether the destination country's laws or practices could undermine the protections provided by the transfer mechanism, such as SCCs.
Question 77: A privacy engineer is reviewing cookie consent implementation. Which technical configuration ensures that a session cookie is not accessible to JavaScript (mitigating XSS-based cookie theft)?
- Setting the cookie domain to a single subdomain
- Setting the HttpOnly attribute on the cookie (Correct answer)
- Setting the Secure attribute on the cookie
- Setting the SameSite attribute to 'Strict'
Correct answer: Setting the HttpOnly attribute on the cookie
The HttpOnly flag instructs the browser not to expose the cookie to JavaScript APIs, preventing XSS scripts from stealing session cookies containing user identity.
Question 78: In the context of federated learning, what is the primary privacy benefit compared to centralized machine learning?
- Only aggregate outputs are used, never model weights
- Models are never shared with any party
- Raw training data stays on local devices rather than being sent to a central server (Correct answer)
- All data is encrypted with homomorphic encryption before training
Correct answer: Raw training data stays on local devices rather than being sent to a central server
Federated learning trains models locally on devices and shares only model updates (not raw data) with a central coordinator, keeping personal data on the originating device.
Question 79: What would be the BEST justification from a privacy standpoint for including log generation in a system's design?
- Facilitate early detection of abuse or misuse of the data that a system processes. (Correct answer)
- Allow to save the evidence of all operations carried out with the system.
- Investigate fraud after it has occurred.
- Facilitate the recovery of information in case of system damage.
Correct answer: Facilitate early detection of abuse or misuse of the data that a system processes.
From a privacy standpoint, log generation is crucial for accountability and oversight of data processing activities. By recording system events and user actions, logs enable organizations to detect and investigate any unauthorized access, misuse, or abuse of personal data early on. This proactive monitoring helps protect privacy by allowing for timely intervention and mitigation of potential breaches.
Question 80: What does the right to restriction of processing allow a data subject to do under GDPR?
- Limit how the controller uses their data while a dispute is resolved (Correct answer)
- Opt out of automated decision-making
- Delete all their personal data permanently
- Receive their data in a portable format
Correct answer: Limit how the controller uses their data while a dispute is resolved
The right to restriction (Article 18) allows data subjects to limit processing of their data, for example while contesting its accuracy.
Question 81: What does 'data residency' control ensure in cloud deployments involving personal data?
- Data is encrypted using keys managed within the same cloud region
- Data is replicated to at least three geographic regions for resilience
- Personal data is stored and processed only within specified geographic boundaries (Correct answer)
- Data is deleted automatically when it leaves the designated environment
Correct answer: Personal data is stored and processed only within specified geographic boundaries
Data residency controls enforce that personal data remains within a defined jurisdiction to satisfy legal and regulatory requirements such as GDPR adequacy decisions.
Question 82: A global e-commerce company has a well-established ISO/IEC 27001 certified Information Security Management System (ISMS). To better align with global privacy regulations like GDPR and CCPA, the company decides to implement ISO/IEC 27701. How does ISO/IEC 27701 relate to their existing ISMS?
- It is a certification that is only applicable to data processors, not data controllers.
- It serves as a privacy-specific extension, enhancing the ISMS to become a Privacy Information Management System (PIMS). (Correct answer)
- It operates as a separate, parallel framework exclusively for the legal department.
- It replaces the existing ISMS with a more privacy-focused framework.
Correct answer: It serves as a privacy-specific extension, enhancing the ISMS to become a Privacy Information Management System (PIMS).
ISO/IEC 27701 is designed as an extension to an existing ISO/IEC 27001 ISMS. It adds privacy-specific requirements and controls, effectively upgrading the ISMS into a PIMS (Privacy Information Management System). It does not replace the ISMS but builds upon its foundation.
Question 83: Which governance control ensures that employees across all business units understand their privacy responsibilities?
- Restricting access to privacy policies to compliance personnel only
- Role-based privacy awareness training and regular refreshers (Correct answer)
- Publishing policies on the intranet without training
- Having the DPO answer all employee privacy questions ad hoc
Correct answer: Role-based privacy awareness training and regular refreshers
Role-based training ensures employees understand privacy obligations specific to their data-handling activities, reducing human-error-related violations.
Question 84: A privacy engineer is conducting a privacy risk assessment for a new HR system. The process involves identifying potential threats to personal data, analyzing the likelihood and impact of these threats, and then determining the overall level of risk. This phase of the risk management process is known as:
- Risk Evaluation
- Risk Analysis (Correct answer)
- Risk Identification
- Risk Treatment
Correct answer: Risk Analysis
Risk analysis is the process of comprehending the nature of risk and determining the level of risk. It involves analyzing potential threats and vulnerabilities, and considering the likelihood and consequences of an incident to determine the magnitude of the risk. This step follows risk identification and precedes risk evaluation.
Question 85: What distinguishes a 'screening' phase from a 'full DPIA' in a two-stage impact assessment methodology?
- The screening phase is performed by external auditors only
- The screening phase focuses only on cybersecurity controls
- The screening phase determines whether the processing meets the threshold to require a full DPIA (Correct answer)
- The screening phase replaces the need for senior management review
Correct answer: The screening phase determines whether the processing meets the threshold to require a full DPIA
A screening or threshold assessment evaluates whether the proposed processing is likely to result in high risk, which then triggers the obligation to conduct a full DPIA.
Question 86: What is 'bundled consent' and why do data protection authorities consider it invalid under GDPR?
- Bundled consent is consent collected by a data processor on behalf of the controller; it is invalid because only controllers may collect consent
- Bundled consent is consent collected through a mobile app bundle rather than a web interface; it is invalid because it lacks cross-platform compatibility
- Bundled consent combines unrelated processing purposes into a single checkbox, making it impossible for users to consent selectively, thus violating the specificity and freely given requirements (Correct answer)
- Bundled consent refers to consent collected in bulk from multiple users at once, which is invalid because consent must be individual
Correct answer: Bundled consent combines unrelated processing purposes into a single checkbox, making it impossible for users to consent selectively, thus violating the specificity and freely given requirements
Bundled consent packages consent for multiple purposes (e.g., marketing, profiling, sharing) into a single accept-all action, denying users the ability to accept some and decline others as required by GDPR.
Question 87: What is the maximum fee a GDPR controller can charge for handling a data subject access request?
- A flat fee of €10
- A reasonable fee based on administrative costs
- €50 per request
- No fee may be charged for the first request (Correct answer)
Correct answer: No fee may be charged for the first request
Under GDPR, the first copy of data requested must be provided free of charge; fees may only be charged for additional copies or manifestly unfounded/excessive requests.
Question 88: A data privacy engineer is tasked with integrating privacy risk management into the organization's existing Information Security Management System (ISMS). Which international standard provides a framework for establishing, implementing, and continually improving a Privacy Information Management System (PIMS) as an extension to ISO/IEC 27001?
- NIST Privacy Framework
- ITIL 4
- COBIT 2019
- ISO/IEC 27701 (Correct answer)
Correct answer: ISO/IEC 27701
ISO/IEC 27701 is an extension to the ISO/IEC 27001 and ISO/IEC 27002 standards for information security management. It specifies the requirements for, and provides guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS). It is designed to help organizations manage privacy risks related to personally identifiable information (PII).
Question 89: A senior executive directs the privacy team to waive a required DPIA to accelerate a product launch. What is the privacy professional's MOST appropriate response?
- Document the risk, escalate to the DPO or legal counsel, and formally record the decision (Correct answer)
- Proceed with the waiver but complete the DPIA retroactively
- Comply with the directive to support business goals
- Immediately report the executive to the supervisory authority
Correct answer: Document the risk, escalate to the DPO or legal counsel, and formally record the decision
The appropriate response is to document the risk, escalate through proper governance channels, and ensure the decision is formally recorded for accountability.
Question 90: Which element is MOST critical to include in an initial breach notification to affected individuals?
- The name of the employee who caused the breach
- The financial cost of the breach to the organization
- A complete technical root-cause analysis
- Steps individuals can take to protect themselves (Correct answer)
Correct answer: Steps individuals can take to protect themselves
Notifications to individuals must include actionable steps they can take to mitigate potential harm to themselves.
Question 91: In the context of subject rights, what is a 'Supervisory Authority' responsible for under GDPR?
- Enforcing data protection law and handling complaints from data subjects (Correct answer)
- Providing technical storage for personal data
- Issuing commercial licenses for data processing
- Processing personal data on behalf of controllers
Correct answer: Enforcing data protection law and handling complaints from data subjects
Supervisory Authorities are independent public bodies that enforce GDPR, investigate complaints from data subjects, and impose sanctions on non-compliant organizations.
Question 92: Under GDPR, which role is responsible for independently monitoring an organization's compliance with data protection obligations?
- Privacy Engineer
- Internal Auditor
- Data Protection Officer (DPO) (Correct answer)
- Chief Information Security Officer
Correct answer: Data Protection Officer (DPO)
The DPO is a legally mandated role under GDPR that independently oversees compliance, advises on obligations, and acts as the point of contact for supervisory authorities.
Question 93: When integrating a newly acquired company into an existing privacy governance framework, the FIRST step should be:
- Terminating the acquired company's existing vendor contracts
- Conducting a privacy gap assessment of the acquired company's data practices (Correct answer)
- Notifying all acquired customers of the acquisition
- Immediately applying all existing privacy policies to the acquired entity
Correct answer: Conducting a privacy gap assessment of the acquired company's data practices
A gap assessment identifies how the acquired company's practices differ from existing governance standards, enabling a structured integration plan.
Question 94: Under GDPR, when does the right to data portability apply?
- Only for sensitive categories of data
- Whenever the data subject is an EU citizen
- Only when processing is based on consent or a contract and carried out by automated means (Correct answer)
- Whenever a data subject makes any access request
Correct answer: Only when processing is based on consent or a contract and carried out by automated means
The right to portability under GDPR Article 20 applies only when processing is based on consent or contract, and is carried out by automated means.
Question 95: What is a Record of Processing Activities (RoPA) primarily used for?
- Encrypting data in transit
- Monitoring employee data access logs
- Documenting all personal data processing operations within an organization (Correct answer)
- Generating automated data deletion schedules
Correct answer: Documenting all personal data processing operations within an organization
A RoPA is a compliance document required under GDPR Article 30 that records the purposes, categories, and flows of all personal data processing activities.
Question 96: A multinational organization operates across the EU, US, and Brazil. When conducting an impact assessment, which regulatory framework should guide the assessment of Brazilian data subjects' privacy risks?
- ISO 27001, as a global security standard
- Lei Geral de Proteção de Dados (LGPD) (Correct answer)
- GDPR, since it has extraterritorial effect globally
- CCPA, as Brazil follows US standards
Correct answer: Lei Geral de Proteção de Dados (LGPD)
Brazil's LGPD governs the processing of personal data of individuals located in Brazil and requires its own compliance analysis separate from GDPR or US state laws.
Question 97: Which of the following BEST describes the relationship between a privacy program and an information security program within a governance framework?
- Privacy is a subset of security with no independent requirements
- Privacy and security are identical programs requiring only one team
- Security protects data from unauthorized access; privacy governs how data is legitimately collected and used (Correct answer)
- Security programs are optional when a privacy program exists
Correct answer: Security protects data from unauthorized access; privacy governs how data is legitimately collected and used
Security and privacy are complementary but distinct: security ensures confidentiality/integrity/availability while privacy governs appropriate data use and individual rights.
Question 98: During a privacy risk assessment, what is the role of threat modeling?
- To identify vulnerabilities in network infrastructure only
- To calculate the financial cost of potential data breaches
- To systematically identify actors, motivations, and attack vectors that could compromise personal data (Correct answer)
- To assign compliance ratings to third-party vendors
Correct answer: To systematically identify actors, motivations, and attack vectors that could compromise personal data
Threat modeling in privacy risk assessment identifies who might misuse data, why, and how, enabling more targeted and effective risk treatment.
Question 99: In an Algorithmic Impact Assessment (AIA), what is the primary focus beyond standard privacy risk?
- Determining the algorithm's computational efficiency
- Assessing the financial return on investment of the algorithm
- Reviewing intellectual property protection for the model
- Evaluating fairness, bias, and discriminatory outcomes for affected individuals (Correct answer)
Correct answer: Evaluating fairness, bias, and discriminatory outcomes for affected individuals
An AIA extends privacy impact analysis to include fairness, bias, and whether the algorithm produces discriminatory outcomes that could violate individuals' rights.
Question 100: During a Privacy Impact Assessment for a new employee monitoring software, the privacy team identifies a risk of 'function creep'. Which scenario BEST illustrates this specific risk?
- A system administrator gains unauthorized access to the monitoring data.
- The software, initially approved for tracking productivity, is later used to monitor union-related activities. (Correct answer)
- The data collected by the software is inadvertently exposed due to a misconfigured cloud server.
- The software's vendor goes out of business, leaving the system unsupported.
Correct answer: The software, initially approved for tracking productivity, is later used to monitor union-related activities.
Function creep (or purpose creep) occurs when personal data collected for one specific, legitimate purpose is subsequently used for a different, unstated, and often inappropriate purpose. Using a productivity tool to monitor union activities is a classic example of expanding the system's function beyond its original, stated purpose, thereby violating the principle of purpose limitation.
Question 101: Which privacy compliance framework specifically requires organizations to implement a Privacy Management Program and demonstrate accountability to regulators?
- HIPAA Security Rule
- Generally Accepted Privacy Principles (GAPP) (Correct answer)
- NIST Cybersecurity Framework
- PCI DSS
Correct answer: Generally Accepted Privacy Principles (GAPP)
GAPP, developed by AICPA and CICA, provides ten privacy principles and requires organizations to establish a comprehensive Privacy Management Program with documented accountability.
Question 102: An engineer needs to ensure that personal data in a database cannot be altered or deleted without detection. Which control provides tamper evidence for stored records?
- Write-once storage (WORM) with hardware enforcement
- Cryptographic hashing with hash chaining or a Merkle tree structure (Correct answer)
- Row-level encryption with AES-GCM authenticated encryption
- Database activity monitoring with real-time alerts
Correct answer: Cryptographic hashing with hash chaining or a Merkle tree structure
Hash chaining or Merkle trees create a cryptographic dependency between records so that any modification to historical data is immediately detectable by recomputing the chain.
Question 103: A privacy governance policy requires employees to report suspected privacy violations. What governance element BEST supports this requirement?
- A non-retaliation clause and accessible reporting channels (Correct answer)
- Annual policy acknowledgment signatures only
- A complex reporting web portal
- Mandatory external reporting to regulators
Correct answer: A non-retaliation clause and accessible reporting channels
Non-retaliation protections and accessible reporting channels encourage employees to surface privacy concerns without fear of consequences.
Question 104: What is the purpose of a privacy attestation in a vendor relationship?
- To transfer liability for data breaches to the vendor
- To formally confirm that a vendor meets specified privacy and data protection requirements (Correct answer)
- To obtain discounts on vendor services in exchange for privacy commitments
- To certify that a vendor's products are free of security bugs
Correct answer: To formally confirm that a vendor meets specified privacy and data protection requirements
A privacy attestation is a formal statement from a vendor confirming compliance with agreed privacy standards, providing documented assurance to the contracting organization.
Question 105: Which technique renders personal data permanently unusable by removing all direct and indirect identifiers?
- Anonymization (Correct answer)
- Tokenization
- Encryption
- Pseudonymization
Correct answer: Anonymization
Anonymization irreversibly removes all identifying information so that re-identification is not reasonably possible, taking the data outside the scope of most privacy regulations.
Question 106: Which governance mechanism allows organizations to demonstrate ongoing compliance rather than point-in-time compliance with privacy requirements?
- Continuous monitoring and periodic privacy reviews (Correct answer)
- Single vendor risk assessments
- Annual employee privacy training only
- One-time privacy audits
Correct answer: Continuous monitoring and periodic privacy reviews
Continuous monitoring and periodic reviews provide ongoing assurance that controls remain effective as organizational and regulatory conditions change.
Question 107: An organization wants to repurpose customer purchase history for an AI training dataset. What privacy step must occur FIRST?
- Delete customers who opt out before training
- Obtain a new technology license
- Assess whether the new use is compatible with the original collection purpose (Correct answer)
- Encrypt the dataset with AES-256
Correct answer: Assess whether the new use is compatible with the original collection purpose
A compatibility assessment and, if needed, obtaining a new legal basis or fresh consent is required before data can be repurposed for a materially different use.
Question 108: A CDPSE discovers that an automated profiling system makes decisions about loan eligibility using personal data without human review. Which privacy risk category BEST describes this situation?
- Cross-border transfer risk
- Automated decision-making risk (Correct answer)
- Data minimization risk
- Data retention risk
Correct answer: Automated decision-making risk
Automated decision-making risk arises when systems make significant decisions about individuals without human oversight, a concern addressed by regulations like GDPR Article 22.
Question 109: What does 'privacy by default' require in practice for a new digital service?
- That all user data is encrypted by default
- That the most privacy-protective settings are applied automatically without requiring user action (Correct answer)
- That users must opt out of data collection before using the service
- That no personal data is collected under any circumstances
Correct answer: That the most privacy-protective settings are applied automatically without requiring user action
Privacy by default means systems are configured to process the minimum necessary data with the most restrictive privacy settings active from the moment the service is launched.
Question 110: Which data lifecycle stage presents the HIGHEST risk of unauthorized re-identification?
- Data storage
- Data creation
- Data disposal (Correct answer)
- Data sharing
Correct answer: Data disposal
Improper disposal—such as discarding unwiped storage media—can expose de-identified or supposedly deleted personal data to re-identification by unauthorized parties.
Question 111: Why is data lineage documentation important for CDPSE professionals?
- It automatically enforces access control policies
- It reduces the cost of cloud data storage
- It enables organizations to trace data transformations and demonstrate compliance accountability (Correct answer)
- It speeds up database query performance
Correct answer: It enables organizations to trace data transformations and demonstrate compliance accountability
Data lineage provides an auditable record of how personal data has been processed and transformed, which is essential for regulatory accountability and breach investigations.
Question 112: Data containing end user details was retrieved by an attacker from a test and development environment. Which hardening method from the list below would best stop this assault from becoming a significant privacy breach?
- Data obfuscation (Correct answer)
- Data classification
- Data normalization
- Data dictionary
Correct answer: Data obfuscation
Data obfuscation involves transforming sensitive data to make it unreadable or unusable without specific decryption keys or processes, such as anonymization or pseudonymization. If the end-user details in the test environment had been obfuscated, even if an attacker retrieved them, the actual personal information would be protected, preventing a significant privacy breach.
Question 113: When data is frequently moved outside of the company as part of its life cycle, which standards in a service level agreement would be BEST to include?
- Data persistence requirements
- Data minimization requirements
- Quality and privacy requirements (Correct answer)
- Data modeling requirements
Correct answer: Quality and privacy requirements
When data is frequently transferred to third-party vendors, it is essential to include explicit quality and privacy requirements in the Service Level Agreement (SLA). This ensures that the vendor maintains the integrity and accuracy of the data, and more importantly, adheres to strict privacy standards for handling, processing, and protecting the personal information, mitigating risks of breaches or non-compliance.
Question 114: In a multinational organization, which governance structure best ensures consistent privacy practices across all jurisdictions?
- Decentralized teams applying local rules independently
- A federated model with global standards and local compliance adaptations (Correct answer)
- A single centralized team managing all regions identically
- Outsourcing all privacy decisions to local legal counsel
Correct answer: A federated model with global standards and local compliance adaptations
A federated model balances global consistency with the flexibility to meet jurisdiction-specific requirements.
Question 115: An organization's privacy risk register has not been updated in 18 months. Which of the following risks is MOST likely to be understated as a result?
- Risks that were transferred to insurance coverage
- Risks from legacy systems already identified
- Risks from previously accepted low-severity items
- Risks from new regulatory requirements or business changes (Correct answer)
Correct answer: Risks from new regulatory requirements or business changes
A stale risk register fails to capture risks introduced by new regulations, business processes, or technology changes that occurred since the last update.
Question 116: What is 'data mapping' in the context of the personal data lifecycle?
- Converting data from one format to another
- Encrypting data as it flows between systems
- Backing up data to multiple geographic locations
- Documenting where personal data originates, moves, and is stored across the organization (Correct answer)
Correct answer: Documenting where personal data originates, moves, and is stored across the organization
Data mapping creates a comprehensive inventory of personal data flows, which is foundational to demonstrating compliance and identifying privacy risks.
Question 117: An organization operates in a jurisdiction that has enacted a new data privacy law. How should this be reflected in the privacy risk register?
- Create a new risk entry for regulatory non-compliance exposure (Correct answer)
- Classify the regulatory change as an opportunity, not a risk
- Remove existing risks that the new law renders irrelevant
- Wait until the regulator issues enforcement actions before updating the register
Correct answer: Create a new risk entry for regulatory non-compliance exposure
New regulatory requirements introduce compliance risk that must be formally documented and tracked in the risk register.
Question 118: Binding Corporate Rules (BCRs) are MOST appropriate for which scenario?
- Data transfers between unrelated businesses in different countries
- Transfers of anonymized research data to universities
- Intra-group data transfers among entities within a multinational corporation (Correct answer)
- Data transfers to government agencies in non-adequate countries
Correct answer: Intra-group data transfers among entities within a multinational corporation
BCRs are approved internal data protection policies that allow multinational groups to transfer personal data among their own affiliated entities across borders.
Question 119: Which privacy engineering principle, if applied before an incident occurs, MOST reduces the volume of data exposed during a breach?
- Data minimization (Correct answer)
- Privacy notice clarity
- Transparency
- User consent management
Correct answer: Data minimization
Data minimization limits the collection and retention of personal data, directly reducing the number of records and fields that can be exposed in a breach.
Question 120: A privacy governance framework's scope statement should define which of the following?
- The types of personal data, processing activities, and organizational units covered by the framework (Correct answer)
- The compensation structure for the privacy team
- The specific vendors the organization uses for cloud storage
- The technical architecture of data systems
Correct answer: The types of personal data, processing activities, and organizational units covered by the framework
A scope statement delimits what data, activities, and units fall under the governance framework, preventing ambiguity and gaps.
CDPSE - Certified Data Privacy Solutions Engineer
The CDPSE certification, offered by ISACA, validates technical privacy implementation skills across governance, risk management, data lifecycle, and engineering domains. It is designed for IT and security professionals who design and implement enterprise privacy solutions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds