By Design Principles Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 By Design Principles flashcards as text
Under GDPR Article 25, Privacy by Design is legally required. Which action best demonstrates compliance with this obligation during product development?
Answer: Documenting privacy controls considered and integrated during the design phase
GDPR Article 25 requires controllers to implement appropriate technical and organizational measures at the time of design, which must be documented as evidence of compliance.
A company wants to analyze customer purchase trends without exposing individual customer data. Which Privacy by Design technique achieves both business and privacy goals (positive-sum)?
Answer: Using differential privacy to add statistical noise to aggregate outputs
Differential privacy allows meaningful statistical analysis while mathematically limiting the ability to infer any individual's data, achieving both functionality and privacy.
Which Privacy by Design principle is most directly supported by publishing an organization's privacy architecture and data flow documentation to stakeholders?
Answer: Visibility and Transparency — Keep it Open
Visibility and Transparency requires that organizations openly communicate their privacy practices, architectures, and policies so stakeholders can verify claims.
An organization uses a single system to process both highly sensitive health data and general marketing preferences. A privacy architect proposes separating these into distinct systems. This addresses which risk?
Answer: Aggregation risk and data contamination across contexts
Separating systems prevents aggregation risk, where combining disparate data types creates a more sensitive profile than any single dataset would represent.
When implementing Privacy by Design in a microservices architecture, which approach best supports the 'Embedded into Design' principle?
Answer: Defining privacy contracts and data handling rules within each service's API specification
Defining privacy handling within each service's API specification makes privacy a first-class architectural concern rather than an external enforcement layer.
A privacy engineer is evaluating two database architectures: one stores full PII for analytics, the other stores only hashed identifiers with separate re-identification keys held by a different team. Which principle does the second architecture embody?
Answer: Separation of Duties combined with Pseudonymization
Pseudonymization combined with separation of duties ensures that no single team can re-identify individuals, reducing insider threat and unauthorized linkage.
Which statement best describes how Privacy by Design addresses the tension between innovation and privacy compliance?
Answer: Privacy by Design resolves the tension by proving both can be achieved simultaneously through positive-sum design
The Positive-Sum principle explicitly rejects false trade-offs, showing that innovative and privacy-respecting systems are mutually achievable.