โ† All CDPSE Flashcard Decks

Privacy Compliance and Auditing Flashcards

6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Privacy Compliance and Auditing flashcards as text
  1. What is the key difference between a privacy audit and a security audit?

    Answer: Privacy audits evaluate compliance with personal data rights and regulations; security audits assess technical controls protecting data confidentiality and integrity

    While overlapping, privacy audits focus on regulatory compliance, individual rights, and data use legitimacy, whereas security audits focus on technical protections against unauthorized access.

  2. Which privacy compliance framework specifically requires organizations to implement a Privacy Management Program and demonstrate accountability to regulators?

    Answer: Generally Accepted Privacy Principles (GAPP)

    GAPP, developed by AICPA and CICA, provides ten privacy principles and requires organizations to establish a comprehensive Privacy Management Program with documented accountability.

  3. A privacy compliance team discovers that a third-party vendor has been processing personal data beyond the scope defined in the Data Processing Agreement. What is the FIRST action to take?

    Answer: Assess the extent of unauthorized processing and formally notify the vendor to cease the activity

    The immediate priority is to understand the scope of unauthorized processing and formally direct the vendor to stop, before escalating to regulators or data subjects depending on the risk level.

  4. What does 'privacy by default' require in practice for a new digital service?

    Answer: That the most privacy-protective settings are applied automatically without requiring user action

    Privacy by default means systems are configured to process the minimum necessary data with the most restrictive privacy settings active from the moment the service is launched.

  5. Which metric BEST measures the effectiveness of an organization's privacy awareness training program?

    Answer: Reduction in privacy-related incidents attributable to employee error over time

    Outcome-based metrics like reduction in privacy incidents demonstrate actual behavior change, which is the true goal of awareness training rather than mere completion rates.

  6. Under GDPR Article 83, which factor is considered when determining administrative fines for privacy violations?

    Answer: The nature, gravity, duration, and intentionality of the infringement

    Article 83 specifies multiple factors including severity, intentionality, cooperation with authorities, categories of data affected, and the organization's remediation actions.