Governance Frameworks Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance Frameworks flashcards as text
Which governance principle requires that individuals responsible for privacy decisions be held answerable for their actions and outcomes?
Answer: Accountability
Accountability is the governance principle requiring that decision-makers are answerable for how personal data is handled.
A privacy governance framework should include which of the following as a primary component for managing third-party data processors?
Answer: Data Processing Agreements (DPAs) with contractual privacy obligations
DPAs are the contractual mechanism requiring third-party processors to uphold the controller's privacy obligations.
In a multinational organization, which governance structure best ensures consistent privacy practices across all jurisdictions?
Answer: A federated model with global standards and local compliance adaptations
A federated model balances global consistency with the flexibility to meet jurisdiction-specific requirements.
Which element of privacy governance ensures that personal data is only used for the purposes for which it was originally collected?
Answer: Purpose limitation
Purpose limitation restricts the use of personal data to the specific, stated purposes communicated at collection.
A company's privacy governance framework lacks defined escalation paths for privacy incidents. What risk does this create?
Answer: Delayed breach response and regulatory notification failures
Without escalation paths, incidents may not reach decision-makers in time to meet regulatory breach notification deadlines.
Which governance document typically defines an organization's high-level commitment to data privacy and sets the tone for all subordinate policies?
Answer: Privacy policy statement
A privacy policy statement expresses the organization's overarching commitment and principles, driving all subordinate privacy policies.
Under a mature privacy governance framework, who is ultimately accountable for organizational privacy risk?
Answer: The Board of Directors or senior executive leadership
Ultimate accountability for privacy risk rests with the Board or senior leadership, who set strategy and oversee compliance.