Governance Frameworks Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance Frameworks flashcards as text
Which of the following BEST describes the relationship between a privacy program and an information security program within a governance framework?
Answer: Security protects data from unauthorized access; privacy governs how data is legitimately collected and used
Security and privacy are complementary but distinct: security ensures confidentiality/integrity/availability while privacy governs appropriate data use and individual rights.
A governance framework that requires business units to complete a privacy threshold assessment before launching new projects primarily serves to:
Answer: Identify privacy risks early enough to address them before deployment
Privacy threshold assessments are early-stage screening tools that flag high-risk projects requiring deeper privacy analysis before deployment.
Which governance control ensures that employees across all business units understand their privacy responsibilities?
Answer: Role-based privacy awareness training and regular refreshers
Role-based training ensures employees understand privacy obligations specific to their data-handling activities, reducing human-error-related violations.
Under a privacy governance framework, what is the purpose of a data protection impact assessment (DPIA) trigger list?
Answer: To identify processing activities that automatically require a DPIA before commencement
A DPIA trigger list enumerates high-risk processing scenarios (e.g., large-scale profiling, biometric processing) that mandatorily require a DPIA.
In privacy governance, 'privacy by default' means that:
Answer: Systems are configured to apply the most privacy-protective settings automatically without user action
Privacy by default requires systems to process only the minimum personal data necessary and apply the strictest settings out of the box.
A senior executive directs the privacy team to waive a required DPIA to accelerate a product launch. What is the privacy professional's MOST appropriate response?
Answer: Document the risk, escalate to the DPO or legal counsel, and formally record the decision
The appropriate response is to document the risk, escalate through proper governance channels, and ensure the decision is formally recorded for accountability.
Which governance principle ensures that individuals are informed about how their personal data will be used at or before the time of collection?
Answer: Openness and transparency
Openness and transparency require organizations to make their data processing practices known to individuals before or at the point of collection.