← All CDPSE Flashcard Decks

Impact Assessments Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Impact Assessments flashcards as text
  1. Which of the following BEST describes the concept of 'residual risk' in the context of a DPIA?

    Answer: Risk that remains after all identified mitigation measures have been applied

    Residual risk is the level of privacy risk that persists even after all feasible safeguards and mitigations have been implemented.

  2. Under California's CPRA, which agency is responsible for establishing rules around privacy risk assessments for certain high-risk processing activities?

    Answer: California Privacy Protection Agency (CPPA)

    The CPRA established the California Privacy Protection Agency (CPPA), which is authorized to issue regulations requiring privacy risk assessments for high-risk data processing activities.

  3. An organization's DPIA reveals that a new loyalty program will involve tracking customer locations throughout the day. Which privacy risk category does this MOST directly implicate?

    Answer: Surveillance and tracking risk resulting in potential chilling effects on behavior

    Continuous location tracking enables pervasive surveillance, which can create chilling effects on individual behavior and movement — a core privacy harm category.

  4. What is the function of 'threat modeling' within an impact assessment for a data-intensive system?

    Answer: Systematically identifying potential adversaries, attack vectors, and privacy harms they could cause

    Threat modeling identifies who might seek to misuse data, how they could do so, and what privacy harms could result — informing the risk assessment phase of the DPIA.

  5. A multinational organization operates across the EU, US, and Brazil. When conducting an impact assessment, which regulatory framework should guide the assessment of Brazilian data subjects' privacy risks?

    Answer: Lei Geral de Proteção de Dados (LGPD)

    Brazil's LGPD governs the processing of personal data of individuals located in Brazil and requires its own compliance analysis separate from GDPR or US state laws.

  6. In a DPIA, which control measure specifically addresses the risk of unauthorized internal access to sensitive personal data?

    Answer: Role-based access control (RBAC) limiting data access to those with a legitimate need

    RBAC ensures that employees can only access personal data required for their specific roles, directly mitigating the insider threat identified in a DPIA.

  7. Which statement BEST captures the relationship between a Record of Processing Activities (RoPA) and a DPIA?

    Answer: The RoPA provides the processing inventory that helps identify which activities may require a DPIA

    The RoPA documents all processing activities and serves as the starting point for identifying which activities might meet the threshold criteria requiring a full DPIA.