โ† All CDPSE Flashcard Decks

Subject Rights Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Subject Rights flashcards as text
  1. A US healthcare organization is subject to HIPAA. A patient requests a copy of their medical records. What is the maximum number of days the covered entity has to respond?

    Answer: 30 days

    HIPAA requires covered entities to provide access to protected health information within 30 days of a request, with one 30-day extension permitted.

  2. Under GDPR, when does the right to data portability apply?

    Answer: Only when processing is based on consent or a contract and carried out by automated means

    The right to portability under GDPR Article 20 applies only when processing is based on consent or contract, and is carried out by automated means.

  3. An organization processes children's data. Under COPPA, what right do parents have regarding their child's personal information?

    Answer: Right to review, delete, and refuse further collection of their child's data

    COPPA grants parents the right to review, request deletion of, and refuse further collection or use of their child's personal information.

  4. Which of the following best describes a 'data subject' under GDPR?

    Answer: An identified or identifiable natural person whose personal data is processed

    A data subject is a living, identified or identifiable natural person to whom personal data relates.

  5. A data subject exercises their right to object to processing based on legitimate interests. What must the controller demonstrate to continue processing?

    Answer: Compelling legitimate grounds that override the individual's interests, rights, and freedoms

    Under GDPR Article 21, when a data subject objects to processing based on legitimate interests, the controller must show compelling grounds that override the subject's rights to continue.

  6. In the context of subject rights, what is a 'Supervisory Authority' responsible for under GDPR?

    Answer: Enforcing data protection law and handling complaints from data subjects

    Supervisory Authorities are independent public bodies that enforce GDPR, investigate complaints from data subjects, and impose sanctions on non-compliant organizations.

  7. A company's privacy notice fails to inform data subjects of their right to withdraw consent. Under GDPR, what is the consequence?

    Answer: Consent obtained without this information may be invalid, rendering the processing unlawful

    GDPR requires that privacy notices include the right to withdraw consent; failure to inform means consent may not have been freely given and could be deemed invalid.