CDPSE CDPSE 3 — Questions and Answers
Question 1: Which element is MOST important when designing a consent management platform?
- Single opt-in checkbox for all processing purposes
- Granular consent per purpose with easy withdrawal (Correct answer)
- Pre-ticked boxes for non-essential cookies
- Bundling consent with terms of service acceptance
Correct answer: Granular consent per purpose with easy withdrawal
Valid consent under GDPR must be granular, freely given, and as easy to withdraw as to give.
Question 2: A CDPSE is reviewing a vendor contract for cloud data processing. What privacy clause is MOST critical to include?
- SLA guarantees for 99.9% uptime
- A Data Processing Agreement (DPA) specifying controller obligations (Correct answer)
- A non-disclosure agreement covering proprietary algorithms
- Insurance coverage for business interruption
Correct answer: A Data Processing Agreement (DPA) specifying controller obligations
A Data Processing Agreement is legally required under GDPR when a controller engages a processor, defining each party's data protection obligations.
Question 3: What does the concept of 'privacy by default' require?
- Applying maximum privacy settings automatically without user action (Correct answer)
- Offering users a privacy dashboard to customize settings
- Encrypting data by default on all storage systems
- Publishing a privacy policy before collecting data
Correct answer: Applying maximum privacy settings automatically without user action
Privacy by default means the most privacy-protective settings are applied automatically, so individuals don't need to take action to protect their privacy.
Question 4: An organization processes data based on legitimate interests. Which step is REQUIRED before relying on this lawful basis?
- Obtain explicit consent from all data subjects
- Conduct a Legitimate Interests Assessment (LIA) (Correct answer)
- Appoint a Data Protection Officer
- Register the processing with the supervisory authority
Correct answer: Conduct a Legitimate Interests Assessment (LIA)
A Legitimate Interests Assessment balances the organization's interests against data subjects' rights and must be documented before relying on legitimate interests.
Question 5: Which data lifecycle phase presents the HIGHEST privacy risk if not properly managed?
- Data collection
- Data retention beyond stated purpose (Correct answer)
- Data transformation for analytics
- Data transmission to internal systems
Correct answer: Data retention beyond stated purpose
Retaining data longer than necessary violates storage limitation principles and increases exposure to breaches, legal liability, and unauthorized use.
Question 6: A mobile app sends user location data to a third-party analytics SDK by default. What privacy principle does this MOST likely violate?
- Data accuracy
- Privacy by design and by default (Correct answer)
- Data portability
- Purpose specification
Correct answer: Privacy by design and by default
Sharing sensitive data with third parties by default without user knowledge violates privacy by default, which requires the most protective settings to be on by default.
Question 7: Which framework provides a structured approach to managing privacy risk using a five-function core: Identify, Govern, Control, Communicate, Protect?
- NIST Privacy Framework (Correct answer)
- ISO/IEC 27701
- GDPR
- APEC Privacy Framework
Correct answer: NIST Privacy Framework
The NIST Privacy Framework uses the five core functions—Identify, Govern, Control, Communicate, and Protect—to manage privacy risk.
Which element is MOST important when designing a consent management platform?