CDPSE Governance Frameworks 4 — Questions and Answers
Question 1: An organization is building a privacy governance committee. Which representation is MOST critical for effective privacy decision-making?
- Only legal and compliance personnel
- Cross-functional representation including legal, IT, HR, marketing, and operations (Correct answer)
- External privacy consultants only
- The DPO and CISO exclusively
Correct answer: Cross-functional representation including legal, IT, HR, marketing, and operations
Cross-functional representation ensures privacy decisions account for all business functions that process personal data.
Question 2: Which approach to privacy governance treats privacy as a competitive differentiator and business enabler rather than just a compliance obligation?
- Compliance-first governance
- Privacy as a business value and trust driver (Correct answer)
- Minimal viable compliance posture
- Risk transfer through cyber insurance
Correct answer: Privacy as a business value and trust driver
Treating privacy as a business value positions it as a trust-building asset that can differentiate products and attract privacy-conscious customers.
Question 3: Under the GDPR accountability principle, which of the following BEST demonstrates that an organization has embedded governance?
- Publishing a privacy notice on the company website
- Maintaining records of processing activities and documented evidence of compliance measures (Correct answer)
- Obtaining ISO 27001 certification
- Subscribing to a legal update service
Correct answer: Maintaining records of processing activities and documented evidence of compliance measures
Records of processing activities (Article 30) and documented compliance measures are the primary evidence of embedded accountability under GDPR.
Question 4: A privacy governance framework's scope statement should define which of the following?
- The specific vendors the organization uses for cloud storage
- The types of personal data, processing activities, and organizational units covered by the framework (Correct answer)
- The technical architecture of data systems
- The compensation structure for the privacy team
Correct answer: The types of personal data, processing activities, and organizational units covered by the framework
A scope statement delimits what data, activities, and units fall under the governance framework, preventing ambiguity and gaps.
Question 5: Which privacy governance concept requires organizations to limit the collection of personal data to what is directly relevant and necessary for the stated purpose?
- Privacy by Default
- Data minimization (Correct answer)
- Consent management
- Pseudonymization
Correct answer: Data minimization
Data minimization requires collecting only the personal data that is adequate, relevant, and limited to what is necessary for the specified purpose.
Question 6: When integrating a newly acquired company into an existing privacy governance framework, the FIRST step should be:
- Immediately applying all existing privacy policies to the acquired entity
- Conducting a privacy gap assessment of the acquired company's data practices (Correct answer)
- Terminating the acquired company's existing vendor contracts
- Notifying all acquired customers of the acquisition
Correct answer: Conducting a privacy gap assessment of the acquired company's data practices
A gap assessment identifies how the acquired company's practices differ from existing governance standards, enabling a structured integration plan.
Question 7: A privacy governance policy requires employees to report suspected privacy violations. What governance element BEST supports this requirement?
- A complex reporting web portal
- A non-retaliation clause and accessible reporting channels (Correct answer)
- Annual policy acknowledgment signatures only
- Mandatory external reporting to regulators
Correct answer: A non-retaliation clause and accessible reporting channels
Non-retaliation protections and accessible reporting channels encourage employees to surface privacy concerns without fear of consequences.
An organization is building a privacy governance committee.
Which representation is MOST critical for effective privacy decision-making?