CDPSE Governance Frameworks 5 — Questions and Answers
Question 1: Which of the following BEST describes the relationship between a privacy program and an information security program within a governance framework?
- Privacy and security are identical programs requiring only one team
- Security protects data from unauthorized access; privacy governs how data is legitimately collected and used (Correct answer)
- Privacy is a subset of security with no independent requirements
- Security programs are optional when a privacy program exists
Correct answer: Security protects data from unauthorized access; privacy governs how data is legitimately collected and used
Security and privacy are complementary but distinct: security ensures confidentiality/integrity/availability while privacy governs appropriate data use and individual rights.
Question 2: A governance framework that requires business units to complete a privacy threshold assessment before launching new projects primarily serves to:
- Slow down project timelines unnecessarily
- Identify privacy risks early enough to address them before deployment (Correct answer)
- Replace the need for a full PIA/DPIA
- Satisfy vendor onboarding requirements
Correct answer: Identify privacy risks early enough to address them before deployment
Privacy threshold assessments are early-stage screening tools that flag high-risk projects requiring deeper privacy analysis before deployment.
Question 3: Which governance control ensures that employees across all business units understand their privacy responsibilities?
- Publishing policies on the intranet without training
- Role-based privacy awareness training and regular refreshers (Correct answer)
- Having the DPO answer all employee privacy questions ad hoc
- Restricting access to privacy policies to compliance personnel only
Correct answer: Role-based privacy awareness training and regular refreshers
Role-based training ensures employees understand privacy obligations specific to their data-handling activities, reducing human-error-related violations.
Question 4: Under a privacy governance framework, what is the purpose of a data protection impact assessment (DPIA) trigger list?
- To define which data can be deleted without review
- To identify processing activities that automatically require a DPIA before commencement (Correct answer)
- To replace the need for data processing agreements
- To establish data retention schedules
Correct answer: To identify processing activities that automatically require a DPIA before commencement
A DPIA trigger list enumerates high-risk processing scenarios (e.g., large-scale profiling, biometric processing) that mandatorily require a DPIA.
Question 5: In privacy governance, 'privacy by default' means that:
- All privacy settings are visible to users on their profile pages
- Systems are configured to apply the most privacy-protective settings automatically without user action (Correct answer)
- Privacy controls are enabled only after users opt in
- Default passwords must be changed at first login
Correct answer: Systems are configured to apply the most privacy-protective settings automatically without user action
Privacy by default requires systems to process only the minimum personal data necessary and apply the strictest settings out of the box.
Question 6: A senior executive directs the privacy team to waive a required DPIA to accelerate a product launch. What is the privacy professional's MOST appropriate response?
- Comply with the directive to support business goals
- Document the risk, escalate to the DPO or legal counsel, and formally record the decision (Correct answer)
- Immediately report the executive to the supervisory authority
- Proceed with the waiver but complete the DPIA retroactively
Correct answer: Document the risk, escalate to the DPO or legal counsel, and formally record the decision
The appropriate response is to document the risk, escalate through proper governance channels, and ensure the decision is formally recorded for accountability.
Question 7: Which governance principle ensures that individuals are informed about how their personal data will be used at or before the time of collection?
- Accountability
- Openness and transparency (Correct answer)
- Individual participation
- Data quality
Correct answer: Openness and transparency
Openness and transparency require organizations to make their data processing practices known to individuals before or at the point of collection.
Which of the following BEST describes the relationship between a privacy program and an information security program within a governance framework?