CDPSE Impact Assessments 5 — Questions and Answers
Question 1: Which of the following BEST describes the concept of 'residual risk' in the context of a DPIA?
- Risk that has been fully eliminated through technical controls
- Risk that remains after all identified mitigation measures have been applied (Correct answer)
- Risk transferred to a third-party processor via contract
- Risk covered by the organization's cyber insurance policy
Correct answer: Risk that remains after all identified mitigation measures have been applied
Residual risk is the level of privacy risk that persists even after all feasible safeguards and mitigations have been implemented.
Question 2: Under California's CPRA, which agency is responsible for establishing rules around privacy risk assessments for certain high-risk processing activities?
- Federal Trade Commission (FTC)
- California Privacy Protection Agency (CPPA) (Correct answer)
- California Department of Justice
- Office of the Attorney General
Correct answer: California Privacy Protection Agency (CPPA)
The CPRA established the California Privacy Protection Agency (CPPA), which is authorized to issue regulations requiring privacy risk assessments for high-risk data processing activities.
Question 3: An organization's DPIA reveals that a new loyalty program will involve tracking customer locations throughout the day. Which privacy risk category does this MOST directly implicate?
- Data minimization non-compliance only
- Surveillance and tracking risk resulting in potential chilling effects on behavior (Correct answer)
- Inadequate data subject consent documentation
- Insufficient vendor management controls
Correct answer: Surveillance and tracking risk resulting in potential chilling effects on behavior
Continuous location tracking enables pervasive surveillance, which can create chilling effects on individual behavior and movement — a core privacy harm category.
Question 4: What is the function of 'threat modeling' within an impact assessment for a data-intensive system?
- Estimating software development costs for privacy features
- Systematically identifying potential adversaries, attack vectors, and privacy harms they could cause (Correct answer)
- Reviewing physical security of server facilities
- Auditing third-party contract compliance
Correct answer: Systematically identifying potential adversaries, attack vectors, and privacy harms they could cause
Threat modeling identifies who might seek to misuse data, how they could do so, and what privacy harms could result — informing the risk assessment phase of the DPIA.
Question 5: A multinational organization operates across the EU, US, and Brazil. When conducting an impact assessment, which regulatory framework should guide the assessment of Brazilian data subjects' privacy risks?
- GDPR, since it has extraterritorial effect globally
- Lei Geral de Proteção de Dados (LGPD) (Correct answer)
- CCPA, as Brazil follows US standards
- ISO 27001, as a global security standard
Correct answer: Lei Geral de Proteção de Dados (LGPD)
Brazil's LGPD governs the processing of personal data of individuals located in Brazil and requires its own compliance analysis separate from GDPR or US state laws.
Question 6: In a DPIA, which control measure specifically addresses the risk of unauthorized internal access to sensitive personal data?
- Penetration testing of external-facing systems
- Role-based access control (RBAC) limiting data access to those with a legitimate need (Correct answer)
- Encrypting data in transit between cloud regions
- Publishing a privacy policy on the organization's website
Correct answer: Role-based access control (RBAC) limiting data access to those with a legitimate need
RBAC ensures that employees can only access personal data required for their specific roles, directly mitigating the insider threat identified in a DPIA.
Question 7: Which statement BEST captures the relationship between a Record of Processing Activities (RoPA) and a DPIA?
- The RoPA replaces the need for individual DPIAs
- The RoPA provides the processing inventory that helps identify which activities may require a DPIA (Correct answer)
- The DPIA supersedes and invalidates existing RoPA entries
- The RoPA and DPIA are entirely independent with no relationship
Correct answer: The RoPA provides the processing inventory that helps identify which activities may require a DPIA
The RoPA documents all processing activities and serves as the starting point for identifying which activities might meet the threshold criteria requiring a full DPIA.
Which of the following BEST describes the concept of 'residual risk' in the context of a DPIA?