CDPSE Risk Management 5 — Questions and Answers
Question 1: Which of the following BEST describes the difference between a privacy risk assessment and a Data Protection Impact Assessment (DPIA)?
- A DPIA is broader and covers all organizational risks, while a privacy risk assessment is narrower
- A DPIA is legally mandated for high-risk processing under GDPR, while a privacy risk assessment is a general best-practice tool (Correct answer)
- A privacy risk assessment replaces the need for a DPIA under all frameworks
- A DPIA focuses on technical controls while a privacy risk assessment focuses on legal compliance
Correct answer: A DPIA is legally mandated for high-risk processing under GDPR, while a privacy risk assessment is a general best-practice tool
Under GDPR Article 35, a DPIA is legally required for high-risk processing activities, whereas a privacy risk assessment is a broader, framework-agnostic practice.
Question 2: An organization processes personal data in Country A and transfers it to a processor in Country B, which lacks an adequacy decision. What privacy risk does this introduce?
- Increased risk of data corruption during transit
- Risk of non-compliance with data transfer restrictions and inadequate protection standards (Correct answer)
- Risk of losing intellectual property rights to the data
- Risk of the processor retaining data beyond the agreed retention period
Correct answer: Risk of non-compliance with data transfer restrictions and inadequate protection standards
Transferring data to a country without an adequacy decision creates legal and protection-level risk, requiring additional safeguards such as Standard Contractual Clauses.
Question 3: A CDPSE is evaluating privacy risks associated with a biometric authentication system. Which risk is MOST specific to biometric data?
- Risk of system downtime affecting user access
- Risk of irreversible harm since biometric data cannot be changed if compromised (Correct answer)
- Risk of users forgetting their biometric credentials
- Risk of the authentication system being slower than password-based alternatives
Correct answer: Risk of irreversible harm since biometric data cannot be changed if compromised
Unlike passwords, biometric identifiers (fingerprints, facial features) are permanent; a compromise creates lifelong risk because they cannot be reset.
Question 4: Which of the following scenarios BEST demonstrates the concept of 'data minimization' as a risk control?
- Encrypting all personal data stored in a database
- Collecting only the personal data fields strictly necessary for the stated purpose (Correct answer)
- Deleting all personal data after five years regardless of business need
- Anonymizing data before sharing it with third parties
Correct answer: Collecting only the personal data fields strictly necessary for the stated purpose
Data minimization reduces privacy risk by limiting the volume and sensitivity of personal data held, thereby reducing the potential impact of a breach or misuse.
Question 5: A CDPSE is performing a risk assessment on an employee monitoring program. Which factor is MOST critical to evaluate for privacy risk?
- The technical specification of the monitoring software
- The proportionality of monitoring scope relative to its stated business purpose (Correct answer)
- The cost of implementing the monitoring solution
- The frequency with which monitoring data is reviewed by HR
Correct answer: The proportionality of monitoring scope relative to its stated business purpose
Proportionality—whether the intrusiveness of monitoring is justified by the business purpose—is the central privacy risk factor in employee monitoring programs.
Question 6: During a risk workshop, a stakeholder argues that encrypting personal data eliminates privacy risk entirely. How should the CDPSE respond?
- Agree, since encrypted data cannot be misused
- Explain that encryption reduces confidentiality risk but does not address risks like unauthorized disclosure, consent violations, or data misuse by authorized parties (Correct answer)
- Confirm that encryption alone satisfies all GDPR requirements
- Suggest switching to anonymization as a complete solution
Correct answer: Explain that encryption reduces confidentiality risk but does not address risks like unauthorized disclosure, consent violations, or data misuse by authorized parties
Encryption is a control for unauthorized access, but privacy risks such as misuse by authorized users, lack of consent, or purpose limitation violations remain unaddressed.
Question 7: What is the PRIMARY purpose of a privacy risk heat map?
- To document all personal data flows across the organization
- To provide a visual representation of risks by likelihood and impact to prioritize treatment (Correct answer)
- To assign compliance scores to business units
- To track the status of data subject access requests
Correct answer: To provide a visual representation of risks by likelihood and impact to prioritize treatment
A heat map visually plots risks on a likelihood-versus-impact grid, enabling stakeholders to quickly identify which risks require the most urgent treatment.
Which of the following BEST describes the difference between a privacy risk assessment and a Data Protection Impact Assessment (DPIA)?