CDPSE Subject Rights 4 — Questions and Answers
Question 1: A US healthcare organization is subject to HIPAA. A patient requests a copy of their medical records. What is the maximum number of days the covered entity has to respond?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
HIPAA requires covered entities to provide access to protected health information within 30 days of a request, with one 30-day extension permitted.
Question 2: Under GDPR, when does the right to data portability apply?
- Whenever a data subject makes any access request
- Only when processing is based on consent or a contract and carried out by automated means (Correct answer)
- Only for sensitive categories of data
- Whenever the data subject is an EU citizen
Correct answer: Only when processing is based on consent or a contract and carried out by automated means
The right to portability under GDPR Article 20 applies only when processing is based on consent or contract, and is carried out by automated means.
Question 3: An organization processes children's data. Under COPPA, what right do parents have regarding their child's personal information?
- Right to financial compensation for data use
- Right to review, delete, and refuse further collection of their child's data (Correct answer)
- Right to transfer data to competitors
- Right to automated decision-making review
Correct answer: Right to review, delete, and refuse further collection of their child's data
COPPA grants parents the right to review, request deletion of, and refuse further collection or use of their child's personal information.
Question 4: Which of the following best describes a 'data subject' under GDPR?
- Any legal entity whose data is processed
- An identified or identifiable natural person whose personal data is processed (Correct answer)
- A controller who processes data on behalf of others
- A processor acting under controller instructions
Correct answer: An identified or identifiable natural person whose personal data is processed
A data subject is a living, identified or identifiable natural person to whom personal data relates.
Question 5: A data subject exercises their right to object to processing based on legitimate interests. What must the controller demonstrate to continue processing?
- That the data was collected with consent
- Compelling legitimate grounds that override the individual's interests, rights, and freedoms (Correct answer)
- That the supervisory authority has approved continued processing
- That deletion is technically impossible
Correct answer: Compelling legitimate grounds that override the individual's interests, rights, and freedoms
Under GDPR Article 21, when a data subject objects to processing based on legitimate interests, the controller must show compelling grounds that override the subject's rights to continue.
Question 6: In the context of subject rights, what is a 'Supervisory Authority' responsible for under GDPR?
- Processing personal data on behalf of controllers
- Enforcing data protection law and handling complaints from data subjects (Correct answer)
- Issuing commercial licenses for data processing
- Providing technical storage for personal data
Correct answer: Enforcing data protection law and handling complaints from data subjects
Supervisory Authorities are independent public bodies that enforce GDPR, investigate complaints from data subjects, and impose sanctions on non-compliant organizations.
Question 7: A company's privacy notice fails to inform data subjects of their right to withdraw consent. Under GDPR, what is the consequence?
- Processing is automatically lawful because other bases may apply
- Consent obtained without this information may be invalid, rendering the processing unlawful (Correct answer)
- The company must pay a fixed fine of €1,000
- The supervisory authority must be notified within 24 hours
Correct answer: Consent obtained without this information may be invalid, rendering the processing unlawful
GDPR requires that privacy notices include the right to withdraw consent; failure to inform means consent may not have been freely given and could be deemed invalid.
A US healthcare organization is subject to HIPAA.
A patient requests a copy of their medical records.
What is the maximum number of days the covered entity has to respond?