CDPSE Subject Rights 5 — Questions and Answers
Question 1: Under GDPR, what is the standard timeframe for a controller to respond to a data subject access request?
- 14 days
- One month (Correct answer)
- 45 days
- Six months
Correct answer: One month
GDPR Article 12 requires controllers to respond to data subject requests without undue delay and at most within one month of receiving the request.
Question 2: Which of the following is an example of 'pseudonymization' that still retains subject rights applicability?
- Replacing names with irreversible random codes with no key retained
- Replacing names with codes where the mapping key is retained separately (Correct answer)
- Publishing aggregate statistics with no individual-level data
- Encrypting data with a key held only by a regulator
Correct answer: Replacing names with codes where the mapping key is retained separately
Pseudonymization replaces identifying information with a code, but because the key exists to re-identify, the data remains personal data and subject rights still apply.
Question 3: An employee asks their employer to delete all personal data collected about them. Under GDPR, which exemption most likely allows the employer to retain employment records?
- Legitimate interest in retaining all HR data indefinitely
- Legal obligation to maintain employment and payroll records under national law (Correct answer)
- Contractual necessity with the employee
- Consent obtained during onboarding
Correct answer: Legal obligation to maintain employment and payroll records under national law
Employment records are typically subject to statutory retention requirements, qualifying as a legal obligation that overrides the erasure right under GDPR Article 17(3)(b).
Question 4: The Colorado Privacy Act (CPA) grants consumers a right to appeal. What does this right entail?
- The right to sue the controller in federal court
- The right to appeal a controller's refusal to act on a rights request within a specified period (Correct answer)
- The right to request a government audit of the controller
- The right to receive financial compensation for privacy violations
Correct answer: The right to appeal a controller's refusal to act on a rights request within a specified period
The Colorado Privacy Act requires controllers to establish an appeals process allowing consumers to challenge a controller's refusal to honor a privacy rights request.
Question 5: A data subject requests their personal data be ported to a new service provider. The controller argues the data is too voluminous to transfer. Is this a valid reason to refuse portability under GDPR?
- Yes, volume is an accepted exemption under GDPR
- No, volume alone is not a valid exemption; the controller must provide the data (Correct answer)
- Yes, if the data exceeds 1GB
- No, but the controller may charge extra for large transfers
Correct answer: No, volume alone is not a valid exemption; the controller must provide the data
GDPR does not recognize data volume as an exemption for portability; controllers must provide the data unless a specific legal exception applies.
Question 6: Under the CCPA, what does the 'right to know' allow a consumer to request?
- Only the categories of personal information collected
- Categories and specific pieces of personal information collected, sources, business purpose, and third parties it was shared with (Correct answer)
- Only information shared with third parties in the past 12 months
- A financial audit of how their data generated revenue
Correct answer: Categories and specific pieces of personal information collected, sources, business purpose, and third parties it was shared with
The CCPA right to know covers categories and specific pieces of personal information, sources, business or commercial purposes, and categories of third parties the data was shared with.
Question 7: Which GDPR principle directly underpins subject rights by requiring data to be accurate and kept up to date?
- Data minimization
- Storage limitation
- Accuracy (Correct answer)
- Integrity and confidentiality
Correct answer: Accuracy
The accuracy principle (Article 5(1)(d)) requires that personal data be accurate and, where necessary, kept up to date, directly supporting the right to rectification.
Under GDPR, what is the standard timeframe for a controller to respond to a data subject access request?