CDS Regulatory Compliance & Data Privacy 2 — Questions and Answers
Question 1: Under CCPA, which right allows California consumers to prevent businesses from selling their personal information to third parties?
- Right to Erasure
- Right to Opt-Out (Correct answer)
- Right to Portability
- Right to Rectification
Correct answer: Right to Opt-Out
CCPA grants consumers the Right to Opt-Out, allowing them to direct businesses not to sell their personal information to third parties.
Question 2: A data steward discovers that a vendor processes EU resident data without a valid data transfer mechanism. Which action is the MOST appropriate immediate step?
- Terminate the vendor contract immediately
- Notify affected data subjects
- Suspend data transfers until a lawful mechanism is established (Correct answer)
- File a complaint with the supervisory authority
Correct answer: Suspend data transfers until a lawful mechanism is established
Suspending transfers until a valid mechanism (SCCs, adequacy decision, BCRs) is in place prevents ongoing GDPR violations while allowing time to remediate.
Question 3: HIPAA's Minimum Necessary Standard requires covered entities to:
- Encrypt all PHI at rest and in transit
- Limit PHI access and disclosures to the least amount needed for the purpose (Correct answer)
- Obtain written authorization for every use of PHI
- Report all PHI disclosures to HHS within 60 days
Correct answer: Limit PHI access and disclosures to the least amount needed for the purpose
The Minimum Necessary Standard mandates that only the amount of PHI reasonably needed to accomplish the intended purpose should be used or disclosed.
Question 4: Which GDPR lawful basis would a company MOST likely rely on when processing employee payroll data?
- Consent
- Legitimate interests
- Legal obligation (Correct answer)
- Vital interests
Correct answer: Legal obligation
Processing payroll data is required to comply with tax and employment laws, making legal obligation the most appropriate lawful basis.
Question 5: Under PCI DSS, what is the PRIMARY purpose of network segmentation?
- To improve network throughput for payment systems
- To reduce the scope of the cardholder data environment (Correct answer)
- To eliminate the need for encryption of card data
- To separate development and production environments
Correct answer: To reduce the scope of the cardholder data environment
Network segmentation isolates the cardholder data environment (CDE), reducing the scope of systems subject to PCI DSS compliance requirements.
Question 6: Which regulation introduced the concept of Privacy by Design as a legal requirement for data controllers?
- CCPA
- HIPAA
- GDPR (Correct answer)
- GLBA
Correct answer: GDPR
GDPR Article 25 mandates Data Protection by Design and by Default, requiring privacy considerations to be embedded into systems from the outset.
Question 7: A financial institution must implement safeguards to protect customer financial information under which US federal law?
- Sarbanes-Oxley Act (SOX)
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Fair Credit Reporting Act (FCRA)
- Electronic Communications Privacy Act (ECPA)
Correct answer: Gramm-Leach-Bliley Act (GLBA)
GLBA's Safeguards Rule requires financial institutions to develop and maintain a written information security program to protect customer financial data.
Under CCPA, which right allows California consumers to prevent businesses from selling their personal information to third parties?