CDS Regulatory Compliance & Data Privacy 3 — Questions and Answers
Question 1: When a GDPR Data Protection Impact Assessment (DPIA) identifies a high residual risk that cannot be mitigated, what must the data controller do?
- Proceed with processing and document the risk
- Consult with the supervisory authority before processing (Correct answer)
- Appoint an external Data Protection Officer
- Obtain explicit consent from all data subjects
Correct answer: Consult with the supervisory authority before processing
GDPR Article 36 requires prior consultation with the competent supervisory authority when a DPIA shows high residual risk that the controller cannot mitigate.
Question 2: Under CCPA/CPRA, what is the maximum civil penalty per intentional violation?
- $1,000
- $2,500
- $7,500 (Correct answer)
- $25,000
Correct answer: $7,500
CCPA/CPRA allows civil penalties of up to $2,500 per unintentional violation and up to $7,500 per intentional violation.
Question 3: A hospital shares de-identified patient data with a research university. Under HIPAA, which method allows sharing data with NO residual risk threshold requirement?
- Safe Harbor method (Correct answer)
- Expert Determination method
- Limited Data Set method
- Hybrid entity method
Correct answer: Safe Harbor method
The Safe Harbor method requires removal of 18 specific identifiers and provides a defined standard, while Expert Determination requires a statistical expert to certify very small re-identification risk.
Question 4: Which GDPR principle requires that personal data be kept in a form that permits identification of data subjects for no longer than necessary?
- Data minimization
- Purpose limitation
- Storage limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Storage limitation
The storage limitation principle (Article 5(1)(e)) requires data to be deleted or anonymized once the purpose for which it was collected has been fulfilled.
Question 5: SOX Section 404 places primary responsibility for assessing and reporting on internal controls over financial reporting on:
- External auditors
- The company's management (Correct answer)
- The SEC's enforcement division
- The audit committee of the board
Correct answer: The company's management
SOX Section 404(a) requires management to assess and report on the effectiveness of internal controls over financial reporting, with external auditors attesting to that assessment.
Question 6: Which data transfer mechanism allows multinational corporations to transfer personal data within their group from the EU without needing separate agreements for each transfer?
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs) (Correct answer)
- Adequacy Decisions
- Derogations under Article 49
Correct answer: Binding Corporate Rules (BCRs)
Binding Corporate Rules (BCRs) are approved by a lead supervisory authority and allow intra-group data transfers globally without additional transfer tools.
Question 7: A data steward must ensure that a new marketing analytics platform complies with the CAN-SPAM Act. Which requirement is MOST critical to verify?
- All emails must use TLS encryption
- Recipients must have opted in before receiving commercial emails
- Every commercial email must include a functioning opt-out mechanism (Correct answer)
- Email subject lines must not exceed 50 characters
Correct answer: Every commercial email must include a functioning opt-out mechanism
CAN-SPAM requires every commercial email to include a clear, working mechanism that allows recipients to opt out of future messages, and opt-outs must be honored within 10 business days.
When a GDPR Data Protection Impact Assessment (DPIA) identifies a high residual risk that cannot be mitigated, what must the data controller do?