CEA Privacy & Data Ethics 2 — Questions and Answers
Question 1: A company collects customer location data to improve delivery routes but later decides to use it for targeted advertising without notifying customers. This practice violates which core data ethics principle?
- Data minimization
- Purpose limitation (Correct answer)
- Data accuracy
- Storage limitation
Correct answer: Purpose limitation
Purpose limitation requires that data collected for one specific purpose not be used for a different, incompatible purpose without obtaining new consent.
Question 2: Which legal framework established the 'right to be forgotten,' allowing individuals to request deletion of their personal data from online platforms?
- HIPAA
- COPPA
- GDPR (Correct answer)
- CCPA
Correct answer: GDPR
The EU's General Data Protection Regulation (GDPR) codified the right to erasure, commonly called the 'right to be forgotten,' in Article 17.
Question 3: An employee accidentally emails a spreadsheet containing Social Security numbers to the wrong distribution list. Under data breach ethics, what is the FIRST obligation of the organization?
- Terminate the employee responsible
- Assess the scope and notify affected individuals promptly (Correct answer)
- Delete the email from all recipients' inboxes immediately
- Issue a public press release
Correct answer: Assess the scope and notify affected individuals promptly
Ethical breach response prioritizes assessing harm and notifying affected individuals in a timely manner so they can take protective action.
Question 4: What does 'contextual integrity' mean in the context of privacy ethics?
- Encrypting data within its original database
- Information flows appropriately when they match the norms of the context in which data was shared (Correct answer)
- Storing data only in its country of origin
- Verifying the accuracy of personal data before processing
Correct answer: Information flows appropriately when they match the norms of the context in which data was shared
Contextual integrity, developed by philosopher Helen Nissenbaum, holds that privacy is violated when information flows in ways that don't match the norms of the original social context.
Question 5: A data analytics firm de-identifies patient records before sharing them with researchers. However, researchers later re-identify individuals by combining the data with publicly available datasets. This scenario illustrates the risk of:
- Data hoarding
- Re-identification (Correct answer)
- Data poisoning
- Informed consent failure
Correct answer: Re-identification
Re-identification occurs when anonymized data is combined with auxiliary information to reveal the identity of individuals, undermining de-identification protections.
Question 6: Which of the following best describes a 'privacy by design' approach?
- Adding privacy features as an afterthought after a product launch
- Embedding privacy protections into systems and processes from the outset (Correct answer)
- Publishing a detailed privacy policy on the company website
- Restricting data access to senior management only
Correct answer: Embedding privacy protections into systems and processes from the outset
Privacy by design, developed by Ann Cavoukian, requires that privacy be proactively integrated into the design of systems and business practices from the very beginning.
Question 7: Under the Children's Online Privacy Protection Act (COPPA), operators of websites directed to children under 13 must obtain verifiable parental consent before:
- Displaying any advertisements
- Collecting personal information from the child (Correct answer)
- Allowing the child to create a username
- Providing educational content
Correct answer: Collecting personal information from the child
COPPA mandates verifiable parental consent before collecting, using, or disclosing personal information from children under age 13.
A company collects customer location data to improve delivery routes but later decides to use it for targeted advertising without notifying customers.
This practice violates which core data ethics principle?