CEA Privacy & Data Ethics 4 — Questions and Answers
Question 1: A technology company processes biometric data to grant physical access to its facilities. Under most modern privacy frameworks, biometric data is treated as:
- Standard operational data requiring no special protections
- A special category of sensitive data requiring heightened protections (Correct answer)
- Public information because it is physically observable
- Trade secret data protected only under intellectual property law
Correct answer: A special category of sensitive data requiring heightened protections
Biometric data — such as fingerprints, facial geometry, and iris scans — is classified as sensitive personal data under frameworks like GDPR and state laws like Illinois BIPA because its compromise cannot be undone.
Question 2: What is 'informed consent' in the context of data collection ethics?
- Consent given after a data breach has already occurred
- Agreement by a data subject who fully understands what data is collected, why, how it is used, and who it is shared with (Correct answer)
- A signed contract between two corporations for data sharing
- Automatic opt-in based on terms of service acceptance at account creation
Correct answer: Agreement by a data subject who fully understands what data is collected, why, how it is used, and who it is shared with
Informed consent requires that individuals have sufficient knowledge of data practices and freely agree to them without coercion or deception.
Question 3: An AI system trained on historical lending data learns to deny loans at higher rates to certain zip codes. This is an example of:
- Underfitting
- Proxy discrimination (Correct answer)
- Overfitting
- Transfer learning failure
Correct answer: Proxy discrimination
Proxy discrimination occurs when a seemingly neutral variable — like zip code — encodes protected characteristics such as race or national origin, perpetuating historical inequities.
Question 4: Which of the following actions best exemplifies the 'data minimization' principle?
- Collecting all available user data and filtering it later
- Only collecting the specific data necessary for a clearly defined purpose (Correct answer)
- Compressing data files to reduce storage costs
- Sharing data only with a minimum number of third parties
Correct answer: Only collecting the specific data necessary for a clearly defined purpose
Data minimization means collecting only the personal data that is adequate, relevant, and limited to what is necessary for the specified purpose.
Question 5: A researcher wants to study social media behavior and scrapes publicly posted content without obtaining individual consent. The primary ethical argument AGAINST this practice is:
- Publicly posted data is legally protected by copyright
- Users did not anticipate their data being used for research purposes when they posted it (Correct answer)
- Scraping violates platform terms of service in all cases
- The data cannot be statistically analyzed without consent forms
Correct answer: Users did not anticipate their data being used for research purposes when they posted it
Even publicly available data carries ethical obligations; users posting in a social context did not necessarily consent to having their data extracted and analyzed for unrelated research purposes.
Question 6: Under the California Consumer Privacy Act (CCPA), which right allows consumers to instruct businesses not to sell their personal information?
- Right to erasure
- Right to opt-out of sale (Correct answer)
- Right to data portability
- Right to non-discrimination
Correct answer: Right to opt-out of sale
The CCPA grants California consumers the right to opt-out of the sale of their personal information to third parties, which businesses must honor via a 'Do Not Sell My Personal Information' link.
Question 7: When an organization conducts a Privacy Impact Assessment (PIA), the primary goal is to:
- Calculate the financial cost of a data breach
- Identify and mitigate privacy risks before launching a new project or system (Correct answer)
- Audit past data practices for regulatory compliance
- Determine which employees have access to sensitive data
Correct answer: Identify and mitigate privacy risks before launching a new project or system
A Privacy Impact Assessment proactively identifies privacy risks and recommends safeguards during the design phase, before a system is deployed.
A technology company processes biometric data to grant physical access to its facilities.
Under most modern privacy frameworks, biometric data is treated as: