CEA Privacy & Data Ethics 5 — Questions and Answers
Question 1: A company retains customer purchase data indefinitely 'just in case it is useful someday.' Which data ethics principle does this most directly violate?
- Data accuracy
- Fairness
- Storage limitation (Correct answer)
- Purpose limitation
Correct answer: Storage limitation
Storage limitation requires that personal data be kept only for as long as necessary for the stated purpose, after which it should be deleted or anonymized.
Question 2: Which ethical theory most strongly supports an absolute prohibition on collecting personal data without consent, regardless of beneficial outcomes?
- Utilitarianism
- Virtue ethics
- Deontological ethics (Correct answer)
- Care ethics
Correct answer: Deontological ethics
Deontological ethics (associated with Kant) holds that certain actions — like violating consent — are inherently wrong regardless of their consequences or benefits.
Question 3: A whistleblower discloses to a journalist that their employer is secretly selling patient data to insurers. From an ethics standpoint, the whistleblower's action is best evaluated against which principle?
- Loyalty to employer
- Prevention of harm to vulnerable individuals (Correct answer)
- Personal financial gain
- Competitive advantage
Correct answer: Prevention of harm to vulnerable individuals
Ethical whistleblowing is justified when exposing wrongdoing prevents significant harm to vulnerable third parties, outweighing the duty of organizational loyalty.
Question 4: What is 'differential privacy' as a technical approach to data ethics?
- Storing different types of data in separate, isolated databases
- Adding calibrated statistical noise to datasets so individual data points cannot be identified (Correct answer)
- Providing different privacy protections based on data sensitivity tiers
- Differentiating between first-party and third-party data collection
Correct answer: Adding calibrated statistical noise to datasets so individual data points cannot be identified
Differential privacy is a mathematical technique that adds carefully calibrated noise to query outputs so that individual records cannot be inferred while aggregate patterns remain useful.
Question 5: An organization's ethics policy prohibits sharing employee health data with managers. A manager pressures HR to share an employee's medical leave reason. The HR professional's ethically correct response is to:
- Share the data to maintain a positive relationship with the manager
- Refuse and cite the policy and applicable privacy law protecting health information (Correct answer)
- Share only a summary to partially satisfy the request
- Escalate by sharing the data with the CEO instead
Correct answer: Refuse and cite the policy and applicable privacy law protecting health information
Refusing to disclose protected health information upholds both the organization's ethics policy and legal protections such as HIPAA, regardless of internal pressure.
Question 6: The concept of 'privacy as a human right' is most prominently enshrined in which foundational international document?
- The Kyoto Protocol
- The Universal Declaration of Human Rights (Article 12) (Correct answer)
- The Geneva Conventions
- The UN Convention on the Rights of the Child
Correct answer: The Universal Declaration of Human Rights (Article 12)
Article 12 of the Universal Declaration of Human Rights states that no one shall be subjected to arbitrary interference with their privacy, family, home, or correspondence.
Question 7: A tech startup collects extensive personal data under a free service model. Users 'pay' with their data rather than money. The primary ethical critique of this model is that:
- Free services cannot generate revenue
- Users cannot meaningfully evaluate the true cost of surrendering their personal data (Correct answer)
- Data collection is illegal without a subscription fee
- Free models always result in lower data security standards
Correct answer: Users cannot meaningfully evaluate the true cost of surrendering their personal data
When users exchange data for services, they often lack the ability to assess the long-term value and risk of their data, making the exchange ethically problematic due to information asymmetry.
A company retains customer purchase data indefinitely 'just in case it is useful someday.' Which data ethics principle does this most directly violate?