Certified Information Privacy Professional CCPA and CPRA Compliance 2 — Questions and Answers
Question 1: What is the CPRA's data retention principle that businesses must follow?
- Retain personal information only as long as reasonably necessary for the disclosed purpose (Correct answer)
- Retain data indefinitely unless the consumer requests deletion
- Retain data for a minimum of 7 years
- Retain data only for 30 days
Correct answer: Retain personal information only as long as reasonably necessary for the disclosed purpose
CPRA requires businesses to retain personal information only as long as reasonably necessary and proportionate to the purposes for which it was collected.
Question 2: Under the CCPA, which category is considered 'sensitive personal information' that triggers additional obligations under CPRA?
- Social Security numbers and precise geolocation data (Correct answer)
- General browsing history
- IP addresses without device linking
- Business email addresses
Correct answer: Social Security numbers and precise geolocation data
SSNs and precise geolocation are among the CPRA's defined categories of sensitive personal information with additional use limitation rights.
Question 3: What right allows California consumers to correct inaccurate personal information held by a business?
- Right to Correct (added by CPRA) (Correct answer)
- Right to Erasure
- Right to Access
- Right to Portability
Correct answer: Right to Correct (added by CPRA)
The CPRA introduced the Right to Correct inaccurate personal information, a right not present in the original CCPA.
Question 4: The CCPA's private right of action is limited to which type of data breach?
- Breaches of non-encrypted or non-redacted personal information due to failure to maintain reasonable security (Correct answer)
- Any unauthorized disclosure of personal information
- Breaches involving only sensitive personal information
- Breaches where the FTC has already taken action
Correct answer: Breaches of non-encrypted or non-redacted personal information due to failure to maintain reasonable security
The CCPA's private right of action applies only to breaches of non-encrypted or non-redacted personal information resulting from failure to implement reasonable security.
Question 5: Which business practice allows a company to offer financial incentives for consumers to share their personal information under CCPA?
- Financial incentive programs with required notice and opt-in (Correct answer)
- Automatic enrollment in data sharing for discounts
- Mandatory data sharing as a condition of service
- Silent data collection without disclosure
Correct answer: Financial incentive programs with required notice and opt-in
CCPA allows financial incentive programs for sharing personal information, but businesses must provide conspicuous notice and obtain opt-in consent.
Question 6: Under the CPRA, what is a 'contractor' as distinct from a 'service provider'?
- An entity that receives personal information pursuant to a written contract but not in the context of providing services to the business (Correct answer)
- An employee of the business who handles data
- A government entity receiving data under a legal process
- A marketing partner that buys data
Correct answer: An entity that receives personal information pursuant to a written contract but not in the context of providing services to the business
CPRA defines 'contractor' as an entity that receives personal information for business purposes under contract but not in a service-provider relationship.
What is the CPRA's data retention principle that businesses must follow?