CFP Regulatory Compliance & Standards 3 — Questions and Answers
Question 1: Which GDPR principle requires that personal data be kept in a form that allows identification of data subjects for no longer than necessary?
- Data minimization
- Purpose limitation
- Storage limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Storage limitation
The storage limitation principle under GDPR Article 5(1)(e) restricts retention of identifiable personal data beyond the period necessary for its purpose.
Question 2: What is the primary purpose of a Suspicious Activity Report (SAR) filed by a fintech company?
- Report large cash deposits to the IRS
- Notify customers of account freezes
- Alert FinCEN to potential money laundering or fraud (Correct answer)
- Disclose data breaches to regulators
Correct answer: Alert FinCEN to potential money laundering or fraud
SARs are filed with FinCEN to report transactions that may involve money laundering, fraud, or other financial crimes.
Question 3: Under the Dodd-Frank Act, which threshold determines whether a swap dealer must register with the CFTC?
- $1 billion in aggregate notional swap positions
- $3 billion in aggregate notional swap positions
- $8 billion in aggregate notional swap positions (Correct answer)
- $25 billion in aggregate notional swap positions
Correct answer: $8 billion in aggregate notional swap positions
The CFTC set the de minimis threshold at $8 billion in aggregate notional amount of swaps over a 12-month period for swap dealer registration.
Question 4: A fintech operating in California must comply with the CCPA, which grants consumers the right to:
- Receive a physical copy of all stored data within 24 hours
- Opt out of the sale of their personal information (Correct answer)
- Demand deletion of data held by third-party processors outside California
- Require encrypted storage of all financial records
Correct answer: Opt out of the sale of their personal information
The CCPA gives California residents the right to opt out of the sale of their personal information to third parties.
Question 5: Which international standard provides a framework for information security management systems (ISMS) commonly used by fintech firms?
- ISO 9001
- ISO 27001 (Correct answer)
- SOC 2 Type II
- NIST SP 800-53
Correct answer: ISO 27001
ISO 27001 is the international standard that specifies requirements for establishing, implementing, and maintaining an ISMS.
Question 6: Under the Electronic Fund Transfer Act (EFTA), what is the maximum liability for a consumer who reports an unauthorized debit card transaction within 60 days of the statement date?
- $0
- $50
- $500 (Correct answer)
- Unlimited
Correct answer: $500
Under EFTA, consumers who report unauthorized EFT transactions after 2 business days but within 60 days face a maximum liability of $500.
Question 7: Which regulation requires US broker-dealers to maintain records of all communications related to their business for at least three years?
- SEC Rule 17a-4 (Correct answer)
- FINRA Rule 4370
- Regulation S-P
- SEC Rule 15c3-3
Correct answer: SEC Rule 17a-4
SEC Rule 17a-4 mandates that broker-dealers retain business-related records, including electronic communications, for at least three years.
Which GDPR principle requires that personal data be kept in a form that allows identification of data subjects for no longer than necessary?