CGRC CGRC Privacy and Data Protection 4 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), which of the following is NOT a right granted to California consumers?
- Right to know what personal information is collected
- Right to delete personal information
- Right to data portability in a machine-readable format
- Right to receive monetary compensation for every privacy violation (Correct answer)
Correct answer: Right to receive monetary compensation for every privacy violation
CCPA grants rights to know, delete, opt-out, and non-discrimination, but does not guarantee automatic monetary compensation for every violation — only statutory damages for data breaches.
Question 2: A healthcare organization shares de-identified patient data with a research partner. Under HIPAA's Safe Harbor method, how many specific identifiers must be removed before data is considered de-identified?
- 12
- 18 (Correct answer)
- 24
- 32
Correct answer: 18
HIPAA's Safe Harbor de-identification method requires removal of 18 specific identifiers including names, geographic data, dates, and contact information.
Question 3: Which privacy principle requires that personal data collected for one specific purpose should not be used for a different, incompatible purpose without consent?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
Purpose limitation restricts the use of personal data to the specific, explicit purpose for which it was originally collected.
Question 4: An organization conducts a Privacy Impact Assessment (PIA). Which scenario would MOST likely trigger the need for a PIA?
- Upgrading the company's internal email client
- Deploying a new biometric time-tracking system for employees (Correct answer)
- Replacing office furniture in the HR department
- Renewing an existing third-party payroll contract with no changes
Correct answer: Deploying a new biometric time-tracking system for employees
A PIA is most commonly required when introducing new technologies or processes that significantly change how personal — especially sensitive — data is collected or processed.
Question 5: Under GDPR, what is the maximum timeframe within which a data controller must notify the supervisory authority of a personal data breach that poses a risk to individuals' rights and freedoms?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a qualifying personal data breach.
Question 6: A company's privacy policy states it retains customer purchase data for 10 years, but regulatory requirements only mandate 3 years. Which privacy principle is most directly violated by the company's practice?
- Lawfulness, fairness, and transparency
- Purpose limitation
- Storage limitation (Correct answer)
- Data subject rights
Correct answer: Storage limitation
Storage limitation requires that personal data not be kept longer than necessary for its stated purpose, and retaining data beyond regulatory requirements without justification violates this principle.
Question 7: Which of the following best describes the role of a Data Protection Officer (DPO) under GDPR?
- Making final decisions on data processing activities
- Serving as an independent advisor who monitors compliance and liaises with supervisory authorities (Correct answer)
- Approving all contracts involving personal data on behalf of the organization
- Acting as the legal representative of the data controller in court proceedings
Correct answer: Serving as an independent advisor who monitors compliance and liaises with supervisory authorities
A DPO under GDPR is an independent advisor who monitors compliance, advises on DPIAs, and serves as a contact point for supervisory authorities and data subjects.
Under the California Consumer Privacy Act (CCPA), which of the following is NOT a right granted to California consumers?