CGRC CGRC Privacy and Data Protection 5 — Questions and Answers
Question 1: An organization transfers personal data of EU residents to a US-based cloud provider after the invalidation of the EU-US Privacy Shield. Which mechanism provides a valid legal basis for this transfer?
- Relying on the expired Privacy Shield certification
- Using Standard Contractual Clauses (SCCs) approved by the European Commission (Correct answer)
- Obtaining a one-time verbal consent from data subjects
- Filing a notice with the US Federal Trade Commission
Correct answer: Using Standard Contractual Clauses (SCCs) approved by the European Commission
Standard Contractual Clauses (SCCs) are a Commission-approved transfer mechanism that remain valid for transferring EU personal data to third countries after Privacy Shield's invalidation.
Question 2: Which federal law in the United States specifically governs the collection of personal information from children under 13 years old?
- FERPA
- HIPAA
- COPPA (Correct answer)
- GLBA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13.
Question 3: During a CGRC assessment, an auditor reviews an organization's consent management practices. Which characteristic makes consent valid under GDPR?
- Pre-checked boxes included in terms and conditions
- Freely given, specific, informed, and unambiguous indication of agreement (Correct answer)
- A blanket consent clause embedded in the employment contract
- Implied consent based on continued use of the service
Correct answer: Freely given, specific, informed, and unambiguous indication of agreement
GDPR requires consent to be freely given, specific, informed, and unambiguous — pre-ticked boxes and implied consent do not meet this standard.
Question 4: A multinational company appoints a lead supervisory authority under GDPR's one-stop-shop mechanism. What determines which data protection authority serves as the lead?
- The country where the largest number of data subjects reside
- The location of the company's main establishment where central administration decisions are made (Correct answer)
- The country where the data controller was originally incorporated
- The location of the company's largest data center
Correct answer: The location of the company's main establishment where central administration decisions are made
The lead supervisory authority is determined by the location of the controller's or processor's main establishment, where decisions about processing purposes are made.
Question 5: Which privacy framework uses the Fair Information Practice Principles (FIPPs) as its foundational basis and is commonly referenced in US federal agency privacy programs?
- ISO/IEC 27701
- NIST Privacy Framework (Correct answer)
- GDPR
- PCI DSS
Correct answer: NIST Privacy Framework
The NIST Privacy Framework is grounded in FIPPs and is designed to help US organizations — including federal agencies — manage privacy risk.
Question 6: An organization identifies that a third-party vendor processing personal data on its behalf has suffered a breach. Under GDPR, who bears the primary responsibility for notifying affected data subjects?
- The data processor (vendor)
- The data controller (organization) (Correct answer)
- The supervisory authority
- The joint responsibility is shared 50/50
Correct answer: The data controller (organization)
Under GDPR, the data controller is ultimately responsible for notifying data subjects of breaches, while the processor must notify the controller without undue delay.
Question 7: Which privacy-by-design principle requires that privacy protections be built into system architecture from the start rather than added on afterward?
- Privacy as the default setting
- End-to-end security
- Proactive not reactive; preventative not remedial (Correct answer)
- Visibility and transparency
Correct answer: Proactive not reactive; preventative not remedial
The 'proactive not reactive; preventative not remedial' principle of privacy by design means anticipating and preventing privacy-invasive events before they occur, rather than fixing problems after the fact.
An organization transfers personal data of EU residents to a US-based cloud provider after the invalidation of the EU-US Privacy Shield.
Which mechanism provides a valid legal basis for this transfer?