CIPM CIPM Privacy Risk Management 1 — Questions and Answers
Question 1: What is the primary purpose of a Privacy Impact Assessment (PIA)?
- To identify and mitigate privacy risks before implementing a new project or system (Correct answer)
- To document all existing data processing activities
- To train employees on privacy regulations
- To respond to data subject access requests
Correct answer: To identify and mitigate privacy risks before implementing a new project or system
A PIA systematically identifies privacy risks associated with a new project, product, or process and proposes measures to mitigate those risks before implementation.
Question 2: Under GDPR, what is a Data Protection Impact Assessment (DPIA) specifically designed to address?
- Processing operations likely to result in high risk to individuals' rights and freedoms (Correct answer)
- All routine data processing activities
- Data breaches that have already occurred
- Vendor contracts involving personal data
Correct answer: Processing operations likely to result in high risk to individuals' rights and freedoms
GDPR Article 35 requires a DPIA for processing operations that are likely to result in high risk to the rights and freedoms of natural persons.
Question 3: Which of the following scenarios mandates a DPIA under GDPR?
- Large-scale processing of special categories of personal data (Correct answer)
- Sending a monthly newsletter to opted-in subscribers
- Storing employee contact information in an HR system
- Collecting cookies with user consent
Correct answer: Large-scale processing of special categories of personal data
GDPR Article 35(3) explicitly requires DPIAs for large-scale processing of special categories of data such as health, biometric, or racial data.
Question 4: In privacy risk management, what does 'inherent risk' refer to?
- The level of risk present before any controls or mitigations are applied (Correct answer)
- The risk remaining after all controls have been implemented
- Risk arising from third-party vendors only
- Risk identified after a privacy breach
Correct answer: The level of risk present before any controls or mitigations are applied
Inherent risk is the raw level of risk associated with a processing activity before any privacy or security controls are applied to reduce it.
Question 5: Which NIST publication provides a voluntary privacy framework to help organizations manage privacy risk?
- NIST Privacy Framework Version 1.0 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
- NIST Cybersecurity Framework 2.0
Correct answer: NIST Privacy Framework Version 1.0
The NIST Privacy Framework Version 1.0, published in January 2020, provides a voluntary, flexible tool for organizations to manage privacy risk through five functions: Identify, Govern, Control, Communicate, and Protect.
Question 6: What is 'residual risk' in the context of a privacy risk management program?
- The risk that remains after privacy controls and mitigations have been applied (Correct answer)
- The initial risk before any assessment is done
- Risk transferred to a third-party vendor
- Risk arising from regulatory non-compliance only
Correct answer: The risk that remains after privacy controls and mitigations have been applied
Residual risk is the level of risk that remains after the organization has implemented its chosen controls and mitigation measures, which management must accept or address further.
What is the primary purpose of a Privacy Impact Assessment (PIA)?