CIPT Data Lifecycle Management and Governance 2 — Questions and Answers
Question 1: What is the purpose of a data processing agreement (DPA) between a controller and a processor?
- To contractually bind the processor to process data only on documented instructions and implement adequate safeguards (Correct answer)
- To transfer data ownership from controller to processor
- To allow the processor to sell data to third parties
- To replace a privacy policy for end users
Correct answer: To contractually bind the processor to process data only on documented instructions and implement adequate safeguards
A DPA ensures the processor acts only on the controller's instructions, maintains confidentiality, and implements appropriate technical and organizational security measures.
Question 2: A company maintains records of all its data processing activities including purposes, categories of data, and retention periods. What is this record called?
- Record of Processing Activities (RoPA) (Correct answer)
- Privacy impact assessment
- Data breach register
- Information security policy
Correct answer: Record of Processing Activities (RoPA)
A Record of Processing Activities (RoPA) is a documented inventory of all processing activities required by privacy regulations such as GDPR Article 30.
Question 3: Which concept describes tracking the origin, movement, and transformations of data across its entire lifecycle within an organization?
- Data lineage (Correct answer)
- Data provenance auditing
- Database versioning
- Change data capture
Correct answer: Data lineage
Data lineage documents where data comes from, how it moves through systems, and how it is transformed, enabling accountability and privacy compliance verification.
Question 4: An organization must delete a customer's data upon request. Which governance process ensures all copies — including backups — are identified and removed?
- Data mapping combined with a defined erasure workflow (Correct answer)
- Deleting only the primary production record
- Issuing a SQL DELETE command on the main database
- Waiting for backup rotation to naturally overwrite data
Correct answer: Data mapping combined with a defined erasure workflow
Effective erasure requires a comprehensive data map to locate all copies — production, backup, archives, and third-party processors — followed by a documented deletion workflow.
Question 5: What does 'data sovereignty' mean in the context of data governance?
- Data is subject to the laws of the country in which it is collected or stored (Correct answer)
- The organization owns all data it collects indefinitely
- Users can export their data in any format they choose
- Data must be stored on on-premises servers only
Correct answer: Data is subject to the laws of the country in which it is collected or stored
Data sovereignty means that data is governed by the legal and regulatory framework of the jurisdiction where it resides, affecting cross-border transfer decisions.
Question 6: Which governance mechanism ensures that personal data collected for one purpose is not used for an incompatible second purpose?
- Purpose limitation controls (Correct answer)
- Data retention policies
- Encryption at rest
- Role-based access control
Correct answer: Purpose limitation controls
Purpose limitation controls — including technical restrictions and policy enforcement — prevent data from being repurposed beyond its original, consented-to use.
What is the purpose of a data processing agreement (DPA) between a controller and a processor?