CIPT Privacy Risk Assessment and Management 2 — Questions and Answers
Question 1: Which element must be included in a DPIA report according to GDPR Article 35?
- A description of the processing, necessity assessment, risk evaluation, and planned mitigation measures (Correct answer)
- Only the names of the data subjects affected
- A list of all system vulnerabilities discovered during testing
- The organization's annual privacy budget
Correct answer: A description of the processing, necessity assessment, risk evaluation, and planned mitigation measures
GDPR Article 35 specifies that a DPIA must include: a description of the processing, assessment of necessity and proportionality, risk assessment, and the measures to address risks.
Question 2: When must an organization consult with the supervisory authority (e.g., a DPA) after completing a DPIA?
- When the DPIA indicates a high residual risk that the organization cannot sufficiently mitigate (Correct answer)
- After every DPIA regardless of the findings
- Only when a data breach has already occurred
- When processing data of fewer than 500 individuals
Correct answer: When the DPIA indicates a high residual risk that the organization cannot sufficiently mitigate
Prior consultation with the supervisory authority is required when the DPIA shows that high risks remain after the organization's mitigation efforts.
Question 3: A privacy risk register documents identified risks, their scores, and assigned owners. What is the primary benefit of maintaining this register?
- Enables tracking of risk treatment progress and accountability over time (Correct answer)
- Replaces the need for technical security controls
- Satisfies all GDPR documentation requirements
- Provides legal immunity in case of a breach
Correct answer: Enables tracking of risk treatment progress and accountability over time
A risk register creates an auditable record of known risks, their status, and who is responsible for treatment, supporting continuous privacy risk management.
Question 4: Which privacy threat category involves an attacker combining publicly available data from multiple sources to re-identify an anonymized individual?
- Aggregation attack (Correct answer)
- SQL injection
- Phishing attack
- Man-in-the-middle attack
Correct answer: Aggregation attack
An aggregation attack combines individually harmless data elements from multiple sources to reconstruct a person's identity or sensitive information.
Question 5: In privacy risk management, what does 'risk tolerance' define?
- The level of risk the organization is willing to accept without further treatment (Correct answer)
- The maximum financial penalty a regulator can impose
- The number of data breaches an organization can absorb annually
- The technical threshold for encryption key length
Correct answer: The level of risk the organization is willing to accept without further treatment
Risk tolerance sets the boundary between acceptable and unacceptable risk, guiding decisions about whether residual risks require further mitigation or can be accepted.
Question 6: Which privacy risk factor specifically relates to the harm an individual may suffer if their personal data is exposed or misused?
- Impact to data subjects (Correct answer)
- Threat likelihood
- Vulnerability severity
- Organizational reputational risk
Correct answer: Impact to data subjects
Privacy risk assessment must center on the potential harm to individuals — including financial loss, discrimination, or reputational damage — not just organizational risk.
Which element must be included in a DPIA report according to GDPR Article 35?