CIPT Privacy Risk Assessment and Management 1 — Questions and Answers
Question 1: What is the primary objective of a Data Protection Impact Assessment (DPIA)?
- Identify and mitigate privacy risks of high-risk processing activities before they begin (Correct answer)
- Document data breaches for regulatory reporting
- Audit employee compliance with data handling policies
- Calculate the financial cost of a potential data breach
Correct answer: Identify and mitigate privacy risks of high-risk processing activities before they begin
A DPIA systematically analyzes how a high-risk processing activity will affect individual privacy and requires implementing measures to reduce identified risks.
Question 2: Which factor most commonly triggers the requirement to conduct a DPIA under GDPR?
- Systematic and large-scale processing of sensitive personal data (Correct answer)
- Processing data for payroll purposes
- Storing employee email addresses
- Publishing a public website privacy policy
Correct answer: Systematic and large-scale processing of sensitive personal data
GDPR Article 35 requires a DPIA when processing is likely to result in high risk, particularly for large-scale processing of special category data or systematic profiling.
Question 3: In a privacy risk assessment, what is a 'threat' in relation to personal data?
- Any potential cause of an unwanted event that could result in privacy harm to individuals (Correct answer)
- A known vulnerability in software code
- A regulatory fine imposed by a supervisory authority
- A negative user review about data practices
Correct answer: Any potential cause of an unwanted event that could result in privacy harm to individuals
A threat is a potential event or action — such as unauthorized access or insider misuse — that could exploit a vulnerability and cause privacy harm.
Question 4: Which risk treatment option involves stopping a high-risk data processing activity because residual risk cannot be reduced to an acceptable level?
- Risk avoidance (Correct answer)
- Risk transfer
- Risk acceptance
- Risk mitigation
Correct answer: Risk avoidance
Risk avoidance means ceasing or not starting the processing activity entirely when the risk cannot be adequately controlled.
Question 5: A privacy risk assessment rates risks using 'likelihood' and 'impact'. What does the combination of these two factors produce?
- A risk score or risk level (Correct answer)
- A compliance checklist
- A data flow diagram
- A breach notification timeline
Correct answer: A risk score or risk level
Risk level = likelihood × impact; this score prioritizes which risks require immediate mitigation versus those that can be monitored.
Question 6: What is 'residual risk' in the context of privacy risk management?
- The remaining risk after controls and mitigations have been applied (Correct answer)
- The initial risk before any controls are considered
- The total financial exposure from a data breach
- The risk transferred to cyber insurance
Correct answer: The remaining risk after controls and mitigations have been applied
Residual risk is what remains after all identified controls are implemented; it must be accepted, transferred, or reduced further if it exceeds the organization's risk tolerance.
What is the primary objective of a Data Protection Impact Assessment (DPIA)?