CIPT Certified Information Privacy Technologist: Data Privacy Frameworks and Models 2 — Questions and Answers
Question 1: Which NIST Privacy Framework core function focuses on developing and implementing organizational activities to identify privacy risk?
- Identify-P (Correct answer)
- Govern-P
- Control-P
- Protect-P
Correct answer: Identify-P
The Identify-P function in the NIST Privacy Framework helps organizations develop an organizational understanding of privacy risk to individuals.
Question 2: In the context of the ISO 29101 privacy architecture framework, what does the 'PII principal' refer to?
- The organization processing data
- The individual to whom the PII relates (Correct answer)
- The data protection authority
- The system administrator managing data
Correct answer: The individual to whom the PII relates
In ISO 29101, the PII principal is the natural person to whom the personally identifiable information relates.
Question 3: A company implements a data minimization strategy where it only collects data fields absolutely necessary for a transaction. Which Fair Information Practice Principle does this best exemplify?
- Purpose specification
- Collection limitation (Correct answer)
- Use limitation
- Individual participation
Correct answer: Collection limitation
Collection limitation is the FIPP that restricts data collection to what is necessary, relevant, and obtained fairly.
Question 4: Under the APEC Privacy Framework, which principle requires organizations to give individuals an opportunity to have inaccurate data corrected?
- Preventing Harm
- Integrity of Personal Information
- Access and Correction (Correct answer)
- Accountability
Correct answer: Access and Correction
The Access and Correction principle in the APEC Privacy Framework requires that individuals be able to access their data and correct inaccuracies.
Question 5: Which model explicitly uses 'contextual integrity' to evaluate whether information flows are appropriate?
- The OECD Privacy Guidelines model
- Helen Nissenbaum's privacy-as-contextual-integrity model (Correct answer)
- The EU adequacy decision model
- The NIST Cybersecurity Framework
Correct answer: Helen Nissenbaum's privacy-as-contextual-integrity model
Helen Nissenbaum's contextual integrity model holds that privacy is violated when information flows do not match the norms of the context in which data was shared.
Question 6: In the GDPR's data protection framework, what is the primary legal basis for processing special categories of personal data in a workplace health context?
- Legitimate interests of the employer
- Explicit consent or a specific legal obligation (Correct answer)
- Contract performance with the employee
- Public interest without any additional safeguard
Correct answer: Explicit consent or a specific legal obligation
Article 9 GDPR requires explicit consent or a qualifying legal obligation/employment law basis to process health data as a special category.
Question 7: The 'Accountability' principle in the OECD Privacy Guidelines assigns responsibility for compliance to which party?
- The data subject
- The supervisory authority
- The data controller (Correct answer)
- The data processor
Correct answer: The data controller
Under the OECD Accountability principle, the data controller is responsible for ensuring the other principles are complied with.
Which NIST Privacy Framework core function focuses on developing and implementing organizational activities to identify privacy risk?