CIPT Certified Information Privacy Technologist: Data Privacy Frameworks and Models 3 — Questions and Answers
Question 1: A U.S. healthcare organization is evaluating privacy frameworks. Which framework is specifically designed for health information and mandates a Notice of Privacy Practices?
- FERPA
- HIPAA Privacy Rule (Correct answer)
- COPPA
- CCPA
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule requires covered entities to provide patients with a Notice of Privacy Practices describing how PHI is used and disclosed.
Question 2: Which privacy engineering objective focuses on limiting the ability of systems to link data to specific individuals across contexts?
- Disassociability (Correct answer)
- Predictability
- Manageability
- Data integrity
Correct answer: Disassociability
Disassociability is the privacy engineering objective aimed at ensuring data cannot be linked or associated with individuals beyond what is necessary.
Question 3: In Privacy by Design, which foundational principle states that privacy must be proactive rather than reactive?
- Privacy as the default setting
- Privacy embedded into design
- Proactive not reactive; preventive not remedial (Correct answer)
- Full functionality — positive-sum not zero-sum
Correct answer: Proactive not reactive; preventive not remedial
Ann Cavoukian's first principle of Privacy by Design emphasizes anticipating and preventing privacy issues before they occur.
Question 4: An e-commerce platform stores customer purchase history indefinitely 'just in case it is useful later.' Which privacy principle does this most directly violate?
- Security safeguards
- Purpose specification (Correct answer)
- Openness
- Individual participation
Correct answer: Purpose specification
Purpose specification requires that the purposes for which data is collected be specified before collection; storing data for vague future use violates this.
Question 5: Which GDPR mechanism allows a company with entities in multiple EU member states to deal with a single lead supervisory authority?
- Standard Contractual Clauses
- Binding Corporate Rules
- The One-Stop-Shop mechanism (Correct answer)
- The adequacy decision process
Correct answer: The One-Stop-Shop mechanism
The One-Stop-Shop mechanism under GDPR allows multinational companies to engage primarily with the supervisory authority of their EU main establishment.
Question 6: Under the CCPA/CPRA framework, which right allows California consumers to correct inaccurate personal information held by a business?
- Right to Know
- Right to Delete
- Right to Correct (Correct answer)
- Right to Opt-Out
Correct answer: Right to Correct
The CPRA added the Right to Correct, enabling consumers to request that businesses fix inaccurate personal information.
Question 7: The concept of 'purpose limitation' in European data protection law is most closely aligned with which OECD Privacy Guideline?
- Use Limitation Principle (Correct answer)
- Data Quality Principle
- Openness Principle
- Security Safeguards Principle
Correct answer: Use Limitation Principle
The OECD Use Limitation Principle restricts personal data from being used for purposes other than those specified, mirroring the GDPR's purpose limitation concept.
A U.S. healthcare organization is evaluating privacy frameworks.
Which framework is specifically designed for health information and mandates a Notice of Privacy Practices?