CIPT Certified Information Privacy Technologist: Data Privacy Frameworks and Models 4 — Questions and Answers
Question 1: A privacy technologist is conducting a Data Protection Impact Assessment. Which GDPR article makes DPIAs mandatory for high-risk processing?
- Article 13
- Article 25
- Article 35 (Correct answer)
- Article 44
Correct answer: Article 35
GDPR Article 35 requires a DPIA before processing that is likely to result in a high risk to individuals' rights and freedoms.
Question 2: Which framework component in the NIST Privacy Framework maps most closely to implementing access controls and encryption for personal data?
- Communicate-P
- Protect-P (Correct answer)
- Govern-P
- Detect-P
Correct answer: Protect-P
The Protect-P function in the NIST Privacy Framework covers activities that develop and implement safeguards to prevent privacy incidents.
Question 3: An organization in Australia processes personal information under the Australian Privacy Act. Which document sets out the 13 Australian Privacy Principles?
- The Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Correct answer)
- The Notifiable Data Breaches Scheme
- The Office of the Australian Information Commissioner guidelines
- The Privacy Regulation 2013
Correct answer: The Privacy Amendment (Enhancing Privacy Protection) Act 2012
The Privacy Amendment (Enhancing Privacy Protection) Act 2012 replaced the former Information Privacy Principles and National Privacy Principles with the 13 APPs.
Question 4: In a federated identity model, how does the approach support the privacy principle of data minimization?
- By requiring central storage of all user credentials
- By sharing only necessary attributes rather than full identity records (Correct answer)
- By eliminating authentication requirements entirely
- By storing biometric data locally at each service provider
Correct answer: By sharing only necessary attributes rather than full identity records
Federated identity allows a user's home organization to vouch for specific attributes, so relying parties receive only what they need rather than complete identity dossiers.
Question 5: Which term describes the privacy risk scenario where combining non-sensitive datasets produces a result that reveals sensitive personal information?
- Re-identification
- The aggregation problem (Correct answer)
- Linkage attack
- Inference disclosure
Correct answer: The aggregation problem
The aggregation problem refers to the privacy risk where combining multiple individually harmless data elements creates a sensitive composite picture of an individual.
Question 6: Under Brazil's Lei Geral de Proteção de Dados (LGPD), which body is responsible for enforcing the law and issuing guidance?
- Conselho Nacional de Justiça (CNJ)
- Autoridade Nacional de Proteção de Dados (ANPD) (Correct answer)
- Agência Nacional de Telecomunicações (ANATEL)
- Ministério da Justiça
Correct answer: Autoridade Nacional de Proteção de Dados (ANPD)
The ANPD (National Data Protection Authority) is Brazil's supervisory authority established under the LGPD to enforce data protection requirements.
Question 7: A technology firm transfers EU personal data to the U.S. using Standard Contractual Clauses. After the Schrems II ruling, what additional step is now required?
- Filing a notification with the European Data Protection Board
- Conducting a Transfer Impact Assessment to evaluate the destination country's laws (Correct answer)
- Obtaining a separate adequacy decision for each data category
- Encrypting data only at the application layer
Correct answer: Conducting a Transfer Impact Assessment to evaluate the destination country's laws
Post-Schrems II, organizations must conduct a Transfer Impact Assessment (TIA) to determine whether the third country's law undermines the SCCs' protections.
A privacy technologist is conducting a Data Protection Impact Assessment.
Which GDPR article makes DPIAs mandatory for high-risk processing?