CIPT Certified Information Privacy Technologist: Privacy Regulations and Compliance Practice 2 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), which threshold triggers the law's applicability to a for-profit business?
- Annual gross revenue exceeding $10 million
- Annual gross revenue exceeding $25 million (Correct answer)
- Processing personal data of more than 50,000 consumers per year
- Having more than 100 employees in California
Correct answer: Annual gross revenue exceeding $25 million
CCPA applies to for-profit businesses that meet at least one of three thresholds: annual gross revenue exceeding $25 million, buying/selling/receiving/sharing personal information of 100,000+ consumers/households annually, or deriving 50%+ of annual revenue from selling consumers' personal information.
Question 2: Which GDPR article establishes the right to data portability?
- Article 15
- Article 17
- Article 20 (Correct answer)
- Article 22
Correct answer: Article 20
Article 20 of the GDPR grants data subjects the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Question 3: A company processes employee health data for workplace safety compliance. Under HIPAA, which entity type classification would typically apply?
- Covered entity
- Business associate
- Hybrid entity (Correct answer)
- Exempt entity
Correct answer: Hybrid entity
A hybrid entity is an organization that performs both covered and non-covered functions; it can designate only its healthcare components as subject to HIPAA requirements.
Question 4: Under the EU-U.S. Data Privacy Framework, what must a U.S. organization do to legitimately receive personal data transferred from the EU?
- Obtain explicit consent from every EU data subject
- Self-certify with the U.S. Department of Commerce (Correct answer)
- Execute standard contractual clauses with the EU exporter
- Register with the European Data Protection Board
Correct answer: Self-certify with the U.S. Department of Commerce
Organizations must self-certify their adherence to the EU-U.S. Data Privacy Framework Principles with the U.S. Department of Commerce to lawfully receive personal data from EU entities.
Question 5: Which provision of the Children's Online Privacy Protection Act (COPPA) requires operators to provide notice?
- Operators must post a privacy policy describing their information practices for children under 13 (Correct answer)
- Operators must verify parental age before collecting any data
- Operators must encrypt all data collected from minors
- Operators must delete all children's data after 30 days
Correct answer: Operators must post a privacy policy describing their information practices for children under 13
COPPA requires operators of websites or online services directed to children under 13 to post a clear and comprehensive privacy policy describing their information practices.
Question 6: A financial institution shares customer data with a third-party service provider for marketing purposes. Under the Gramm-Leach-Bliley Act (GLBA), what must customers receive before this sharing occurs?
- An opt-in consent form
- A privacy notice with opt-out opportunity (Correct answer)
- A signed data processing agreement
- A breach notification letter
Correct answer: A privacy notice with opt-out opportunity
GLBA requires financial institutions to provide customers with a clear privacy notice explaining their information-sharing practices and give customers an opportunity to opt out of sharing with non-affiliated third parties.
Question 7: Under Virginia's Consumer Data Protection Act (VCDPA), which data processing activity requires a data protection assessment?
- Processing data for internal analytics
- Processing sensitive data or data for targeted advertising (Correct answer)
- Processing publicly available information
- Processing data for order fulfillment
Correct answer: Processing sensitive data or data for targeted advertising
VCDPA requires data protection assessments for processing activities presenting heightened risk, including processing sensitive data, targeted advertising, profiling, and sale of personal data.
Under the California Consumer Privacy Act (CCPA), which threshold triggers the law's applicability to a for-profit business?