CIPT Certified Information Privacy Technologist: Privacy Regulations and Compliance Practice 3 — Questions and Answers
Question 1: A data processor experiences a breach affecting EU residents' data. Under GDPR, within what timeframe must the processor notify the controller?
- Without undue delay (Correct answer)
- Within 24 hours
- Within 72 hours
- Within 7 business days
Correct answer: Without undue delay
Under GDPR Article 33(2), processors must notify controllers of a personal data breach without undue delay after becoming aware of it, without a specific hour limit for processor-to-controller notification.
Question 2: Which U.S. federal sector-specific law primarily governs the privacy of student education records?
- HIPAA
- FERPA (Correct answer)
- COPPA
- GLBA
Correct answer: FERPA
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records and gives parents (or eligible students) the right to access and correct those records.
Question 3: Under the Colorado Privacy Act (CPA), what is the maximum civil penalty per intentional violation?
- $2,500
- $7,500 (Correct answer)
- $20,000
- $50,000
Correct answer: $7,500
The Colorado Privacy Act allows the Attorney General to seek civil penalties of up to $20,000 per violation, but enforcement is similar to other state laws with a 60-day cure period in some circumstances.
Question 4: An organization subject to GDPR wants to transfer personal data to a country without an adequacy decision. Which mechanism allows transfer to a new vendor without individual consent?
- Binding corporate rules
- Standard contractual clauses (Correct answer)
- Explicit consent of each data subject
- Derogations under Article 49
Correct answer: Standard contractual clauses
Standard contractual clauses (SCCs) are a widely used GDPR-approved mechanism that allow personal data transfers to third countries without adequacy decisions without requiring individual data subject consent.
Question 5: Under CCPA/CPRA, which consumer right was newly added by the California Privacy Rights Act (CPRA)?
- Right to know
- Right to delete
- Right to correct inaccurate personal information (Correct answer)
- Right to opt out of sale
Correct answer: Right to correct inaccurate personal information
The CPRA, which amended CCPA, added the right to correct inaccurate personal information as a new consumer right not present in the original CCPA.
Question 6: A healthcare startup uses de-identified patient data for AI model training. Under HIPAA's Safe Harbor method, how many specific identifiers must be removed?
- 15
- 18 (Correct answer)
- 21
- 24
Correct answer: 18
HIPAA's Safe Harbor de-identification method requires removal of 18 specific categories of identifiers, including names, geographic subdivisions smaller than a state, dates, phone numbers, and others.
Question 7: Which principle in the OECD Privacy Guidelines requires that personal data collected should be relevant to the purposes for which it is used and not excessive?
- Purpose Specification
- Data Quality (Correct answer)
- Use Limitation
- Collection Limitation
Correct answer: Data Quality
The OECD Data Quality principle requires that personal data should be relevant to the purposes for which they are to be used, and should be accurate, complete, and kept up-to-date.
A data processor experiences a breach affecting EU residents' data.
Under GDPR, within what timeframe must the processor notify the controller?