CIPT Certified Information Privacy Technologist: Privacy Regulations and Compliance Practice 4 — Questions and Answers
Question 1: Under GDPR, processing personal data based on legitimate interests requires a balancing test. Which factor weighs AGAINST legitimate interests?
- The data subject has a reasonable expectation of the processing
- The processing involves sensitive categories of personal data (Correct answer)
- The processing is limited to what is necessary
- The data subject can easily opt out
Correct answer: The processing involves sensitive categories of personal data
Processing sensitive categories of personal data weighs heavily against relying on legitimate interests as a legal basis, as such data carries heightened privacy risks requiring stronger justification.
Question 2: Which U.S. law requires federal agencies to publish notices in the Federal Register describing their systems of records?
- Freedom of Information Act (FOIA)
- E-Government Act
- Privacy Act of 1974 (Correct answer)
- Federal Information Security Management Act (FISMA)
Correct answer: Privacy Act of 1974
The Privacy Act of 1974 requires federal agencies to publish System of Records Notices (SORNs) in the Federal Register describing collections of personal information maintained in systems of records.
Question 3: A company collects biometric data in Illinois. Under the Illinois Biometric Information Privacy Act (BIPA), what must the company do BEFORE collection?
- Notify state regulators within 30 days
- Obtain written release from the subject and publish a retention schedule (Correct answer)
- Anonymize the data before storage
- Submit a privacy impact assessment to the Attorney General
Correct answer: Obtain written release from the subject and publish a retention schedule
BIPA requires companies to inform subjects in writing about the collection, its purpose, and duration; and obtain a written release before collecting biometric identifiers or information.
Question 4: Under the Texas Data Privacy and Security Act (TDPSA), which entity is exempt from the law's requirements?
- Small businesses with fewer than 25 employees
- Nonprofit organizations
- Financial institutions subject to GLBA (Correct answer)
- Companies processing data of fewer than 10,000 Texans annually
Correct answer: Financial institutions subject to GLBA
TDPSA exempts financial institutions and data subject to the GLBA, as well as covered entities and business associates subject to HIPAA, from its requirements.
Question 5: A multinational company implements binding corporate rules (BCRs) to enable intra-group data transfers. Who must approve BCRs before they can be relied upon?
- The EU Commission
- A competent supervisory authority (Correct answer)
- The European Data Protection Board alone
- The data subjects whose data is transferred
Correct answer: A competent supervisory authority
BCRs must be approved by a competent supervisory authority (the lead Data Protection Authority for the group) following the cooperation procedure, before they can be used as a transfer mechanism.
Question 6: Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing is 'likely to result in a high risk.' Which scenario clearly triggers this requirement?
- Sending a monthly newsletter to opted-in subscribers
- Systematic monitoring of publicly accessible areas using CCTV (Correct answer)
- Processing employee names for payroll on behalf of a small business
- Storing anonymized research data with no re-identification capability
Correct answer: Systematic monitoring of publicly accessible areas using CCTV
GDPR Article 35 lists systematic monitoring of publicly accessible areas on a large scale as one of the types of processing requiring a DPIA due to the high risk to individuals' rights and freedoms.
Question 7: Which principle from the Fair Information Practice Principles (FIPPs) requires that individuals be able to find out what personal information about them is on record?
- Use Limitation
- Individual Participation (Correct answer)
- Security Safeguards
- Openness
Correct answer: Individual Participation
The Individual Participation principle ensures that individuals have a right to know about and access personal information held about them, and can challenge inaccurate or incomplete data.
Under GDPR, processing personal data based on legitimate interests requires a balancing test.
Which factor weighs AGAINST legitimate interests?