CIPT Certified Information Privacy Technologist: Privacy Regulations and Compliance Practice 5 — Questions and Answers
Question 1: An e-commerce company based in the U.S. sells goods to EU residents without any EU establishment. Does GDPR apply to this company?
- No, because the company has no EU establishment
- Yes, because it offers goods to EU data subjects (Correct answer)
- Only if annual revenue exceeds €10 million
- Only if it processes sensitive personal data
Correct answer: Yes, because it offers goods to EU data subjects
GDPR Article 3(2) extends the regulation's territorial scope to controllers outside the EU that offer goods or services to data subjects in the EU, regardless of whether payment is required.
Question 2: Under HIPAA's Minimum Necessary standard, when does it NOT apply to a use or disclosure of PHI?
- Disclosures to business associates
- Disclosures to the individual who is the subject of the PHI (Correct answer)
- Uses for treatment purposes by workforce members
- Research uses with a waiver of authorization
Correct answer: Disclosures to the individual who is the subject of the PHI
The Minimum Necessary standard does not apply to disclosures made to or requested by the individual who is the subject of the information, as they have an inherent right to their own PHI.
Question 3: A privacy engineer applies 'privacy by design' during system development. Which of the following best describes the 'proactive not reactive' principle of Privacy by Design?
- Respond to privacy breaches within 72 hours
- Anticipate and prevent privacy risks before they occur rather than remediate after (Correct answer)
- Use privacy-enhancing technologies in all data stores
- Conduct privacy audits after system deployment
Correct answer: Anticipate and prevent privacy risks before they occur rather than remediate after
Privacy by Design's first foundational principle, 'Proactive not Reactive; Preventative not Remedial,' means anticipating and preventing privacy risks before they materialize rather than responding after.
Question 4: Under the Connecticut Data Privacy Act (CTDPA), what is the cure period provided to controllers before the Attorney General may initiate enforcement?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
The CTDPA provides a 60-day cure period through the end of 2024, after which cure opportunities become discretionary for the Attorney General.
Question 5: A company uses automated profiling to make credit decisions with significant effects on individuals. Under GDPR Article 22, what right do affected individuals have?
- The right to erasure of the decision
- The right to obtain human review and contest the decision (Correct answer)
- The right to opt out of all profiling activities permanently
- The right to compensation for any adverse decision
Correct answer: The right to obtain human review and contest the decision
GDPR Article 22 gives individuals the right not to be subject to solely automated decisions with significant effects, and the right to obtain human intervention, express their point of view, and contest the decision.
Question 6: Which of the following is considered 'sensitive personal data' under the GDPR requiring explicit consent or another specific condition for processing?
- Home address
- Email address used for work
- Trade union membership (Correct answer)
- Employment history
Correct answer: Trade union membership
GDPR Article 9 lists trade union membership as a special category of sensitive personal data, along with racial/ethnic origin, health data, genetic data, biometric data, and others.
Question 7: An organization subject to the FTC Act engages in a data practice it did not disclose to consumers. The FTC considers this a violation under which authority?
- Section 5 prohibition on unfair or deceptive acts or practices (Correct answer)
- Section 13 injunctive relief provisions
- The FTC Privacy Rule under GLBA
- The Safeguards Rule enforcement authority
Correct answer: Section 5 prohibition on unfair or deceptive acts or practices
The FTC uses Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, to take action when companies engage in undisclosed or misleading data practices.
An e-commerce company based in the U.S. sells goods to EU residents without any EU establishment.
Does GDPR apply to this company?