CIPT Privacy Incident Response and Breach Management 1 — Questions and Answers
Question 1: What is the first step an organization should take upon discovering a potential privacy breach?
- Contain the breach and preserve evidence (Correct answer)
- Notify all affected individuals immediately
- Contact law enforcement agencies
- Issue a public press release
Correct answer: Contain the breach and preserve evidence
Containment is the first priority to stop further exposure, followed by evidence preservation to support investigation.
Question 2: Under GDPR Article 33, within how many hours must a personal data breach be reported to the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 96 hours
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of the breach, where feasible.
Question 3: Which of the following best defines a 'personal data breach' under GDPR Article 4(12)?
- Any unauthorized access to a computer system
- A security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data (Correct answer)
- The loss of any device containing encrypted data
- Any violation of an organization's internal data security policy
Correct answer: A security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data
GDPR Article 4(12) defines a personal data breach as a security incident affecting the confidentiality, integrity, or availability of personal data.
Question 4: What is the primary purpose of a privacy incident response plan?
- To provide a structured approach for detecting, containing, and recovering from privacy incidents (Correct answer)
- To avoid regulatory fines by demonstrating documented compliance
- To transfer breach liability to third-party data processors
- To eliminate the need for cyber liability insurance
Correct answer: To provide a structured approach for detecting, containing, and recovering from privacy incidents
An incident response plan provides a systematic, pre-defined process to manage breaches efficiently and minimize harm to individuals.
Question 5: Which factor is most critical when determining whether a breach requires notification to affected individuals?
- The likelihood and severity of harm to affected individuals (Correct answer)
- The size of the organization experiencing the breach
- Whether the media has already reported the incident
- The cost of sending individual breach notifications
Correct answer: The likelihood and severity of harm to affected individuals
Most breach notification laws hinge on whether there is a reasonable risk of harm to individuals, making harm assessment the primary trigger.
Question 6: What does 'containment' mean in the context of privacy incident response?
- Notifying all internal and external stakeholders about the breach
- Documenting all categories of data that were compromised
- Stopping the breach from spreading and preventing further unauthorized access or exposure (Correct answer)
- Encrypting affected data systems after a breach has occurred
Correct answer: Stopping the breach from spreading and preventing further unauthorized access or exposure
Containment involves isolating affected systems, revoking unauthorized access, and stopping additional data exposure before investigation begins.
Question 7: Which type of data breach typically poses the HIGHEST risk to individuals' rights and freedoms?
- Temporary loss of access to a public-facing website
- Accidental email to a wrong internal address containing non-sensitive scheduling data
- Unauthorized disclosure of combined medical records and financial information enabling identity theft (Correct answer)
- Loss of an encrypted device where no decryption key is known to exist
Correct answer: Unauthorized disclosure of combined medical records and financial information enabling identity theft
Breaches exposing sensitive categories of data that can enable discrimination, identity theft, or financial harm pose the highest risk under GDPR risk-assessment criteria.
What is the first step an organization should take upon discovering a potential privacy breach?