CRM Legal & Regulatory Compliance 3 — Questions and Answers
Question 1: Under HIPAA, how long must a covered entity retain its written privacy policies and procedures?
- 6 years from creation or last effective date (Correct answer)
- 3 years from creation
- 10 years from creation
- Indefinitely
Correct answer: 6 years from creation or last effective date
HIPAA requires covered entities to retain privacy policies, procedures, and related documentation for 6 years from the date of creation or the date it was last in effect.
Question 2: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule primarily requires financial institutions to do which of the following?
- Develop and maintain a written information security program (Correct answer)
- Retain all customer records for a minimum of 7 years
- Encrypt all paper-based customer records
- Obtain prior written consent before sharing any customer data
Correct answer: Develop and maintain a written information security program
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive written information security program to protect customer information.
Question 3: Which principle from the EU General Data Protection Regulation (GDPR) limits how long personal data may be retained?
- Storage limitation (Correct answer)
- Data minimization
- Purpose limitation
- Integrity and confidentiality
Correct answer: Storage limitation
GDPR's storage limitation principle requires that personal data be kept in a form that permits identification of data subjects for no longer than necessary for the processing purpose.
Question 4: An organization operating in California must comply with which state privacy law that grants consumers the right to request deletion of their personal information?
- California Consumer Privacy Act (CCPA) (Correct answer)
- California Online Privacy Protection Act (CalOPPA)
- California Financial Information Privacy Act
- California Electronic Commerce Act
Correct answer: California Consumer Privacy Act (CCPA)
The CCPA grants California consumers the right to request that businesses delete their personal information, subject to certain exceptions.
Question 5: Under the Securities Exchange Act, broker-dealers must retain certain records for a minimum of how many years?
- 3 years for most records; 6 years for certain records (Correct answer)
- 1 year for all records
- 5 years for all records
- 10 years for financial records
Correct answer: 3 years for most records; 6 years for certain records
SEC Rule 17a-4 requires broker-dealers to retain most records for 3 years and certain records (such as blotters and general ledgers) for 6 years.
Question 6: What is the purpose of a records management 'legal hold notice'?
- To formally notify custodians to suspend routine destruction of potentially relevant records (Correct answer)
- To authorize the destruction of records that have met their retention period
- To transfer records ownership to outside counsel
- To classify records as privileged attorney-client communications
Correct answer: To formally notify custodians to suspend routine destruction of potentially relevant records
A legal hold notice formally instructs record custodians to suspend normal disposition of records that may be relevant to anticipated or pending litigation.
Question 7: Which IRS regulation governs electronic storage systems for tax records?
- Revenue Procedure 98-25 (Correct answer)
- IRS Publication 583
- IRC Section 6001
- Treasury Regulation 1.6001-1
Correct answer: Revenue Procedure 98-25
Revenue Procedure 98-25 establishes the IRS requirements for using electronic storage systems to maintain books and records required under the Internal Revenue Code.
Under HIPAA, how long must a covered entity retain its written privacy policies and procedures?