CSC - Cybersecurity Compliance Data Privacy and Breach Notification Laws Questions and Answers Flashcards
6 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CSC - Cybersecurity Compliance Data Privacy and Breach Notification Laws Questions and Answers flashcards as text
The California Privacy Rights Act (CPRA), which amended and strengthened the CCPA, became fully operative on which date?
Answer: January 1, 2023
The CPRA, passed as Proposition 24 in November 2020, became fully operative on January 1, 2023, adding new consumer rights and creating the California Privacy Protection Agency.
What new right did the CPRA add for California consumers that was not included in the original CCPA?
Answer: Right to correct inaccurate personal information
The CPRA introduced the right to correct inaccurate personal information held by businesses, a right not present in the original CCPA.
Under the Virginia Consumer Data Protection Act (VCDPA), which type of data processing requires an organization to conduct a data protection assessment?
Answer: Processing sensitive personal data or data for targeted advertising
The VCDPA requires controllers to conduct data protection assessments for processing activities involving sensitive data, targeted advertising, sale of personal data, or profiling.
Which U.S. state law created the first dedicated state privacy enforcement agency, the California Privacy Protection Agency (CPPA)?
Answer: CPRA (California Privacy Rights Act)
The CPRA, passed in November 2020, created the CPPA as a standalone agency with rulemaking and enforcement authority over California privacy law.
What is the primary difference between an 'opt-in' and an 'opt-out' consent model in U.S. data privacy law?
Answer: Opt-in requires affirmative consent before data is collected; opt-out allows data use unless the consumer objects
An opt-in model requires explicit consumer consent before data collection or use, while an opt-out model allows processing unless the consumer actively objects.
Which provision of the FTC Act is most commonly used to bring enforcement actions against companies for inadequate data security practices?
Answer: Section 5 — prohibition on unfair or deceptive acts or practices
The FTC uses Section 5 of the FTC Act to pursue companies whose data security failures constitute unfair or deceptive trade practices, even without a specific data security statute.