CSL Data Protection & Privacy Laws 2 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), which threshold triggers a business's compliance obligations based on annual gross revenue?
- $10 million
- $25 million (Correct answer)
- $50 million
- $100 million
Correct answer: $25 million
The CCPA applies to for-profit businesses with annual gross revenues exceeding $25 million.
Question 2: The Health Insurance Portability and Accountability Act (HIPAA) Security Rule specifically governs which type of health information?
- All individually identifiable health information
- Electronic protected health information (ePHI) only (Correct answer)
- Paper records and oral communications only
- Aggregated and de-identified health datasets
Correct answer: Electronic protected health information (ePHI) only
The HIPAA Security Rule applies exclusively to electronic protected health information (ePHI), while the Privacy Rule covers all PHI formats.
Question 3: Which EU GDPR principle requires that personal data be collected only for specified, explicit, and legitimate purposes?
- Data minimization
- Storage limitation
- Purpose limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Purpose limitation
Purpose limitation under GDPR Article 5(1)(b) restricts data use to the specific purposes for which it was originally collected.
Question 4: A U.S. company transfers personal data of EU residents to its servers in Texas. Under GDPR, what must the company ensure?
- The transfer complies with a lawful transfer mechanism such as Standard Contractual Clauses (Correct answer)
- The data is encrypted using AES-256 during transit only
- The company registers with the EU Data Protection Board
- EU residents consent only at the time of collection, not transfer
Correct answer: The transfer complies with a lawful transfer mechanism such as Standard Contractual Clauses
GDPR Chapter V requires that international data transfers use approved mechanisms like Standard Contractual Clauses (SCCs) or adequacy decisions.
Question 5: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule primarily applies to which category of organizations?
- Healthcare providers and hospitals
- Financial institutions offering consumer financial products or services (Correct answer)
- Federal government agencies handling citizen records
- Retailers collecting credit card information
Correct answer: Financial institutions offering consumer financial products or services
The GLBA Safeguards Rule requires financial institutions to protect the security and confidentiality of customers' nonpublic personal information.
Question 6: Under COPPA, parental consent is required before collecting personal information from children under what age threshold?
- 13 (Correct answer)
- 16
- 18
- 21
Correct answer: 13
The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal data from children under 13.
Question 7: Which GDPR right allows an individual to request that their personal data be transferred from one controller to another in a machine-readable format?
- Right to erasure
- Right to rectification
- Right to data portability (Correct answer)
- Right to restriction of processing
Correct answer: Right to data portability
GDPR Article 20 grants the right to data portability, enabling individuals to receive and transfer their data between controllers.
Under the California Consumer Privacy Act (CCPA), which threshold triggers a business's compliance obligations based on annual gross revenue?