CSL Data Protection & Privacy Laws 3 — Questions and Answers
Question 1: A breach notification requirement under HIPAA's Breach Notification Rule generally mandates notifying affected individuals within how many days of discovering a breach?
- 30 days
- 45 days
- 60 days (Correct answer)
- 72 hours
Correct answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and within 60 days of discovery.
Question 2: The GDPR's 'legitimate interests' lawful basis for processing personal data requires which balancing test?
- Comparing data volume against revenue generated from processing
- Weighing the controller's interests against the data subject's rights and freedoms (Correct answer)
- Assessing whether the data is sensitive or special category data only
- Evaluating the cost of implementing consent management systems
Correct answer: Weighing the controller's interests against the data subject's rights and freedoms
Legitimate interests (GDPR Article 6(1)(f)) requires a three-part test balancing the controller's purpose, necessity, and the data subject's overriding interests.
Question 3: Under the California Privacy Rights Act (CPRA), which new category of sensitive personal information receives heightened protection?
- Email addresses and postal codes
- Social Security numbers, precise geolocation, and racial or ethnic origin (Correct answer)
- Publicly available government records
- Aggregated consumer preferences
Correct answer: Social Security numbers, precise geolocation, and racial or ethnic origin
The CPRA introduced a 'sensitive personal information' category including SSNs, precise geolocation, racial origin, and health data with additional consumer rights.
Question 4: Which federal law governs the privacy of student education records maintained by schools receiving federal funding?
- FERPA (Correct answer)
- COPPA
- GLBA
- HIPAA
Correct answer: FERPA
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records at federally funded institutions.
Question 5: A GDPR Data Protection Impact Assessment (DPIA) is mandatory when processing is likely to result in what?
- Any use of cloud storage services
- A high risk to the rights and freedoms of natural persons (Correct answer)
- Collection of more than 500 records
- Cross-border data transfers to any third country
Correct answer: A high risk to the rights and freedoms of natural persons
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to individuals' rights and freedoms, such as large-scale profiling.
Question 6: The concept of 'pseudonymization' under GDPR is best described as which of the following?
- Permanently removing all identifying information so re-identification is impossible
- Processing data in a way that it can no longer be attributed to a specific individual without additional information held separately (Correct answer)
- Encrypting data so only authorized recipients can read it
- Deleting data after its retention period expires
Correct answer: Processing data in a way that it can no longer be attributed to a specific individual without additional information held separately
Pseudonymization replaces direct identifiers with artificial ones; the data remains personal data because re-identification is possible with the separately stored key.
Question 7: Under the FTC Act Section 5, the FTC can take enforcement action against companies for privacy violations primarily on what legal theory?
- Violations of specific federal data protection statutes
- Unfair or deceptive acts or practices in or affecting commerce (Correct answer)
- Failure to pay federal privacy registration fees
- Non-compliance with state breach notification laws
Correct answer: Unfair or deceptive acts or practices in or affecting commerce
The FTC uses its Section 5 authority to pursue companies whose privacy practices constitute unfair or deceptive acts or practices harming consumers.
A breach notification requirement under HIPAA's Breach Notification Rule generally mandates notifying affected individuals within how many days of discovering a breach?