CTO CTO Regulatory Compliance & Legal 1 — Questions and Answers
Question 1: Under GDPR, which role is responsible for ensuring technology systems process personal data lawfully, and what is their primary obligation?
- The Data Protection Officer (DPO), who oversees compliance and advises on data protection obligations (Correct answer)
- The CTO, who must personally approve every data processing request
- The CISO, who encrypts all personal data by default
- The CEO, who signs all data processing agreements
Correct answer: The Data Protection Officer (DPO), who oversees compliance and advises on data protection obligations
The DPO is the designated compliance role under GDPR responsible for monitoring data protection practices and serving as the point of contact for supervisory authorities.
Question 2: A US-based healthcare technology company must ensure its platform complies with patient data privacy requirements. Which regulation is primarily applicable?
- HIPAA (Health Insurance Portability and Accountability Act) (Correct answer)
- SOX (Sarbanes-Oxley Act)
- FERPA (Family Educational Rights and Privacy Act)
- CAN-SPAM Act
Correct answer: HIPAA (Health Insurance Portability and Accountability Act)
HIPAA sets the federal standard for protecting sensitive patient health information (PHI) in the United States, applying to covered entities and their business associates.
Question 3: What is a Software Bill of Materials (SBOM) and why is it increasingly required by US regulators for technology vendors?
- A formal inventory of software components and dependencies used in a product, required to identify supply chain vulnerabilities (Correct answer)
- A financial statement of software licensing costs
- A list of approved software vendors for government contracts
- A project plan for software development milestones
Correct answer: A formal inventory of software components and dependencies used in a product, required to identify supply chain vulnerabilities
An SBOM provides transparency into the open-source and third-party components within software, enabling organizations to quickly assess exposure when new vulnerabilities are disclosed.
Question 4: The Sarbanes-Oxley Act (SOX) Section 404 has significant implications for CTOs of publicly traded US companies. What does it primarily require?
- Management to assess and report on the effectiveness of internal controls over financial reporting, including IT controls (Correct answer)
- Annual security penetration testing of all systems
- Third-party audits of software development practices
- Encryption of all financial data at rest
Correct answer: Management to assess and report on the effectiveness of internal controls over financial reporting, including IT controls
SOX Section 404 requires management to evaluate and attest to the effectiveness of internal controls over financial reporting, with IT general controls being a critical component.
Question 5: A CTO is launching a product that collects personal data from California residents. Which state privacy law must the product comply with?
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) (Correct answer)
- New York SHIELD Act
- Illinois Biometric Information Privacy Act (BIPA)
- Texas Data Privacy and Security Act
Correct answer: California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
The CCPA (amended by CPRA) grants California residents rights over their personal data and imposes obligations on businesses that collect or sell that data.
Question 6: What is the purpose of a Data Processing Agreement (DPA) between a technology company and its cloud provider?
- To define the legal obligations of the processor when handling personal data on behalf of the controller (Correct answer)
- To set service level agreements for uptime and performance
- To negotiate pricing for cloud infrastructure services
- To establish intellectual property ownership of data stored in the cloud
Correct answer: To define the legal obligations of the processor when handling personal data on behalf of the controller
A DPA is a legally required contract under GDPR and similar laws that specifies how a processor must handle personal data on behalf of the controller, including security measures and data subject rights.
Under GDPR, which role is responsible for ensuring technology systems process personal data lawfully, and what is their primary obligation?