Data Processing Data Security and Privacy 2 — Questions and Answers
Question 1: What does GDPR stand for?
- General Data Protection Regulation (Correct answer)
- Global Data Privacy Requirements
- Government Data Processing Rules
- General Database Protection Rights
Correct answer: General Data Protection Regulation
GDPR stands for General Data Protection Regulation, a comprehensive EU data privacy law that governs how organizations collect, store, and process personal data.
Question 2: Which of the following best describes personally identifiable information (PII)?
- Any data that can be used to identify a specific individual (Correct answer)
- Data stored on personal computers and mobile devices
- Encrypted data belonging to registered users
- Information accessed using personal login credentials
Correct answer: Any data that can be used to identify a specific individual
PII refers to any information that can be used alone or combined with other data to identify, contact, or locate a specific individual.
Question 3: What is data anonymization?
- Removing or altering personally identifiable information so individuals cannot be identified (Correct answer)
- Encrypting data with an anonymous key pair for secure transmission
- Storing data without assigning ownership or metadata attributes
- Routing data through anonymous network proxies for privacy
Correct answer: Removing or altering personally identifiable information so individuals cannot be identified
Data anonymization removes or modifies PII from datasets so that individuals can no longer be identified, enabling data to be used for analysis while protecting privacy.
Question 4: Under HIPAA, what category of information is protected?
- Health information that can be linked to a specific individual (Correct answer)
- All financial data belonging to healthcare organizations
- Research data published in peer-reviewed medical journals
- General healthcare statistics and aggregate demographic data
Correct answer: Health information that can be linked to a specific individual
HIPAA protects Protected Health Information (PHI), which is any health information that can be linked to a specific individual, including medical records and billing information.
Question 5: What is the primary purpose of a privacy policy?
- To inform users how their personal data will be collected, used, and protected (Correct answer)
- To restrict employee access to internal company systems and networks
- To define the technical security measures used to protect databases
- To establish legal penalties for unauthorized data access incidents
Correct answer: To inform users how their personal data will be collected, used, and protected
A privacy policy is a legal document that discloses how an organization collects, uses, stores, and shares personal data, informing users of their rights.
Question 6: What does data sovereignty mean?
- Data is subject to the laws and regulations of the country where it is stored (Correct answer)
- An individual's right to own and control their personal information
- A company's exclusive ownership of all data its systems generate
- Government agencies have priority access to all citizen-generated data
Correct answer: Data is subject to the laws and regulations of the country where it is stored
Data sovereignty is the principle that digital data is subject to the laws and governance structures of the nation in which it is stored or processed.
Question 7: What does the GDPR 'right to erasure' (right to be forgotten) allow individuals to do?
- Request that an organization permanently delete their personal data (Correct answer)
- Require companies to erase data after a government-mandated retention period
- Hide browsing history and online activity from third parties
- Force organizations to delete all backups when a user closes their account
Correct answer: Request that an organization permanently delete their personal data
The right to erasure allows individuals to request that an organization permanently delete their personal data under certain circumstances defined by GDPR.
What does GDPR stand for?