GPHR (GPHR) Global Risk and Compliance 4 — Questions and Answers
Question 1: What does the term 'employer of record' (EOR) mean in international HR risk management?
- The parent company that sets global HR policy
- A third-party entity that legally employs workers on behalf of a company in a foreign jurisdiction (Correct answer)
- The HR director responsible for compliance documentation
- The local government authority overseeing employment
Correct answer: A third-party entity that legally employs workers on behalf of a company in a foreign jurisdiction
An EOR assumes legal employment responsibilities in a foreign country, allowing the client company to operate without establishing a local legal entity.
Question 2: Which approach to global compliance training BEST accounts for cultural and linguistic differences across a multinational workforce?
- Delivering a single English-language training globally to ensure consistency
- Localizing content for language, cultural context, and regulatory specifics in each country (Correct answer)
- Using external consultants to train all employees simultaneously
- Conducting annual in-person training at headquarters for all managers
Correct answer: Localizing content for language, cultural context, and regulatory specifics in each country
Localized training that reflects local language, cultural norms, and regulatory requirements is more effective and defensible than a one-size-fits-all approach.
Question 3: Under GDPR, what is the maximum fine for the most serious data protection violations involving employee personal data?
- €10 million or 2% of global annual turnover, whichever is higher
- €20 million or 4% of global annual turnover, whichever is higher (Correct answer)
- €5 million or 1% of global annual turnover, whichever is higher
- €50 million regardless of company size
Correct answer: €20 million or 4% of global annual turnover, whichever is higher
GDPR's upper tier penalty is €20 million or 4% of global annual turnover—whichever is higher—for the most serious infringements.
Question 4: A GPHR professional is reviewing the company's global anti-harassment policy. Which element is LEGALLY essential to include for operations in the United States?
- Mandatory arbitration clauses for all harassment claims
- A clear complaint procedure and prohibition against retaliation (Correct answer)
- A cap on damages claimants may seek
- Supervisor immunity provisions
Correct answer: A clear complaint procedure and prohibition against retaliation
US anti-harassment policies must include a clear reporting mechanism and strong non-retaliation protections to meet EEOC compliance expectations.
Question 5: An MNC's global mobility policy must address which risk when employees work remotely from a country where the company has no legal entity?
- Currency fluctuation risk
- Permanent establishment (PE) risk (Correct answer)
- Intellectual property dilution risk
- Workforce planning risk
Correct answer: Permanent establishment (PE) risk
Remote workers based in a country where the employer has no entity can trigger permanent establishment status, creating corporate tax obligations in that jurisdiction.
Question 6: Which of the following is a key principle of the OECD Guidelines for Multinational Enterprises related to HR and labor?
- Maximizing shareholder value above worker rights
- Respecting internationally recognized human rights and labor standards in all operations (Correct answer)
- Prioritizing home-country employment practices globally
- Limiting union representation to host-country requirements
Correct answer: Respecting internationally recognized human rights and labor standards in all operations
The OECD Guidelines call on MNEs to respect internationally recognized human rights and core labor standards across all their global operations.
Question 7: A global company experiences a data breach exposing employee personal data in the EU. Under GDPR, within what timeframe must the supervisory authority be notified?
- 24 hours
- 72 hours (Correct answer)
- 7 business days
- 30 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.
What does the term 'employer of record' (EOR) mean in international HR risk management?