GRC GRC Data Privacy and Information Governance 2 — Questions and Answers
Question 1: Which of the following best describes a Privacy Impact Assessment (PIA)?
- A financial audit of marketing spend on data advertising
- A systematic process for evaluating privacy risks of a new system or process (Correct answer)
- A legal contract between data processors and controllers
- A technical scan for malware on data servers
Correct answer: A systematic process for evaluating privacy risks of a new system or process
A PIA is a structured analysis used to identify and mitigate privacy risks before deploying a new project, system, or business process involving personal data.
Question 2: Which data classification level typically requires the highest level of security controls within a U.S. enterprise GRC framework?
- Public
- Internal
- Confidential
- Restricted/Top Secret (Correct answer)
Correct answer: Restricted/Top Secret
Restricted or Top Secret data classification represents the most sensitive information and mandates the strictest access and protection controls.
Question 3: The role of a Data Protection Officer (DPO) under privacy regulations is to:
- Encrypt all organizational databases
- Oversee compliance with data protection laws and serve as a point of contact for regulators (Correct answer)
- Manage IT infrastructure budgets
- Approve all marketing campaigns involving customer data
Correct answer: Oversee compliance with data protection laws and serve as a point of contact for regulators
A DPO is responsible for monitoring internal compliance with data protection requirements and acts as the primary liaison with data protection authorities.
Question 4: Which principle ensures that individuals can obtain their personal data in a usable format and transfer it to another service provider?
- Right to erasure
- Data portability (Correct answer)
- Data minimization
- Purpose limitation
Correct answer: Data portability
Data portability is the right that allows individuals to receive their personal data in a structured, commonly used format and move it between services.
Question 5: In a GRC context, 'data lineage' refers to:
- The genealogy of corporate data ownership records over decades
- Tracking the origin, movement, and transformation of data through its lifecycle (Correct answer)
- The legal chain of custody for evidence in litigation
- The hierarchy of data governance committee members
Correct answer: Tracking the origin, movement, and transformation of data through its lifecycle
Data lineage documents where data comes from, how it moves through systems, and how it is transformed, supporting auditability and compliance.
Question 6: Which U.S. law requires financial institutions to explain their information-sharing practices to customers and safeguard sensitive customer data?
- SOX
- GLBA (Correct answer)
- FERPA
- CAN-SPAM
Correct answer: GLBA
The Gramm-Leach-Bliley Act (GLBA) mandates that financial institutions protect the privacy and security of consumers' personal financial information.
Which of the following best describes a Privacy Impact Assessment (PIA)?