GRC Regulatory and Legal Compliance 3 — Questions and Answers
Question 1: Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority after the controller becomes aware of it?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 2: The Children's Online Privacy Protection Act (COPPA) applies to websites and online services directed to children under what age?
- 12
- 13 (Correct answer)
- 16
- 18
Correct answer: 13
COPPA protects the online privacy of children under 13 by requiring verifiable parental consent before collecting their personal information.
Question 3: An organization wants to transfer personal data from the EU to a country without an adequacy decision. Which mechanism provides an appropriate safeguard under GDPR?
- Data Processing Agreement (DPA)
- Standard Contractual Clauses (SCCs) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Memorandum of Understanding (MOU)
Correct answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are pre-approved contractual mechanisms that provide adequate safeguards for transferring personal data outside the EU.
Question 4: Which provision of the Gramm-Leach-Bliley Act (GLBA) requires financial institutions to develop a written information security program?
- Financial Privacy Rule
- Safeguards Rule (Correct answer)
- Pretexting Provisions
- Fair Lending Rule
Correct answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a comprehensive written information security program to protect customer financial information.
Question 5: In a compliance program, a 'whistleblower hotline' is primarily designed to satisfy which element of an effective compliance program?
- Risk assessment
- Training and education
- Reporting mechanisms (Correct answer)
- Disciplinary procedures
Correct answer: Reporting mechanisms
Whistleblower hotlines serve as anonymous reporting mechanisms that allow employees to report potential violations without fear of retaliation.
Question 6: A U.S. company's foreign subsidiary pays bribes to a government official to win a contract. Which U.S. law has most likely been violated?
- Sarbanes-Oxley Act
- Foreign Corrupt Practices Act (FCPA) (Correct answer)
- Bank Secrecy Act
- Dodd-Frank Act
Correct answer: Foreign Corrupt Practices Act (FCPA)
The FCPA prohibits U.S. companies and their subsidiaries from bribing foreign government officials to obtain or retain business.
Question 7: Which concept in regulatory compliance refers to the practice of treating similar regulatory requirements across different jurisdictions as a single, unified standard?
- Regulatory arbitrage
- Harmonization (Correct answer)
- Extraterritoriality
- Preemption
Correct answer: Harmonization
Harmonization is the process of aligning different regulatory requirements across jurisdictions into a common standard to reduce compliance complexity.
Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority after the controller becomes aware of it?