IGP Compliance & Risk Management 5 — Questions and Answers
Question 1: A multinational company transferring EU personal data to the US in the absence of an adequacy decision should use which approved mechanism?
- Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs) (Correct answer)
- A self-certification letter from the receiving company
- An internal data governance policy approved by the DPO
- Pseudonymization applied before transfer
Correct answer: Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs)
GDPR Chapter V allows cross-border data transfers via approved safeguards including BCRs and SCCs when no adequacy decision exists.
Question 2: Which federal law requires financial institutions to implement information security programs and protect customer financial information?
- GLBA (Gramm-Leach-Bliley Act) (Correct answer)
- FERPA
- COPPA
- CAN-SPAM Act
Correct answer: GLBA (Gramm-Leach-Bliley Act)
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program.
Question 3: In a risk register, the 'inherent risk' rating represents risk:
- After all controls have been applied
- Before any controls are applied (Correct answer)
- That cannot be mitigated under any circumstances
- Identified through penetration testing
Correct answer: Before any controls are applied
Inherent risk is the raw or untreated risk level that exists before any controls or mitigations are applied.
Question 4: A data protection impact assessment (DPIA) under GDPR is mandatory when processing is likely to result in:
- Any collection of personal data from EU residents
- High risk to the rights and freedoms of natural persons (Correct answer)
- Cross-border transfers to countries with adequacy decisions
- Processing by any company with more than 250 employees
Correct answer: High risk to the rights and freedoms of natural persons
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of individuals.
Question 5: Which of the following is the BEST example of a preventive compliance control?
- Reviewing audit logs after a data breach
- Requiring dual authorization for large financial transactions (Correct answer)
- Generating monthly compliance status reports
- Conducting a root cause analysis after a policy violation
Correct answer: Requiring dual authorization for large financial transactions
Preventive controls stop violations before they occur; dual authorization prevents unauthorized transactions from being processed in the first place.
Question 6: Under the concept of 'privacy by design,' privacy protections should be:
- Added to systems after deployment when required by auditors
- Embedded into systems and processes from the outset (Correct answer)
- Applied only to data classified as highly sensitive
- Documented in a privacy policy but not technically enforced
Correct answer: Embedded into systems and processes from the outset
Privacy by design requires that privacy protections be built into technology and business practices from the initial design stage, not retrofitted.
Question 7: A company's Chief Compliance Officer (CCO) reports directly to the Board of Directors. This reporting structure is significant because it:
- Reduces the cost of compliance operations
- Ensures compliance independence from business unit pressure (Correct answer)
- Eliminates the need for external audits
- Satisfies HIPAA's designated privacy officer requirement
Correct answer: Ensures compliance independence from business unit pressure
A CCO reporting to the Board rather than operational management preserves independence and ensures compliance concerns reach the highest governance level without being filtered.
A multinational company transferring EU personal data to the US in the absence of an adequacy decision should use which approved mechanism?