IGP Records Management & Data Privacy 4 — Questions and Answers
Question 1: What is the role of a Data Protection Officer (DPO) under GDPR?
- To process personal data on behalf of the controller
- To monitor compliance with data protection laws and advise on obligations (Correct answer)
- To act as the primary decision-maker for data collection activities
- To manage IT security infrastructure
Correct answer: To monitor compliance with data protection laws and advise on obligations
The DPO monitors compliance with GDPR, advises the organization on its data protection obligations, and acts as a contact point for supervisory authorities and data subjects.
Question 2: In electronic records management, what is 'format migration' intended to prevent?
- Unauthorized access to archived records
- Loss of access to records due to obsolete file formats or technology (Correct answer)
- Duplication of records across multiple systems
- Unauthorized modification of official records
Correct answer: Loss of access to records due to obsolete file formats or technology
Format migration converts records from obsolete or at-risk file formats to current ones to ensure long-term accessibility and usability as technology evolves.
Question 3: Under Sarbanes-Oxley (SOX), what is the retention requirement for audit workpapers?
- 3 years
- 5 years
- 7 years (Correct answer)
- 10 years
Correct answer: 7 years
SOX Section 802 requires that audit and review workpapers be retained for seven years from the end of the fiscal period covered by the audit.
Question 4: What is 'pseudonymization' of personal data?
- Permanently deleting identifying information from a dataset
- Replacing identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information (Correct answer)
- Encrypting personal data so only authorized parties can access it
- Masking personal data when displayed on screen
Correct answer: Replacing identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces direct identifiers with artificial ones, reducing privacy risk while allowing re-identification if the key is available, unlike anonymization which is irreversible.
Question 5: Which concept in records management ensures that a record has not been altered since it was created?
- Reliability
- Integrity (Correct answer)
- Authenticity
- Completeness
Correct answer: Integrity
Integrity means the record is complete and unaltered, while authenticity means it is what it purports to be — together they are distinct but related concepts in records management.
Question 6: A company transfers employee records from a US office to a subsidiary in Germany. Under GDPR, this constitutes what type of transfer?
- An intra-company transfer exempt from GDPR
- A third-country transfer requiring adequate safeguards (Correct answer)
- A domestic transfer subject only to German law
- An exempt controller-to-processor transfer
Correct answer: A third-country transfer requiring adequate safeguards
Any transfer of personal data from the EU/EEA to a third country like the US—even between related entities—requires appropriate safeguards such as SCCs, BCRs, or adequacy decisions.
Question 7: What does a Records Management Program 'vital records' designation indicate?
- Records that are used daily by employees
- Records essential for an organization to resume critical functions after a disaster (Correct answer)
- Records with the longest retention periods
- Records that require executive-level approval to access
Correct answer: Records essential for an organization to resume critical functions after a disaster
Vital records are those deemed essential for an organization to reconstruct its operations and meet its obligations after an emergency, making their protection a business continuity priority.
What is the role of a Data Protection Officer (DPO) under GDPR?