IGP Records Management & Data Privacy 5 — Questions and Answers
Question 1: What is 'consent fatigue' in the context of data privacy, and why is it a concern?
- Regulators becoming less strict about enforcing consent requirements over time
- Users habitually accepting consent requests without reading them, undermining informed consent (Correct answer)
- Organizations exhausting their budget for consent management systems
- Data subjects withdrawing previously given consent en masse
Correct answer: Users habitually accepting consent requests without reading them, undermining informed consent
Consent fatigue occurs when users are presented with so many consent requests that they stop reading and simply click 'accept,' making consent less meaningful as a privacy protection.
Question 2: Under the FTC Act, what standard has the FTC used to regulate data privacy practices of US companies?
- Companies must comply with GDPR standards for all US consumers
- Unfair or deceptive acts or practices, including failing to honor stated privacy policies (Correct answer)
- All personal data collected must be encrypted using AES-256
- Companies must appoint a DPO if they process data on more than 500 individuals
Correct answer: Unfair or deceptive acts or practices, including failing to honor stated privacy policies
The FTC uses its Section 5 authority to take action against unfair or deceptive practices, including when companies violate their own privacy policies or fail to adequately protect consumer data.
Question 3: Which element is typically NOT included in a Data Processing Agreement (DPA) between a controller and processor?
- The subject matter and duration of processing
- The obligations and rights of the controller
- The processor's marketing strategy for the data (Correct answer)
- Security measures the processor must implement
Correct answer: The processor's marketing strategy for the data
DPAs under GDPR Article 28 must include processing scope, security measures, and rights/obligations, but a processor's marketing strategy for the data would violate the purpose limitation principle.
Question 4: What is the significance of 'chain of custody' documentation for records in legal proceedings?
- It proves the records were created by a licensed professional
- It establishes that records have been controlled and preserved without unauthorized alteration (Correct answer)
- It confirms records were stored in an approved government facility
- It demonstrates the records have been independently audited
Correct answer: It establishes that records have been controlled and preserved without unauthorized alteration
Chain of custody documentation tracks who had possession of records and what was done with them, establishing that the records were not tampered with and are admissible as evidence.
Question 5: An organization in California collects personal data from 80,000 consumers annually. Under CCPA, which obligation applies?
- The organization is exempt because it has fewer than 100,000 consumers
- The organization must provide notice, opt-out rights, and a privacy policy meeting CCPA requirements (Correct answer)
- The organization must obtain opt-in consent before collecting any data
- The organization must register with the California Attorney General
Correct answer: The organization must provide notice, opt-out rights, and a privacy policy meeting CCPA requirements
A business that buys, sells, receives, or shares the personal information of 100,000 or more consumers or households annually is subject to CCPA—80,000 alone may not trigger the threshold but combined factors could, and notice/opt-out requirements apply when thresholds are met.
Question 6: What does 'records appraisal' determine in an archival or records management context?
- The monetary insurance value of physical records
- The long-term historical, legal, fiscal, or administrative value of records to determine retention (Correct answer)
- Whether records are authentic originals or copies
- The security classification level of sensitive records
Correct answer: The long-term historical, legal, fiscal, or administrative value of records to determine retention
Records appraisal is the process of evaluating records to determine their value and how long they should be retained, balancing business, legal, and historical considerations.
Question 7: Which practice best supports 'privacy by design' in a new software system that processes personal data?
- Adding a privacy policy page to the system's help documentation after launch
- Embedding privacy controls and data minimization into the system's architecture from the start (Correct answer)
- Hiring a DPO to review the system after it is deployed
- Conducting an annual privacy audit once the system has been in production for one year
Correct answer: Embedding privacy controls and data minimization into the system's architecture from the start
Privacy by design requires integrating privacy protections into the system's architecture proactively from the earliest design stages rather than adding them afterward.
What is 'consent fatigue' in the context of data privacy, and why is it a concern?