PLC Privacy by Design & Technology Compliance 1 — Questions and Answers
Question 1: Who is credited with developing the 'Privacy by Design' (PbD) framework that has been widely adopted in global privacy law?
- Alan Westin
- Ann Cavoukian (Correct answer)
- Robert Gellman
- Paul Schwartz
Correct answer: Ann Cavoukian
Ann Cavoukian, former Information and Privacy Commissioner of Ontario, developed the Privacy by Design framework with its seven foundational principles.
Question 2: Which of the following is NOT one of the seven foundational principles of Privacy by Design?
- Proactive not reactive; preventive not remedial
- Privacy as the default setting
- Mandatory third-party audits at every design stage (Correct answer)
- Full functionality — positive-sum, not zero-sum
Correct answer: Mandatory third-party audits at every design stage
The seven PbD principles do not include mandatory third-party audits; they focus on embedding privacy proactively, by default, end-to-end, and with full functionality.
Question 3: Under GDPR Article 25, 'data protection by design and by default' requires controllers to implement appropriate technical measures at what point?
- Only before launching a new product to market
- At the time of determining means of processing AND at the time of processing itself (Correct answer)
- Only when processing special category data
- After completing a Data Protection Impact Assessment
Correct answer: At the time of determining means of processing AND at the time of processing itself
GDPR Article 25 requires controllers to implement privacy-protective measures both when designing the processing system and during the actual processing of personal data.
Question 4: What is 'data minimization' in the context of Privacy by Design?
- Deleting all data after 30 days
- Collecting only the minimum personal data necessary for the specified purpose (Correct answer)
- Storing data on the smallest possible servers
- Using compression to reduce data file sizes
Correct answer: Collecting only the minimum personal data necessary for the specified purpose
Data minimization means limiting personal data collection to what is strictly necessary for the stated purpose, reducing privacy risk by avoiding excess data.
Question 5: A company wants to analyze user behavior patterns without exposing individual identities. Which Privacy by Design technique BEST supports this goal?
- Full anonymization of all datasets used in analysis
- Data aggregation and statistical analysis at the group level (Correct answer)
- Storing raw data in encrypted form only
- Requiring user consent before any analysis
Correct answer: Data aggregation and statistical analysis at the group level
Aggregating data at the group level allows meaningful analysis while preventing re-identification of individuals, embodying the PbD principle of positive-sum functionality.
Question 6: Under the California Privacy Rights Act (CPRA), businesses must conduct cybersecurity audits and risk assessments when their processing poses what type of risk?
- Any risk involving more than 10,000 consumers
- Significant risk to consumers' privacy or security (Correct answer)
- Risk involving sensitive personal information only
- Risk to minors under age 16 only
Correct answer: Significant risk to consumers' privacy or security
The CPRA requires the California Privacy Protection Agency to establish regulations mandating audits and risk assessments for processing that poses significant privacy or security risks.
Who is credited with developing the 'Privacy by Design' (PbD) framework that has been widely adopted in global privacy law?