← All PLC Flashcard Decks

Mixed Deck — All PLC Topics Flashcards

100 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All PLC Topics flashcards as text
  1. What is the PRIMARY objective of legal research & case analysis in the Privacy Law field?

    Answer: To ensure adherence to established standards and protect stakeholders

    The primary objective of compliance and regulatory frameworks is to ensure adherence to standards that protect stakeholders.

  2. When facing an unfamiliar challenge in document preparation & filing within Privacy Law, what is the BEST approach?

    Answer: Research established best practices, consult colleagues, and document the approach

    Researching best practices and consulting colleagues combines established knowledge with practical experience, while documentation supports future reference.

  3. What makes consent valid under GDPR?

    Answer: Freely given and informed

    Under GDPR, valid consent must be freely given, specific, informed, and unambiguous. This means individuals must have a genuine choice without pressure, understand exactly what they are consenting to, and provide a clear affirmative action. Bundled consent or assumed consent is generally not considered valid, ensuring the individual's true intent.

  4. Under GDPR, data must be accurate and kept up to date. Which principle does this reflect?

    Answer: Accuracy

    The accuracy principle under GDPR mandates that personal data must be accurate and, where necessary, kept up to date. This ensures that decisions made about individuals are based on correct information and prevents harm that could arise from processing outdated or incorrect data. Organizations are responsible for taking reasonable steps to ensure data integrity.

  5. Which action BEST demonstrates a commitment to regulatory frameworks & compliance in Privacy Law?

    Answer: Maintaining current knowledge of all applicable regulations and standards

    Actively maintaining current knowledge of applicable regulations demonstrates genuine commitment to compliance and helps prevent violations.

  6. Which of the following best describes 'notification fatigue' and its relevance to breach response?

    Answer: Consumers becoming desensitized to breach notices, reducing protective action

    Notification fatigue refers to consumers becoming so accustomed to breach notices that they fail to take protective actions, undermining the consumer-protection purpose of notification laws.

  7. GPS tracking installed on an employee-owned personal vehicle used for work is:

    Answer: Generally impermissible without the employee's explicit consent

    Tracking employee-owned vehicles raises significant privacy concerns, and most jurisdictions require explicit employee consent; employers have broader latitude with company-owned vehicles.

  8. Who is credited with developing the 'Privacy by Design' (PbD) framework that has been widely adopted in global privacy law?

    Answer: Ann Cavoukian

    Ann Cavoukian, former Information and Privacy Commissioner of Ontario, developed the Privacy by Design framework with its seven foundational principles.

  9. An organization's incident response plan (IRP) should be tested using tabletop exercises at minimum how often, according to NIST SP 800-61 guidance?

    Answer: Annually

    NIST SP 800-61 recommends that incident response plans be reviewed and tested at least annually to ensure effectiveness and currency.

  10. What is the purpose of a 'post-mortem' or 'lessons learned' meeting after a data breach incident?

    Answer: To identify what worked, what failed, and how to improve future response

    Post-incident reviews identify gaps in preparation, response, and recovery to strengthen the organization's future incident handling capabilities.

  11. Under the concept of 'Privacy by Default,' what should the default settings of a new application be configured to?

    Answer: The most privacy-protective settings, requiring users to opt in for additional sharing

    Privacy by Default means that without any action by the user, only the minimum necessary data is processed, and the strictest privacy settings are active out of the box.

  12. Which action BEST demonstrates a commitment to ethics & professional responsibility in Privacy Law?

    Answer: Maintaining current knowledge of all applicable regulations and standards

    Actively maintaining current knowledge of applicable regulations demonstrates genuine commitment to compliance and helps prevent violations.

  13. Which technique involves replacing direct identifiers (like names or SSNs) with artificial identifiers while retaining the ability to re-identify the data?

    Answer: Pseudonymization

    Pseudonymization replaces identifying fields with artificial identifiers while keeping a separate key that enables re-identification, unlike full anonymization which is irreversible.

  14. Which document outlines internal rules for cross-border data transfers within multinational companies?

    Answer: Binding Corporate Rules

    Binding Corporate Rules (BCRs) are a set of internal, legally binding rules adopted by multinational corporations to govern their transfers of personal data from the EU/EEA to their entities located outside the EU/EEA. They serve as a robust mechanism to ensure that all intra-group data transfers comply with GDPR standards, especially when no adequacy decision exists for the recipient country. BCRs are approved by data protection authorities and provide a comprehensive framework for data protection within a corporate group.

  15. What is the primary privacy concern with 'cookie walls' — requiring users to accept all cookies or be denied access to a website?

    Answer: They undermine the freely given nature of consent required by GDPR and state laws

    Regulators have found that cookie walls coerce consent, making it not 'freely given' as required by GDPR and similar state privacy laws, because users have no real choice.

  16. What did the Schrems II ruling invalidate?

    Answer: Privacy Shield

    The Schrems II ruling by the Court of Justice of the European Union (CJEU) invalidated the EU-U.S. Privacy Shield framework. The court found that the protections offered by the Privacy Shield for EU data subjects' data transferred to the U.S. were insufficient, particularly concerning U.S. government surveillance programs. This decision significantly impacted transatlantic data transfers and emphasized the need for robust safeguards.

  17. Which of the following is NOT one of the seven foundational principles of Privacy by Design?

    Answer: Mandatory third-party audits at every design stage

    The seven PbD principles do not include mandatory third-party audits; they focus on embedding privacy proactively, by default, end-to-end, and with full functionality.

  18. In Privacy Law, how does contract review & negotiation contribute to professional credibility?

    Answer: By demonstrating competence, maintaining standards, and delivering consistent results

    Professional credibility is built through demonstrated competence, consistent adherence to standards, and reliable delivery of quality results.

  19. Which user right involves correction of inaccurate personal data?

    Answer: Right to rectification

    The Right to Rectification allows individuals to request that inaccurate personal data concerning them be corrected without undue delay. If the data is incomplete, they also have the right to have it completed, taking into account the purposes of the processing. This ensures the accuracy and fairness of personal information, preventing harm from incorrect data.

  20. A company wants to analyze user behavior patterns without exposing individual identities. Which Privacy by Design technique BEST supports this goal?

    Answer: Data aggregation and statistical analysis at the group level

    Aggregating data at the group level allows meaningful analysis while preventing re-identification of individuals, embodying the PbD principle of positive-sum functionality.