Privacy by Design & Technology Compliance Flashcards
6 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Privacy by Design & Technology Compliance flashcards as text
Who is credited with developing the 'Privacy by Design' (PbD) framework that has been widely adopted in global privacy law?
Answer: Ann Cavoukian
Ann Cavoukian, former Information and Privacy Commissioner of Ontario, developed the Privacy by Design framework with its seven foundational principles.
Which of the following is NOT one of the seven foundational principles of Privacy by Design?
Answer: Mandatory third-party audits at every design stage
The seven PbD principles do not include mandatory third-party audits; they focus on embedding privacy proactively, by default, end-to-end, and with full functionality.
Under GDPR Article 25, 'data protection by design and by default' requires controllers to implement appropriate technical measures at what point?
Answer: At the time of determining means of processing AND at the time of processing itself
GDPR Article 25 requires controllers to implement privacy-protective measures both when designing the processing system and during the actual processing of personal data.
What is 'data minimization' in the context of Privacy by Design?
Answer: Collecting only the minimum personal data necessary for the specified purpose
Data minimization means limiting personal data collection to what is strictly necessary for the stated purpose, reducing privacy risk by avoiding excess data.
A company wants to analyze user behavior patterns without exposing individual identities. Which Privacy by Design technique BEST supports this goal?
Answer: Data aggregation and statistical analysis at the group level
Aggregating data at the group level allows meaningful analysis while preventing re-identification of individuals, embodying the PbD principle of positive-sum functionality.
Under the California Privacy Rights Act (CPRA), businesses must conduct cybersecurity audits and risk assessments when their processing poses what type of risk?
Answer: Significant risk to consumers' privacy or security
The CPRA requires the California Privacy Protection Agency to establish regulations mandating audits and risk assessments for processing that poses significant privacy or security risks.