Privacy Law Certification (PLC) — Questions and Answers
Question 1: Which of the following is NOT one of the seven foundational principles of Privacy by Design?
- Privacy as the default setting
- Mandatory third-party audits at every design stage (Correct answer)
- Full functionality — positive-sum, not zero-sum
- Proactive not reactive; preventive not remedial
Correct answer: Mandatory third-party audits at every design stage
The seven PbD principles do not include mandatory third-party audits; they focus on embedding privacy proactively, by default, end-to-end, and with full functionality.
Question 2: In Privacy Law, what is the MOST appropriate response when a potential compliance violation is discovered?
- Report it immediately through established channels and document findings (Correct answer)
- Wait to see if the violation causes harm before reporting
- Address it only if a supervisor specifically asks about it
- Discuss it informally without documentation
Correct answer: Report it immediately through established channels and document findings
Immediate reporting through established channels with proper documentation ensures timely resolution and maintains the integrity of the compliance program.
Question 3: Which of the following is NOT typically required in a state breach notification letter to affected individuals?
- Description of what happened
- The name of the employee responsible for the breach (Correct answer)
- Types of information involved
- Contact information for further inquiries
Correct answer: The name of the employee responsible for the breach
State breach notification laws do not require naming the responsible employee; they require a description of the incident, data types involved, and remediation steps.
Question 4: Which right involves receiving personal data in a machine-readable format?
- Right to object
- Right to data portability (Correct answer)
- Right to access
- Right to erasure
Correct answer: Right to data portability
The Right to Data Portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It enables them to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller without hindrance. This promotes competition and user control over their digital footprint.
Question 5: Which user right involves correction of inaccurate personal data?
- Right to restrict processing
- Right to portability
- Right to erasure
- Right to rectification (Correct answer)
Correct answer: Right to rectification
The Right to Rectification allows individuals to request that inaccurate personal data concerning them be corrected without undue delay. If the data is incomplete, they also have the right to have it completed, taking into account the purposes of the processing. This ensures the accuracy and fairness of personal information, preventing harm from incorrect data.
Question 6: What does the term 'safe harbor' mean in the context of US data breach notification laws?
- A federal preemption of state notification requirements
- An exemption from notification if the breached data was encrypted (Correct answer)
- A limit on damages available in breach lawsuits
- A grace period before notification must occur
Correct answer: An exemption from notification if the breached data was encrypted
Most US state breach notification laws provide a safe harbor exempting organizations from notification obligations when the exposed data was encrypted and the encryption key was not also compromised.
Question 7: What principle requires that personal data be collected for specified, legitimate purposes?
- Purpose limitation (Correct answer)
- Data minimization
- Accountability
- Accuracy
Correct answer: Purpose limitation
The principle of purpose limitation requires that personal data be collected for specified, explicit, and legitimate purposes. This means organizations cannot collect data for one reason and then use it for unrelated purposes without further justification or consent. It ensures transparency and prevents the arbitrary use of personal information.
Question 8: What is required for consent to be valid under privacy regulations?
- Requested after processing
- Freely given and informed (Correct answer)
- Given automatically
- Implied by default
Correct answer: Freely given and informed
For consent to be valid under privacy regulations like GDPR, it must be freely given, specific, informed, and unambiguous. 'Freely given' means without coercion, and 'informed' means the individual understands what they are consenting to, including the purpose of processing and their right to withdraw. This ensures genuine choice and control for the individual over their data.
Question 9: Which competency is MOST essential for professionals working in dispute resolution & mediation in Privacy Law?
- Memorization of procedures without understanding principles
- Critical thinking combined with practical application of knowledge (Correct answer)
- Speed of task completion above all else
- Seniority-based decision making
Correct answer: Critical thinking combined with practical application of knowledge
Critical thinking allows professionals to apply knowledge effectively in varied situations, leading to better outcomes than rote procedures.
Question 10: Which action BEST demonstrates a commitment to legal research & case analysis in Privacy Law?
- Relying on colleagues to interpret regulatory requirements
- Maintaining current knowledge of all applicable regulations and standards (Correct answer)
- Addressing compliance issues only when audited
- Following only the regulations that are convenient
Correct answer: Maintaining current knowledge of all applicable regulations and standards
Actively maintaining current knowledge of applicable regulations demonstrates genuine commitment to compliance and helps prevent violations.
Question 11: Which US state was the FIRST to enact a data breach notification law, creating a model that most other states subsequently followed?
- Texas
- California (Correct answer)
- Massachusetts
- New York
Correct answer: California
California enacted the first US state data breach notification law (SB 1386) in 2002, which became the template for nearly all subsequent state laws.
Question 12: Employer workplace monitoring policies are most legally defensible when they:
- Are limited exclusively to monitoring activities outside business hours
- Target only employees currently under performance improvement plans
- Are disclosed in writing and employees are notified before monitoring begins (Correct answer)
- Are implemented secretly to detect policy violations without alerting employees
Correct answer: Are disclosed in writing and employees are notified before monitoring begins
Transparent monitoring policies that are disclosed in writing and communicated to employees before implementation are most legally defensible and reduce exposure to privacy claims.
Question 13: In Privacy Law, how does dispute resolution & mediation contribute to professional credibility?
- By avoiding challenging situations
- By demonstrating competence, maintaining standards, and delivering consistent results (Correct answer)
- Through the number of years in practice alone
- By using impressive terminology
Correct answer: By demonstrating competence, maintaining standards, and delivering consistent results
Professional credibility is built through demonstrated competence, consistent adherence to standards, and reliable delivery of quality results.
Question 14: Under the Electronic Communications Privacy Act (ECPA), which exception allows employers to monitor employee communications on company-owned networks without employee consent?
- Emergency exception
- Law enforcement exception
- Provider exception (Correct answer)
- Business necessity exception
Correct answer: Provider exception
The provider exception allows employers who own and operate the communication system to monitor its use without needing employee consent.
Question 15: What is 'differential privacy,' and how is it used by companies like Apple and Google?
- A mathematical technique adding statistical noise to datasets so individual data cannot be inferred (Correct answer)
- A method of distinguishing between different categories of personal data
- An encryption standard for differentiating internal vs. external data flows
- A policy of treating different user groups with different privacy protections
Correct answer: A mathematical technique adding statistical noise to datasets so individual data cannot be inferred
Differential privacy adds calibrated statistical noise to query results so that the presence or absence of any individual's data cannot be determined from the output.
Question 16: Which of the following best describes 'privacy theater' — a concept privacy professionals must help organizations avoid?
- Implementing visible but ineffective privacy measures that create a false appearance of compliance (Correct answer)
- Staging mock privacy audits for employee training
- Theatrical presentations used in privacy awareness training
- Public advocacy campaigns promoting consumer privacy rights
Correct answer: Implementing visible but ineffective privacy measures that create a false appearance of compliance
Privacy theater refers to cosmetic compliance measures — like dense privacy policies or cookie banners — that appear protective but do not meaningfully reduce privacy risks or respect user rights.
Question 17: When facing an unfamiliar challenge in contract review & negotiation within Privacy Law, what is the BEST approach?
- Apply the most familiar technique regardless of suitability
- Avoid the challenge if possible
- Research established best practices, consult colleagues, and document the approach (Correct answer)
- Attempt to resolve it independently without consultation
Correct answer: Research established best practices, consult colleagues, and document the approach
Researching best practices and consulting colleagues combines established knowledge with practical experience, while documentation supports future reference.
Question 18: When facing an unfamiliar challenge in document preparation & filing within Privacy Law, what is the BEST approach?
- Avoid the challenge if possible
- Research established best practices, consult colleagues, and document the approach (Correct answer)
- Attempt to resolve it independently without consultation
- Apply the most familiar technique regardless of suitability
Correct answer: Research established best practices, consult colleagues, and document the approach
Researching best practices and consulting colleagues combines established knowledge with practical experience, while documentation supports future reference.
Question 19: Which of the following is NOT a requirement for an adequacy decision?
- Political alignment with EU (Correct answer)
- Rule of law and data protection safeguards
- Existence of supervisory authorities
- International commitments
Correct answer: Political alignment with EU
When the European Commission assesses a non-EU country for an adequacy decision, it primarily focuses on the country's data protection laws, the existence of independent supervisory authorities, and its international commitments regarding human rights and data protection. While political relations might exist, "political alignment with EU" is not a formal criterion for determining an adequate level of data protection. The assessment is strictly based on the legal framework and practical safeguards for personal data.
Question 20: Which is a lawful basis for data transfer under GDPR when no adequacy decision exists?
- Safe Harbor
- Binding Corporate Rules (Correct answer)
- Global Certification
- Privacy Consent Shield
Correct answer: Binding Corporate Rules
Binding Corporate Rules (BCRs) are internal codes of conduct approved by data protection authorities that allow multinational companies to transfer personal data internationally within their corporate group. They provide a robust legal framework for data transfers to countries without an adequacy decision, ensuring all entities within the group adhere to the same high standards of data protection. BCRs are a complex but effective mechanism for intra-group transfers.
Question 21: In Privacy Law, what is the MOST appropriate response when a potential compliance violation is discovered?
- Wait to see if the violation causes harm before reporting
- Address it only if a supervisor specifically asks about it
- Discuss it informally without documentation
- Report it immediately through established channels and document findings (Correct answer)
Correct answer: Report it immediately through established channels and document findings
Immediate reporting through established channels with proper documentation ensures timely resolution and maintains the integrity of the compliance program.
Question 22: Which element is CRITICAL for maintaining proficiency in courtroom procedures & protocols within Privacy Law?
- Performing techniques only when absolutely necessary
- Regular practice with ongoing professional development and skill updates (Correct answer)
- Learning from informal sources without verification
- Initial certification alone without continuing education
Correct answer: Regular practice with ongoing professional development and skill updates
Maintaining proficiency requires regular practice combined with ongoing professional development to stay current with evolving best practices.
Question 23: Which competency is MOST essential for professionals working in contract review & negotiation in Privacy Law?
- Memorization of procedures without understanding principles
- Seniority-based decision making
- Critical thinking combined with practical application of knowledge (Correct answer)
- Speed of task completion above all else
Correct answer: Critical thinking combined with practical application of knowledge
Critical thinking allows professionals to apply knowledge effectively in varied situations, leading to better outcomes than rote procedures.
Question 24: Which of the following is a potential penalty under the CCPA for intentional violations?
- $10,000 per violation
- $5,000 per violation
- $7,500 per violation (Correct answer)
- $2,500 per violation
Correct answer: $7,500 per violation
The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), specify penalties for violations. For intentional violations, the California Attorney General can impose civil penalties of up to $7,500 per violation. For unintentional violations, the penalty is $2,500 per violation, provided the business fails to cure the violation within 30 days after being notified.
Question 25: Which element is ESSENTIAL for an effective legal research & case analysis program in Privacy Law?
- Regular audits and continuous monitoring processes (Correct answer)
- Documentation stored without regular updates
- Annual review without interim checks
- Compliance responsibility assigned to one individual only
Correct answer: Regular audits and continuous monitoring processes
Regular audits and continuous monitoring enable early detection of compliance gaps and ensure ongoing adherence to standards.
Question 26: A breach notification to a state Attorney General is typically triggered when the number of affected state residents exceeds what threshold under most state laws?
- 100 residents
- 500 residents
- 1,000 residents
- Threshold varies; some states require notification regardless of number (Correct answer)
Correct answer: Threshold varies; some states require notification regardless of number
Most state breach notification laws require AG notification when the breach exceeds 500 or 1,000 residents, but thresholds vary widely by state and some states have no minimum.
Question 27: What is a risk of non-compliance in cross-border data transfers?
- No business impact
- Verbal warning
- Fines and legal actions (Correct answer)
- License revocation only
Correct answer: Fines and legal actions
Non-compliance with cross-border data transfer regulations, such as those under GDPR, carries significant risks for organizations. These risks include substantial administrative fines, which can be millions of euros or a percentage of global annual turnover, as well as legal actions from supervisory authorities or data subjects. Additionally, non-compliance can lead to reputational damage and a loss of customer trust.
Question 28: Which of the following employee records is generally NOT subject to heightened confidentiality requirements under U.S. federal privacy law?
- Genetic test results disclosed to an employer
- Performance review ratings shared through normal HR management processes (Correct answer)
- Workers' compensation claim details and related medical information
- Medical examination results obtained during employment
Correct answer: Performance review ratings shared through normal HR management processes
Performance review ratings shared within normal HR and management processes are not subject to the same heightened confidentiality protections that apply to medical, genetic, or workers' compensation information.
Question 29: Which US federal law specifically governs the privacy of video rental and streaming records, and what does it prohibit?
- ECPA — prohibits warrantless interception of electronic communications
- FCRA — prohibits using viewing history in credit decisions
- COPPA — prohibits collecting viewing history from children under 13
- VPPA — prohibits disclosure of video viewing records without consent (Correct answer)
Correct answer: VPPA — prohibits disclosure of video viewing records without consent
The Video Privacy Protection Act (VPPA) prohibits video service providers from knowingly disclosing personally identifiable information about consumers' video rental or streaming choices without consent.
Question 30: What makes consent valid under GDPR?
- Bundled with terms and conditions
- Freely given and informed (Correct answer)
- Assumed unless objected
- Requested after processing
Correct answer: Freely given and informed
Under GDPR, valid consent must be freely given, specific, informed, and unambiguous. This means individuals must have a genuine choice without pressure, understand exactly what they are consenting to, and provide a clear affirmative action. Bundled consent or assumed consent is generally not considered valid, ensuring the individual's true intent.
Question 31: When an employee is terminated, privacy best practices require the employer to:
- Transfer all employee records to a third-party vendor for indefinite storage
- Limit disclosure of termination reasons and follow data retention policies for personal information (Correct answer)
- Retain all employee personal data indefinitely to prepare for potential litigation
- Immediately inform all coworkers of the specific reason for termination
Correct answer: Limit disclosure of termination reasons and follow data retention policies for personal information
Upon termination, employers should limit disclosure of termination reasons to reduce defamation exposure and follow established data retention and destruction policies to protect the former employee's personal information.
Question 32: Which document typically outlines how and why user data is collected and used?
- Terms of service
- Privacy policy (Correct answer)
- Security notice
- Cookie banner
Correct answer: Privacy policy
A privacy policy is a legal document that explicitly informs users about how an organization collects, uses, stores, and protects their personal data. It details the types of data gathered, the purposes for collection, data sharing practices, and user rights regarding their information. This transparency is crucial for compliance with data protection laws and building user trust.
Question 33: What consequence can result from failing to maintain proper ethics & professional responsibility standards in Privacy Law?
- Lower training requirements
- Increased customer satisfaction
- Loss of certification, legal penalties, and reputational damage (Correct answer)
- Reduced workload for staff
Correct answer: Loss of certification, legal penalties, and reputational damage
Non-compliance can result in serious consequences including certification revocation, legal penalties, fines, and significant reputational damage.
Question 34: Which term describes the process of preserving digital evidence in a forensically sound manner following a data breach?
- Privilege log
- Chain of custody (Correct answer)
- Data minimization
- Litigation hold
Correct answer: Chain of custody
Chain of custody refers to the documented process of collecting, preserving, and handling digital evidence so it remains admissible and unaltered.
Question 35: When facing an unfamiliar challenge in dispute resolution & mediation within Privacy Law, what is the BEST approach?
- Research established best practices, consult colleagues, and document the approach (Correct answer)
- Avoid the challenge if possible
- Attempt to resolve it independently without consultation
- Apply the most familiar technique regardless of suitability
Correct answer: Research established best practices, consult colleagues, and document the approach
Researching best practices and consulting colleagues combines established knowledge with practical experience, while documentation supports future reference.
Question 36: In Privacy Law, which factor MOST influences the selection of appropriate courtroom procedures & protocols?
- Cost as the sole determining factor
- The most recently developed technique only
- The specific requirements and constraints of the situation (Correct answer)
- Personal preference of the practitioner
Correct answer: The specific requirements and constraints of the situation
The specific requirements and constraints of each situation should drive technique selection to ensure the most effective and appropriate approach.
Question 37: What is the PRIMARY benefit of documenting courtroom procedures & protocols in Privacy Law?
- Protecting against client complaints only
- Meeting minimum paperwork requirements
- Reducing the workload for future practitioners
- Creating a reference for quality assurance, training, and continuous improvement (Correct answer)
Correct answer: Creating a reference for quality assurance, training, and continuous improvement
Documentation serves multiple purposes including quality assurance, training resources, and a foundation for continuous improvement.
Question 38: What is the MOST important consideration when applying courtroom procedures & protocols in Privacy Law?
- Relying solely on personal experience without referencing standards
- Following established protocols while adapting to specific circumstances (Correct answer)
- Using the same approach for every situation regardless of context
- Prioritizing speed over accuracy
Correct answer: Following established protocols while adapting to specific circumstances
Following established protocols ensures consistency and safety, while adapting to specific circumstances accounts for unique variables in each situation.
Question 39: Under the GDPR (applicable to US companies with EU data subjects), a personal data breach must be reported to the supervisory authority within how many hours of becoming aware?
- 72 hours (Correct answer)
- 96 hours
- 48 hours
- 24 hours
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Question 40: Under HIPAA, when a breach affects 500 or more individuals in a single state or jurisdiction, covered entities must also notify:
- The HHS Office for Civil Rights within 60 days and prominent local media outlets (Correct answer)
- Only the affected individuals — no media or HHS notification required
- The FBI Cyber Division within 30 days
- The FTC and HHS simultaneously within 72 hours
Correct answer: The HHS Office for Civil Rights within 60 days and prominent local media outlets
HIPAA requires that breaches affecting 500+ individuals in a jurisdiction be reported to HHS-OCR within 60 days and to prominent media outlets in that jurisdiction.
Question 41: An organization's incident response plan (IRP) should be tested using tabletop exercises at minimum how often, according to NIST SP 800-61 guidance?
- Monthly
- Annually (Correct answer)
- Quarterly
- Every two years
Correct answer: Annually
NIST SP 800-61 recommends that incident response plans be reviewed and tested at least annually to ensure effectiveness and currency.
Question 42: In Privacy Law, how does document preparation & filing contribute to professional credibility?
- By using impressive terminology
- By demonstrating competence, maintaining standards, and delivering consistent results (Correct answer)
- Through the number of years in practice alone
- By avoiding challenging situations
Correct answer: By demonstrating competence, maintaining standards, and delivering consistent results
Professional credibility is built through demonstrated competence, consistent adherence to standards, and reliable delivery of quality results.
Question 43: A company discovers that an employee accidentally emailed a spreadsheet containing 500 customers' Social Security numbers to the wrong recipient. What is the FIRST step in proper incident response?
- Immediately notify all 500 affected customers
- Contain the incident and assess its scope (Correct answer)
- File a police report
- Notify the FTC within 24 hours
Correct answer: Contain the incident and assess its scope
Incident response best practice dictates that containment and assessment of scope must occur first before notifications or external reporting.
Question 44: Under FTC Act Section 5, failure to maintain reasonable security measures that leads to a data breach can be considered:
- A criminal offense requiring DOJ prosecution
- A violation only if negligence is proven
- An unfair or deceptive trade practice (Correct answer)
- A strict liability tort
Correct answer: An unfair or deceptive trade practice
The FTC has consistently held that inadequate data security practices that result in consumer harm constitute unfair or deceptive acts or practices under FTC Act Section 5.
Question 45: In Privacy Law, how does contract review & negotiation contribute to professional credibility?
- By demonstrating competence, maintaining standards, and delivering consistent results (Correct answer)
- Through the number of years in practice alone
- By avoiding challenging situations
- By using impressive terminology
Correct answer: By demonstrating competence, maintaining standards, and delivering consistent results
Professional credibility is built through demonstrated competence, consistent adherence to standards, and reliable delivery of quality results.
Question 46: Data integrity & confidentiality fall under which data processing principle?
- Integrity & confidentiality (Correct answer)
- Minimization
- Lawfulness
- Transparency
Correct answer: Integrity & confidentiality
The principle of integrity and confidentiality, often referred to as 'security,' mandates that personal data be processed in a manner that ensures appropriate security. This includes protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using suitable technical or organizational measures. It safeguards data from breaches and ensures its trustworthiness.
Question 47: Transparency in data collection ensures that:
- Data is hidden from users
- Individuals know how their data is used (Correct answer)
- Organizations collect data anonymously
- Consent is optional
Correct answer: Individuals know how their data is used
Transparency in data collection ensures that individuals are clearly informed about what data is being collected, why it's being collected, how it will be used, and who it will be shared with. This empowers individuals to make informed decisions about their personal data and exercise their rights. It builds trust and promotes fair and lawful processing.
Question 48: An organization's breach response team should include representatives from which departments to be most effective?
- IT Security and Legal only
- Legal, IT Security, Communications, and Executive Leadership (Correct answer)
- Legal, IT Security, and HR only
- Privacy, IT Security, and Finance only
Correct answer: Legal, IT Security, Communications, and Executive Leadership
Effective breach response requires coordination among Legal (liability/notification), IT Security (containment/forensics), Communications (PR/messaging), and Executive Leadership (decisions/resources).
Question 49: How does ongoing professional development support regulatory frameworks & compliance in Privacy Law?
- It keeps professionals informed of evolving standards and best practices (Correct answer)
- It only benefits entry-level professionals
- It is irrelevant to compliance outcomes
- It replaces the need for formal compliance audits
Correct answer: It keeps professionals informed of evolving standards and best practices
Ongoing professional development ensures that practitioners stay current with evolving regulations, standards, and best practices in their field.
Question 50: When addressing difficult situations through client communication & advocacy in Privacy Law, what strategy is BEST?
- Acknowledging concerns, providing clear information, and offering solutions (Correct answer)
- Minimizing the significance of the issue
- Avoiding the conversation until the situation resolves itself
- Responding defensively to protect professional reputation
Correct answer: Acknowledging concerns, providing clear information, and offering solutions
Acknowledging concerns validates the other party experience, clear information builds trust, and offering solutions demonstrates commitment to resolution.
Question 51: What role does documentation play in client communication & advocacy within Privacy Law?
- It is optional and rarely reviewed
- It is only needed for legal protection
- It replaces the need for verbal communication
- It ensures continuity, accountability, and serves as a reference for all parties (Correct answer)
Correct answer: It ensures continuity, accountability, and serves as a reference for all parties
Proper documentation ensures continuity of care or service, establishes accountability, and provides a reliable reference for all involved parties.
Question 52: Under the California Consumer Privacy Act (CCPA), businesses that suffer a data breach exposing consumers' unencrypted personal information may face statutory damages of how much per consumer, per incident?
- $100 to $750 (Correct answer)
- $250 to $2,500
- $1,000 to $10,000
- $500 to $5,000
Correct answer: $100 to $750
The CCPA allows affected consumers to seek statutory damages between $100 and $750 per consumer per incident for data breaches of unencrypted personal information.
Question 53: Which of the following is a legal basis for processing personal data under GDPR?
- Data portability
- Consent (Correct answer)
- Right to object
- Public availability
Correct answer: Consent
Under GDPR, consent is one of the primary legal bases for processing personal data. It means individuals have given clear, affirmative permission for their data to be processed for specific purposes. Other legal bases include contractual necessity, legal obligation, vital interests, public task, and legitimate interests, but consent empowers individuals with direct control.
Question 54: Which entity evaluates whether a non-EU country provides adequate protection?
- European Commission (Correct answer)
- Supervisory Authority
- Data Protection Officer
- European Parliament
Correct answer: European Commission
The European Commission is the executive arm of the European Union and is responsible for assessing whether a non-EU country provides an "adequate level of data protection." An adequacy decision means that personal data can flow from the EU/EEA to that third country without needing additional safeguards. This assessment considers the country's domestic law, international commitments, and the existence of independent supervisory authorities.
Question 55: What is the primary privacy concern with 'cookie walls' — requiring users to accept all cookies or be denied access to a website?
- They undermine the freely given nature of consent required by GDPR and state laws (Correct answer)
- They are prohibited by the CFPB's consumer financial protection rules
- They violate CCPA's right to opt out of sale
- They create ADA accessibility violations
Correct answer: They undermine the freely given nature of consent required by GDPR and state laws
Regulators have found that cookie walls coerce consent, making it not 'freely given' as required by GDPR and similar state privacy laws, because users have no real choice.
Question 56: Under GDPR, data must be accurate and kept up to date. Which principle does this reflect?
- Accuracy (Correct answer)
- Security
- Accountability
- Data integrity
Correct answer: Accuracy
The accuracy principle under GDPR mandates that personal data must be accurate and, where necessary, kept up to date. This ensures that decisions made about individuals are based on correct information and prevents harm that could arise from processing outdated or incorrect data. Organizations are responsible for taking reasonable steps to ensure data integrity.
Question 57: How can client communication & advocacy be improved in a Privacy Law setting?
- Eliminating face-to-face interactions
- Reducing the frequency of communications
- Standardizing all messages without personalization
- Regular feedback mechanisms and training in communication skills (Correct answer)
Correct answer: Regular feedback mechanisms and training in communication skills
Regular feedback mechanisms identify communication gaps while training develops the skills needed to address them effectively.
Question 58: Which right allows individuals to request a copy of their personal data?
- Right to object
- Right to rectify
- Right to access (Correct answer)
- Right to be informed
Correct answer: Right to access
The Right to Access allows individuals to obtain confirmation as to whether their personal data is being processed, and if so, to access that data and supplementary information. This empowers individuals to understand what information an organization holds about them and how it is being used. It is a fundamental right for data subjects to maintain control over their personal information.
Question 59: What is the PRIMARY objective of legal research & case analysis in the Privacy Law field?
- To create additional paperwork for professionals
- To limit the scope of professional practice
- To ensure adherence to established standards and protect stakeholders (Correct answer)
- To increase operational costs for organizations
Correct answer: To ensure adherence to established standards and protect stakeholders
The primary objective of compliance and regulatory frameworks is to ensure adherence to standards that protect stakeholders.
Question 60: When learning new courtroom procedures & protocols in Privacy Law, which approach is MOST effective?
- Observing others without ever performing the techniques
- Learning theory only without hands-on practice
- Practicing without understanding underlying principles
- Combining theoretical study with supervised practical application (Correct answer)
Correct answer: Combining theoretical study with supervised practical application
The combination of theoretical knowledge and supervised practical application provides the deepest understanding and develops competent practitioners.
Question 61: Before disciplining an employee based on social media activity discovered through employer monitoring, the employer must first:
- Obtain a signed acknowledgment from the employee about the monitored activity
- Report the findings to the Department of Labor within 30 days
- Publish the findings in an internal compliance report
- Evaluate whether the activity constitutes protected concerted activity under the NLRA (Correct answer)
Correct answer: Evaluate whether the activity constitutes protected concerted activity under the NLRA
Employers must evaluate whether social media activity involves protected concerted activity under the NLRA before taking disciplinary action, as doing so otherwise could be an unfair labor practice.
Question 62: Under the California Privacy Rights Act (CPRA), businesses must conduct cybersecurity audits and risk assessments when their processing poses what type of risk?
- Any risk involving more than 10,000 consumers
- Risk to minors under age 16 only
- Risk involving sensitive personal information only
- Significant risk to consumers' privacy or security (Correct answer)
Correct answer: Significant risk to consumers' privacy or security
The CPRA requires the California Privacy Protection Agency to establish regulations mandating audits and risk assessments for processing that poses significant privacy or security risks.
Question 63: What did the Schrems II ruling invalidate?
- Safe Harbor Agreement
- GDPR
- Privacy Shield (Correct answer)
- Standard Contractual Clauses
Correct answer: Privacy Shield
The Schrems II ruling by the Court of Justice of the European Union (CJEU) invalidated the EU-U.S. Privacy Shield framework. The court found that the protections offered by the Privacy Shield for EU data subjects' data transferred to the U.S. were insufficient, particularly concerning U.S. government surveillance programs. This decision significantly impacted transatlantic data transfers and emphasized the need for robust safeguards.
Question 64: The National Labor Relations Act (NLRA) protects employees' rights to discuss which of the following with coworkers?
- Trade secrets and proprietary formulas
- Company financial projections not yet disclosed publicly
- Confidential client information
- Wages, hours, and working conditions (Correct answer)
Correct answer: Wages, hours, and working conditions
The NLRA protects concerted activity, including employees' rights to discuss wages, hours, and working conditions among themselves, and employer policies restricting such discussion may be unlawful.
Question 65: What is required before processing personal data under consent basis?
- Implied through use
- Pre-checked boxes
- Passive browsing
- Explicit opt-in (Correct answer)
Correct answer: Explicit opt-in
For consent to be valid under GDPR, it generally requires an explicit opt-in, meaning individuals must take a clear, affirmative action to indicate their agreement. Pre-checked boxes, passive browsing, or implied consent are typically not sufficient. This ensures that consent is unambiguous and genuinely reflects the individual's informed choice, giving them true control.
Question 66: What is the PRIMARY objective of document preparation & filing within the Privacy Law profession?
- To limit the scope of professional activities
- To create additional requirements for practitioners
- To maintain the status quo without change
- To ensure quality outcomes through standardized practices and continuous improvement (Correct answer)
Correct answer: To ensure quality outcomes through standardized practices and continuous improvement
The primary objective is ensuring quality outcomes through established standards while continuously improving practices and processes.
Question 67: Which U.S. agency is primarily responsible for enforcing consumer privacy laws?
- Consumer Financial Protection Bureau (CFPB)
- Federal Communications Commission (FCC)
- Federal Trade Commission (FTC) (Correct answer)
- Department of Justice (DOJ)
Correct answer: Federal Trade Commission (FTC)
In the United States, the Federal Trade Commission (FTC) is the primary agency responsible for enforcing consumer privacy laws. The FTC uses its authority under Section 5 of the FTC Act, which prohibits unfair and deceptive practices, to take action against companies that fail to protect consumer data or misrepresent their privacy practices. It also enforces specific privacy laws like COPPA (Children's Online Privacy Protection Act).
Question 68: GPS tracking installed on an employee-owned personal vehicle used for work is:
- Regulated exclusively by federal transportation law
- Always permissible once disclosed in a company vehicle policy
- Generally impermissible without the employee's explicit consent (Correct answer)
- Unrestricted by privacy law during scheduled working hours
Correct answer: Generally impermissible without the employee's explicit consent
Tracking employee-owned vehicles raises significant privacy concerns, and most jurisdictions require explicit employee consent; employers have broader latitude with company-owned vehicles.
Question 69: Which principle gives users the ability to withdraw consent at any time?
- Right to object
- Right to be informed
- Right to portability
- Right to withdraw consent (Correct answer)
Correct answer: Right to withdraw consent
A fundamental aspect of valid consent under privacy laws like GDPR is that individuals must have the right to withdraw their consent at any time. This means that if they initially agreed to data processing, they can later revoke that permission, and the organization must cease processing their data based on that consent. This ensures ongoing control over personal information.
Question 70: Which of the following best describes 'notification fatigue' and its relevance to breach response?
- Legal teams growing tired of drafting notification letters
- Systems slowing down when processing large batches of notifications
- Consumers becoming desensitized to breach notices, reducing protective action (Correct answer)
- Regulators becoming lenient after repeated breaches
Correct answer: Consumers becoming desensitized to breach notices, reducing protective action
Notification fatigue refers to consumers becoming so accustomed to breach notices that they fail to take protective actions, undermining the consumer-protection purpose of notification laws.
Question 71: What must organizations do before transferring data using SCCs?
- Use Privacy Shield
- Notify the European Commission
- Obtain ISO certification
- Conduct a Transfer Impact Assessment (Correct answer)
Correct answer: Conduct a Transfer Impact Assessment
Following the Schrems II ruling, organizations using Standard Contractual Clauses (SCCs) are now required to conduct a Transfer Impact Assessment (TIA). This assessment evaluates whether the laws and practices of the recipient country might undermine the protections guaranteed by the SCCs, particularly regarding government access to data. If risks are identified, supplementary measures must be implemented to ensure an equivalent level of protection for the transferred data.
Question 72: What is the PRIMARY objective of regulatory frameworks & compliance in the Privacy Law field?
- To increase operational costs for organizations
- To ensure adherence to established standards and protect stakeholders (Correct answer)
- To create additional paperwork for professionals
- To limit the scope of professional practice
Correct answer: To ensure adherence to established standards and protect stakeholders
The primary objective of compliance and regulatory frameworks is to ensure adherence to standards that protect stakeholders.
Question 73: Which right allows individuals to request deletion of their data?
- Right to restrict
- Right to object
- Right to rectify
- Right to erasure (Correct answer)
Correct answer: Right to erasure
The Right to Erasure, often called the 'Right to be Forgotten,' allows individuals to request the deletion or removal of their personal data where there is no compelling reason for its continued processing. This right applies in specific circumstances, such as when the data is no longer necessary for the purpose for which it was collected or when consent is withdrawn. It empowers individuals to control their digital footprint.
Question 74: Which principle emphasizes collecting only data necessary for the purpose?
- Data minimization (Correct answer)
- Transparency
- Storage limitation
- Lawfulness
Correct answer: Data minimization
Data minimization is a core privacy principle emphasizing that organizations should collect and process only the personal data that is absolutely necessary for the specified purpose. This reduces the amount of sensitive information held, thereby lowering the risk in case of a data breach and limiting potential misuse. It promotes a 'less is more' approach to data handling.
Question 75: The legal concept of 'legitimate expectation of privacy' in the workplace is evaluated by:
- Whether the employer has an explicit written policy covering every monitored activity
- Whether the expectation was both subjectively held and objectively reasonable given the work context (Correct answer)
- Whether the employee signed a waiver of all privacy rights upon hiring
- Whether the employee subjectively felt their activities were private
Correct answer: Whether the expectation was both subjectively held and objectively reasonable given the work context
Courts analyze workplace privacy claims by determining whether the employee had a subjective expectation of privacy that society would recognize as objectively reasonable given the specific work environment and context.
Question 76: What principle mandates that personal data not be kept longer than necessary?
- Integrity
- Lawfulness
- Storage limitation (Correct answer)
- Minimization
Correct answer: Storage limitation
The storage limitation principle dictates that personal data should not be kept longer than is necessary for the purposes for which it was collected. Once the purpose is fulfilled, the data should be securely deleted or anonymized. This prevents indefinite retention of personal information and reduces the risk associated with holding outdated data.
Question 77: Which phase of NIST's incident response lifecycle involves activities to stop the spread of an incident and prevent further damage?
- Post-Incident Activity
- Containment, Eradication, and Recovery (Correct answer)
- Preparation
- Detection and Analysis
Correct answer: Containment, Eradication, and Recovery
The Containment, Eradication, and Recovery phase focuses on stopping the incident spread, removing the threat, and restoring normal operations.
Question 78: Under the Children's Online Privacy Protection Act (COPPA), websites and apps directed to children under 13 must obtain verifiable parental consent before:
- Allowing children to create any account
- Using cookies of any kind on the platform
- Collecting, using, or disclosing personal information from children (Correct answer)
- Displaying any advertising to children
Correct answer: Collecting, using, or disclosing personal information from children
COPPA requires verifiable parental consent before collecting, using, or sharing personal information from children under 13, as enforced by the FTC.
Question 79: The accountability principle requires organizations to:
- Store data indefinitely
- Demonstrate compliance (Correct answer)
- Ignore breach notifications
- Publish all data publicly
Correct answer: Demonstrate compliance
The accountability principle under GDPR requires organizations to not only comply with data protection principles but also to be able to demonstrate that compliance. This involves implementing robust data protection policies, maintaining records of processing activities, and conducting impact assessments. It shifts the burden of proof to the data controller to show they are upholding privacy standards.
Question 80: Which document outlines internal rules for cross-border data transfers within multinational companies?
- Standard Contractual Clauses
- Privacy Charter
- Binding Corporate Rules (Correct answer)
- Data Impact Framework
Correct answer: Binding Corporate Rules
Binding Corporate Rules (BCRs) are a set of internal, legally binding rules adopted by multinational corporations to govern their transfers of personal data from the EU/EEA to their entities located outside the EU/EEA. They serve as a robust mechanism to ensure that all intra-group data transfers comply with GDPR standards, especially when no adequacy decision exists for the recipient country. BCRs are approved by data protection authorities and provide a comprehensive framework for data protection within a corporate group.
Question 81: Under HIPAA, covered entities must notify affected individuals of a breach affecting their protected health information within how many days of discovering the breach?
- 60 days (Correct answer)
- 90 days
- 30 days
- 45 days
Correct answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
Question 82: What is the PRIMARY objective of contract review & negotiation within the Privacy Law profession?
- To create additional requirements for practitioners
- To limit the scope of professional activities
- To ensure quality outcomes through standardized practices and continuous improvement (Correct answer)
- To maintain the status quo without change
Correct answer: To ensure quality outcomes through standardized practices and continuous improvement
The primary objective is ensuring quality outcomes through established standards while continuously improving practices and processes.
Question 83: Which factor BEST indicates mastery of document preparation & filing in Privacy Law?
- Number of certifications held
- Speed of task completion
- The ability to adapt knowledge and skills to varying contexts while maintaining standards (Correct answer)
- Years of experience in a single setting
Correct answer: The ability to adapt knowledge and skills to varying contexts while maintaining standards
True mastery is demonstrated by the ability to apply knowledge flexibly across different contexts while consistently maintaining quality standards.
Question 84: A US company experiences a breach affecting EU residents' data. Under GDPR, if the breach is unlikely to result in a risk to individuals' rights, the company must:
- Document the breach internally without notifying authorities (Correct answer)
- Notify affected individuals immediately
- Notify both the supervisory authority and individuals within 72 hours
- Notify the supervisory authority within 72 hours
Correct answer: Document the breach internally without notifying authorities
GDPR Article 33(1) states that breaches unlikely to result in risk to individuals' rights need not be reported to supervisory authorities but must be documented internally.
Question 85: Biometric information collected from employees (such as fingerprints for timekeeping) is primarily regulated by:
- The ADA exclusively
- The Genetic Information Nondiscrimination Act (GINA)
- The ECPA at the federal level
- State biometric privacy laws such as Illinois BIPA (Correct answer)
Correct answer: State biometric privacy laws such as Illinois BIPA
Biometric data collection in the workplace is primarily regulated by state laws like Illinois' Biometric Information Privacy Act (BIPA), which requires written consent, a public retention policy, and limits on data sharing.
Question 86: In Privacy Law, what is the MOST appropriate response when a potential compliance violation is discovered?
- Wait to see if the violation causes harm before reporting
- Address it only if a supervisor specifically asks about it
- Discuss it informally without documentation
- Report it immediately through established channels and document findings (Correct answer)
Correct answer: Report it immediately through established channels and document findings
Immediate reporting through established channels with proper documentation ensures timely resolution and maintains the integrity of the compliance program.
Question 87: Consent must be as easy to withdraw as it was to:
- Store
- Ignore
- Provide (Correct answer)
- Obtain passively
Correct answer: Provide
A key requirement for valid consent under GDPR is that it must be as easy for an individual to withdraw their consent as it was to provide it. This ensures that individuals retain control over their personal data and are not trapped into ongoing processing once they have given permission. It prevents organizations from making withdrawal unnecessarily difficult, upholding user autonomy.
Question 88: What is the purpose of a 'post-mortem' or 'lessons learned' meeting after a data breach incident?
- To assign legal blame to responsible employees
- To identify what worked, what failed, and how to improve future response (Correct answer)
- To calculate financial losses for insurance claims
- To draft the customer notification letter
Correct answer: To identify what worked, what failed, and how to improve future response
Post-incident reviews identify gaps in preparation, response, and recovery to strengthen the organization's future incident handling capabilities.
Question 89: When an employee returns from FMLA leave, their medical certification and related health information must be:
- Shared with the employee's direct supervisor to facilitate return-to-work planning
- Kept in a separate confidential medical file, apart from the general personnel file (Correct answer)
- Disclosed to HR and senior management but not line supervisors
- Retained in the general personnel file with role-based access controls
Correct answer: Kept in a separate confidential medical file, apart from the general personnel file
FMLA regulations, consistent with ADA requirements, mandate that employee medical information be maintained in separate confidential files distinct from general personnel records.
Question 90: Which element is ESSENTIAL for an effective ethics & professional responsibility program in Privacy Law?
- Documentation stored without regular updates
- Compliance responsibility assigned to one individual only
- Annual review without interim checks
- Regular audits and continuous monitoring processes (Correct answer)
Correct answer: Regular audits and continuous monitoring processes
Regular audits and continuous monitoring enable early detection of compliance gaps and ensure ongoing adherence to standards.
Privacy Law Certification (PLC)
The Privacy Law Certification (PLC) validates expertise in privacy law, data protection regulations, and legal practice. It covers GDPR, CCPA, consent frameworks, breach response, and professional conduct for attorneys and privacy legal practitioners.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds