RCC Data Privacy and Information Security Compliance Flashcards
6 cards from real RCC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 RCC Data Privacy and Information Security Compliance flashcards as text
Under the California Consumer Privacy Act (CCPA), consumers have the right to:
Answer: Know what personal information is collected about them and request its deletion
The CCPA grants California consumers rights to know about, access, delete, and opt out of the sale of their personal information, with some exceptions.
Which US federal law governs the privacy of student educational records?
Answer: FERPA (Family Educational Rights and Privacy Act)
FERPA protects the privacy of student education records and grants parents and eligible students rights to access and control those records.
A 'data breach notification' requirement typically obligates an organization to:
Answer: Notify affected individuals and relevant authorities within a specified timeframe after discovering a breach
Most US state data breach laws and sector-specific regulations require timely notification to affected individuals and, in many cases, state attorneys general or sector regulators.
What does 'data minimization' mean in a privacy compliance context?
Answer: Collecting only the personal data necessary for the specified purpose
Data minimization is a privacy principle requiring organizations to collect and retain only the personal data that is necessary and proportionate to the purpose for which it was collected.
HIPAA's Security Rule applies specifically to:
Answer: Electronic protected health information (ePHI) held by covered entities and their business associates
The HIPAA Security Rule establishes national standards for protecting ePHI that is created, received, used, or maintained by covered entities and business associates.
A 'Privacy Impact Assessment (PIA)' is MOST useful for:
Answer: Identifying and addressing privacy risks before launching a new program or technology
A PIA evaluates how a new system, program, or process will collect and use personal data, enabling organizations to address privacy risks proactively at the design stage.