โ† All RCMS Flashcard Decks

Data Privacy & Protection Compliance Flashcards

7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Privacy & Protection Compliance flashcards as text
  1. Under CCPA, which of the following rights must be honored within 45 days of a verifiable consumer request?

    Answer: Right to know and right to delete

    CCPA requires businesses to fulfill verified right-to-know and right-to-delete requests within 45 days, with a possible 45-day extension.

  2. A company transfers EU resident data to a U.S. vendor without an adequacy decision. Which mechanism best legitimizes this transfer under GDPR?

    Answer: Standard Contractual Clauses (SCCs)

    SCCs are the most commonly used transfer mechanism after Privacy Shield was invalidated; they are pre-approved by the European Commission.

  3. Which HIPAA rule specifically governs the administrative, physical, and technical safeguards for electronic protected health information (ePHI)?

    Answer: Security Rule

    The HIPAA Security Rule sets standards for protecting ePHI through administrative, physical, and technical safeguards.

  4. A data processor suffers a breach affecting data it holds on behalf of a controller. Who bears primary GDPR notification responsibility to the supervisory authority?

    Answer: The data controller, within 72 hours

    Under GDPR Article 33, the data controller must notify the supervisory authority within 72 hours; the processor must notify the controller without undue delay.

  5. The concept of 'Privacy by Design' requires privacy protections to be embedded into systems at which stage?

    Answer: From the earliest design and development stage

    Privacy by Design mandates that privacy controls are built into products and processes from inception, not added as an afterthought.

  6. Which of the following qualifies as 'sensitive personal data' under GDPR Article 9, requiring explicit consent or another specific basis?

    Answer: Biometric data used for unique identification

    Article 9 lists special categories including biometric data processed to uniquely identify a natural person, requiring heightened protection.

  7. A company's privacy notice fails to disclose a secondary use of customer data it later pursues. Under FTC Act Section 5, this most likely constitutes:

    Answer: An unfair or deceptive act or practice

    The FTC treats failure to honor disclosed privacy promises as a deceptive practice under Section 5 of the FTC Act.