โ† All RCMS Flashcard Decks

Data Privacy & Protection Compliance Flashcards

7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Privacy & Protection Compliance flashcards as text
  1. When a company uses personal data collected for marketing purposes to later conduct fraud investigations, this violates which data protection principle?

    Answer: Purpose limitation

    Purpose limitation prohibits using personal data for purposes incompatible with those originally specified at collection.

  2. A healthcare organization must conduct a risk analysis under HIPAA Security Rule. Which of the following best describes the scope of this analysis?

    Answer: All potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI

    The HIPAA Security Rule requires an accurate and thorough assessment of all potential risks to ePHI across all systems and processes.

  3. Which legal basis under GDPR Article 6 is most appropriate when processing is necessary for compliance with a legal obligation to which the controller is subject?

    Answer: Legal obligation (Art. 6(1)(c))

    Article 6(1)(c) covers processing necessary for compliance with a legal obligation of the controller under EU or member state law.

  4. The Colorado Privacy Act (CPA) grants consumers the right to opt out of personal data processing for which of the following purposes?

    Answer: Targeted advertising, sale of personal data, and profiling for significant decisions

    Colorado's CPA grants opt-out rights for targeted advertising, sale of personal data, and profiling in furtherance of decisions with legal or significant effects.

  5. A compliance officer is designing a data retention schedule. Which factor is LEAST relevant to determining the appropriate retention period for personal data?

    Answer: The number of employees in the organization

    Employee count does not determine data retention periods; legal requirements, business need, and contractual obligations are the primary drivers.

  6. Under COPPA, websites directed to children under 13 must obtain verifiable parental consent before:

    Answer: Collecting, using, or disclosing personal information from children

    COPPA requires verifiable parental consent before any collection, use, or disclosure of personal information from children under 13.

  7. Which of the following best describes a 'legitimate interest' assessment (LIA) under GDPR?

    Answer: A three-part test balancing the controller's interest, necessity, and impact on data subjects

    An LIA involves a three-part test: identifying a legitimate interest, confirming necessity, and balancing it against data subjects' interests and rights.