← All RCMS Flashcard Decks

Data Privacy & Protection Compliance Flashcards

7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Data Privacy & Protection Compliance flashcards as text
  1. A company appoints a Data Protection Officer (DPO) under GDPR. Which of the following tasks falls OUTSIDE the DPO's role?

    Answer: Making final decisions on data processing legal bases

    The DPO advises and monitors but does not make binding decisions on legal bases; that responsibility rests with the controller or processor.

  2. Under the GLBA Safeguards Rule (updated 2023), covered financial institutions must designate a qualified individual to oversee their information security program. This person is commonly referred to as a:

    Answer: Chief Information Security Officer (CISO) or equivalent

    The FTC's updated Safeguards Rule requires a qualified individual — often a CISO or equivalent — to implement and supervise the information security program.

  3. Which scenario represents a violation of the 'data minimization' principle under GDPR?

    Answer: Requiring users to submit their Social Security Number to create a free loyalty account

    Collecting a Social Security Number for a loyalty account exceeds what is adequate, relevant, and limited to what is necessary for that purpose.

  4. A data subject submits a Subject Access Request (SAR) under GDPR. The controller may extend the response period from one month to three months if:

    Answer: The request is complex or the controller receives a high number of requests

    GDPR Article 12(3) allows an extension of up to two additional months where requests are complex or numerous, provided the data subject is informed within the first month.

  5. What does the principle of 'accountability' under GDPR primarily require of a data controller?

    Answer: Being able to demonstrate compliance with GDPR principles through documented measures

    Article 5(2) places the burden on the controller to demonstrate compliance with GDPR principles through records, policies, and other documented measures.

  6. Under U.S. state privacy law frameworks, which of the following processing activities typically requires a Data Protection Assessment (DPA) prior to initiation?

    Answer: Processing sensitive data or conducting targeted advertising

    States like Virginia, Colorado, and Connecticut require data protection assessments before processing sensitive data or engaging in targeted advertising.

  7. An organization experiences a ransomware attack that encrypts ePHI. Under HIPAA, how should this incident be treated unless the organization can demonstrate a low probability of compromise?

    Answer: As a breach triggering notification obligations

    HHS guidance clarifies that ransomware encrypting ePHI is presumed a breach unless a four-factor risk assessment shows a low probability of compromise.