RCMS Data Privacy & Protection Compliance 2 — Questions and Answers
Question 1: Under CCPA, which of the following rights must be honored within 45 days of a verifiable consumer request?
- Right to data portability only
- Right to know and right to delete (Correct answer)
- Right to correct inaccurate data only
- Right to opt into data sale
Correct answer: Right to know and right to delete
CCPA requires businesses to fulfill verified right-to-know and right-to-delete requests within 45 days, with a possible 45-day extension.
Question 2: A company transfers EU resident data to a U.S. vendor without an adequacy decision. Which mechanism best legitimizes this transfer under GDPR?
- Binding Corporate Rules (BCRs)
- Standard Contractual Clauses (SCCs) (Correct answer)
- EU-U.S. Privacy Shield
- Article 49 derogations for commercial interests
Correct answer: Standard Contractual Clauses (SCCs)
SCCs are the most commonly used transfer mechanism after Privacy Shield was invalidated; they are pre-approved by the European Commission.
Question 3: Which HIPAA rule specifically governs the administrative, physical, and technical safeguards for electronic protected health information (ePHI)?
- Privacy Rule
- Breach Notification Rule
- Security Rule (Correct answer)
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule sets standards for protecting ePHI through administrative, physical, and technical safeguards.
Question 4: A data processor suffers a breach affecting data it holds on behalf of a controller. Who bears primary GDPR notification responsibility to the supervisory authority?
- The data processor, within 72 hours
- The data controller, within 72 hours (Correct answer)
- Both jointly, within 48 hours
- The national government, within 30 days
Correct answer: The data controller, within 72 hours
Under GDPR Article 33, the data controller must notify the supervisory authority within 72 hours; the processor must notify the controller without undue delay.
Question 5: The concept of 'Privacy by Design' requires privacy protections to be embedded into systems at which stage?
- During the post-launch audit phase
- Only when a data breach occurs
- From the earliest design and development stage (Correct answer)
- After receiving a data subject access request
Correct answer: From the earliest design and development stage
Privacy by Design mandates that privacy controls are built into products and processes from inception, not added as an afterthought.
Question 6: Which of the following qualifies as 'sensitive personal data' under GDPR Article 9, requiring explicit consent or another specific basis?
- Name and email address
- Biometric data used for unique identification (Correct answer)
- Publicly available phone numbers
- Business contact information
Correct answer: Biometric data used for unique identification
Article 9 lists special categories including biometric data processed to uniquely identify a natural person, requiring heightened protection.
Question 7: A company's privacy notice fails to disclose a secondary use of customer data it later pursues. Under FTC Act Section 5, this most likely constitutes:
- A permissible business practice if no harm occurred
- An unfair or deceptive act or practice (Correct answer)
- A violation only if a breach later occurs
- A breach of contract but not a regulatory violation
Correct answer: An unfair or deceptive act or practice
The FTC treats failure to honor disclosed privacy promises as a deceptive practice under Section 5 of the FTC Act.
Under CCPA, which of the following rights must be honored within 45 days of a verifiable consumer request?