RCMS Data Privacy & Protection Compliance 3 — Questions and Answers
Question 1: FERPA protects the educational records of students at institutions receiving federal funding. At what age do FERPA rights transfer from parents to the student?
- 16
- 18 (Correct answer)
- 21
- Upon high school graduation only
Correct answer: 18
FERPA rights transfer to the eligible student at age 18 or upon enrollment in a postsecondary institution.
Question 2: A Data Protection Impact Assessment (DPIA) under GDPR is mandatory when processing is likely to result in:
- Any use of cookies on a website
- High risk to the rights and freedoms of natural persons (Correct answer)
- Processing of fewer than 500 records
- Use of encryption for stored data
Correct answer: High risk to the rights and freedoms of natural persons
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to individuals' rights and freedoms, especially with new technologies.
Question 3: Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers a privacy notice:
- Only when customers request it
- At account opening and annually thereafter (Correct answer)
- Every five years
- Only when sharing data with affiliates
Correct answer: At account opening and annually thereafter
GLBA requires financial institutions to provide an initial privacy notice at the time of establishing a customer relationship and annually thereafter.
Question 4: Which principle from the OECD Privacy Guidelines requires that personal data should only be collected for specified, explicit purposes?
- Individual Participation Principle
- Purpose Specification Principle (Correct answer)
- Data Quality Principle
- Use Limitation Principle
Correct answer: Purpose Specification Principle
The Purpose Specification Principle requires that the purposes for data collection be specified no later than at the time of collection.
Question 5: A compliance officer discovers that a third-party vendor is processing personal data beyond the scope of the signed data processing agreement. The FIRST corrective action should be:
- Immediately terminate the vendor contract
- Notify the supervisory authority before investigating
- Issue a formal cure notice and suspend processing pending remediation (Correct answer)
- Wait for the annual vendor audit to address the issue
Correct answer: Issue a formal cure notice and suspend processing pending remediation
The immediate step is to halt unauthorized processing and provide the vendor an opportunity to cure the breach per the contract terms.
Question 6: Under NIST Privacy Framework, which core function focuses on developing organizational understanding to manage privacy risk?
- Protect
- Detect
- Identify-P (Correct answer)
- Respond-P
Correct answer: Identify-P
The Identify-P function in the NIST Privacy Framework focuses on developing an organizational understanding of privacy risk to individuals.
Question 7: Virginia's Consumer Data Protection Act (VCDPA) excludes which of the following from its definition of 'personal data'?
- Browsing history linked to a device
- De-identified data and publicly available information (Correct answer)
- Sensitive data like racial or ethnic origin
- Precise geolocation data
Correct answer: De-identified data and publicly available information
VCDPA explicitly excludes de-identified data and publicly available information from its definition of personal data.
FERPA protects the educational records of students at institutions receiving federal funding.
At what age do FERPA rights transfer from parents to the student?