RCMS Data Privacy & Protection Compliance 4 — Questions and Answers
Question 1: When a company uses personal data collected for marketing purposes to later conduct fraud investigations, this violates which data protection principle?
- Data minimization
- Storage limitation
- Purpose limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Purpose limitation
Purpose limitation prohibits using personal data for purposes incompatible with those originally specified at collection.
Question 2: A healthcare organization must conduct a risk analysis under HIPAA Security Rule. Which of the following best describes the scope of this analysis?
- Only systems that directly store ePHI
- All potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI (Correct answer)
- Physical security controls only
- Administrative safeguards for paper records
Correct answer: All potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI
The HIPAA Security Rule requires an accurate and thorough assessment of all potential risks to ePHI across all systems and processes.
Question 3: Which legal basis under GDPR Article 6 is most appropriate when processing is necessary for compliance with a legal obligation to which the controller is subject?
- Consent (Art. 6(1)(a))
- Legitimate interests (Art. 6(1)(f))
- Legal obligation (Art. 6(1)(c)) (Correct answer)
- Vital interests (Art. 6(1)(d))
Correct answer: Legal obligation (Art. 6(1)(c))
Article 6(1)(c) covers processing necessary for compliance with a legal obligation of the controller under EU or member state law.
Question 4: The Colorado Privacy Act (CPA) grants consumers the right to opt out of personal data processing for which of the following purposes?
- Internal analytics only
- Targeted advertising, sale of personal data, and profiling for significant decisions (Correct answer)
- Email marketing only
- Fraud detection and security purposes
Correct answer: Targeted advertising, sale of personal data, and profiling for significant decisions
Colorado's CPA grants opt-out rights for targeted advertising, sale of personal data, and profiling in furtherance of decisions with legal or significant effects.
Question 5: A compliance officer is designing a data retention schedule. Which factor is LEAST relevant to determining the appropriate retention period for personal data?
- Applicable legal and regulatory requirements
- The number of employees in the organization (Correct answer)
- Business operational necessity
- Contractual obligations with data subjects
Correct answer: The number of employees in the organization
Employee count does not determine data retention periods; legal requirements, business need, and contractual obligations are the primary drivers.
Question 6: Under COPPA, websites directed to children under 13 must obtain verifiable parental consent before:
- Displaying any advertisements
- Collecting, using, or disclosing personal information from children (Correct answer)
- Requiring account registration for adults
- Using cookies for site analytics
Correct answer: Collecting, using, or disclosing personal information from children
COPPA requires verifiable parental consent before any collection, use, or disclosure of personal information from children under 13.
Question 7: Which of the following best describes a 'legitimate interest' assessment (LIA) under GDPR?
- A formal audit conducted by a supervisory authority
- A three-part test balancing the controller's interest, necessity, and impact on data subjects (Correct answer)
- An assessment required only for cross-border data transfers
- A self-certification process filed with the DPA
Correct answer: A three-part test balancing the controller's interest, necessity, and impact on data subjects
An LIA involves a three-part test: identifying a legitimate interest, confirming necessity, and balancing it against data subjects' interests and rights.
When a company uses personal data collected for marketing purposes to later conduct fraud investigations, this violates which data protection principle?