RCMS Data Privacy & Protection Compliance 5 — Questions and Answers
Question 1: A company appoints a Data Protection Officer (DPO) under GDPR. Which of the following tasks falls OUTSIDE the DPO's role?
- Monitoring internal compliance with GDPR
- Acting as the contact point for supervisory authorities
- Making final decisions on data processing legal bases (Correct answer)
- Providing advice on DPIAs
Correct answer: Making final decisions on data processing legal bases
The DPO advises and monitors but does not make binding decisions on legal bases; that responsibility rests with the controller or processor.
Question 2: Under the GLBA Safeguards Rule (updated 2023), covered financial institutions must designate a qualified individual to oversee their information security program. This person is commonly referred to as a:
- Chief Privacy Officer (CPO)
- Chief Information Security Officer (CISO) or equivalent (Correct answer)
- Data Protection Officer (DPO)
- Compliance Coordinator
Correct answer: Chief Information Security Officer (CISO) or equivalent
The FTC's updated Safeguards Rule requires a qualified individual — often a CISO or equivalent — to implement and supervise the information security program.
Question 3: Which scenario represents a violation of the 'data minimization' principle under GDPR?
- Collecting only name and email for a newsletter subscription
- Requiring users to submit their Social Security Number to create a free loyalty account (Correct answer)
- Storing transaction records for the legally required period
- Pseudonymizing customer IDs in analytics logs
Correct answer: Requiring users to submit their Social Security Number to create a free loyalty account
Collecting a Social Security Number for a loyalty account exceeds what is adequate, relevant, and limited to what is necessary for that purpose.
Question 4: A data subject submits a Subject Access Request (SAR) under GDPR. The controller may extend the response period from one month to three months if:
- The request is submitted by email rather than in writing
- The request is complex or the controller receives a high number of requests (Correct answer)
- The data subject has previously submitted a SAR
- The data involves third-party information
Correct answer: The request is complex or the controller receives a high number of requests
GDPR Article 12(3) allows an extension of up to two additional months where requests are complex or numerous, provided the data subject is informed within the first month.
Question 5: What does the principle of 'accountability' under GDPR primarily require of a data controller?
- Publishing all data processing records on its public website
- Being able to demonstrate compliance with GDPR principles through documented measures (Correct answer)
- Sharing audit reports with all data subjects annually
- Registering with the supervisory authority before processing any data
Correct answer: Being able to demonstrate compliance with GDPR principles through documented measures
Article 5(2) places the burden on the controller to demonstrate compliance with GDPR principles through records, policies, and other documented measures.
Question 6: Under U.S. state privacy law frameworks, which of the following processing activities typically requires a Data Protection Assessment (DPA) prior to initiation?
- Sending transactional emails to existing customers
- Processing sensitive data or conducting targeted advertising (Correct answer)
- Storing employee payroll records in encrypted form
- Publishing aggregated, de-identified research findings
Correct answer: Processing sensitive data or conducting targeted advertising
States like Virginia, Colorado, and Connecticut require data protection assessments before processing sensitive data or engaging in targeted advertising.
Question 7: An organization experiences a ransomware attack that encrypts ePHI. Under HIPAA, how should this incident be treated unless the organization can demonstrate a low probability of compromise?
- As an internal security event requiring only an incident log
- As a security incident only, with no breach notification required
- As a breach triggering notification obligations (Correct answer)
- As a potential breach only if data is confirmed exfiltrated
Correct answer: As a breach triggering notification obligations
HHS guidance clarifies that ransomware encrypting ePHI is presumed a breach unless a four-factor risk assessment shows a low probability of compromise.
A company appoints a Data Protection Officer (DPO) under GDPR.
Which of the following tasks falls OUTSIDE the DPO's role?