CPA Isc Quiz: Apply Data Privacy Principles And Regulations
20 questions · exam conditions
0:00
Apply Data Privacy Principles And RegulationsQuestion 1 of 20

A retailer operates loyalty programs in California and collects customer purchase history. Under CCPA, if the retailer sells this data to third-party advertisers, it must:

Obtain explicit written consent from each customer before any data sale.
Encrypt all purchase history data before transferring it to advertisers.
Provide customers with a clear opt-out mechanism and disclose that their data is sold, such as a 'Do Not Sell My Personal Information' link.
Delete all purchase history data within 12 months of collection.
← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Apply Data Privacy Principles And Regulations

Practice Apply Data Privacy Principles And Regulations in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Apply Data Privacy Principles And Regulations, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

A retailer operates loyalty programs in California and collects customer purchase history. Under CCPA, if the retailer sells this data to third-party advertisers, it must:

  1. Obtain explicit written consent from each customer before any data sale.
  2. Encrypt all purchase history data before transferring it to advertisers.
  3. Provide customers with a clear opt-out mechanism and disclose that their data is sold, such as a 'Do Not Sell My Personal Information' link. (correct answer)
  4. Delete all purchase history data within 12 months of collection.

Explanation: CCPA requires businesses that sell personal information to disclose this practice and provide a prominent opt-out mechanism, such as the 'Do Not Sell My Personal Information' link. Answer C is correct. CCPA does not require explicit opt-in consent for data sales (A), encryption of sold data (B), or 12-month deletion (D).

Question 2

Under GDPR, a Data Protection Officer (DPO) is required when:

  1. Any organization collects personal data from more than 100 individuals.
  2. The organization is a public authority, or its core activities involve large-scale systematic monitoring of individuals or large-scale processing of special categories of data. (correct answer)
  3. The organization operates in more than one EU member state.
  4. The organization's annual revenue exceeds €50 million.

Explanation: GDPR Article 37 requires a DPO for public authorities, organizations conducting large-scale systematic monitoring, and those processing large-scale special category data (e.g., health, biometric). Answer B is correct. The threshold is not based on number of data subjects (A), multi-country operations (C), or revenue (D).

Question 3

Under GDPR, organizations must notify the relevant supervisory authority of a personal data breach within:

  1. 72 hours of becoming aware of the breach, where feasible. (correct answer)
  2. 30 days of the breach being discovered.
  3. 24 hours of the breach occurring.
  4. 7 business days of confirming the breach through a formal investigation.

Explanation: GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a breach, where feasible. This is one of the tightest breach notification requirements globally. Answer A is correct. 30 days (B), 24 hours (C), and 7 business days (D) are all incorrect timeframes.

Question 4

An organization's employee accidentally emails a file containing 50,000 customer records including names, addresses, and credit card numbers to an external party. Under GDPR, this event is best classified as:

  1. A personal data breach requiring assessment for supervisory authority notification within 72 hours and potential notification to affected data subjects. (correct answer)
  2. A minor operational error that requires only internal documentation.
  3. A security incident requiring only IT remediation with no regulatory reporting obligations.
  4. A breach requiring notification only if the data is subsequently misused.

Explanation: Unauthorized disclosure of personal data to an external party is a personal data breach under GDPR. Given the sensitivity (financial data) and volume (50,000 records), notification to the supervisory authority within 72 hours and likely to affected individuals is required. Answer A is correct. The number of affected individuals and data sensitivity preclude treating it as minor (B) or purely an IT matter (C). GDPR requires assessment and likely notification regardless of known misuse (D).

Question 5

A company's privacy impact assessment (PIA) identifies that a new customer analytics system will process sensitive financial data at a large scale. Under GDPR, which additional requirement is most likely triggered?

  1. A Data Protection Impact Assessment (DPIA) must be completed before the processing begins. (correct answer)
  2. The company must register the system with its national tax authority.
  3. All data subjects must be individually notified before the system goes live.
  4. The system must use only on-premises infrastructure with no cloud components.

Explanation: GDPR Article 35 requires a DPIA when processing is likely to result in high risk to individuals, such as large-scale processing of sensitive financial data. The DPIA must be completed before processing begins. Answer A is correct. Tax authority registration (B) is unrelated. Individual notification before go-live (C) is not a GDPR requirement. Infrastructure restrictions (D) are not prescribed by GDPR.

Question 6

Under data privacy principles, 'storage limitation' requires that:

  1. Data must be stored in encrypted format at all times.
  2. Personal data must be stored in the country where the data subject resides.
  3. Personal data should be kept in a form that identifies individuals for no longer than necessary for the specified purpose. (correct answer)
  4. Storage systems must be audited annually by an independent third party.

Explanation: The storage limitation principle (GDPR Article 5(1)(e)) requires that personal data not be retained in identifiable form longer than necessary for its original purpose. Answer C is correct. Encryption (A) relates to data security. Data localization (B) is a separate concept not universally required by GDPR. Annual audits (D) are not the definition of storage limitation.

Question 7

Which of the following best describes the 'principle of integrity and confidentiality' under GDPR?

  1. Organizations must verify the accuracy of all personal data before processing it.
  2. Data subjects must be informed of all parties with whom their data is shared.
  3. Organizations must obtain separate consent for each category of personal data they process.
  4. Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized access, loss, or destruction. (correct answer)

Explanation: The integrity and confidentiality principle (GDPR Article 5(1)(f)) requires appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. Answer D is correct. Data accuracy (A) relates to the accuracy principle. Disclosure notifications (B) relate to transparency. Separate consent per category (C) is not a GDPR requirement.

Question 8

A company transfers personal data of EU residents to a U.S.-based cloud provider. Under GDPR, which mechanism could legitimize this data transfer?

  1. Standard Contractual Clauses (SCCs) approved by the European Commission. (correct answer)
  2. A mutual nondisclosure agreement between the company and the cloud provider.
  3. The company's internal data governance policy stating that transfers are secure.
  4. An annual privacy audit conducted by the cloud provider.

Explanation: GDPR Chapter V restricts personal data transfers to third countries. Approved mechanisms include SCCs, adequacy decisions, and Binding Corporate Rules. Standard Contractual Clauses are the most commonly used mechanism for transfers to the U.S. Answer A is correct. NDAs (B), internal policies (C), and audits (D) are not GDPR-recognized transfer mechanisms.

Question 9

The California Consumer Privacy Act (CCPA) grants California residents which of the following rights?

  1. The right to require organizations to delete all data about them within 24 hours of a request.
  2. The right to receive compensation for any collection of their personal data.
  3. The right to know what personal information is collected, the right to delete it, and the right to opt out of its sale. (correct answer)
  4. The right to prevent organizations from collecting any data without prior written consent.

Explanation: The CCPA grants California residents the right to know what personal information is collected and how it is used, the right to request deletion, and the right to opt out of the sale of their personal information. Answer C is correct. CCPA does not require 24-hour deletion (A), automatic compensation (B), or prior written consent for all data collection (D).

Question 10

A company collects biometric data from employees for building access control. Under GDPR, processing this data requires:

  1. Only a standard privacy notice informing employees of the collection.
  2. A specific lawful basis under Article 9 for special category data, such as explicit consent or necessity for employment law obligations. (correct answer)
  3. Approval from the national data protection authority before any processing begins.
  4. Anonymization of all biometric templates within 30 days of collection.

Explanation: Biometric data is a special category under GDPR Article 9, requiring a specific legal basis beyond the standard Article 6 bases - such as explicit consent or a basis under member state employment law. Answer B is correct. A standard privacy notice alone (A) is insufficient for special category data. Prior approval from authorities (C) is not a blanket requirement. 30-day anonymization (D) is not an GDPR requirement.

Question 11

HIPAA's Privacy Rule primarily applies to which types of organizations?

  1. All organizations that collect any personally identifiable information from individuals.
  2. Organizations with annual revenue exceeding $10 million that handle patient data.
  3. State and local government health departments only.
  4. Covered entities such as healthcare providers, health plans, and healthcare clearinghouses, and their business associates. (correct answer)

Explanation: HIPAA's Privacy Rule applies specifically to covered entities (healthcare providers, health plans, clearinghouses) and their business associates who handle protected health information (PHI). Answer D is correct. HIPAA does not apply to all PII collectors (A), all organizations above a revenue threshold (B), or only government entities (C).

Question 12

Which of the following data elements is classified as 'special category data' under GDPR, requiring heightened protection?

  1. An individual's email address and phone number.
  2. An individual's health information, biometric data, or racial/ethnic origin. (correct answer)
  3. An individual's employer name and job title.
  4. An individual's shipping address and purchase history.

Explanation: GDPR Article 9 defines special categories of data requiring stricter processing conditions, including health data, biometric data, genetic data, racial or ethnic origin, and similar sensitive categories. Answer B is correct. Email and phone (A), employer information (C), and purchase history (D) are personal data but not special category data under GDPR.

Question 13

A company's privacy notice fails to disclose the retention period for personal data collected from website visitors. Under GDPR, this most likely violates which requirement?

  1. The right to erasure, which requires organizations to delete data upon request.
  2. The data breach notification requirement.
  3. The requirement to appoint a Data Protection Officer.
  4. The transparency and right to information requirements, which mandate clear disclosure of how personal data will be used and retained. (correct answer)

Explanation: GDPR Articles 13 and 14 require organizations to provide data subjects with transparent information about data processing, including retention periods. Omitting this information violates transparency requirements. Answer D is correct. Right to erasure (A) is a separate right. Breach notification (B) is unrelated. DPO appointment (C) depends on organization type.

Question 14

Which of the following best describes the concept of 'Privacy by Design'?

  1. A reactive approach where privacy controls are added to systems after they are deployed.
  2. An approach in which privacy protections are embedded into the design and architecture of systems and processes from the outset. (correct answer)
  3. A privacy audit methodology conducted annually to assess compliance.
  4. A technical standard for encrypting personal data at rest and in transit.

Explanation: Privacy by Design, codified in GDPR Article 25, requires that data protection is considered and built into systems and processes from the earliest design stages rather than added as an afterthought. Answer B is correct. A reactive post-deployment approach (A) is the opposite of Privacy by Design. Annual audits (C) and encryption standards (D) are components of privacy programs but not the definition of Privacy by Design.

Question 15

Under GDPR, the 'right to erasure' (also known as the 'right to be forgotten') allows individuals to:

  1. Require organizations to correct inaccurate personal data about them.
  2. Access all personal data an organization holds about them.
  3. Restrict the processing of their personal data while a complaint is being investigated.
  4. Request deletion of their personal data when it is no longer necessary, consent is withdrawn, or other specified conditions are met. (correct answer)

Explanation: The right to erasure (GDPR Article 17) allows individuals to request deletion of their personal data under specific circumstances, including when the data is no longer needed or consent is withdrawn. Answer D is correct. Correcting inaccurate data (A) is the right to rectification. Accessing data (B) is the right of access. Restricting processing (C) is the right to restriction of processing.

Question 16

Which of the following correctly describes the difference between 'data controller' and 'data processor' under GDPR?

  1. A data controller processes data on behalf of a data processor's instructions.
  2. A data processor determines the purposes and means of processing; a controller executes the processing.
  3. A data controller determines the purposes and means of processing personal data; a data processor processes data on behalf of the controller. (correct answer)
  4. Both terms refer to the same role under GDPR and may be used interchangeably.

Explanation: Under GDPR, the data controller decides why and how personal data is processed (the decision-maker). The data processor acts on the controller's behalf and instructions. Answer C is correct. Answers A and B reverse the roles. They are distinct roles with different responsibilities and liabilities (D).

Question 17

The privacy principle of 'purpose limitation' means that:

  1. Organizations must limit the number of purposes for which they collect data to no more than three.
  2. Personal data may only be retained for a limited period before being deleted.
  3. Personal data collected for one specified purpose should not be used for a different, incompatible purpose without additional consent or lawful basis. (correct answer)
  4. Organizations must limit access to personal data to a specific number of authorized employees.

Explanation: Purpose limitation requires that data be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Answer C is correct. There is no three-purpose limit (A). Retention limits (B) describe the storage limitation principle. Access limits (D) describe access control principles.

Question 18

Under the principle of 'accountability' in GDPR, organizations are required to:

  1. Report all personal data processing activities to their national supervisory authority annually.
  2. Obtain board-level approval for all personal data processing activities.
  3. Demonstrate compliance with GDPR principles through documented policies, procedures, and records of processing activities. (correct answer)
  4. Publish their full data inventory on their public website.

Explanation: The accountability principle (GDPR Article 5(2)) requires controllers to not only comply with GDPR but to be able to demonstrate their compliance through documentation, policies, and records. Answer C is correct. Annual reporting to supervisory authorities (A) is not required. Board approval of all processing (B) is not required. Public disclosure of the full data inventory (D) is not required.

Question 19

Which of the following best describes 'pseudonymization' as a data protection technique under GDPR?

  1. Permanently deleting personal data so it can never be recovered.
  2. Encrypting personal data using a public key so only the data subject can decrypt it.
  3. Replacing all personal data fields with randomly generated codes that have no link to real identities.
  4. Processing personal data in a way that it can no longer be attributed to a specific individual without the use of additional information held separately. (correct answer)

Explanation: Pseudonymization replaces directly identifying information with a pseudonym while retaining the ability to re-identify using separately stored key data. This reduces risk while preserving some analytical utility. Answer D is correct. Permanent deletion (A) is anonymization. Public-key encryption (B) is a security technique. Completely random codes with no linkage (C) describes anonymization, not pseudonymization.

Question 20

Under GDPR, which of the following represents a lawful basis for processing personal data?

  1. The data subject has given explicit, informed consent to the processing for a specified purpose. (correct answer)
  2. The organization has a legitimate business interest in collecting as much data as possible.
  3. The data has already been publicly posted on social media by the individual.
  4. The organization's privacy policy states that data may be collected and used for any purpose.

Explanation: GDPR Article 6 requires a lawful basis for processing, one of which is explicit, informed consent from the data subject for a specific purpose. Answer A is correct. A vague 'business interest' without necessity and proportionality analysis (B) does not satisfy the legitimate interests basis. Public posting (C) does not constitute consent for further processing. A broad privacy policy (D) is not a lawful basis under GDPR.