Under GDPR, which of the following represents a lawful basis for processing personal data?
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Apply Data Privacy Principles And Regulations in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
Under GDPR, which of the following represents a lawful basis for processing personal data?
This quiz focuses on Apply Data Privacy Principles And Regulations, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
Under GDPR, which of the following represents a lawful basis for processing personal data?
Explanation: GDPR Article 6 requires a lawful basis for processing, one of which is explicit, informed consent from the data subject for a specific purpose. Answer A is correct. A vague 'business interest' without necessity and proportionality analysis (B) does not satisfy the legitimate interests basis. Public posting (C) does not constitute consent for further processing. A broad privacy policy (D) is not a lawful basis under GDPR.
HIPAA's Privacy Rule primarily applies to which types of organizations?
Explanation: HIPAA's Privacy Rule applies specifically to covered entities (healthcare providers, health plans, clearinghouses) and their business associates who handle protected health information (PHI). Answer D is correct. HIPAA does not apply to all PII collectors (A), all organizations above a revenue threshold (B), or only government entities (C).
Under GDPR, organizations must notify the relevant supervisory authority of a personal data breach within:
Explanation: GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a breach, where feasible. This is one of the tightest breach notification requirements globally. Answer A is correct. 30 days (B), 24 hours (C), and 7 business days (D) are all incorrect timeframes.
Which of the following data elements is classified as 'special category data' under GDPR, requiring heightened protection?
Explanation: GDPR Article 9 defines special categories of data requiring stricter processing conditions, including health data, biometric data, genetic data, racial or ethnic origin, and similar sensitive categories. Answer B is correct. Email and phone (A), employer information (C), and purchase history (D) are personal data but not special category data under GDPR.
A company's privacy notice fails to disclose the retention period for personal data collected from website visitors. Under GDPR, this most likely violates which requirement?
Explanation: GDPR Articles 13 and 14 require organizations to provide data subjects with transparent information about data processing, including retention periods. Omitting this information violates transparency requirements. Answer D is correct. Right to erasure (A) is a separate right. Breach notification (B) is unrelated. DPO appointment (C) depends on organization type.
Which of the following best describes the concept of 'Privacy by Design'?
Explanation: Privacy by Design, codified in GDPR Article 25, requires that data protection is considered and built into systems and processes from the earliest design stages rather than added as an afterthought. Answer B is correct. A reactive post-deployment approach (A) is the opposite of Privacy by Design. Annual audits (C) and encryption standards (D) are components of privacy programs but not the definition of Privacy by Design.
Under GDPR, the 'right to erasure' (also known as the 'right to be forgotten') allows individuals to:
Explanation: The right to erasure (GDPR Article 17) allows individuals to request deletion of their personal data under specific circumstances, including when the data is no longer needed or consent is withdrawn. Answer D is correct. Correcting inaccurate data (A) is the right to rectification. Accessing data (B) is the right of access. Restricting processing (C) is the right to restriction of processing.
An organization's employee accidentally emails a file containing 50,000 customer records including names, addresses, and credit card numbers to an external party. Under GDPR, this event is best classified as:
Explanation: Unauthorized disclosure of personal data to an external party is a personal data breach under GDPR. Given the sensitivity (financial data) and volume (50,000 records), notification to the supervisory authority within 72 hours and likely to affected individuals is required. Answer A is correct. The number of affected individuals and data sensitivity preclude treating it as minor (B) or purely an IT matter (C). GDPR requires assessment and likely notification regardless of known misuse (D).
Which of the following correctly describes the difference between 'data controller' and 'data processor' under GDPR?
Explanation: Under GDPR, the data controller decides why and how personal data is processed (the decision-maker). The data processor acts on the controller's behalf and instructions. Answer C is correct. Answers A and B reverse the roles. They are distinct roles with different responsibilities and liabilities (D).
A company's privacy impact assessment (PIA) identifies that a new customer analytics system will process sensitive financial data at a large scale. Under GDPR, which additional requirement is most likely triggered?
Explanation: GDPR Article 35 requires a DPIA when processing is likely to result in high risk to individuals, such as large-scale processing of sensitive financial data. The DPIA must be completed before processing begins. Answer A is correct. Tax authority registration (B) is unrelated. Individual notification before go-live (C) is not a GDPR requirement. Infrastructure restrictions (D) are not prescribed by GDPR.
Under data privacy principles, 'storage limitation' requires that:
Explanation: The storage limitation principle (GDPR Article 5(1)(e)) requires that personal data not be retained in identifiable form longer than necessary for its original purpose. Answer C is correct. Encryption (A) relates to data security. Data localization (B) is a separate concept not universally required by GDPR. Annual audits (D) are not the definition of storage limitation.
Which of the following best describes the 'principle of integrity and confidentiality' under GDPR?
Explanation: The integrity and confidentiality principle (GDPR Article 5(1)(f)) requires appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. Answer D is correct. Data accuracy (A) relates to the accuracy principle. Disclosure notifications (B) relate to transparency. Separate consent per category (C) is not a GDPR requirement.
The privacy principle of 'purpose limitation' means that:
Explanation: Purpose limitation requires that data be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Answer C is correct. There is no three-purpose limit (A). Retention limits (B) describe the storage limitation principle. Access limits (D) describe access control principles.
A company transfers personal data of EU residents to a U.S.-based cloud provider. Under GDPR, which mechanism could legitimize this data transfer?
Explanation: GDPR Chapter V restricts personal data transfers to third countries. Approved mechanisms include SCCs, adequacy decisions, and Binding Corporate Rules. Standard Contractual Clauses are the most commonly used mechanism for transfers to the U.S. Answer A is correct. NDAs (B), internal policies (C), and audits (D) are not GDPR-recognized transfer mechanisms.
Under the principle of 'accountability' in GDPR, organizations are required to:
Explanation: The accountability principle (GDPR Article 5(2)) requires controllers to not only comply with GDPR but to be able to demonstrate their compliance through documentation, policies, and records. Answer C is correct. Annual reporting to supervisory authorities (A) is not required. Board approval of all processing (B) is not required. Public disclosure of the full data inventory (D) is not required.
The California Consumer Privacy Act (CCPA) grants California residents which of the following rights?
Explanation: The CCPA grants California residents the right to know what personal information is collected and how it is used, the right to request deletion, and the right to opt out of the sale of their personal information. Answer C is correct. CCPA does not require 24-hour deletion (A), automatic compensation (B), or prior written consent for all data collection (D).
A company collects biometric data from employees for building access control. Under GDPR, processing this data requires:
Explanation: Biometric data is a special category under GDPR Article 9, requiring a specific legal basis beyond the standard Article 6 bases - such as explicit consent or a basis under member state employment law. Answer B is correct. A standard privacy notice alone (A) is insufficient for special category data. Prior approval from authorities (C) is not a blanket requirement. 30-day anonymization (D) is not an GDPR requirement.
Which of the following best describes 'pseudonymization' as a data protection technique under GDPR?
Explanation: Pseudonymization replaces directly identifying information with a pseudonym while retaining the ability to re-identify using separately stored key data. This reduces risk while preserving some analytical utility. Answer D is correct. Permanent deletion (A) is anonymization. Public-key encryption (B) is a security technique. Completely random codes with no linkage (C) describes anonymization, not pseudonymization.
A U.S.-based company receives a verifiable consumer request under CCPA to delete all personal information it has collected about the requestor. The company must respond within:
Explanation: CCPA requires businesses to respond to verifiable consumer requests within 45 days. If more time is needed, an extension of up to 45 additional days is permitted with notice to the consumer. Answer B is correct. 24 hours (A), 90 days (C), and 30 days with no extension (D) are all incorrect timeframes under CCPA.
The General Data Protection Regulation (GDPR) applies to organizations that:
Explanation: GDPR Article 3 establishes extraterritorial reach in two ways: it applies to organizations established in the EU (Article 3(1)), and to non-EU organizations that offer goods or services to, or monitor the behavior of, individuals located in the EU (Article 3(2)). Simply processing data of EU nationals outside this context is not sufficient to trigger GDPR. Answer D is correct. GDPR is not limited to EU-headquartered organizations alone (A), a transaction volume threshold (B), or financial industry organizations (C).