Home

Tutoring

Subjects

Live Classes

Study Coach

Essay Review

On-Demand Courses

Colleges

Games


Sign up

Log in

Opening subject page...

Loading your content

Practice

  • All Subjects
  • Algebra Flashcards
  • SAT Math Practice Tests
  • Math Question of the Day
  • Live Classes
  • On-Demand Courses

Varsity Tutors

  • Find a Tutor
  • Test Prep
  • Online Classes
  • K-12 Learning
  • College Search
  • VarsityTutors.com

© 2026 Varsity Tutors. All rights reserved.

← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Apply Data Privacy Principles And Regulations

Practice Apply Data Privacy Principles And Regulations in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

Question 1 / 20

0 of 20 answered

Under GDPR, which of the following represents a lawful basis for processing personal data?

Select an answer to continue

What this quiz covers

This quiz focuses on Apply Data Privacy Principles And Regulations, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

Under GDPR, which of the following represents a lawful basis for processing personal data?

  1. The data subject has given explicit, informed consent to the processing for a specified purpose. (correct answer)
  2. The organization has a legitimate business interest in collecting as much data as possible.
  3. The data has already been publicly posted on social media by the individual.
  4. The organization's privacy policy states that data may be collected and used for any purpose.

Explanation: GDPR Article 6 requires a lawful basis for processing, one of which is explicit, informed consent from the data subject for a specific purpose. Answer A is correct. A vague 'business interest' without necessity and proportionality analysis (B) does not satisfy the legitimate interests basis. Public posting (C) does not constitute consent for further processing. A broad privacy policy (D) is not a lawful basis under GDPR.

Question 2

HIPAA's Privacy Rule primarily applies to which types of organizations?

  1. All organizations that collect any personally identifiable information from individuals.
  2. Organizations with annual revenue exceeding $10 million that handle patient data.
  3. State and local government health departments only.
  4. Covered entities such as healthcare providers, health plans, and healthcare clearinghouses, and their business associates. (correct answer)

Explanation: HIPAA's Privacy Rule applies specifically to covered entities (healthcare providers, health plans, clearinghouses) and their business associates who handle protected health information (PHI). Answer D is correct. HIPAA does not apply to all PII collectors (A), all organizations above a revenue threshold (B), or only government entities (C).

Question 3

Under GDPR, organizations must notify the relevant supervisory authority of a personal data breach within:

  1. 72 hours of becoming aware of the breach, where feasible. (correct answer)
  2. 30 days of the breach being discovered.
  3. 24 hours of the breach occurring.
  4. 7 business days of confirming the breach through a formal investigation.

Explanation: GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a breach, where feasible. This is one of the tightest breach notification requirements globally. Answer A is correct. 30 days (B), 24 hours (C), and 7 business days (D) are all incorrect timeframes.

Question 4

Which of the following data elements is classified as 'special category data' under GDPR, requiring heightened protection?

  1. An individual's email address and phone number.
  2. An individual's health information, biometric data, or racial/ethnic origin. (correct answer)
  3. An individual's employer name and job title.
  4. An individual's shipping address and purchase history.

Explanation: GDPR Article 9 defines special categories of data requiring stricter processing conditions, including health data, biometric data, genetic data, racial or ethnic origin, and similar sensitive categories. Answer B is correct. Email and phone (A), employer information (C), and purchase history (D) are personal data but not special category data under GDPR.

Question 5

A company's privacy notice fails to disclose the retention period for personal data collected from website visitors. Under GDPR, this most likely violates which requirement?

  1. The right to erasure, which requires organizations to delete data upon request.
  2. The data breach notification requirement.
  3. The requirement to appoint a Data Protection Officer.
  4. The transparency and right to information requirements, which mandate clear disclosure of how personal data will be used and retained. (correct answer)

Explanation: GDPR Articles 13 and 14 require organizations to provide data subjects with transparent information about data processing, including retention periods. Omitting this information violates transparency requirements. Answer D is correct. Right to erasure (A) is a separate right. Breach notification (B) is unrelated. DPO appointment (C) depends on organization type.

Question 6

Which of the following best describes the concept of 'Privacy by Design'?

  1. A reactive approach where privacy controls are added to systems after they are deployed.
  2. An approach in which privacy protections are embedded into the design and architecture of systems and processes from the outset. (correct answer)
  3. A privacy audit methodology conducted annually to assess compliance.
  4. A technical standard for encrypting personal data at rest and in transit.

Explanation: Privacy by Design, codified in GDPR Article 25, requires that data protection is considered and built into systems and processes from the earliest design stages rather than added as an afterthought. Answer B is correct. A reactive post-deployment approach (A) is the opposite of Privacy by Design. Annual audits (C) and encryption standards (D) are components of privacy programs but not the definition of Privacy by Design.

Question 7

Under GDPR, the 'right to erasure' (also known as the 'right to be forgotten') allows individuals to:

  1. Require organizations to correct inaccurate personal data about them.
  2. Access all personal data an organization holds about them.
  3. Restrict the processing of their personal data while a complaint is being investigated.
  4. Request deletion of their personal data when it is no longer necessary, consent is withdrawn, or other specified conditions are met. (correct answer)

Explanation: The right to erasure (GDPR Article 17) allows individuals to request deletion of their personal data under specific circumstances, including when the data is no longer needed or consent is withdrawn. Answer D is correct. Correcting inaccurate data (A) is the right to rectification. Accessing data (B) is the right of access. Restricting processing (C) is the right to restriction of processing.

Question 8

An organization's employee accidentally emails a file containing 50,000 customer records including names, addresses, and credit card numbers to an external party. Under GDPR, this event is best classified as:

  1. A personal data breach requiring assessment for supervisory authority notification within 72 hours and potential notification to affected data subjects. (correct answer)
  2. A minor operational error that requires only internal documentation.
  3. A security incident requiring only IT remediation with no regulatory reporting obligations.
  4. A breach requiring notification only if the data is subsequently misused.

Explanation: Unauthorized disclosure of personal data to an external party is a personal data breach under GDPR. Given the sensitivity (financial data) and volume (50,000 records), notification to the supervisory authority within 72 hours and likely to affected individuals is required. Answer A is correct. The number of affected individuals and data sensitivity preclude treating it as minor (B) or purely an IT matter (C). GDPR requires assessment and likely notification regardless of known misuse (D).

Question 9

Which of the following correctly describes the difference between 'data controller' and 'data processor' under GDPR?

  1. A data controller processes data on behalf of a data processor's instructions.
  2. A data processor determines the purposes and means of processing; a controller executes the processing.
  3. A data controller determines the purposes and means of processing personal data; a data processor processes data on behalf of the controller. (correct answer)
  4. Both terms refer to the same role under GDPR and may be used interchangeably.

Explanation: Under GDPR, the data controller decides why and how personal data is processed (the decision-maker). The data processor acts on the controller's behalf and instructions. Answer C is correct. Answers A and B reverse the roles. They are distinct roles with different responsibilities and liabilities (D).

Question 10

A company's privacy impact assessment (PIA) identifies that a new customer analytics system will process sensitive financial data at a large scale. Under GDPR, which additional requirement is most likely triggered?

  1. A Data Protection Impact Assessment (DPIA) must be completed before the processing begins. (correct answer)
  2. The company must register the system with its national tax authority.
  3. All data subjects must be individually notified before the system goes live.
  4. The system must use only on-premises infrastructure with no cloud components.

Explanation: GDPR Article 35 requires a DPIA when processing is likely to result in high risk to individuals, such as large-scale processing of sensitive financial data. The DPIA must be completed before processing begins. Answer A is correct. Tax authority registration (B) is unrelated. Individual notification before go-live (C) is not a GDPR requirement. Infrastructure restrictions (D) are not prescribed by GDPR.

Question 11

Under data privacy principles, 'storage limitation' requires that:

  1. Data must be stored in encrypted format at all times.
  2. Personal data must be stored in the country where the data subject resides.
  3. Personal data should be kept in a form that identifies individuals for no longer than necessary for the specified purpose. (correct answer)
  4. Storage systems must be audited annually by an independent third party.

Explanation: The storage limitation principle (GDPR Article 5(1)(e)) requires that personal data not be retained in identifiable form longer than necessary for its original purpose. Answer C is correct. Encryption (A) relates to data security. Data localization (B) is a separate concept not universally required by GDPR. Annual audits (D) are not the definition of storage limitation.

Question 12

Which of the following best describes the 'principle of integrity and confidentiality' under GDPR?

  1. Organizations must verify the accuracy of all personal data before processing it.
  2. Data subjects must be informed of all parties with whom their data is shared.
  3. Organizations must obtain separate consent for each category of personal data they process.
  4. Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized access, loss, or destruction. (correct answer)

Explanation: The integrity and confidentiality principle (GDPR Article 5(1)(f)) requires appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. Answer D is correct. Data accuracy (A) relates to the accuracy principle. Disclosure notifications (B) relate to transparency. Separate consent per category (C) is not a GDPR requirement.

Question 13

The privacy principle of 'purpose limitation' means that:

  1. Organizations must limit the number of purposes for which they collect data to no more than three.
  2. Personal data may only be retained for a limited period before being deleted.
  3. Personal data collected for one specified purpose should not be used for a different, incompatible purpose without additional consent or lawful basis. (correct answer)
  4. Organizations must limit access to personal data to a specific number of authorized employees.

Explanation: Purpose limitation requires that data be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Answer C is correct. There is no three-purpose limit (A). Retention limits (B) describe the storage limitation principle. Access limits (D) describe access control principles.

Question 14

A company transfers personal data of EU residents to a U.S.-based cloud provider. Under GDPR, which mechanism could legitimize this data transfer?

  1. Standard Contractual Clauses (SCCs) approved by the European Commission. (correct answer)
  2. A mutual nondisclosure agreement between the company and the cloud provider.
  3. The company's internal data governance policy stating that transfers are secure.
  4. An annual privacy audit conducted by the cloud provider.

Explanation: GDPR Chapter V restricts personal data transfers to third countries. Approved mechanisms include SCCs, adequacy decisions, and Binding Corporate Rules. Standard Contractual Clauses are the most commonly used mechanism for transfers to the U.S. Answer A is correct. NDAs (B), internal policies (C), and audits (D) are not GDPR-recognized transfer mechanisms.

Question 15

Under the principle of 'accountability' in GDPR, organizations are required to:

  1. Report all personal data processing activities to their national supervisory authority annually.
  2. Obtain board-level approval for all personal data processing activities.
  3. Demonstrate compliance with GDPR principles through documented policies, procedures, and records of processing activities. (correct answer)
  4. Publish their full data inventory on their public website.

Explanation: The accountability principle (GDPR Article 5(2)) requires controllers to not only comply with GDPR but to be able to demonstrate their compliance through documentation, policies, and records. Answer C is correct. Annual reporting to supervisory authorities (A) is not required. Board approval of all processing (B) is not required. Public disclosure of the full data inventory (D) is not required.

Question 16

The California Consumer Privacy Act (CCPA) grants California residents which of the following rights?

  1. The right to require organizations to delete all data about them within 24 hours of a request.
  2. The right to receive compensation for any collection of their personal data.
  3. The right to know what personal information is collected, the right to delete it, and the right to opt out of its sale. (correct answer)
  4. The right to prevent organizations from collecting any data without prior written consent.

Explanation: The CCPA grants California residents the right to know what personal information is collected and how it is used, the right to request deletion, and the right to opt out of the sale of their personal information. Answer C is correct. CCPA does not require 24-hour deletion (A), automatic compensation (B), or prior written consent for all data collection (D).

Question 17

A company collects biometric data from employees for building access control. Under GDPR, processing this data requires:

  1. Only a standard privacy notice informing employees of the collection.
  2. A specific lawful basis under Article 9 for special category data, such as explicit consent or necessity for employment law obligations. (correct answer)
  3. Approval from the national data protection authority before any processing begins.
  4. Anonymization of all biometric templates within 30 days of collection.

Explanation: Biometric data is a special category under GDPR Article 9, requiring a specific legal basis beyond the standard Article 6 bases - such as explicit consent or a basis under member state employment law. Answer B is correct. A standard privacy notice alone (A) is insufficient for special category data. Prior approval from authorities (C) is not a blanket requirement. 30-day anonymization (D) is not an GDPR requirement.

Question 18

Which of the following best describes 'pseudonymization' as a data protection technique under GDPR?

  1. Permanently deleting personal data so it can never be recovered.
  2. Encrypting personal data using a public key so only the data subject can decrypt it.
  3. Replacing all personal data fields with randomly generated codes that have no link to real identities.
  4. Processing personal data in a way that it can no longer be attributed to a specific individual without the use of additional information held separately. (correct answer)

Explanation: Pseudonymization replaces directly identifying information with a pseudonym while retaining the ability to re-identify using separately stored key data. This reduces risk while preserving some analytical utility. Answer D is correct. Permanent deletion (A) is anonymization. Public-key encryption (B) is a security technique. Completely random codes with no linkage (C) describes anonymization, not pseudonymization.

Question 19

A U.S.-based company receives a verifiable consumer request under CCPA to delete all personal information it has collected about the requestor. The company must respond within:

  1. 24 hours of receiving the request.
  2. 45 days of receiving the request, with the option to extend by an additional 45 days with notice. (correct answer)
  3. 90 days for requests involving financial or health data.
  4. 30 days with no extension permitted.

Explanation: CCPA requires businesses to respond to verifiable consumer requests within 45 days. If more time is needed, an extension of up to 45 additional days is permitted with notice to the consumer. Answer B is correct. 24 hours (A), 90 days (C), and 30 days with no extension (D) are all incorrect timeframes under CCPA.

Question 20

The General Data Protection Regulation (GDPR) applies to organizations that:

  1. Are headquartered within the European Union only.
  2. Process more than one million records per year regardless of location.
  3. Operate in industries handling financial data globally.
  4. Are established in the EU, or - if not established in the EU - offer goods or services to, or monitor the behavior of, individuals located in the EU. (correct answer)

Explanation: GDPR Article 3 establishes extraterritorial reach in two ways: it applies to organizations established in the EU (Article 3(1)), and to non-EU organizations that offer goods or services to, or monitor the behavior of, individuals located in the EU (Article 3(2)). Simply processing data of EU nationals outside this context is not sufficient to trigger GDPR. Answer D is correct. GDPR is not limited to EU-headquartered organizations alone (A), a transaction volume threshold (B), or financial industry organizations (C).