CPA Quiz: Apply Data Privacy Principles And Regulations
20 questions · exam conditions
0:00
Apply Data Privacy Principles And RegulationsQuestion 1 of 20

A retailer operates loyalty programs in California and collects customer purchase history. Under CCPA, if the retailer sells this data to third-party advertisers, it must:

Obtain explicit written consent from each customer before any data sale.
Encrypt all purchase history data before transferring it to advertisers.
Provide customers with a clear opt-out mechanism and disclose that their data is sold, such as a 'Do Not Sell My Personal Information' link.
Delete all purchase history data within 12 months of collection.
← Back to quizzes

CPA Quiz

CPA Quiz: Apply Data Privacy Principles And Regulations

Practice Apply Data Privacy Principles And Regulations in CPA with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Apply Data Privacy Principles And Regulations, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

A retailer operates loyalty programs in California and collects customer purchase history. Under CCPA, if the retailer sells this data to third-party advertisers, it must:

  1. Obtain explicit written consent from each customer before any data sale.
  2. Encrypt all purchase history data before transferring it to advertisers.
  3. Provide customers with a clear opt-out mechanism and disclose that their data is sold, such as a 'Do Not Sell My Personal Information' link. (correct answer)
  4. Delete all purchase history data within 12 months of collection.
Explanation: CCPA requires businesses that sell personal information to disclose this practice and provide a prominent opt-out mechanism, such as the 'Do Not Sell My Personal Information' link. Answer C is correct. CCPA does not require explicit opt-in consent for data sales (A), encryption of sold data (B), or 12-month deletion (D).

Question 2

Under GDPR, a Data Protection Officer (DPO) is required when:

  1. Any organization collects personal data from more than 100 individuals.
  2. The organization is a public authority, or its core activities involve large-scale systematic monitoring of individuals or large-scale processing of special categories of data. (correct answer)
  3. The organization operates in more than one EU member state.
  4. The organization's annual revenue exceeds €50 million.
Explanation: GDPR Article 37 requires a DPO for public authorities, organizations conducting large-scale systematic monitoring, and those processing large-scale special category data (e.g., health, biometric). Answer B is correct. The threshold is not based on number of data subjects (A), multi-country operations (C), or revenue (D).

Question 3

A billing clerk faxes an entire medical record to a payer when only diagnosis codes are needed. This violates HIPAA's:

  1. Consent and authorization rule
  2. Minimum necessary standard (correct answer)
  3. Notice of privacy practices
  4. Accounting of disclosures rule
Explanation: HIPAA's minimum necessary standard requires you to disclose only the least amount of protected health information needed for the purpose. Faxing the whole record when diagnosis codes alone would satisfy the payer violates that standard. The tempting wrong answer is the consent and authorization rule, but that concerns patient permission; here the disclosure was permissible but you sent too much.

Question 4

A bank keeps IP logs after account closure solely to detect fraud. Under GDPR, which basis supports this?

  1. Legitimate interest, balanced (correct answer)
  2. Consent at account opening
  3. Contract performance duty
  4. Task in the public interest
Explanation: After account closure the contract no longer requires processing, and consent would need a fresh, specific opt-in. The bank's need to keep IP logs to detect fraud is therefore a legitimate interest, provided the balancing test shows it does not override your privacy rights. The tempting wrong answer is contract performance, but that basis ends with the account relationship.

Question 5

An EU company hires an unrelated cloud provider in a country with no adequacy decision. Which GDPR mechanism applies?

  1. Privacy Shield certification
  2. Binding corporate rules (BCRs)
  3. Explicit consent of the user
  4. Standard contractual clauses (correct answer)
Explanation: The cloud provider is an unrelated recipient in a country with no adequacy decision, so you need a GDPR transfer mechanism that works between separate companies. Standard contractual clauses provide that safeguard. Binding corporate rules are the tempting wrong choice, but they only cover intra-group transfers, not an outside provider.

Question 6

Store shares past purchase history with an insurer for underwriting after order fulfillment. This violates GDPR's:

  1. Data minimization
  2. Purpose limitation (correct answer)
  3. Storage limitation
  4. Accuracy principle
Explanation: Purchase history was collected to fulfill your order, so sharing it with an insurer for underwriting is a different, incompatible purpose. That is the core prohibition of purpose limitation. Data minimization is tempting because the sharing seems excessive, but the decisive flaw is the new purpose, not the amount of data shared.

Question 7

A data broker buys users' location history from an app and pays with analytics services, not cash. Under CCPA, this is:

  1. A share; no cash changed hands
  2. A business-purpose disclosure
  3. A sale; analytics have value (correct answer)
  4. An exempt business transfer
Explanation: Paying with analytics services is valuable consideration, and CCPA defines a sale as transferring personal information for monetary or other valuable consideration. Cash isn't required, so this is a sale. The tempting wrong answer is 'a share; no cash changed hands' - a share does not apply because the transaction is an exchange for value, and lack of cash doesn't make it exempt.

Question 8

Under GDPR, organizations must notify the relevant supervisory authority of a personal data breach within:

  1. 72 hours of becoming aware of the breach, where feasible. (correct answer)
  2. 30 days of the breach being discovered.
  3. 24 hours of the breach occurring.
  4. 7 business days of confirming the breach through a formal investigation.
Explanation: GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a breach, where feasible. This is one of the tightest breach notification requirements globally. Answer A is correct. 30 days (B), 24 hours (C), and 7 business days (D) are all incorrect timeframes.

Question 9

An organization's employee accidentally emails a file containing 50,000 customer records including names, addresses, and credit card numbers to an external party. Under GDPR, this event is best classified as:

  1. A personal data breach requiring assessment for supervisory authority notification within 72 hours and potential notification to affected data subjects. (correct answer)
  2. A minor operational error that requires only internal documentation.
  3. A security incident requiring only IT remediation with no regulatory reporting obligations.
  4. A breach requiring notification only if the data is subsequently misused.
Explanation: Unauthorized disclosure of personal data to an external party is a personal data breach under GDPR. Given the sensitivity (financial data) and volume (50,000 records), notification to the supervisory authority within 72 hours and likely to affected individuals is required. Answer A is correct. The number of affected individuals and data sensitivity preclude treating it as minor (B) or purely an IT matter (C). GDPR requires assessment and likely notification regardless of known misuse (D).

Question 10

A company's privacy impact assessment (PIA) identifies that a new customer analytics system will process sensitive financial data at a large scale. Under GDPR, which additional requirement is most likely triggered?

  1. A Data Protection Impact Assessment (DPIA) must be completed before the processing begins. (correct answer)
  2. The company must register the system with its national tax authority.
  3. All data subjects must be individually notified before the system goes live.
  4. The system must use only on-premises infrastructure with no cloud components.
Explanation: GDPR Article 35 requires a DPIA when processing is likely to result in high risk to individuals, such as large-scale processing of sensitive financial data. The DPIA must be completed before processing begins. Answer A is correct. Tax authority registration (B) is unrelated. Individual notification before go-live (C) is not a GDPR requirement. Infrastructure restrictions (D) are not prescribed by GDPR.

Question 11

Under data privacy principles, 'storage limitation' requires that:

  1. Data must be stored in encrypted format at all times.
  2. Personal data must be stored in the country where the data subject resides.
  3. Personal data should be kept in a form that identifies individuals for no longer than necessary for the specified purpose. (correct answer)
  4. Storage systems must be audited annually by an independent third party.
Explanation: The storage limitation principle (GDPR Article 5(1)(e)) requires that personal data not be retained in identifiable form longer than necessary for its original purpose. Answer C is correct. Encryption (A) relates to data security. Data localization (B) is a separate concept not universally required by GDPR. Annual audits (D) are not the definition of storage limitation.

Question 12

Which of the following best describes the 'principle of integrity and confidentiality' under GDPR?

  1. Organizations must verify the accuracy of all personal data before processing it.
  2. Data subjects must be informed of all parties with whom their data is shared.
  3. Organizations must obtain separate consent for each category of personal data they process.
  4. Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized access, loss, or destruction. (correct answer)
Explanation: The integrity and confidentiality principle (GDPR Article 5(1)(f)) requires appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage. Answer D is correct. Data accuracy (A) relates to the accuracy principle. Disclosure notifications (B) relate to transparency. Separate consent per category (C) is not a GDPR requirement.

Question 13

A company transfers personal data of EU residents to a U.S.-based cloud provider. Under GDPR, which mechanism could legitimize this data transfer?

  1. Standard Contractual Clauses (SCCs) approved by the European Commission. (correct answer)
  2. A mutual nondisclosure agreement between the company and the cloud provider.
  3. The company's internal data governance policy stating that transfers are secure.
  4. An annual privacy audit conducted by the cloud provider.
Explanation: GDPR Chapter V restricts personal data transfers to third countries. Approved mechanisms include SCCs, adequacy decisions, and Binding Corporate Rules. Standard Contractual Clauses are the most commonly used mechanism for transfers to the U.S. Answer A is correct. NDAs (B), internal policies (C), and audits (D) are not GDPR-recognized transfer mechanisms.

Question 14

The California Consumer Privacy Act (CCPA) grants California residents which of the following rights?

  1. The right to require organizations to delete all data about them within 24 hours of a request.
  2. The right to receive compensation for any collection of their personal data.
  3. The right to know what personal information is collected, the right to delete it, and the right to opt out of its sale. (correct answer)
  4. The right to prevent organizations from collecting any data without prior written consent.
Explanation: The CCPA grants California residents the right to know what personal information is collected and how it is used, the right to request deletion, and the right to opt out of the sale of their personal information. Answer C is correct. CCPA does not require 24-hour deletion (A), automatic compensation (B), or prior written consent for all data collection (D).

Question 15

A company collects biometric data from employees for building access control. Under GDPR, processing this data requires:

  1. Only a standard privacy notice informing employees of the collection.
  2. A specific lawful basis under Article 9 for special category data, such as explicit consent or necessity for employment law obligations. (correct answer)
  3. Approval from the national data protection authority before any processing begins.
  4. Anonymization of all biometric templates within 30 days of collection.
Explanation: Biometric data is a special category under GDPR Article 9, requiring a specific legal basis beyond the standard Article 6 bases - such as explicit consent or a basis under member state employment law. Answer B is correct. A standard privacy notice alone (A) is insufficient for special category data. Prior approval from authorities (C) is not a blanket requirement. 30-day anonymization (D) is not an GDPR requirement.

Question 16

HIPAA's Privacy Rule primarily applies to which types of organizations?

  1. All organizations that collect any personally identifiable information from individuals.
  2. Organizations with annual revenue exceeding $10 million that handle patient data.
  3. State and local government health departments only.
  4. Covered entities such as healthcare providers, health plans, and healthcare clearinghouses, and their business associates. (correct answer)
Explanation: HIPAA's Privacy Rule applies specifically to covered entities (healthcare providers, health plans, clearinghouses) and their business associates who handle protected health information (PHI). Answer D is correct. HIPAA does not apply to all PII collectors (A), all organizations above a revenue threshold (B), or only government entities (C).

Question 17

Which of the following data elements is classified as 'special category data' under GDPR, requiring heightened protection?

  1. An individual's email address and phone number.
  2. An individual's health information, biometric data, or racial/ethnic origin. (correct answer)
  3. An individual's employer name and job title.
  4. An individual's shipping address and purchase history.
Explanation: GDPR Article 9 defines special categories of data requiring stricter processing conditions, including health data, biometric data, genetic data, racial or ethnic origin, and similar sensitive categories. Answer B is correct. Email and phone (A), employer information (C), and purchase history (D) are personal data but not special category data under GDPR.

Question 18

A company's privacy notice fails to disclose the retention period for personal data collected from website visitors. Under GDPR, this most likely violates which requirement?

  1. The right to erasure, which requires organizations to delete data upon request.
  2. The data breach notification requirement.
  3. The requirement to appoint a Data Protection Officer.
  4. The transparency and right to information requirements, which mandate clear disclosure of how personal data will be used and retained. (correct answer)
Explanation: GDPR Articles 13 and 14 require organizations to provide data subjects with transparent information about data processing, including retention periods. Omitting this information violates transparency requirements. Answer D is correct. Right to erasure (A) is a separate right. Breach notification (B) is unrelated. DPO appointment (C) depends on organization type.

Question 19

Which of the following best describes the concept of 'Privacy by Design'?

  1. A reactive approach where privacy controls are added to systems after they are deployed.
  2. An approach in which privacy protections are embedded into the design and architecture of systems and processes from the outset. (correct answer)
  3. A privacy audit methodology conducted annually to assess compliance.
  4. A technical standard for encrypting personal data at rest and in transit.
Explanation: Privacy by Design, codified in GDPR Article 25, requires that data protection is considered and built into systems and processes from the earliest design stages rather than added as an afterthought. Answer B is correct. A reactive post-deployment approach (A) is the opposite of Privacy by Design. Annual audits (C) and encryption standards (D) are components of privacy programs but not the definition of Privacy by Design.

Question 20

Under GDPR, the 'right to erasure' (also known as the 'right to be forgotten') allows individuals to:

  1. Require organizations to correct inaccurate personal data about them.
  2. Access all personal data an organization holds about them.
  3. Restrict the processing of their personal data while a complaint is being investigated.
  4. Request deletion of their personal data when it is no longer necessary, consent is withdrawn, or other specified conditions are met. (correct answer)
Explanation: The right to erasure (GDPR Article 17) allows individuals to request deletion of their personal data under specific circumstances, including when the data is no longer needed or consent is withdrawn. Answer D is correct. Correcting inaccurate data (A) is the right to rectification. Accessing data (B) is the right of access. Restricting processing (C) is the right to restriction of processing.