Question 1 of 10 · Privacy Program: Developing a Framework
Which is the purpose of a gap assessment against a framework?
A gap assessment compares current practices with requirements to prioritize work. It does not certify compliance.
Question 2 of 10 · Privacy Program: Establishing Program Governance
How should the privacy program report to senior leadership?
Regular reporting with risks, metrics and asks keeps leadership informed and engaged.
Question 3 of 10 · Privacy Program Operational Life Cycle: Assessing Data
What should a DPIA do if high risk remains after mitigation?
Under Article 36, if high residual risk remains, the controller consults the supervisory authority before processing.
Question 4 of 10 · Privacy Program Operational Life Cycle: Protecting Personal Data
What does encryption protect against in a lost laptop scenario?
Encryption at rest keeps data unreadable without the key; it does not prevent loss.
Question 5 of 10 · Privacy Program Operational Life Cycle: Sustaining Program Performance
What does a control self-assessment involve?
Self-assessments engage owners and complement independent audit.
Question 6 of 10 · Privacy Program Operational Life Cycle: Responding to Requests and Incidents
Why keep evidence of how a breach was contained?
Documentation supports accountability and defense.
Question 7 of 10 · Privacy Program: Developing a Framework
A privacy leader must justify the program's budget. What is the most persuasive approach?
Leaders fund programs that reduce risk and enable business, such as faster sales approvals or new markets. Comparisons, law lists and workload descriptions are less persuasive.
Question 8 of 10 · Privacy Program: Establishing Program Governance
What should happen when an employee repeatedly breaches privacy policy?
Policies need consistent consequences; regulator referral and public disclosure are not appropriate internal responses.
Question 9 of 10 · Privacy Program Operational Life Cycle: Assessing Data
What should a privacy assessment of a merger target check about past incidents?
Past incidents and enforcement indicate liabilities and program weaknesses.
Question 10 of 10 · Privacy Program Operational Life Cycle: Protecting Personal Data
How should consent be managed in systems?
Valid consent must be recorded and withdrawal honored.
0 of 10
Privacy Program: Developing a Framework
Privacy Program: Establishing Program Governance
Privacy Program Operational Life Cycle: Assessing Data
Privacy Program Operational Life Cycle: Protecting Personal Data
Privacy Program Operational Life Cycle: Sustaining Program Performance
Privacy Program Operational Life Cycle: Responding to Requests and Incidents
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.