ExamGecko
Question list
Search
Search

Related questions











Question 131 - CIPP-US discussion

Report
Export

SCENARIO

Please use the following to answer the next QUESTION

Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asia. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.

Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.

The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.

What can Otto do to most effectively minimize the privacy risks involved in using a cloud provider for the HR data?

A.

Request that the Board sign off in a written document on the choice of cloud provider.

Answers
A.

Request that the Board sign off in a written document on the choice of cloud provider.

B.

Ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit.

Answers
B.

Ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit.

C.

Obtain express consent from employees for storing the HR data in the cloud and keep a record of the employee consents.

Answers
C.

Obtain express consent from employees for storing the HR data in the cloud and keep a record of the employee consents.

D.

Negotiate a Business Associate Agreement with the cloud provider to protect any health-related data employees might share with Filtration Station.

Answers
D.

Negotiate a Business Associate Agreement with the cloud provider to protect any health-related data employees might share with Filtration Station.

Suggested answer: B

Explanation:

The best way for Otto to minimize the privacy risks involved in using a cloud provider for the HR data is to ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit. This would allow Otto to verify that the cloud provider has implemented adequate security measures, such as encryption, access controls, and backup systems, to protect the HR data from unauthorized access, use, or disclosure. It would also allow Otto to check that the cloud provider is complying with the applicable privacy laws and regulations, such as the CCPA, the APEC Privacy Framework, and the breach notification requirements. By conducting an on-site audit, Otto can identify any gaps or weaknesses in the cloud provider's privacy practices and address them promptly. This would also demonstrate due diligence and accountability on the part of Filtration Station, which could mitigate the legal and reputational consequences of a data breach.Reference:

[IAPP CIPP/US Study Guide], Chapter 3: Data Assessments, pp. 77-78.

IAPP CIPP/US Body of Knowledge, Section III: Government and Court Access to Private-sector Information, Subsection B: Cross-Border Data Transfer, Topic 2: APEC Privacy Framework.

IAPP CIPP/US Practice Questions, Question 125.

asked 22/11/2024
Alvin Thomas
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first