ExamGecko
Question list
Search
Search

Related questions











Question 134 - CIPP-US discussion

Report
Export

Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusing on placing privacy professionals in roles at major companies. Job candidates create online profiles outlining their experience and credentials, and can pay $19.99/month via credit card to have their profiles promoted to potential employers. Privacy Is Hiring Inc. keeps all customer data at rest encrypted on its servers.

Under what circumstances would Privacy Is Hiring Inc., need to notify affected individuals in the event of a data breach?

A.

If law enforcement has completed its investigation and has authorized Privacy Is Hiring Inc. to provide the notification to clients and applicable regulators.

Answers
A.

If law enforcement has completed its investigation and has authorized Privacy Is Hiring Inc. to provide the notification to clients and applicable regulators.

B.

If the job candidates' credit card information and the encryption keys were among the information taken.

Answers
B.

If the job candidates' credit card information and the encryption keys were among the information taken.

C.

If Privacy Is Hiring Inc., reasonably believes that job candidates will be harmed by the data breach.

Answers
C.

If Privacy Is Hiring Inc., reasonably believes that job candidates will be harmed by the data breach.

D.

If the personal information stolen included the individuals' names and credit card pin numbers.

Answers
D.

If the personal information stolen included the individuals' names and credit card pin numbers.

Suggested answer: B

Explanation:

Under the California Consumer Privacy Act (CCPA), a business that collects personal information of California residents must notify them of a data breach if their personal information is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of the duty to implement and maintain reasonable security procedures and practices. However, the CCPA excludes encrypted or redacted personal information from the definition of personal information, unless the encryption key or security credential is also compromised. Therefore, Privacy Is Hiring Inc. would need to notify the affected individuals only if the encryption keys were also taken along with the credit card information, as this would render the encryption ineffective and expose the personal information to unauthorized access. The other options are not relevant to the CCPA notification requirement, although they may be relevant to other laws or best practices.Reference:CCPA(Section 1798.150),IAPP CIPP/US Study Guide(p. 63-64)

asked 22/11/2024
Mark Anthony Simon
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first