ExamGecko
Question list
Search
Search

Related questions











Question 162 - CIPP-US discussion

Report
Export

The CFO of a pharmaceutical company is duped by a phishing email and discloses many of the company's employee personnel files to an online predator. The files include employee contact information, job applications, performance reviews, discipline records, and job descriptions.

Which of the following state laws would be an affected employee's best recourse against the employer?

A.

The state social security number confidentiality statute.

Answers
A.

The state social security number confidentiality statute.

B.

The state personnel record review statute.

Answers
B.

The state personnel record review statute.

C.

The state data destruction statute.

Answers
C.

The state data destruction statute.

D.

The state UDAP statute.

Answers
D.

The state UDAP statute.

Suggested answer: D

Explanation:

The state UDAP statute, which stands for Unfair and Deceptive Acts and Practices, is a law that protects consumers from unfair or deceptive business practices. In this case, the employer's failure to protect the employee's personal information from a phishing attack could be considered an unfair or deceptive act or practice that harmed the employee. The employee could sue the employer under the state UDAP statute for damages, injunctive relief, or other remedies. The other options are not relevant to this scenario, as they deal with different aspects of data protection, such as confidentiality, access, or destruction of personal information.Reference:

[IAPP CIPP/US Study Guide], Chapter 8, Section 8.3.1, page 227

IAPP CIPP/US Practice Questions, Question 153, page 13

asked 22/11/2024
Tomasz Kusmierek
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first