CIPT Practice Questions with Correct Answers
Privacy professionals
Responsible for a company's overall privacy program. They define the privacy policies,
standards, guidelines, auditing and controls. They ensure people are trained on privacy
policies, and they manage relationships with internal and external data handlers.
Information security professionals
Who is responsible for ensuring all data assets, including personal information, are
appropriately safeguarded. They define information security policies, standards, guidelines,
auditing and controls. They make sure people are trained on information security policies.
Company executives
empower privacy programs through their words and actions.
Lawyers
create privacy statements, write contracts, ensure compliance with laws and regulations and
address formal inquiries from regulators.
Marketers
develop email campaigns and web content. They handle customer information gathered from
online registrations and face-to-face events.
Public relations personnel
promote a company's commitment to privacy, communicate responses to privacy incidents,
and help minimize any backlash from the incident.
Human resources personnel
,are responsible for keeping employee information confidential.
All employees
privacy ambassadors who are responsible for ensuring your organization's privacy policies
are followed.
Internal standards
What should be in place to cover the proper classification, collection, storage, usage, sharing
and disposal of the data?
Training
What should cover proper notification, collection, storage, access, processing, sharing and
retention procedures for data
Privacy
The "what" of data protection. It governs policies for the entire data lifecycle including
collection, usage, sharing and retention. Provides the strategy.
Information Security
The "how" of data protection. It protects the confidentiality, integrity and availability of data
by restricting physical and logical access to sensitive information during its collection,
storage, and transmission. Provides the tactics
Privacy Impact Assessment (PIA)
A risk management tool you can use to help develop and advance your strategy by
identifying gaps in privacy coverage and determining how to address them.
Why perform a PIA?
,to verify that a new or existing product, service, data handling practice or other business
process adheres to all appropriate privacy laws, regulations, self-regulatory commitments and
organizational policies.
When to perform a PIA?
Early and upon changes to the methods in which data is handled or anytime there is a
significant change to your environment.
Four Stages of execution for PIA
Preparation
Data Analysis
Privacy Assessment
Reporting
Preparation Phase
An initial analysis is performed to determine whether a PIA is required by law or as a best
practice. Staffing resources are identified, and timelines are drafted for completing both the
initial analysis and the PIA.
Data Analysis Phase
During this stage, the handling of personal information is analyzed and documented. A data
flow diagram can be helpful in documenting where data is collected, which teams within the
organization get access to it, and whether it is shared externally.
Privacy Assessment Phase
Stage during which risks and vulnerabilities to privacy, including legal and regulatory
requirements, are identified and documented.
, Reporting Phase
Phase where discovered risks and vulnerabilities are evaluated, and an attempt is made to
identify remedies. The rationale for selected courses of action is documented in the report.
Privacy Policy
a guiding set of principles intended to help the people in your organization understand and
manage any privacy obligations they encounter in their daily work.
Privacy Policies should cover:
• the types of data classification to use
• data collection principles
• how to protect data
• data retention periods
• the treatment of sensitive data
• sharing of data with across departments and with partners or vendors
• the creation of departmental privacy policies
• the performance of privacy reviews
• participation in a privacy response center
• responding to privacy inquiries
• and responding to data requests
Data handling activities
include commitments made within your organization's privacy notice.
Privacy notices
inform website visitors about requirements regarding the use of the website. They also spell
out the organization's standards for use of the consumer's personal information.
Privacy professionals
Responsible for a company's overall privacy program. They define the privacy policies,
standards, guidelines, auditing and controls. They ensure people are trained on privacy
policies, and they manage relationships with internal and external data handlers.
Information security professionals
Who is responsible for ensuring all data assets, including personal information, are
appropriately safeguarded. They define information security policies, standards, guidelines,
auditing and controls. They make sure people are trained on information security policies.
Company executives
empower privacy programs through their words and actions.
Lawyers
create privacy statements, write contracts, ensure compliance with laws and regulations and
address formal inquiries from regulators.
Marketers
develop email campaigns and web content. They handle customer information gathered from
online registrations and face-to-face events.
Public relations personnel
promote a company's commitment to privacy, communicate responses to privacy incidents,
and help minimize any backlash from the incident.
Human resources personnel
,are responsible for keeping employee information confidential.
All employees
privacy ambassadors who are responsible for ensuring your organization's privacy policies
are followed.
Internal standards
What should be in place to cover the proper classification, collection, storage, usage, sharing
and disposal of the data?
Training
What should cover proper notification, collection, storage, access, processing, sharing and
retention procedures for data
Privacy
The "what" of data protection. It governs policies for the entire data lifecycle including
collection, usage, sharing and retention. Provides the strategy.
Information Security
The "how" of data protection. It protects the confidentiality, integrity and availability of data
by restricting physical and logical access to sensitive information during its collection,
storage, and transmission. Provides the tactics
Privacy Impact Assessment (PIA)
A risk management tool you can use to help develop and advance your strategy by
identifying gaps in privacy coverage and determining how to address them.
Why perform a PIA?
,to verify that a new or existing product, service, data handling practice or other business
process adheres to all appropriate privacy laws, regulations, self-regulatory commitments and
organizational policies.
When to perform a PIA?
Early and upon changes to the methods in which data is handled or anytime there is a
significant change to your environment.
Four Stages of execution for PIA
Preparation
Data Analysis
Privacy Assessment
Reporting
Preparation Phase
An initial analysis is performed to determine whether a PIA is required by law or as a best
practice. Staffing resources are identified, and timelines are drafted for completing both the
initial analysis and the PIA.
Data Analysis Phase
During this stage, the handling of personal information is analyzed and documented. A data
flow diagram can be helpful in documenting where data is collected, which teams within the
organization get access to it, and whether it is shared externally.
Privacy Assessment Phase
Stage during which risks and vulnerabilities to privacy, including legal and regulatory
requirements, are identified and documented.
, Reporting Phase
Phase where discovered risks and vulnerabilities are evaluated, and an attempt is made to
identify remedies. The rationale for selected courses of action is documented in the report.
Privacy Policy
a guiding set of principles intended to help the people in your organization understand and
manage any privacy obligations they encounter in their daily work.
Privacy Policies should cover:
• the types of data classification to use
• data collection principles
• how to protect data
• data retention periods
• the treatment of sensitive data
• sharing of data with across departments and with partners or vendors
• the creation of departmental privacy policies
• the performance of privacy reviews
• participation in a privacy response center
• responding to privacy inquiries
• and responding to data requests
Data handling activities
include commitments made within your organization's privacy notice.
Privacy notices
inform website visitors about requirements regarding the use of the website. They also spell
out the organization's standards for use of the consumer's personal information.