Michigan Data Privacy Compliance
Specialist Exam Practice Questions And
Correct Answers (Verified Answers) Plus
Rationale 2026 Q&A| Instant Download
Pdf
1. A data controller under the Michigan Comprehensive Data Protection
Act (CDPA) is responsible for:
A. Processing personal data solely on behalf of another controller
B. Determining the purposes and means of personal data processing
C. Ensuring compliance with data subject rights and privacy
obligations
D. Acting as a third-party service provider only
Rationale: The data controller decides why and how personal data is
processed and must fulfill compliance duties under the CDPA.
2. Under Michigan data privacy law, which of the following qualifies as
“sensitive data”?
A. Professional email address
B. Genetic or biometric information
C. Public business license number
D. Job title
Rationale: Sensitive data includes specific categories like biometric
and genetic information that require heightened protection.
3. The primary purpose of a privacy impact assessment (PIA) is to:
A. Replace legal counsel review
B. Evaluate risks to personal data in processing activities
C. Publicly disclose all internal security flaws
D. Audit employee performance
, Rationale: A PIA assesses how personal data processing affects
privacy and identifies risk mitigation measures.
4. A data subject makes a verified request to access their personal data.
Under the CDPA, the controller must respond within:
A. 5 business days
B. 15 business days
C. 30 business days
D. 45 business days
Rationale: Michigan’s CDPA mandates a 45-day timeframe for
responding to access requests unless an extension is properly
communicated.
5. Which principle requires that personal data collected should be
limited to what is necessary for the disclosed purpose?
A. Accountability
B. Transparency
C. Data minimization
D. Portability
Rationale: Data minimization focuses on collecting only data
necessary for specified, legitimate purposes.
6. Under Michigan law, a data protection officer (DPO) is:
A. Legally required for all organizations
B. Required when processing sensitive data at scale
C. Only optional advisory role
D. Equivalent to a CFO
Rationale: A DPO is required for certain processing activities,
especially involving sensitive data at scale.
7. A valid lawful basis for processing personal data under Michigan
privacy compliance includes:
A. Public posting of employee data without notice
B. Assumption of consent by inactivity
C. Explicit consent from the data subject
D. Anonymous data sharing with third parties
Rationale: Explicit consent is one recognized lawful basis for lawful
personal data processing.
, 8. What is the minimum age at which parental consent is required for
processing a minor’s personal data under CDPA?
A. 13
B. 16
C. 18
D. 21
Rationale: The CDPA defines minors as individuals under 16 for
purposes of consent requirements.
9. Data retention policies should ensure data is stored:
A. Forever, to avoid deletion disputes
B. Only in hard copy format
C. Only as long as necessary for processing purposes
D. Only with the data subject’s stored copy
Rationale: Retention must be limited to what is reasonably necessary
for legitimate business purposes.
10. Which entity enforces Michigan’s data privacy rules?
A. Federal Trade Commission only
B. Michigan Attorney General
C. Michigan Secretary of State
D. Local municipal office
Rationale: Enforcement authority for state privacy laws typically lies
with the state attorney general.
11. Consent under Michigan privacy law must be:
A. Implied by default settings
B. Freely given, specific, informed, and unambiguous
C. Communicated solely through marketing emails
D. Obtained after data processing
Rationale: Valid consent requires clear affirmative action with
informed choice before processing.
12. A controller must provide a data subject with a right to deletion
when:
A. Data subject has never existed
B. The controller wants to end retention early
C. The data subject withdraws consent and no legitimate exception
applies
Specialist Exam Practice Questions And
Correct Answers (Verified Answers) Plus
Rationale 2026 Q&A| Instant Download
1. A data controller under the Michigan Comprehensive Data Protection
Act (CDPA) is responsible for:
A. Processing personal data solely on behalf of another controller
B. Determining the purposes and means of personal data processing
C. Ensuring compliance with data subject rights and privacy
obligations
D. Acting as a third-party service provider only
Rationale: The data controller decides why and how personal data is
processed and must fulfill compliance duties under the CDPA.
2. Under Michigan data privacy law, which of the following qualifies as
“sensitive data”?
A. Professional email address
B. Genetic or biometric information
C. Public business license number
D. Job title
Rationale: Sensitive data includes specific categories like biometric
and genetic information that require heightened protection.
3. The primary purpose of a privacy impact assessment (PIA) is to:
A. Replace legal counsel review
B. Evaluate risks to personal data in processing activities
C. Publicly disclose all internal security flaws
D. Audit employee performance
, Rationale: A PIA assesses how personal data processing affects
privacy and identifies risk mitigation measures.
4. A data subject makes a verified request to access their personal data.
Under the CDPA, the controller must respond within:
A. 5 business days
B. 15 business days
C. 30 business days
D. 45 business days
Rationale: Michigan’s CDPA mandates a 45-day timeframe for
responding to access requests unless an extension is properly
communicated.
5. Which principle requires that personal data collected should be
limited to what is necessary for the disclosed purpose?
A. Accountability
B. Transparency
C. Data minimization
D. Portability
Rationale: Data minimization focuses on collecting only data
necessary for specified, legitimate purposes.
6. Under Michigan law, a data protection officer (DPO) is:
A. Legally required for all organizations
B. Required when processing sensitive data at scale
C. Only optional advisory role
D. Equivalent to a CFO
Rationale: A DPO is required for certain processing activities,
especially involving sensitive data at scale.
7. A valid lawful basis for processing personal data under Michigan
privacy compliance includes:
A. Public posting of employee data without notice
B. Assumption of consent by inactivity
C. Explicit consent from the data subject
D. Anonymous data sharing with third parties
Rationale: Explicit consent is one recognized lawful basis for lawful
personal data processing.
, 8. What is the minimum age at which parental consent is required for
processing a minor’s personal data under CDPA?
A. 13
B. 16
C. 18
D. 21
Rationale: The CDPA defines minors as individuals under 16 for
purposes of consent requirements.
9. Data retention policies should ensure data is stored:
A. Forever, to avoid deletion disputes
B. Only in hard copy format
C. Only as long as necessary for processing purposes
D. Only with the data subject’s stored copy
Rationale: Retention must be limited to what is reasonably necessary
for legitimate business purposes.
10. Which entity enforces Michigan’s data privacy rules?
A. Federal Trade Commission only
B. Michigan Attorney General
C. Michigan Secretary of State
D. Local municipal office
Rationale: Enforcement authority for state privacy laws typically lies
with the state attorney general.
11. Consent under Michigan privacy law must be:
A. Implied by default settings
B. Freely given, specific, informed, and unambiguous
C. Communicated solely through marketing emails
D. Obtained after data processing
Rationale: Valid consent requires clear affirmative action with
informed choice before processing.
12. A controller must provide a data subject with a right to deletion
when:
A. Data subject has never existed
B. The controller wants to end retention early
C. The data subject withdraws consent and no legitimate exception
applies