Privacy Governance
Drill 20 practice questions focused entirely on Privacy Governance for the ISACA CDPSE exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A privacy engineer reviewing a data governance program finds that a customer analytics data set is stored in a cloud data warehouse managed by the IT infrastructure team, populated by the marketing department, and analyzed by the data science team. When a data subject requests deletion of their personal data, no group takes responsibility for authorizing and executing the deletion, and each team points to the others. Which action would BEST address the underlying governance gap?
A software company is developing a new customer analytics platform that will process personal data. The privacy officer wants to ensure privacy considerations are built into the product from the outset rather than added later. At which point in the development lifecycle should privacy requirements FIRST be integrated to best align with privacy-by-design principles?
A retail company relies on customer consent as the legal basis for its email marketing program. During a privacy program review, the privacy engineer discovers that while customers can grant consent easily during checkout, there is no straightforward way for them to withdraw that consent later, and marketing continues until a customer files a formal complaint. Which action best aligns the program with core privacy principles governing consent?
A multinational retailer is establishing formal privacy governance. Privacy responsibilities are currently scattered across legal, IT security, marketing, and HR, resulting in inconsistent decisions and duplicated efforts. The newly appointed privacy leader wants a sustainable structure to coordinate privacy decisions across these functions while ensuring decisions remain aligned with the organization's overall privacy strategy. Which action BEST addresses this need?
A cloud payroll provider that processes employee personal data on behalf of your organization notifies you that one of its subcontractors experienced a data breach affecting your employees' records. As the privacy solutions engineer coordinating your organization's incident management process, what should be your FIRST priority upon receiving this notification?
A privacy engineer at a healthcare technology company discovers that an internal analytics dashboard accidentally exposed a subset of customer records containing names, email addresses, and appointment histories to a group of employees who had no legitimate business need to access them. No external party accessed the data, and access was revoked within an hour. The privacy incident response plan is being invoked. What should the privacy team do FIRST?
A privacy officer must present the organization's privacy program status to the board of directors on a quarterly basis. The board has expressed frustration that prior reports were highly technical and did not help them understand whether privacy risk was being managed effectively. Which approach should the privacy officer take to BEST demonstrate the value and effectiveness of the privacy program to the board?
A multinational retailer is drafting its enterprise privacy policy to support operations across several jurisdictions with differing privacy laws (GDPR, CCPA, and others). The privacy officer wants the policy to be durable and not require rewriting each time a minor regulatory change occurs. Which approach should the privacy officer take when developing the corporate privacy policy?
A data protection authority sends a formal inquiry to a mid-sized company, asking it to demonstrate how its processing of customer personal data complies with applicable privacy law. The company has strong technical controls and a published privacy policy, but its privacy manager struggles to produce evidence of decision-making, data flows, and control effectiveness on demand. Which privacy principle is the company failing to operationalize?
A retail company's marketing team wants to launch a loyalty program. During design review, the privacy officer notices the sign-up form requests date of birth, home address, government ID number, and household income — but the program's stated purpose is only to award points for purchases and send promotional offers. Which privacy principle should the privacy officer invoke to challenge the proposed data collection?
A retail company originally collected customer email addresses solely to send order confirmations and shipping updates. The marketing department now wants to use those same email addresses to send promotional newsletters and personalized product recommendations. As the privacy solutions engineer advising on this request, which privacy principle is most directly at risk, and what is the appropriate first action?
A privacy officer at a mid-sized healthcare company is establishing a formal privacy program. The organization already maintains a mature information security program aligned to ISO 27001 and an established enterprise risk management (ERM) process. To operationalize the privacy program most efficiently while ensuring accountability and reducing duplication, what should the privacy officer do FIRST?
A multinational retailer established its privacy policy suite three years ago. Since then, two new regional privacy laws have taken effect, the company launched a loyalty program with behavioral analytics, and it acquired a subsidiary in another country. During an internal audit, the privacy officer discovers the policies have not been updated since publication. What should the privacy officer recommend as the MOST effective long-term corrective action?
A global retailer has an approved, board-endorsed privacy policy that commits the organization to honoring data subject access requests (DSARs) within regulatory timelines. Six months later, an internal audit finds that DSARs are handled inconsistently across regions, some are missed, and staff are unsure who is responsible for fulfilling them. The privacy policy itself is clear and current. What is the MOST likely root cause the privacy manager should address?
A newly appointed privacy program manager at a mid-sized financial services firm is chartering the privacy program. The firm operates several business units, uses numerous SaaS tools, and has recently acquired a smaller company that has not yet been integrated. The manager must define the initial scope of the privacy program. What is the MOST important consideration when establishing the program's scope?
A retail company headquartered in Brazil operates only physical stores domestically but launches a new e-commerce website that ships internationally and accepts orders from customers located in the European Union. The privacy officer is determining which legal obligations now apply to the company's processing activities. Which of the following BEST describes the company's regulatory exposure?
A mid-sized organization subject to GDPR appoints a Data Protection Officer (DPO). To save on headcount, senior management asks the DPO to also lead the marketing analytics team, which determines how customer data is processed for targeted campaigns. The DPO would report directly to the Chief Marketing Officer. As the privacy solutions engineer advising on governance, which concern should you raise as the MOST significant?
A global retailer is formalizing its privacy program. The privacy strategy has executive sponsorship, and a cross-functional committee exists. However, during a recent data subject access request, no one could determine who was responsible for locating the data, who approved the response, and who was ultimately accountable if the request was mishandled. The privacy officer wants to prevent this ambiguity across all privacy activities. Which action would MOST effectively address the root cause?
A privacy engineer is asked by the CISO to help justify budget for a new enterprise encryption and access-control initiative. The CISO argues that once these security controls are fully deployed, the organization's privacy obligations will be substantially met. How should the privacy engineer BEST characterize the relationship between privacy and security to executive leadership?
A privacy engineer is defining the working relationship between the privacy office and the information security team for a new customer analytics platform. Security has proposed that, because they already enforce access controls, logging, and encryption, they should assume full accountability for all data protection decisions, including determining what personal data may be processed and for what purposes. How should the privacy engineer respond to best reflect the proper relationship between privacy and security?
More CDPSE practice
Keep going with the other ISACA CDPSE — Certified Data Privacy Solutions Engineer domains, or take a full timed mock exam.
← Back to CDPSE overview