Skip to content

CISSP Certification Guide / Chapter 9

Privacy and Data Protection

Privacy as a claim of the person rather than a property of data, the PII and personal data vocabulary from NIST SP 800-122 and the GDPR, the principle stack from the OECD Guidelines to GDPR Article 5, the GDPR's roles and mechanics, the American sectoral patchwork from HIPAA to CCPA, and the privacy impact assessment as the engine of the program.

Privacy is a claim, not a property

Picture two systems side by side. Both store customer records, both encrypt everything at rest and in transit, both log every access, and both pass the most demanding confidentiality audit you can imagine. In the first system, the data was collected with a consent screen that said what it meant, used only for the purpose that was stated at collection, shared only with partners the customer had been told about, and scheduled for deletion when the purpose ended. In the second, identical in every technical respect, the data was swept in by pre-checked boxes nobody read, used for purposes that were never mentioned on the same page, disclosed to vendors the customers had never heard of, and kept on a backup server for years after any legitimate need had ended.

The two systems have the same security posture. They do not have the same privacy posture. If a regulator or a court asks questions, the first has a paper trail that answers every one of them. The second is a violation factory even though no byte was ever stolen. That contrast is the organizing idea of this chapter, and it is the idea the exam tests whenever a question is really about privacy: privacy is a claim held by a person about how information about that person may be collected, used, disclosed, and retained. Confidentiality is a property of information about who may read it. The two overlap constantly, but they are not the same thing, and a candidate who collapses them together will misread half of the privacy questions on the exam.

This chapter sits in the asset security domain because privacy operates on the assets classified in Chapter 8. The inventory named the data; the classification labeled it; this chapter asks what the label means for a human being. It moves through the material in six movements: the privacy and confidentiality distinction, the vocabulary that defines personal data and its special categories, the principle stack that runs from the OECD Guidelines through the GDPR’s Article 5, the GDPR itself as the reference law that every other regime is compared against, the American sectoral laws that govern health, finance, education, children, and California, and finally the privacy impact assessment, the practical engine that turns principles into decisions.

The person’s claim versus the information’s property

The clearest way to hold the distinction is to name what each one protects. Confidentiality protects information: only authorized parties may read it, and the mechanisms are access control, encryption, and classification. Privacy protects people: an individual has a claim that their information is collected lawfully, used for purposes they were told about, not disclosed beyond what they agreed to or the law permits, and not retained longer than necessary. The subject of confidentiality is the data. The subject of privacy is the data subject. That is why a system with flawless confidentiality can still be a privacy failure: nothing was ever read by the wrong person, but the collection was unlawful, the use drifted from the stated purpose, or the retention was indefinite.

The divergence works in both directions, and the exam likes to test both. A privacy violation without a confidentiality breach is the pre-checked consent box, the purpose drift, the sale of an address list, the data held five years past its purpose. A confidentiality breach without a privacy violation is rarer but real: an organization can suffer a leak of data that is not personal at all, engineering diagrams, pricing models, source code, and the damage is real even though no individual’s claim was touched. The exam question that separates candidates asks which of two harms a scenario describes, and the answer turns on whether an identified person’s information was collected or used improperly, or whether protected information was accessed by unauthorized parties.

There is also a difference in who is harmed and how the harm is measured. A confidentiality failure is typically measured by the organization: lost trade secrets, damaged advantage, reputational cost to the business. A privacy failure is measured by the individual first: embarrassment, discrimination, identity misuse, financial loss, dignity. The law then maps individual harm onto organizational consequences through fines, injunctions, and class actions, which is why the manager-perspective reasoning in this book treats privacy as a risk management problem. The organization cannot make the person’s claim disappear, but it can manage the probability and severity of the consequences that follow when the claim is violated.

One more distinction deserves to be stated before moving on, because candidates routinely blur it: privacy is not secrecy. A person can consent to their name appearing in a public directory, and the publication is a privacy outcome, not a privacy violation. Secrecy says the fact is hidden; privacy says the person controls the fate of the fact. The same information can be public for one person and sensitive for another, which is why privacy analysis is always contextual and always begins with the person, never with the data field alone.

The vocabulary of personal data

The exam expects precise use of the terms that define what the law protects. The definitions differ across regimes, and a good candidate can state each one and name the source, because the differences are what make a question answerable.

NIST Special Publication 800-122, “Guide to Protecting the Confidentiality of Personally Identifiable Information (PII),” gives the definition that anchors the federal vocabulary. It defines PII as any information about an individual maintained by an agency, including any information that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name, or biometric records, and any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information. Two features of this definition matter for the exam. First, it is two-part: identifiers that trace a person directly, and attributes that are merely linked or linkable. Second, it is explicitly contextual: a list of email addresses is PII when it is linkable to individuals in context, and the same fields can be non-PII when they describe a business account. The exam likes this nuance, because the wrong instinct is to treat PII as a fixed list of fields.

The GDPR uses a slightly different construct. Article 4(1) defines personal data as any information relating to an identified or identifiable natural person, where an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person. The GDPR’s version is deliberately broad: an IP address, a device identifier, a loyalty number, or a combination of innocuous fields can each make a person identifiable, and the regulation is written so that anything related to an identifiable person is personal data until proven otherwise.

Article 9 of the GDPR then creates a separate, stricter regime for special categories of personal data, sometimes called sensitive data. The categories are data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, plus genetic data, biometric data processed for the purpose of uniquely identifying a natural person, health data, and data concerning a person’s sex life or sexual orientation. Processing special categories is prohibited by default and permitted only through one of the narrow conditions in Article 9(2), explicit consent or a handful of public-interest, employment, health-care, and legal grounds. The exam’s recurring version of this question offers a list and asks which item is a special category, and the trap is the qualifier on biometric data: facial geometry used to unlock a phone is biometric data for unique identification, while a photo attached to a customer profile is ordinary personal data.

The health sector has its own term. Under the US Health Insurance Portability and Accountability Act of 1996 (HIPAA), protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity in any form or medium. The practical shape of PHI is the combination of health information plus one or more identifiers: a diagnosis alone is not PHI, and a name alone is not PHI, but a diagnosis linked to a name is. HIPAA’s own de-identification standard, at 45 CFR 164.514, offers two routes out of the regime. The safe harbor method requires the removal of 18 categories of identifiers, which run from the obvious (names, social security numbers, phone numbers, email addresses) through the less obvious (full-face photographs, biometric identifiers including finger and voice prints, device identifiers and serial numbers, web URLs, and IP addresses) to the catch-all (any other unique identifying number, characteristic, or code), plus a documented determination that the remaining information could not identify an individual. The expert determination method substitutes statistical judgment: a qualified person applies generally accepted statistical and scientific principles and concludes that the risk of identification is very small. The exam tests the count, the route, and the fact that de-identification is a legal determination, not a technical one.

Two more terms complete the vocabulary because they appear in GDPR questions constantly. Pseudonymization, defined in Article 4(5), replaces identifying attributes so that the data can no longer be attributed to a specific data subject without additional information that is kept separately and protected by technical and organizational measures. Pseudonymized data is still personal data: the link exists, someone holds the key. Anonymization is the stronger operation: it removes the link irreversibly so that the data no longer relates to an identifiable person, and anonymous data falls outside the GDPR’s scope entirely, per Recital 26. The exam loves this pair because the practical consequence is binary: pseudonymized data remains inside the compliance boundary and must be protected, while genuinely anonymized data leaves it. A question that offers “anonymized” as a mitigation for a purpose-limitation problem is usually correct precisely because the data stopped being personal data at all.

The principle stack: from the OECD to the GDPR

The GDPR did not invent privacy principles. It codified a lineage that began in 1980, and the exam rewards candidates who know the lineage because nearly every modern law, and every privacy question, is built from the same small set of ideas.

The Organization for Economic Co-operation and Development (OECD) published its Guidelines on the Protection of Privacy and Transborder Flows of Personal Data in 1980 and revised them in 2013. The guidelines state eight principles: collection limitation (collection should be lawful and with the knowledge and consent of the individual where appropriate), data quality (data should be relevant to the purposes for which they are used, and accurate, complete, and up to date to the extent necessary), purpose specification (purposes should be specified before collection and confined to those purposes), use limitation (data should not be disclosed or used for other purposes without consent or legal authority), security safeguards (data should be protected by reasonable safeguards against loss and unauthorized access, destruction, use, modification, and disclosure), openness (there should be general openness about practices and policies), individual participation (individuals should have the right to learn what is held about them and to challenge and correct it), and accountability (a data controller should be accountable for complying with the measures giving effect to the principles). Every element of that list will look familiar by the end of this chapter, because the GDPR is the OECD principles with enforcement teeth.

The other foundational label is the Fair Information Practice Principles, or FIPPs. The term has been used by the US Federal Trade Commission and others to describe the same family: notice and awareness, choice and consent, access and participation, integrity and security, and enforcement and redress. The exam uses FIPPs as a label for the class of principles, and the correct answer to a question about “the principles that privacy frameworks are based on” is usually this family, whether the question names FIPPs, the OECD Guidelines, or the general idea.

The United States codified parts of this stack early. The Privacy Act of 1974 governs federal agencies’ systems of records, and it is worth knowing for its structure even though it applies to the government rather than to private business. A system of records is a group of records under the control of an agency from which information is retrieved by the name or other identifier of an individual. The Act requires agencies to maintain only such information about an individual as is relevant and necessary to accomplish a purpose required by statute or executive order, to collect information directly from the individual where practicable, to publish notice of their systems of records in the Federal Register, to allow individuals to access and amend their own records, and to refrain from disclosing records without consent except for the statutory exceptions, including routine uses published in the notice. Notice, relevance and necessity, individual access and amendment: the 1974 Act is the OECD principles rendered as federal law.

At the standards level, the modern framework documents give the program its machinery. ISO/IEC 27701:2019 extends ISO/IEC 27001 and ISO/IEC 27002 with a privacy information management system, or PIMS, so that an organization’s existing information security management system can absorb privacy controls and be audited against them. NIST Special Publication 800-53 Revision 5 carries privacy controls in Appendix J, organized into six families that spell out the full lifecycle: Authority and Purpose (AP), Accountability, Audit, and Risk Management (AR), Data Minimization and Retention (DM), Individual Participation and Redress (IP), Security and Privacy (SE), and Transparency (TR). NIST’s Privacy Framework, published in 2020, gives organizations a voluntary structure whose core functions are Identify, Govern, Control, Communicate, and Protect. The exam does not require memorizing every control identifier, but it expects the candidate to know that the security control catalog and the privacy control catalog are separate things that live in the same document, and that privacy is governed as its own discipline, not as a footnote to security.

The GDPR as the reference law

The General Data Protection Regulation (Regulation (EU) 2016/679, in force May 2018) is the law that every other privacy question is compared against, and the exam’s privacy questions lean on it heavily. The chapter treats it in five parts: scope, roles, principles, rights, and consequences.

Scope comes first because the regulation’s reach surprises technical people. Article 3(1) applies to controllers and processors established in the Union regardless of where processing occurs. Article 3(2) extends the reach outward: the GDPR also applies to controllers and processors not established in the Union when they process personal data of data subjects who are in the Union, where the processing is related to offering goods or services to those data subjects, whether or not payment is required, or to monitoring their behavior as far as that behavior takes place within the Union. A company in another country that runs a website selling to EU customers, or that tracks EU visitors with analytics, is inside the regime. This extraterritorial design is why a candidate should never assume geography settles a privacy question: the question is whether the data subject is in the Union and whether the processing targets them.

Roles come second, and the controller and processor distinction is the most tested role concept in the regulation. Article 4(7) defines the controller as the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing. Article 4(8) defines the processor as a natural or legal person which processes personal data on behalf of the controller. The controller is the decision-maker, the processor is the hired hand. The consequence chain matters more than the definitions: the controller bears the primary accountability for lawfulness, must contract with processors through a binding agreement that governs the processing (Article 28), and answers to data subjects and to supervisory authorities. Processors have their own direct obligations, including their own security obligations under Article 32 and their own breach notification duty under Article 33, so the distinction does not let a processor off the hook; it allocates accountability.

A third role completes the cast. Article 37 requires a data protection officer (DPO) where the processing is carried out by a public authority or body, where the core activities of the controller or processor consist of processing operations which require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of large-scale processing of special categories or of data relating to criminal convictions and offences. The exam tests the triggers, and the shape of the correct answer is always “large scale” plus either public authority, systematic monitoring, or special categories. A DPO is not required for every company, and a question that assumes a DPO exists for a small business with ordinary processing is testing exactly that error.

Principles come third, and Article 5 is the provision to memorize. It states that personal data must be processed lawfully, fairly, and in a transparent manner; collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes; adequate, relevant, and limited to what is necessary in relation to the purposes; accurate and kept up to date, with every reasonable step taken to ensure that inaccurate data is erased or rectified; kept in a form which permits identification of data subjects for no longer than is necessary; and processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures. A seventh principle completes the list: the controller is responsible for, and must be able to demonstrate compliance with, all of the above, which is the accountability principle. The exam’s version of Article 5 is usually a scenario with one principle broken, and the five behavioral principles, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality, plus lawfulness, fairness, and transparency, plus accountability, are the seven answer choices in play.

Underneath the principles sits the question of lawful basis, and Article 6 lists six of them: consent, contract, legal obligation, vital interests, public interest, and legitimate interests. A controller must have a lawful basis for every processing operation, and the exam scenario that names a purpose without a basis, marketing profiles built from order data, is testing purpose limitation plus the missing lawful basis. Consent has its own special rules in Article 7: it must be freely given, specific, informed, and unambiguous, given by a clear affirmative act, and withdrawable as easily as it was given. The pre-checked consent box is unlawful precisely because it is not a clear affirmative act.

Rights come fourth. Articles 15 through 22 give data subjects the right of access (a copy of the data and information about the processing), rectification, erasure (the right to be forgotten, subject to conditions such as legal obligations to keep the data), restriction of processing, data portability (receiving the data in a structured, commonly used, machine-readable format and transmitting it to another controller), objection (including objection to processing for direct marketing), and the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. The exam tests these as a set, and the managerial point is that a privacy program is a rights-fulfillment machine: it must be able to find a person’s data across systems, produce it, correct it, delete it, and port it, which is why the data inventory from Chapter 8 is not optional.

Consequences come last, and the numbers are worth holding exactly. Article 33 requires a controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 34 requires the controller to communicate the breach to the data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Article 83 sets the fines: up to 10 million euros or 2 percent of total worldwide annual turnover, whichever is higher, for the lesser tier that includes security obligations and breach notification, and up to 20 million euros or 4 percent of total worldwide annual turnover for the greater tier that includes the Article 5 principles, the Article 6 and 7 conditions on lawful processing and consent, the Article 9 special categories, the data subject rights, and the international transfer rules. A candidate who can state “72 hours” and “four percent of worldwide turnover” has the two numbers the exam actually asks for.

The American sectoral patchwork

The United States has no single privacy law of the GDPR’s shape. Instead it has a sectoral patchwork, one statute per industry, and the exam expects the mapping: which law applies to which industry, and what the law requires in one sentence.

HIPAA governs health information. Its Privacy Rule (45 CFR Part 160 and Part 164 Subparts A and E) sets standards for the use and disclosure of PHI, and its Security Rule (Subpart C) requires administrative, physical, and technical safeguards for electronic PHI, the familiar trio of safeguards the exam loves. The actors are covered entities, health plans, health care clearinghouses, and health care providers that transmit health information electronically, and business associates, persons or entities that create, receive, maintain, or transmit PHI on behalf of a covered entity, such as a billing vendor or a cloud host. A covered entity may share PHI with a business associate only under a contract or other arrangement that meets the standards, the business associate agreement. The Breach Notification Rule (Subparts D of Parts 160 and 164) requires notification to affected individuals without unreasonable delay and in no case later than 60 days after discovery, notification to the Department of Health and Human Services, within 60 days for breaches affecting 500 or more individuals and within 60 days after the end of the calendar year for smaller breaches, and notification to the media for breaches affecting more than 500 individuals in a state or jurisdiction. NIST Special Publication 800-66 offers implementation guidance for the Security Rule, and the exam sometimes names it as the how-to companion to the HIPAA what.

Beyond health, the patchwork includes the Gramm-Leach-Bliley Act (GLBA) for financial institutions, which must protect nonpublic personal information about customers through the Safeguards Rule and give privacy notices with an opt-out for sharing with nonaffiliated third parties; the Family Educational Rights and Privacy Act (FERPA) for education records, which gives parents and eligible students rights over access to and disclosure of those records; and the Children’s Online Privacy Protection Act (COPPA) for online collection of personal information from children under 13, which requires verifiable parental consent. Each of these is a one-line answer on the exam, and the typical question names an industry and asks which law governs it.

The state level has become its own legal layer. The California Consumer Privacy Act (CCPA), effective January 2020 and amended by the California Privacy Rights Act (CPRA), effective January 2023, gives California residents the right to know what personal information a business collects about them, the right to delete it, the right to correct it, the right to opt out of the sale or sharing of their personal information, the right to limit the use of sensitive personal information, and the right to non-discrimination for exercising these rights. The exam asks for the rights set, and the answer is the collection: know, delete, correct, opt out, limit, and equal treatment. Because California is a large market, the law functions as a de facto national baseline, which is exactly the managerial observation the exam wants: privacy obligations now stack, and a program must handle the most restrictive rule that applies.

The international layer completes the picture. The GDPR restricts transfers of personal data to countries outside the European Economic Area unless the transfer has a lawful mechanism under Chapter V: an adequacy decision (Article 45) for countries the Commission has determined provide an essentially equivalent level of protection, or appropriate safeguards such as standard contractual clauses (Article 46) or binding corporate rules (Article 47). The history matters for one exam point. The Court of Justice of the European Union, in its 2020 judgment in Case C-311/18, commonly called Schrems II, invalidated the EU-US Privacy Shield framework because the US legal environment did not provide protections essentially equivalent to the GDPR. Standard contractual clauses survived the judgment, but the court required a case-by-case assessment: the parties must verify that the law and practice of the destination country permit compliance with the clauses, and must add supplementary measures where they do not. In July 2023 the Commission adopted an adequacy decision for the EU-US Data Privacy Framework, a successor certification program for US companies, restoring a direct transfer mechanism. The exam’s question on this material usually offers three wrong mechanisms and one right one, and the right one is whichever matches the lawful transfer machinery, adequacy, SCCs, or binding corporate rules.

Privacy impact assessments

The practical engine of the whole domain is the privacy impact assessment, and it deserves a full section because it is the control that turns principles into decisions. Two near-identical acronyms operate here, and the distinction is one of the cleanest exam points in the book: a PIA is the assessment form used broadly in the US federal context, and a DPIA is the assessment the GDPR makes legally mandatory under Article 35.

In the US federal government, the E-Government Act of 2002 requires an agency to conduct a PIA before developing or procuring information technology that collects, maintains, or disseminates information about individuals, or before initiating a new collection of information that will be collected, maintained, or disseminated using information technology. OMB Circular A-130, “Managing Information as a Strategic Resource,” operationalizes the requirement by directing agencies to conduct PIAs for electronic information systems and collections, and to update them when there is a significant change to the system or its processing. The PIA is thus a pre-launch control: it must be done before the system is built or the collection begins, and it must be revisited when the processing changes. A question that offers “after the breach” as the timing for a PIA is wrong by construction, and the exam includes such an option routinely.

The GDPR’s DPIA has the same timing logic and a stricter trigger. Article 35(1) requires a DPIA where a type of processing, in particular using new technologies, and taking into account the nature, scope, context, and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons. The regulation then gives the mandatory cases: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions that produce legal or similarly significant effects are based; large-scale processing of special categories or of data relating to criminal convictions and offences; and large-scale systematic monitoring of a publicly accessible area. The exam’s version of this question names a processing scenario and asks whether a DPIA is required, and the decision rule is the three-part test: automated decision-making with significant effects, large-scale special category processing, or large-scale public monitoring.

What a DPIA contains is as important as when it is required. Article 35(7) lists the contents: a systematic description of the envisaged processing operations and the purposes of the processing, an assessment of the necessity and proportionality of the processing in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address the risks, including safeguards, security measures, and mechanisms to ensure the protection of personal data and to demonstrate compliance. Notice the two questions embedded in that list: is this processing necessary and proportionate to the purpose, and what will we do about the residual risk? That is a risk assessment structure, the same structure as Chapter 4’s risk management, applied to persons instead of to the enterprise. The practical consequence follows in Article 36: where the DPIA indicates that processing would result in a high risk that cannot be mitigated, the controller must consult the supervisory authority before beginning the processing.

The PIA and the DPIA share a discipline that the exam rewards: they are documented, they happen before processing begins, they are updated on significant change, and they end in a mitigation decision, not a report that is filed and forgotten. NIST’s privacy documentation carries the same shape in the SP 800-53 privacy controls, where the Authority and Purpose family requires determining the authority to collect and specifying the purpose, and the Transparency family requires making the practices visible to the individuals affected. A privacy program that runs on assessments is a program that can answer the regulator’s first question, which is always the same question: what did you know, and when did you know it.

One more architectural principle closes the section. Article 25 requires data protection by design and by default: the controller must implement technical and organizational measures, such as data minimization and pseudonymization, that are designed to implement the data protection principles effectively, and must ensure that by default only personal data necessary for each specific purpose is processed, especially with respect to the amount collected, the extent of processing, the period of storage, and accessibility. Privacy by design, the older framing popularized by the Information and Privacy Commissioner of Ontario, makes privacy the default posture of the architecture rather than an add-on. The exam question built on this material offers four engineering choices and asks which one implements privacy by default, and the correct answer is the one that limits collection and storage by design: collect only the fields the purpose requires, keep them only as long as the purpose lasts, and expose them to as few people as possible.

The manager-perspective pattern

Privacy questions on the exam cluster into a small number of shapes, and the reasoning pattern is consistent across all of them. The first shape asks for a definition, and the pattern is to name the source: PII per NIST SP 800-122, personal data per GDPR Article 4, PHI per HIPAA. The second shape names a scenario and asks which principle was violated, and the pattern is to match the scenario to the principle’s plain meaning: data collected for one purpose and used for another is purpose limitation, data kept past the need is storage limitation, data not given to the person who asks is a failure of individual access, data processed without any legal basis is a failure of lawfulness. The third shape asks who does what, and the pattern is the controller and processor line: the controller decides purposes and means, the processor executes, the DPO exists when the trigger is large scale. The fourth shape asks what happens next, and the pattern is the consequence chain: a breach is reported to the authority in 72 hours under Article 33 unless the risk is unlikely, and to individuals under Article 34 when the risk is high; a high-risk processing starts with a DPIA and may end in prior consultation under Article 36.

The wrong answers in all four shapes share a family resemblance, and naming the family is the fastest way to eliminate them. One member is the technical reflex: the answer that proposes an encryption, access control, or logging fix to a scenario that is really about lawful collection or purpose. Encryption protects confidentiality, and the scenario violated privacy, so the answer fixes the wrong property. Another member is the timing error: the answer that schedules the assessment, the consent refresh, or the notification after the fact, when every privacy control the exam tests is a before-the-fact control. A third member is the jurisdiction error: the answer that assumes a US law stops at the border or that a foreign controller escapes the GDPR. Eliminate the wrong property, the wrong timing, and the wrong jurisdiction, and the remaining answer is almost always the programmatic one: the policy, the role, the assessment, or the documented decision.

The managerial frame that ties it together is this: privacy is a risk to be governed, not a bug to be fixed. The governing loop is the one this chapter has walked: classify the data, apply the principles, allocate the roles, run the assessment before the system exists, and have the breach machinery ready for the day the assessment fails. Every one of those steps is an asset security activity, which is why the exam puts privacy in Domain 2, and why the candidate who reads this chapter will recognize its ideas again in the operations domain, when incident response meets the 72-hour clock.

Practice questions

  1. An auditor reviews two systems that both protect their customer records with strong encryption and access control. System A collected data through an explicit consent screen for a stated purpose and deletes the data when the purpose ends. System B collected the same data through pre-checked boxes, uses it for analytics never mentioned at collection, and retains it indefinitely. Both systems have had no unauthorized access. What is the best conclusion?

A. Both systems have equivalent privacy postures because confidentiality has not been breached in either B. System B violates privacy even though its confidentiality controls have never failed C. System B has no privacy exposure because no data was stolen D. The two systems differ only in their retention schedules

  1. According to NIST SP 800-122, which statement best defines PII?

A. Any information an organization stores about a person in a structured database B. Information that can distinguish or trace an individual’s identity, plus other information that is linked or linkable to the individual C. Any data that contains a person’s name, regardless of context D. Information whose confidentiality would cause harm if disclosed

  1. A company collects order data to fulfill purchases and later uses the same data to build detailed marketing profiles, without any lawful basis for the new use. Which GDPR principle is violated first?

A. Storage limitation B. Data minimization C. Purpose limitation D. Accuracy

  1. Which of the following is a special category of personal data under Article 9 of the GDPR?

A. Purchase history B. An IP address C. Biometric data processed to uniquely identify a person D. A person’s job title

  1. A hospital sends claims and billing information to a third-party vendor that processes the data on the hospital’s behalf. Under HIPAA, what must be in place before the vendor receives protected health information?

A. A data protection impact assessment approved by the vendor B. A business associate agreement meeting the HIPAA requirements C. Written consent from every patient whose data is included D. Encryption of the data in transit only

  1. A researcher wants to de-identify a dataset under the HIPAA safe harbor method. Which of the following is one of the 18 identifiers that must be removed?

A. Hair color B. Device identifiers and serial numbers C. Political party affiliation D. Year of admission, when the year is used alone

  1. A controller becomes aware of a personal data breach that is likely to result in a risk to individuals’ rights and freedoms. Under Article 33 of the GDPR, what must the controller do?

A. Notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after awareness B. Notify the data subjects first, then the supervisory authority within 14 days C. Notify the supervisory authority within 30 days only if the breach involves more than 500 records D. Document the breach internally and notify the authority at the end of the calendar year

  1. A company based outside the European Union operates a website that offers goods to customers in the Union and uses tracking cookies on those visitors. When does the GDPR apply to this company?

A. Never, because the company is not established in the Union B. Only if the company has a physical office in a member state C. When processing personal data of data subjects in the Union in connection with offering goods or services to them or monitoring their behavior in the Union D. Only when the company processes more than 10,000 records of EU data subjects

  1. Under the E-Government Act of 2002, when must a federal agency conduct a privacy impact assessment?

A. Before developing or procuring information technology that collects, maintains, or disseminates information about individuals B. Within 72 hours after a confirmed breach involving personal information C. After the system is deployed, at the first annual audit D. Only when the agency plans to share information with other agencies

  1. Which statement about the data protection impact assessment under Article 35 of the GDPR is correct?

A. A DPIA is required only when a data breach has already occurred B. A DPIA is required where processing is likely to result in a high risk to the rights and freedoms of natural persons, such as large-scale processing of special categories C. A DPIA may be waived by the data controller whenever the processing uses encryption D. A DPIA is the same document as a breach notification

  1. Under the GDPR, which role determines the purposes and means of the processing of personal data?

A. The data processor B. The data protection officer C. The data controller D. The supervisory authority

  1. A company builds a new customer portal and configures it so that it collects only the fields required for the stated purpose, keeps them for the minimum period, and leaves optional sharing disabled unless the customer enables it. Which GDPR requirement does this design most directly implement?

A. Data protection by design and by default under Article 25 B. The right to data portability under Article 20 C. The 72-hour breach notification under Article 33 D. The appointment of a data protection officer under Article 37

  1. Under the OECD Guidelines on the Protection of Privacy, the requirement that personal data be relevant to the purposes for which they are used is expressed in which principle?

A. Collection limitation B. Data quality C. Openness D. Accountability

  1. A controller transfers personal data to a processor in a third country using standard contractual clauses. Following the Court of Justice’s judgment in Schrems II, what else must the controller do?

A. Nothing, because SCCs alone guarantee compliance in all circumstances B. Verify, case by case, that the law and practice of the destination country allow the clauses to be complied with, and add supplementary measures where they do not C. Obtain the consent of the data protection officer of the destination country D. Cease all transfers to any country without an EU-US Data Privacy Framework certification

  1. A covered entity discovers a breach of unsecured protected health information affecting 1,200 individuals. Under the HIPAA Breach Notification Rule, what is the deadline to notify the Department of Health and Human Services?

A. Within 72 hours of discovery B. Within 60 days of discovery C. Within 60 days after the end of the calendar year D. There is no deadline for breaches affecting fewer than 5,000 individuals

  1. Which combination of facts requires an organization to appoint a data protection officer under Article 37 of the GDPR?

A. The organization employs more than 250 people B. The organization’s core activities involve large-scale regular and systematic monitoring of data subjects C. The organization processes any special category data, regardless of scale D. The organization has customers in more than one member state

Answers and rationales

  1. B. Privacy is a claim of the person about how their information is collected and used, and it can be violated with no confidentiality failure at all. System B collected without real consent, used the data beyond its stated purpose, and retained it indefinitely, all privacy violations that encryption and access control do not address (option A conflates the two properties, and option C treats theft as the only harm).

  2. B. NIST SP 800-122 defines PII as information that can distinguish or trace an individual’s identity plus other information that is linked or linkable to the individual. The definition is two-part and contextual, so a name alone in a business context may not be PII (option C), and storage format or harm are not the defining tests (options A and D).

  3. C. Purpose limitation under Article 5(1)(b) requires collection for specified, explicit, and legitimate purposes and forbids further processing incompatible with those purposes. Order fulfillment and marketing profiling are different purposes, so the drift is a purpose limitation failure, and the missing lawful basis for the new use compounds it. Storage and minimization issues (options A and B) are secondary here, and accuracy (option D) is unrelated.

  4. C. Article 9 lists biometric data processed for the purpose of uniquely identifying a natural person among the special categories. Purchase history and an IP address are ordinary personal data in most contexts (options A and B), and a job title is not special category data (option D).

  5. B. HIPAA allows a covered entity to share PHI with a business associate only under a business associate agreement that meets the regulatory requirements. A DPIA is a GDPR instrument, not a HIPAA one (option A), individual consent is not required for every claim-related disclosure (option C), and transit encryption alone does not satisfy the contracting requirement (option D).

  6. B. The safe harbor list of 18 identifiers includes device identifiers and serial numbers, along with names, social security numbers, IP addresses, full-face photographs, and the rest. Hair color, political party, and a year used alone are not on the list (options A, C, and D; dates must be removed, but years may remain except for ages over 89).

  7. A. Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after awareness, unless the breach is unlikely to result in risk. Individual notification under Article 34 follows only when the risk is high, not first (option B), and there is no 500-record threshold or year-end schedule for the authority notification (options C and D).

  8. C. Article 3(2) extends the GDPR to controllers and processors outside the Union when they process data of data subjects in the Union in connection with offering goods or services or monitoring their behavior in the Union. Establishment (options A and B) and record volume (option D) are not the test.

  9. A. The E-Government Act of 2002 requires a PIA before developing or procuring information technology that collects, maintains, or disseminates information about individuals, and OMB Circular A-130 operationalizes that timing. PIAs are pre-launch controls, so after-the-fact timing (options B and C) and narrow trigger readings (option D) are wrong.

  10. B. Article 35 requires a DPIA where processing is likely to result in a high risk to rights and freedoms, with mandatory cases including large-scale processing of special categories, large-scale public monitoring, and automated decision-making with significant effects. The DPIA is a before-the-fact risk assessment, not a breach response document (options A and D), and encryption does not waive it (option C).

  11. C. Article 4(7) defines the controller as the party that determines the purposes and means of processing. The processor executes on the controller’s behalf (option A), the DPO advises on compliance (option B), and the supervisory authority oversees (option D).

  12. A. Article 25 requires data protection by design and by default: measures that implement the principles and default settings that ensure only necessary personal data is processed. Field minimization, storage limits, and disabled-by-default sharing are exactly that requirement. The other options are unrelated rights and duties (options B, C, and D).

  13. B. The OECD data quality principle requires personal data to be relevant to the purposes for which they are used and, to the extent necessary, accurate, complete, and up to date. Collection limitation governs how data is collected (option A), openness concerns transparency about practices (option C), and accountability concerns responsibility for compliance (option D).

  14. B. Schrems II invalidated the Privacy Shield and required parties relying on SCCs to assess, case by case, whether the destination country’s law and practice permit compliance, adding supplementary measures where needed. SCCs are not a guarantee in every destination (option A), there is no consent mechanism from the destination regulator (option C), and the Data Privacy Framework is a separate adequacy-based mechanism, not a universal ban (option D).

  15. B. Under the HIPAA Breach Notification Rule, a breach affecting 500 or more individuals must be reported to HHS within 60 days of discovery. The 72-hour figure belongs to the GDPR (option A), year-end reporting applies to smaller breaches (option C), and the 500-individual threshold triggers the faster clock rather than waiving it (option D).

  16. B. Article 37 requires a DPO where core activities involve large-scale regular and systematic monitoring of data subjects, where the organization is a public authority, or where core activities involve large-scale processing of special categories. Headcount (option A), any special category processing at any scale (option C), and multi-state customers (option D) are not the statutory triggers.

Privacy and data protection on one page

Hold the spine and the rest hangs together. The spine is the distinction this chapter opened with: privacy is a claim of the person about collection, use, disclosure, and retention, and confidentiality is a property of information about who reads it, so a system with perfect confidentiality can still be a privacy failure. The vocabulary is PII per NIST SP 800-122, personal data per GDPR Article 4, special categories per Article 9, and PHI per HIPAA, with pseudonymized data still personal and anonymized data outside the regime. The principles are the OECD stack that the GDPR codified: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; security; and accountability. The GDPR’s mechanics are the controller who decides purposes and means, the processor who executes, the DPO who exists when the triggers are met, the six lawful bases, the rights from access to erasure to portability, the 72-hour breach clock, and the two percent and four percent fine tiers. The US adds the sectoral laws, HIPAA’s covered entities, business associates, safeguards, and 60-day clock, GLBA for finance, FERPA for education, COPPA for children, and the CCPA and CPRA rights for Californians, and the transfer machinery runs on adequacy decisions, SCCs, and binding corporate rules. The engine is the assessment: the E-Government Act’s PIA before the federal system launches, and the GDPR’s DPIA when processing is likely to result in high risk, each a documented necessity-and-proportionality review that ends in mitigations or prior consultation. When the exam offers a privacy answer that is really an encryption answer, a post-breach answer, or a wrong-jurisdiction answer, discard it and keep the programmatic one: the assessment, the role, the documented decision.

Chapter 10 takes the last leg of the asset lifecycle and asks what happens to data when its purpose ends: retention schedules, sanitization methods, remanence, and disposal in the cloud. Before you go, hold the sentence that this chapter keeps returning to: privacy law is the only area in this book that regulates the collection itself, not just the protection, and the candidate who remembers that will never mistake a confidentiality fix for a privacy answer.