When data processing is performed at a third-party data center, ownership of the risk PRIMARILY rests with the:
Which of the following would BEST support an organization in fulfilling data subject rights?
Which of the following needs to be identified FIRST to define the privacy requirements to use when assessing the selection of IT systems?
Type of data being processed
An online retail company is trying to determine how to handle users’ data if they unsubscribe from marketing emails generated from the website. Which of the following is the BEST approach for handling personal data that has been restricted?
Which of the following is the MOST important consideration when writing an organization’s privacy policy?
An organization is creating a personal data processing register to document actions taken with personal data. Which of the following categories should document controls relating to periods of retention for personal data?
What is the PRIMARY means by which an organization communicates customer rights as it relates to the use of their personal information?
To ensure effective management of an organization’s data privacy policy, senior leadership MUST define:
Which of the following is the best way to reduce the risk of compromised credentials when an organization allows employees to have remote access?
Which of the following principles is MOST important to apply when granting access to an enterprise resource planning (ERP) system that contains a significant amount of personal data?