CDPSE · Domain 2
Privacy Risk Management and Compliance
About 18% of the exam
Privacy risk vocabulary
- Inherent risk
- before any controls are applied
- Residual risk
- what remains after mitigation
- Risk appetite
- residual risk leadership will accept
- Risk tolerance
- measurable limit for one risk
- Risk rating
- likelihood times impact, defined criteria
- Risk register
- owner, rating, treatment, review date
- Function creep
- data reused for unrelated purposes
- Risk to individuals
- the harm privacy assessments measure
Rate harm to the data subject, not just harm to the organization
The DPIA process
- Threshold screen
- Describe processing
- Necessity and proportionality
- Identify risks
- Mitigate
- Sign off residual
- Consult if still high
- Review
- Run early in design, update as it evolves
- Keep the threshold record even when not required
- Describe purposes, data, flows, recipients, retention
- Necessity: could a less intrusive way work
- Seek DPO advice, consult affected people
- Prior consultation with the authority if unmitigated
- Register of all DPIAs with owner and status
- Re-run when technology, scope or risk changes
The business owner is accountable for the DPIA; the DPO advises. A finished template is evidence of accountability, so keep it
When a DPIA is mandatory
- Systematic profiling with legal or similar effects
- Large-scale special category or criminal data
- Systematic monitoring of public areas
- New technology with likely high risk
- Children or vulnerable people raise the bar
- Biometrics, tracking, denial of service uses
- Authorities publish lists that require one
- Low risk: document the screening, skip full DPIA
Lawful bases and consent
Six lawful bases
- Consent
- freely given, specific, informed, unambiguous
- Contract
- necessary to perform it
- Legal obligation
- law requires the processing
- Vital interests
- life or death situations
- Public task
- official authority or public interest
- Legitimate interests
- needs the balancing test
Valid consent
- Pre-ticked boxes and silence never count
- Withdrawal as easy as giving it
- Not bundled with access to the service
- Explicit consent for special categories
- Record who, when, what, which version
- Withdrawal must actually stop the processing
Legitimate interest assessment
- Purpose test: is the interest legitimate
- Necessity test: no less intrusive way
- Balancing test: expectations, impact, safeguards
- Children weigh heavily against
- Offer an objection route
- Write the analysis down
Risk treatment decisions
- Mitigate
- controls bring risk to acceptable
- Accept
- named owner, rationale, review date
- Transfer
- insurance covers money, not harm
- Avoid
- stop, restructure or relocate processing
- Critical rating
- halt until mitigated
- Overdue mitigation
- escalate with the residual risk
- Sponsor disagrees
- formal documented acceptance, not re-rating
Cross-border transfers
- Adequacy decision
- destination deemed equivalent, can lapse
- SCCs
- Commission-approved contract clauses
- BCRs
- approved rules inside a group
- Transfer impact assessment
- does local law undermine the clauses
- Supplementary measures
- encryption with keys kept home
- Derogations
- occasional, explicit consent, contract necessity
- No protection possible
- suspend or restructure the transfer
Since Schrems II, clauses alone are not enough; assess the destination and add measures or do not send
Data subject rights and clocks
- Access, rectify, erase
- core rights over one's data
- Restrict, port, object
- pause, move, or stop processing
- Automated decisions
- human intervention, express view, contest
- GDPR deadline
- one month, extendable two more
- CCPA deadline
- 45 days, extendable 45 more
- Identity check
- proportionate, then minimize the proof
- Erasure vs retention law
- decline for the mandated period, explain
Is it a breach
- Event
- any observable occurrence
- Incident
- confirmed adverse effect on personal data
- Personal data breach
- destruction, loss, alteration, disclosure, access
- Confidentiality breach
- unauthorized disclosure or access
- Integrity breach
- unauthorized alteration
- Availability breach
- loss of access or destruction
- Encrypted, keys safe
- low risk, still document it
- MFA blocked login
- incident, not a personal data breach
Breach notification clock
- Detect
- Become aware
- Contain and preserve
- Assess risk
- Authority within 72 hours
- Subjects if high risk
- Register
- Review
- Authority
- 72 hours from awareness, unless unlikely risk
- Phased
- send what you have, supplement later
- Data subjects
- without undue delay when high risk
- Exceptions
- unintelligible data, measures taken, disproportionate effort
- Processor
- tells the controller without undue delay
- Notice content
- nature, contact, consequences, measures
- Register
- every breach, notified or not
- Found late
- notify now, explain the delay
The clock runs from awareness, through weekends and holidays; keys compromised means encryption no longer lowers the risk
Other notification regimes
- HIPAA covered entity
- individuals within 60 days, HHS, media
- HIPAA business associate
- covered entity within 60 days
- CCPA and CPRA
- unencrypted data, private right of action
- US states
- matrix, apply the most stringent
- Cross-border EU
- lead authority coordinates the others
- Special category
- raises severity and notification odds
Incident management practice
- Cross-functional team: security, legal, DPO, communications
- Severity from data sensitivity and volume
- One authoritative incident record, shared timeline
- Single spokesperson, legal reviews statements
- Accurate notices, never downplay the data
- Decision trees prepared before the pressure
- Non-punitive culture speeds reporting
- Tune alerts so real exports surface
- Track MTTD and recurrence by root cause
Vendor and cloud risk
- Assess locations, certifications, sub-processors, notification
- Processor breach, controller still answers
- Contract: instructions, audit rights, timelines
- Sub-processor changes need authorization
- Presume compromise across the attacker dwell window
- Monitor published sub-processor lists
- TIA before non-adequate destinations
Key numbers
- 72 hours
- authority notification from awareness
- One month
- DSAR under GDPR, plus two
- 45 days
- CCPA request, plus 45
- 60 days
- HIPAA individual notification limit
- 500
- HIPAA media and prompt HHS threshold
- 4% or 20 million
- top GDPR fine tier
- Three tests
- purpose, necessity, balancing
- Six
- lawful bases under GDPR
Reference strip: assessment, bases, transfers, breach, rights
Assessment
- Threshold screen, then full DPIA
- Inherent, residual, appetite, tolerance
- Owner accepts, DPO advises
- Register and review cycle
- Consult authority when unmitigated
Lawful bases
- Consent, contract, legal obligation
- Vital, public task, legitimate interests
- Consent: free, specific, informed, clear
- LIA: purpose, necessity, balance
Transfers
- Adequacy first, can be revoked
- SCCs plus transfer impact assessment
- BCRs inside a corporate group
- Supplementary measures or no transfer
Breach
- Awareness starts the 72 hours
- High risk: tell the people
- Encrypted and keys safe: low risk
- Register everything, notified or not
- Processor informs controller promptly
Rights
- Access, rectification, erasure, restriction
- Portability, objection, automated decisions
- GDPR one month, CCPA 45 days
- Verify identity in proportion
Quick exam traps
- Trap: A DPIA is needed only once the system is in production
- Trap: Every security incident is a notifiable personal data breach
- Trap: The 72 hour clock starts when the breach happened
- Trap: Signed standard contractual clauses make any transfer lawful
- Trap: Pre-ticked boxes and continued use count as consent
- Trap: Insurance transfers the privacy harm away from individuals
- Trap: Encrypted data lost together with its keys is still low risk
- Trap: An erasure request always beats a legal retention duty
cybercertprep.com · original revision sheet written from the public body of knowledge