Correct Answer: B,C
Having inadequate privacy policies and procedures can expose an organization to legal risks such as industry or regulatory sanctions and charges of deceptive business practices. Industry or regulatory sanctions can result from violating the laws and regulations that govern data privacy and protection, such as the GDPR, the CCPA, or the GLBA. These sanctions can include fines, penalties, injunctions, or revocation of licenses. Charges of deceptive business practices can arise from misleading or false statements about how the organization collects, uses, or discloses personal data, or from failing to comply with its own privacy policies and procedures. These charges can lead to lawsuits, settlements, or enforcement actions by authorities such as the FTC or the state attorneys general.
References: =
The 4 Biggest Risks of Non-Compliance With Data Privacy Regulations
Security and privacy laws, regulations, and compliance: The complete guide An Ethical Approach to Data Privacy Protection