<< Prev Question Next Question >>

Question 46/52

SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asi a. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
What can Otto do to most effectively minimize the privacy risks involved in using a cloud provider for the HR data?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (52q)
Question 1: A law enforcement subpoenas the ACME telecommunications comp...
Question 2: In 2012, the White House and the FTC both issued reports adv...
Question 3: When developing a company privacy program, which of the foll...
Question 4: What information did the Red Flag Program Clarification Act ...
Question 5: SCENARIO Please use the following to answer the next QUESTIO...
Question 6: When may a financial institution share consumer information ...
Question 7: Which of the following is an example of federal preemption?...
Question 8: SCENARIO Please use the following to answer the next QUESTIO...
Question 9: SCENARIO Please use the following to answer the next QUESTIO...
Question 10: The rules for "e-discovery" mainly prevent which of the foll...
Question 11: What is the most important action an organization can take t...
Question 12: Which of the following became the first state to pass a law ...
Question 13: What privacy concept grants a consumer the right to view and...
Question 14: Which of the following is NOT one of three broad categories ...
Question 15: Which of the following is most likely to provide privacy pro...
Question 16: SCENARIO Please use the following to answer the next QUESTIO...
Question 17: SCENARIO Please use the following to answer the next QUESTIO...
Question 18: Global Manufacturing Co's Human Resources department recentl...
Question 19: What practice do courts commonly require in order to protect...
Question 20: Which statement is FALSE regarding the provisions of the Emp...
Question 21: What are banks required to do under the Gramm-Leach-Bliley A...
Question 22: Which statute is considered part of U.S. federal privacy law...
Question 23: In which situation would a policy of "no consumer choice" or...
Question 24: An organization self-certified under Privacy Shield must, up...
Question 25: Privacy Is Hiring Inc., a CA-based company, is an online spe...
Question 26: SCENARIO Please use the following to answer the next QUESTIO...
Question 27: What is the main purpose of the CAN-SPAM Act?...
Question 28: What was the original purpose of the Federal Trade Commissio...
Question 29: The "Consumer Privacy Bill of Rights" presented in a 2012 Ob...
Question 30: What do the Civil Rights Act, Pregnancy Discrimination Act, ...
Question 31: According to FERPA, when can a school disclose records witho...
Question 32: SCENARIO Please use the following to answer the next QUESTIO...
Question 33: Which jurisdiction must courts have in order to hear a parti...
Question 34: Which act violates the Family Educational Rights and Privacy...
Question 35: SCENARIO Please use the following to answer the next QUESTIO...
Question 36: What is the main purpose of requiring marketers to use the W...
Question 37: In what way does the "Red Flags Rule" under the Fair and Acc...
Question 38: Which entities must comply with the Telemarketing Sales Rule...
Question 39: What consumer service was the Fair Credit Reporting Act (FCR...
Question 40: SCENARIO Please use the following to answer the next QUESTIO...
Question 41: Which of the following laws is NOT involved in the regulatio...
Question 42: SCENARIO Please use the following to answer the next QUESTIO...
Question 43: Which of the following is NOT a principle found in the APEC ...
Question 44: The U.S. Supreme Court has recognized an individual's right ...
Question 45: If an organization maintains data classified as high sensiti...
Question 46: SCENARIO Please use the following to answer the next QUESTIO...
Question 47: SCENARIO Please use the following to answer the next QUESTIO...
Question 48: SCENARIO Please use the following to answer the next QUESTIO...
Question 49: Under the Fair Credit Reporting Act (FCRA), what must a pers...
Question 50: SCENARIO Please use the following to answer the next QUESTIO...
Question 51: Which of the following accurately describes the purpose of a...
Question 52: Which venture would be subject to the requirements of Sectio...