<< Prev Question Next Question >>

Question 33/81

SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the best reason for Cheryl to follow Janice's suggestion about classifying customer data?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (81q)
Question 1: Based on the 2012 Federal Trade Commission report "Protectin...
Question 2: The "Consumer Privacy Bill of Rights" presented in a 2012 Ob...
Question 3: In what way does the "Red Flags Rule" under the Fair and Acc...
Question 4: Most states with data breach notification laws indicate that...
Question 5: Which of the following is NOT a principle found in the APEC ...
Question 6: Global Manufacturing Co's Human Resources department recentl...
Question 7: Which of the following became the first state to pass a law ...
Question 8: Privacy Is Hiring Inc., a CA-based company, is an online spe...
Question 9: What was the original purpose of the Federal Trade Commissio...
Question 10: All of the following common law torts are relevant to employ...
Question 11: SCENARIO - Please use the following to answer the next quest...
Question 12: What is a key way that the Gramm-Leach-Bliley Act (GLBA) pre...
Question 13: Which of the following is an important implication of the Do...
Question 14: Which of the following statements is most accurate in regard...
Question 15: SCENARIO Please use the following to answer the next QUESTIO...
Question 16: When designing contact tracing apps in relation to COVID-19 ...
Question 17: The Family Educational Rights and Privacy Act (FERPA) requir...
Question 18: SCENARIO Please use the following to answer the next questio...
Question 19: Which venture would be subject to the requirements of Sectio...
Question 20: SCENARIO Please use the following to answer the next QUESTIO...
Question 21: SCENARIO Please use the following to answer the next QUESTIO...
Question 22: Which of the following would NOT constitute an exception to ...
Question 23: Which is an exception to the general prohibitions on telepho...
Question 24: SCENARIO Please use the following to answer the next QUESTIO...
Question 25: SCENARIO Please use the following to answer the next QUESTIO...
Question 26: SCENARIO Please use the following to answer the next QUESTIO...
Question 27: Acme Student Loan Company has developed an artificial intell...
Question 28: If an organization maintains data classified as high sensiti...
Question 29: Which of the following does Title VII of the Civil Rights Ac...
Question 30: SCENARIO Please use the following to answer the next QUESTIO...
Question 31: Read this notice: Our website uses cookies. Cookies allow us...
Question 32: What is the main reason some supporters of the European appr...
Question 33: SCENARIO Please use the following to answer the next QUESTIO...
Question 34: SCENARIO Please use the following to answer the next QUESTIO...
Question 35: Although an employer may have a strong incentive or legal ob...
Question 36: Which of the following federal agencies does NOT enforce the...
Question 37: What is the main purpose of requiring marketers to use the W...
Question 38: Which of the following best describes an employer's privacy-...
Question 39: SCENARIO Please use the following to answer the next QUESTIO...
Question 40: Who has rulemaking authority for the Fair Credit Reporting A...
Question 41: In 2014, Google was alleged to have violated the Family Educ...
Question 42: Which authority supervises and enforces laws regarding adver...
Question 43: In what way is the Controlling the Assault of Non-Solicited ...
Question 44: Which of the following types of information would an organiz...
Question 45: Which of the following describes the most likely risk for a ...
Question 46: What practice does the USA FREEDOM Act NOT authorize?...
Question 47: SCENARIO Please use the following to answer the next QUESTIO...
Question 48: What role does the U.S. Constitution play in the area of wor...
Question 49: SCENARIO Please use the following to answer the next QUESTIO...
Question 50: Which of the following conditions would NOT be sufficient to...
Question 51: Which entity within the Department of Health and Human Servi...
Question 52: More than half of U.S. states require telemarketers to?...
Question 53: SCENARIO Please use the following to answer the next QUESTIO...
Question 54: Which federal law or regulation preempts state law?...
Question 55: What is the most likely reason that states have adopted thei...
Question 56: An organization self-certified under Privacy Shield must, up...
Question 57: When developing a company privacy program, which of the foll...
Question 58: Why was the Privacy Protection Act of 1980 drafted?...
Question 59: A large online bookseller decides to contract with a vendor ...
Question 60: Chanel Hair Studio is a busy high-end hair salon. In an effo...
Question 61: SCENARIO Please use the following to answer the next QUESTIO...
Question 62: Under the Driver's Privacy Protection Act (DPPA), which of t...
Question 63: Which of these organizations would be required to provide it...
Question 64: What is the main challenge financial institutions face when ...
Question 65: Which of the following is an example of federal preemption?...
Question 66: The CFO of a pharmaceutical company is duped by a phishing e...
Question 67: Which of the following federal agencies does NOT have regula...
Question 68: In 2014, Google was alleged to have violated the Family Educ...
Question 69: SCENARIO Please use the following to answer the next QUESTIO...
Question 70: In which situation would a policy of "no consumer choice" or...
Question 71: Sarah lives in San Francisco, Californi a. Based on a dramat...
Question 72: SCENARIO Please use the following to answer the next questio...
Question 73: Which of the following best describes the ASIA-Pacific Econo...
Question 74: SCENARIO Please use the following to answer the next QUESTIO...
Question 75: Which of the following laws is NOT involved in the regulatio...
Question 76: SCENARIO Please use the following to answer the next QUESTIO...
Question 77: SCENARIO Please use the following to answer the next QUESTIO...
Question 78: A law enforcement subpoenas the ACME telecommunications comp...
Question 79: Which of the following best describes what a "private right ...
Question 80: A company's employee wellness portal offers an app to track ...
Question 81: What consumer protection did the Fair and Accurate Credit Tr...