<< Prev Question Next Question >>

Question 30/88

SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
Based on the scenario, which of the following would have helped Janice to better meet the company's needs?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (88q)
Question 1: SCENARIO Please use the following to answer the next QUESTIO...
Question 2: SCENARIO Please use the following to answer the next QUESTIO...
Question 3: Which of the following data elements is most likely to be su...
Question 4: SCENARIO Please use the following to answer the next QUESTIO...
Question 5: In March 2012, the FTC released a privacy report that outlin...
Question 6: SCENARIO Please use the following to answer the next QUESTIO...
Question 7: Chanel Hair Studio is a busy high-end hair salon. In an effo...
Question 8: Which of the following state laws has an entity exemption fo...
Question 9: Which of the following practices is NOT a key component of a...
Question 10: Smith Memorial Healthcare (SMH) is a hospital network headqu...
Question 11: SuperMart is a large Nevada-based business that has recently...
Question 12: SCENARIO Please use the following to answer the next QUESTIO...
Question 13: Which of the following best describes what a "private right ...
Question 14: Which of the following federal agencies does NOT have regula...
Question 15: Which of the following became the first state to pass a law ...
Question 16: A large online bookseller decides to contract with a vendor ...
Question 17: All of the following are tasks in the "Discover" phase of bu...
Question 18: What is a legal document approved by a judge that formalizes...
Question 19: SCENARIO Please use the following to answer the next questio...
Question 20: Acme Student Loan Company has developed an artificial intell...
Question 21: SCENARIO Please use the following to answer the next questio...
Question 22: SCENARIO Please use the following to answer the next QUESTIO...
Question 23: When may a financial institution share consumer information ...
Question 24: The CFO of a pharmaceutical company is duped by a phishing e...
Question 25: A law enforcement subpoenas the ACME telecommunications comp...
Question 26: All of the following organizations are specified as covered ...
Question 27: Which statement is FALSE regarding the provisions of the Emp...
Question 28: SCENARIO Please use the following to answer the next QUESTIO...
Question 29: The Cable Communications Policy Act of 1984 requires which a...
Question 30: SCENARIO Please use the following to answer the next QUESTIO...
Question 31: What important action should a health care provider take if ...
Question 32: Which of the following best describes private-sector workpla...
Question 33: More than half of U.S. states require telemarketers to?...
Question 34: One of the most significant elements of Senate Bill No. 260 ...
Question 35: What is the main challenge financial institutions face when ...
Question 36: SCENARIO Please use the following to answer the next QUESTIO...
Question 37: SCENARIO Please use the following to answer the next questio...
Question 38: Which of the following is NOT a principle found in the APEC ...
Question 39: If an organization maintains data classified as high sensiti...
Question 40: How did the Fair and Accurate Credit Transactions Act (FACTA...
Question 41: Which of the following best describes how federal anti-discr...
Question 42: Which of the following privacy rights is NOT available under...
Question 43: In what way does the "Red Flags Rule" under the Fair and Acc...
Question 44: Which action is prohibited under the Electronic Communicatio...
Question 45: SCENARIO Please use the following to answer the next QUESTIO...
Question 46: SCENARIO - Please use the following to answer the next quest...
Question 47: What type of material is exempt from an individual's right t...
Question 48: What is the most likely reason that states have adopted thei...
Question 49: SCENARIO Please use the following to answer the next QUESTIO...
Question 50: Which of the following is NOT one of three broad categories ...
Question 51: The rules for "e-discovery" mainly prevent which of the foll...
Question 52: Mega Corp. is a U.S.-based business with employees in Califo...
Question 53: SCENARIO Please use the following to answer the next QUESTIO...
Question 54: The FTC often negotiates consent decrees with companies foun...
Question 55: SCENARIO - Please use the following to answer the next quest...
Question 56: Which of the following is an important implication of the Do...
Question 57: Which of the following does Title VII of the Civil Rights Ac...
Question 58: In what way is the Controlling the Assault of Non-Solicited ...
Question 59: SCENARIO Please use the following to answer the next QUESTIO...
Question 60: SCENARIO Please use the following to answer the next QUESTIO...
Question 61: What is the purpose of a cure provision in a stale data priv...
Question 62: Although an employer may have a strong incentive or legal ob...
Question 63: SCENARIO Please use the following to answer the next QUESTIO...
Question 64: SCENARIO Please use the following to answer the next QUESTIO...
Question 65: U.S. federal laws protect individuals from employment discri...
Question 66: A student has left high school and is attending a public pos...
Question 67: Global Manufacturing Co's Human Resources department recentl...
Question 68: What does the Massachusetts Personal Information Security Re...
Question 69: Which venture would be subject to the requirements of Sectio...
Question 70: Under the EU-US Data Privacy Framework, what must participat...
Question 71: Which jurisdiction must courts have in order to hear a parti...
Question 72: According to Section 5 of the FTC Act, self-regulation prima...
Question 73: Under the Driver's Privacy Protection Act (DPPA), which of t...
Question 74: Which of the following is NOT a common challenge large organ...
Question 75: Which of the following most accurately describes the regulat...
Question 76: Which of the following describes the most likely risk for a ...
Question 77: What was the original purpose of the Federal Trade Commissio...
Question 78: A California resident has created an account on your company...
Question 79: Which of the following laws is NOT involved in the regulatio...
Question 80: Due to cookie deprecation, businesses will be required to si...
Question 81: Under the Fair and Accurate Credit Transactions Act (FACTA),...
Question 82: A financial services company install "bossware" software on ...
Question 83: What consumer service was the Fair Credit Reporting Act (FCR...
Question 84: Which of the following statements is most accurate in regard...
Question 85: SCENARIO Please use the following to answer the next QUESTIO...
Question 86: Which federal law or regulation preempts state law?...
Question 87: What consumer protection did the Fair and Accurate Credit Tr...
Question 88: Which entities must comply with the Telemarketing Sales Rule...