What is the PRIMARY means by which an organization communicates customer rights as it relates to the use of their personal information?
Correct Answer: B
Explanation
The primary means by which an organization communicates customer rights as it relates to the use of their personal information is publishing a privacy notice. A privacy notice is a document that informs the customers about how the organization collects, uses, shares, and protects their personal information, and what rights and choices they have regarding their data4. A privacy notice is a legal requirement under many data protection laws and regulations, such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), or the Personal Information Protection and Electronic Documents Act (PIPEDA)5 . A privacy notice is also a good practice to demonstrate the organization's commitment to transparency, accountability, and customer trust. References:
* ISACA Glossary of Terms
* Article 13 and 14 of the GDPR
* [Section 1798.100 of the CCPA]
* [Schedule 1, Principle 4.8 of the PIPEDA]
* [ISACA CDPSE Review Manual, Chapter 1, Section 1.3.2]