Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CIPM All Questions

View all questions & answers for the CIPM exam

Exam CIPM topic 1 question 65 discussion

Actual exam question from IAPP's CIPM
Question #: 65
Topic #: 1
[All CIPM Questions]

In which situation would a Privacy Impact Assessment (PIA) be the least likely to be required?

  • A. If a company created a credit-scoring platform five years ago.
  • B. If a health-care professional or lawyer processed personal data from a patient's file.
  • C. If a social media company created a new product compiling personal data to generate user profiles.
  • D. If an after-school club processed children's data to determine which children might have food allergies.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ssourav
Highly Voted 1 year, 3 months ago
Selected Answer: B
In many jurisdictions, the processing of personal data by health-care professionals and lawyers as part of their regular professional duties (for instance, treatment of patients or legal representation) might not necessarily trigger the requirement for a PIA. This is because the processing is generally understood, expected, and subject to other professional and legal obligations, like doctor-patient or attorney-client confidentiality.
upvoted 5 times
...
humhain
Most Recent 9 months ago
Selected Answer: A
A Privacy Impact Assessment (PIA) is a process that helps to identify and mitigate the privacy risks of a project or activity that involves personal data. A PIA is usually required when there is a new or significant change in the way personal data is collected, used, or disclosed. Therefore, a PIA would be the least likely to be required if a company created a credit-scoring platform five years ago, as this would not be a new or significant change. The other situations involve new or changed processing of personal data that could have privacy impacts, such as sensitive data (health or children’s data), profiling data (user profiles), or large-scale data (patient’s file).
upvoted 1 times
...
carlosbui
1 year ago
should be B
upvoted 1 times
...
[Removed]
1 year, 2 months ago
Selected Answer: B
Should be B
upvoted 1 times
...
Adyyogi
1 year, 3 months ago
Privacy assessments measure an organization’s compliance with laws, regulations, adopted standards, and internal policies and procedures. Their scope may include education and awareness; monitoring and responding to the regulatory environment; data, systems, and process assessments; risk assessments; incident response; contracts; remediation; and program assurance, including audits.
upvoted 1 times
...
Boats
1 year, 5 months ago
Selected Answer: A
PIAs are triggered do to some type of new activity. New data being added, new database, new program. A should be the correct answer because a PIA should have been done five years ago.
upvoted 1 times
...
tonik
1 year, 5 months ago
B maybe?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...