nerdexam
Isaca

CDPSE · Question #134

Which of the following is the BEST way to address privacy concerns when an organization captures personal data from a third party through an open application programming interface (API)?

The correct answer is C. Obtain consent from the data subjects. Under virtually all major privacy frameworks (GDPR, CCPA, PIPEDA, etc.), organizations must have a lawful basis to collect and process personal data. Consent from the data subjects is often the primary and most fundamental basis, especially when collecting data through an open…

Data Life Cycle

Question

Which of the following is the BEST way to address privacy concerns when an organization captures personal data from a third party through an open application programming interface (API)?

Options

  • ADevelop a service level agreement (SLA) with the third party
  • BImplement encryption for the data transmission
  • CObtain consent from the data subjects
  • DReview the specification document of the open API.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    84% (21)
  • D
    4% (1)

Explanation

Under virtually all major privacy frameworks (GDPR, CCPA, PIPEDA, etc.), organizations must have a lawful basis to collect and process personal data. Consent from the data subjects is often the primary and most fundamental basis, especially when collecting data through an open third-party API where data subjects may not have directly interacted with the collecting organization. An SLA (A) governs the service relationship with the third party but does not legitimize the data collection itself. Encryption (B) protects data in transit but does not address the legal or ethical right to collect. Reviewing the API specification (D) is a technical due-diligence step but does not resolve the underlying privacy obligation.

Topics

#Consent#Data collection#Third-party data#Legal basis

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice