nerdexam
Isaca

CDPSE · Question #137

Which of the following should be done FIRST when a data collection process is deemed to be a high-level risk?

The correct answer is C. Conduct a privacy Impact assessment (PIA). When a data collection process is identified as high-risk, a Privacy Impact Assessment (PIA) must be conducted first. A PIA is a structured, systematic analysis that identifies what personal data is collected, why, how it is used, who has access, what risks exist, and what…

Privacy Governance

Question

Which of the following should be done FIRST when a data collection process is deemed to be a high-level risk?

Options

  • APerform a business impact analysis (BIA).
  • BImplement remediation actions to mitigate privacy risk.
  • CConduct a privacy Impact assessment (PIA).
  • DCreate a system of records notice (SORN).

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    69% (20)
  • D
    17% (5)

Explanation

When a data collection process is identified as high-risk, a Privacy Impact Assessment (PIA) must be conducted first. A PIA is a structured, systematic analysis that identifies what personal data is collected, why, how it is used, who has access, what risks exist, and what mitigations are appropriate. It produces the evidence base needed to make informed decisions. Without completing a PIA, any remediation actions (B) would be uninformed and possibly misdirected. A Business Impact Analysis (A) focuses on operational continuity, not privacy risk. A System of Records Notice (D) is a U.S. federal government publication requirement that comes after the assessment and decision-making process, not before.

Topics

#Privacy Impact Assessment#Risk management#Data collection#Privacy controls

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice