IAPP CIPP/US Practice Exam

Category - Professional

FTC violations of the GLBA Safeguards Rule include an organization’s failure to take reasonable steps to select third-party data processing vendors capable of safeguarding personal information provided by the organization.

Which of the following is the FTC enforcing in this example?
  1. Effective Vendor Management (with safeguard compliance)
  2. Inaccurate Data Flow Mapping
  3. Non-compliance with Standard Contractual Clauses
  4. Insufficient Binding Corporate Rules
Explanation
Answer: A - Through resolution of a Consent Agreement, the FTC alleged that an organization violated the GLBA Safeguards Rule by failing to implement an effective vendor management program. According to the FTC’s allegations, the organization failed to acknowledge the vendor’s lack of capability for maintaining appropriate safeguards to protect personal information.
Was this helpful? Upvote!
Login to contribute your own answer or details