Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusing on placing privacy professionals in roles at major companies. Job candidates create online profiles
outlining their experience and credentials, and can pay $19.99/month via credit card to have their profiles promoted to potential employers. Privacy Is Hiring Inc. keeps all customer data at rest encrypted on its servers.
Under what circumstances would Privacy Is Hiring Inc., need to notify affected individuals in the event of a data breach?
Under the California Consumer Privacy Act (CCPA), a business that collects personal information of California residents must notify them of a data breach if their personal information is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of the duty to implement and maintain reasonable security procedures and practices. However, the CCPA excludes encrypted or redacted personal information from the definition of personal information, unless the encryption key or security credential is also compromised. Therefore, Privacy Is Hiring Inc. would need to notify the affected individuals only if the encryption keys were also taken along with the credit card information, as this would render the encryption ineffective and expose
the personal information to unauthorized access. The other options are not relevant to the CCPA notification requirement, although they may be relevant to other laws or best practices.Reference:CCPA(Section 1798.150),IAPP CIPP/US Study Guide(p. 63-64)
Jerry
Aleshia
5 days agoDean
10 days agoWilda
15 days agoLawrence
20 days agoJerry
26 days agoAleshia
1 month agoDean
1 month agoLavelle
1 month agoMelissia
2 months agoJamey
2 months agoMira
2 months agoMiriam
2 months agoTamie
2 months agoBernardo
2 months agoLilli
3 months agoClarence
3 months ago