Certified Information Privacy Manager (CIPM) — Question 90
Your company wants to convert paper records that contain customer personal information into electronic form, upload the records into a new third-party marketing tool and then merge the customer personal information in the marketing tool with information from other applications.
As the Privacy Officer, which of the following should you complete to effectively make these changes?
Answer options
- A. A Record of Authority.
- B. A Personal Data Inventory.
- C. A Privacy Threshold Analysis (PTA).
- D. A Privacy Impact Assessment (PIA).
Correct answer: D
Explanation
The correct answer is D, a Privacy Impact Assessment (PIA), as it evaluates how personal data is collected, used, and shared, ensuring compliance with privacy regulations. Options A, B, and C do not specifically address the assessment of risks associated with processing personal information in this context.