Certified Information Privacy Technologist (CIPT) — Question 52
SCENARIO -
Please use the following to answer next question:
EnsureClaim is developing a mobile app platform for managing data used for assessing car accident insurance claims. Individuals use the app to take pictures at the crash site, eliminating the need for a built-in vehicle camera. EnsureClaim uses a third-party hosting provider to store data collected by the app. EnsureClaim customer service employees also receive and review app data before sharing with insurance claim adjusters.
The app collects the following information:
✑ First and last name
✑ Date of birth (DOB)
✑ Mailing address
✑ Email address
✑ Car VIN number
✑ Car model
✑ License plate
✑ Insurance card number
✑ Photo
✑ Vehicle diagnostics
✑ Geolocation
The app is designed to collect and transmit geolocation data. How can data collection best be limited to the necessary minimum?
Answer options
- A. Allow user to opt-out geolocation data collection at any time.
- B. Allow access and sharing of geolocation data only after an accident occurs.
- C. Present a clear and explicit explanation about need for the geolocation data.
- D. Obtain consent and capture geolocation data at all times after consent is received.
Correct answer: B
Explanation
The correct answer, B, limits geolocation data collection to when it is most relevant, which occurs after an accident. Options A and D allow for unnecessary data collection at times when it may not be needed, while C, although informative, does not restrict data collection to only necessary instances.