Certified Data Privacy Solutions Engineer (CDPSE) — Question 71
How can an organization BEST ensure its vendors are complying with data privacy requirements defined in their contracts?
Answer options
- A. Review self-attestations of compliance provided by vendor management.
- B. Obtain independent assessments of the vendors’ data management processes.
- C. Perform penetration tests of the vendors’ data security.
- D. Compare contract requirements against vendor deliverables.
Correct answer: D
Explanation
The correct answer is D because comparing contract requirements with vendor deliverables directly assesses compliance with agreed-upon data privacy standards. Option A relies on self-reporting, which may not be reliable. Option B, while useful, does not directly compare contract compliance. Option C focuses on security testing rather than privacy compliance.