Question 35
Domain 3: The Privacy Technologist’s Role in the OrganizationA smart TV update will use short microphone samples to improve wake-word detection. Which action best translates privacy requirements into a technical and operational control?
Correct answer: A
Explanation
Privacy requirements are translated into controls by giving users notice and choice. Updating the device notice satisfies transparency, and an in-device setting lets users control the microphone-sample feature, aligning with the principle of user control over data use.
Why each option is right or wrong
A. Update the device notice and provide an in-device setting that allows users to control the feature
The strongest control here is the combination of transparency and user choice: under GDPR Articles 12–14, the controller must provide clear notice about the processing, and Article 7 requires consent to be as easy to withdraw as to give, which is operationalized by an in-device toggle. Because short microphone samples are personal data when they can identify or relate to a user, the notice must explain the purpose and retention, and the setting gives the user a practical means to enable or disable that processing rather than relying on a vague policy statement.
B. Hide the feature in release notes because the samples are short
C. Keep the setting enabled with no user-facing information
D. Rely on the television retailer to explain the change