Answer Key C2-001–C2-014
Each item preserves the correct rationale, why distractors are weaker, the source anchor and the main confusion pair.
C2-001 — A
Rationale: Chapter 2 treats ethics as lifecycle responsibility across obtaining, managing, interpreting, using and disposing data, with attention to people/organization consequences.
Why others fail: B is privacy-only and collection-only; C is security-only and excludes interpretation/presentation; D overstates Governance by requiring council approval for every transaction.
Source: pp. 51–53; Figure 12.
Confusion pair: Data Ethics vs privacy/security-only.
C2-002 — B
Rationale: Introductory ethics centers on effects on people, potential misuse, and data's economic value/ownership.
Why others fail: A is operational; C is the security CIA triad; D lists only partial lifecycle stages.
Source: p. 51.
Confusion: ethics concerns vs security triad.
C2-003 — C
Rationale: reliable, complete and accurate data becomes an ethical concern because decisions based on it materially affect people.
Why others fail: A mistakes security for complete ethical duty; B wrongly delegates the issue to software; D warning users does not replace quality management.
Source: pp. 51–53.
Confusion: Data Quality vs security.
C2-004 — D
Rationale: Chapter 2 links ethical handling to trustworthiness, stakeholder relationships, human dignity, Governance and controls.
Why others fail: A is aspirational without mechanisms; B mistakes platform centralization for ethics; C incorrectly delegates organization-wide responsibility to one officer.
Source: p. 53.
Confusion: ethical culture vs public statement/single owner.
C2-005 — A
Rationale: Respect for Persons directly covers autonomy, dignity, meaningful choice and protection where autonomy is diminished.
Why others fail: Beneficence is harm/benefit; Justice is equitable treatment/disparity; Accountability is a governance/privacy theme, not the most direct Belmont principle here.
Source: §3.1, p. 54.
Confusion: Respect vs Beneficence vs Justice.
C2-006 — B
Rationale: Beneficence says maximize possible benefit and minimize possible harm; avoiding unnecessary invasiveness fits directly.
Why others fail: Justice is fairness; Law/Public Interest is broader public/legal duty; Purpose Limitation asks whether use fits specified purpose.
Source: §3.1, p. 54.
Confusion: Beneficence vs Justice/privacy.
C2-007 — C
Rationale: Justice asks whether comparable people/groups receive fair and equitable treatment and whether algorithms disproportionately harm groups.
Why others fail: Respect is autonomy/dignity; Beneficence is relevant but less specific than group disparity; Storage Limitation concerns retention.
Source: §3.1, pp. 54–55.
Confusion: Justice vs Beneficence.
C2-008 — D
Rationale: Menlo adds Respect for Law and Public Interest to Belmont.
Why others fail: minimization and erasure belong to privacy discussions; “Transparency by Default” is not the named Menlo fourth principle.
Source: §3.1, p. 54.
Confusion: Belmont vs Menlo.
C2-009 — A
Rationale: EDPS pillars summarized by Chapter 2 include future-oriented regulation/privacy rights, accountable controllers, privacy-conscious design and empowered individuals.
Why others fail: localization, unlimited secondary use and centralized ownership are not those pillars.
Source: §3.1, p. 55.
C2-010 — B
Rationale: Chapter 2 describes Data Governance as vital for deciding who may do what with which data and whether processing is appropriate/necessary.
Why others fail: Storage, Warehousing and Reference Data are operational/technical functions, not the enterprise decision-rights capability in the stem.
Source: §3.1 p. 55; §3.6 p. 67.
Confusion: Governance vs technical functions.
C2-011 — C
Rationale: specified purpose / purpose limitation ties collection and later use to identified legitimate purposes and challenges incompatible secondary use.
Why others fail: Accuracy is correctness; safeguards are protection, not authorization; portability is an individual right.
Source: §3.2, pp. 55–56.
Confusion: purpose limitation vs security/accuracy.
C2-012 — D
Rationale: Data Minimization requires adequate, relevant and necessary data rather than unnecessary “just in case” collection.
Why others fail: Storage Limitation is duration; Integrity/Confidentiality is protection; Accuracy is correctness/currentness.
Source: Table 1, p. 56.
Confusion: minimization vs storage limitation.
C2-013 — A
Rationale: where consent is the basis, Chapter 2 describes it as affirmative, freely given, specific, informed and unambiguous.
Why others fail: silence is not affirmative; consent does not permanently waive qualified rights; the source does not claim consent is the only basis for every processing activity.
Source: §3.2, p. 56.
Confusion: consent vs notice/rights.
C2-014 — B
Rationale: PIPEDA Accountability assigns responsibility for personal information under organizational control and requires a designated accountable individual.
Why others fail: A invents universal localization; C invents court approval; D confuses retention limitation with immediate deletion.
Source: Table 2, p. 57.
Confusion: PIPEDA Accountability vs retention/access.