Purpose Limits, Risk Assessments, and Security
California, Colorado, Connecticut, Virginia impose purpose/processing limitations and require risk assessments for heightened-risk processing; Utah lacks both. All five require reasonable administrative, technical, and physical security.
How this supports CIPP/US study
Use this lesson to compare state-law scope, rights, exceptions and enforcement before choosing an answer. Continue with the CIPP/US exam questions.
| Obligation | States |
|---|---|
| Purpose/processing limitation (necessary/proportionate) | California, Colorado, Connecticut, Virginia (NOT Utah) |
| Risk assessment for heightened-risk processing | California, Colorado, Connecticut, Virginia (NOT Utah) |
| Reasonable administrative, technical, physical security | All five |
Processing that triggers a risk assessment includes targeted advertising, selling personal data, processing sensitive data, and certain profiling.
Utah is the outlier - it does not impose purpose/processing limitations and does not require risk assessments. But all five states, including Utah, require reasonable security measures.
Key terms - quick answers
What is “Purpose/processing limitation”?
What is “Risk assessment”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.