# CDPSE interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How do you turn privacy requirements into technical controls? | Map each requirement to a control, an owner and a test, and keep the mapping current. | |
| 2 | Who decides what personal data a system may process? | The business owner with privacy and legal input, recorded and reviewed on change. | |
| 3 | How do you design access control for personal data? | Least privilege, role-based access, privileged access controls, and regular reviews. | |
| 4 | Where do encryption and tokenization fit? | Encryption protects data at rest and in transit; tokenization removes real values from systems that do not need them. | |
| 5 | How do you log access to personal data without over-collecting? | Log who, what and when, keep logs only as long as needed, and protect them. | |
| 6 | How do you find personal data across our systems? | Discovery tools, data flow maps and owners who confirm what is there. | |
| 7 | How do you enforce retention and deletion? | Rules in code where possible, scheduled jobs, and evidence they ran. | |
| 8 | How do you handle personal data in test environments? | Synthetic or masked data by default, and approved exceptions only. | |

Source: https://credentialpress.com/guides/cdpse-interview-questions
