Certified Information Privacy Professional/United States (CIPP/US) Exam — Questions and Answers
Question 1: The FTC's approach to mobile app privacy requires that apps:
- Use only government-approved encryption algorithms
- Submit to government certification before launch
- Honor the privacy promises they make to users and avoid deceptive practices (Correct answer)
- Register their data practices with the FTC annually
Correct answer: Honor the privacy promises they make to users and avoid deceptive practices
Under Section 5 of the FTC Act, mobile apps must honor their stated privacy policies and not engage in deceptive or unfair data practices.
Question 2: Which U.S. law governs the privacy of children's personal information online?
- GLBA
- HIPAA
- FERPA
- COPPA (Correct answer)
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) is a landmark U.S. federal law specifically designed to protect the privacy of children under 13 online. It mandates that websites and online services obtain verifiable parental consent before collecting, using, or disclosing personal information from children. COPPA sets strict requirements for operators regarding data collection practices, parental notification, and data security for children's data.
Question 3: Which federal law restricts the government's ability to compel disclosure of stored electronic communications held by service providers?
- FERPA
- COPPA
- CAN-SPAM Act
- ECPA Stored Communications Act (Correct answer)
Correct answer: ECPA Stored Communications Act
The Stored Communications Act (Title II of ECPA) restricts voluntary disclosure by service providers and limits the government's ability to compel access to stored electronic communications.
Question 4: An employer collects biometric data (fingerprints) for employee time-and-attendance tracking. Which state law is most commonly associated with strict regulation of biometric data collection in employment?
- Illinois Biometric Information Privacy Act (BIPA) (Correct answer)
- Texas Identity Theft Enforcement and Protection Act
- California Consumer Privacy Act (CCPA)
- New York SHIELD Act
Correct answer: Illinois Biometric Information Privacy Act (BIPA)
The Illinois BIPA is the most prominent and strictly enforced biometric privacy law in the U.S., requiring informed consent, written policies, and limiting data retention and disclosure.
Question 5: The HIPAA Privacy Rule's 'minimum necessary' standard requires covered entities to:
- Delete patient records within one year of the last treatment
- Limit PHI uses and disclosures to the minimum necessary to accomplish the intended purpose (Correct answer)
- Collect as much patient data as possible for comprehensive care
- Obtain written patient consent before every internal use of PHI
Correct answer: Limit PHI uses and disclosures to the minimum necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI access and disclosure to only what is needed for the specific purpose.
Question 6: Which federal law gives the FTC authority to regulate unfair or deceptive trade practices?
- Health Insurance Portability Act
- Federal Trade Commission Act (Correct answer)
- Communications Act
- Privacy Act of 1974
Correct answer: Federal Trade Commission Act
The Federal Trade Commission Act (FTC Act) is the foundational law that established the Federal Trade Commission and granted it broad authority to prevent unfair methods of competition and unfair or deceptive acts or practices in commerce. This authority is the basis for the FTC's extensive role in enforcing consumer protection and privacy laws in the United States.
Question 7: What is the Plan-Do-Check-Act (PDCA) cycle used for?
- Annual budget allocation
- Employee performance reviews exclusively
- Continuous improvement of processes and practices (Correct answer)
- One-time project planning only
Correct answer: Continuous improvement of processes and practices
The PDCA cycle is a systematic approach to continuous improvement where processes are planned, implemented, evaluated, and refined in an ongoing cycle.
Question 8: The Fair Credit Reporting Act (FCRA) primarily governs:
- The accuracy, fairness, and privacy of consumer credit reports and use of consumer report information (Correct answer)
- Only information held by the three major credit bureaus
- All financial transactions between consumers and banks
- Only mortgage lending practices
Correct answer: The accuracy, fairness, and privacy of consumer credit reports and use of consumer report information
The FCRA regulates consumer reporting agencies and the use of consumer report information by furnishers and users of such reports.
Question 9: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach of unsecured PHI within:
- 60 days of discovery (Correct answer)
- 6 months of discovery
- 90 days of discovery
- 30 days of discovery
Correct answer: 60 days of discovery
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery of the breach.
Question 10: Why is data mapping critical to privacy compliance?
- It helps develop advertisements.
- It ensures better customer service only.
- It helps track how personal data is collected, stored, and used (Correct answer)
- It slows down compliance efforts.
Correct answer: It helps track how personal data is collected, stored, and used
Data mapping is a foundational process for privacy compliance as it creates a visual representation or inventory of an organization's data flows. By identifying where personal data originates, where it is stored, how it is processed, and with whom it is shared, organizations can understand their privacy risks, demonstrate accountability, and ensure compliance with various data protection regulations.
Question 11: Under the Computer Fraud and Abuse Act (CFAA), unauthorized access to a protected computer system is classified as:
- Not regulated unless financial data is stolen
- A federal crime subject to criminal and civil liability (Correct answer)
- A civil matter subject only to private lawsuits
- An issue governed solely by state law
Correct answer: A federal crime subject to criminal and civil liability
The CFAA makes unauthorized access to protected computers a federal crime and also provides a civil cause of action for victims.
Question 12: Which regulation is enforced by state-level privacy agencies like the California Privacy Protection Agency (CPPA)?
- HIPAA
- FERPA
- GDPR
- CCPA/CPRA (Correct answer)
Correct answer: CCPA/CPRA
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is a landmark state-level privacy regulation in the U.S. It is enforced by state-level agencies, primarily the California Privacy Protection Agency (CPPA), which has investigative and enforcement powers to ensure businesses comply with its provisions regarding consumer data rights.
Question 13: A terminated employee requests access to their personnel file. Under which legal framework are they most likely to have this right?
- The FCRA, which mandates employer disclosure of all records used in employment decisions
- State law, as there is no federal law granting private-sector employees access to their personnel files (Correct answer)
- The Privacy Act of 1974, which covers all employment records
- HIPAA, because personnel files contain health-related information
Correct answer: State law, as there is no federal law granting private-sector employees access to their personnel files
The right of private-sector employees to access their personnel files is governed by state law; states like California, Michigan, and Illinois have specific personnel file access statutes.
Question 14: Which approach best describes the integration of theory and practice in this profession?
- Ignoring theory and relying solely on experience
- Following theory exactly without any modification
- Using theory only during examinations
- Applying theoretical knowledge to solve real-world problems while adapting to specific contexts (Correct answer)
Correct answer: Applying theoretical knowledge to solve real-world problems while adapting to specific contexts
Effective professional practice involves applying theoretical foundations to real-world situations while adapting approaches to specific contexts and needs.
Question 15: Why is training important in privacy program management?
- To boost sales
- To reduce server downtime
- To meet contractual obligations
- To educate employees on data protection (Correct answer)
Correct answer: To educate employees on data protection
Training and awareness programs are crucial in privacy program management because they educate employees about their roles and responsibilities in protecting personal data. By understanding privacy policies, procedures, and potential risks, employees can help prevent data breaches, ensure compliance with regulations, and foster a privacy-aware culture within the organization.
Question 16: What enforcement power does the FTC NOT have?
- Enforce consent decrees
- Investigate unfair practices
- Pursue civil penalties
- Issue criminal indictments (Correct answer)
Correct answer: Issue criminal indictments
While the Federal Trade Commission (FTC) has broad powers to investigate unfair or deceptive practices, pursue civil penalties, and enforce consent decrees, it does not have the authority to issue criminal indictments. Criminal enforcement typically falls under the purview of the Department of Justice (DOJ) or state attorneys general.
Question 17: Why is stakeholder buy-in important for strategic implementation?
- Because it eliminates the need for project management
- Because it generates positive media coverage
- Because successful implementation requires support and cooperation from those affected (Correct answer)
- Because it is a legal requirement in all organizations
Correct answer: Because successful implementation requires support and cooperation from those affected
Stakeholder buy-in is critical because successful implementation depends on the active support, cooperation, and engagement of the people who will be affected by or involved in executing the strategy.
Question 18: Which U.S. regulatory agency focuses on financial privacy and data protection?
- FAA
- FDA
- CFPB (Correct answer)
- CPUC
Correct answer: CFPB
The Consumer Financial Protection Bureau (CFPB) is a U.S. government agency responsible for consumer protection in the financial sector. It focuses on ensuring fair and transparent practices for financial products and services, including aspects related to financial privacy and the protection of consumer financial data.
Question 19: What does SWOT analysis evaluate?
- Standards, Warranties, Objectives, and Targets
- Sales, Workers, Outputs, and Timelines
- Systems, Workflows, Operations, and Technology
- Strengths, Weaknesses, Opportunities, and Threats (Correct answer)
Correct answer: Strengths, Weaknesses, Opportunities, and Threats
SWOT analysis is a strategic planning framework that evaluates internal Strengths and Weaknesses and external Opportunities and Threats.
Question 20: What does a risk matrix assess?
- The probability and impact of identified risks (Correct answer)
- The timeline for risk resolution
- Only the financial cost of risks
- The number of employees affected
Correct answer: The probability and impact of identified risks
A risk matrix evaluates risks based on two dimensions: the probability (likelihood) of occurrence and the potential impact (severity) if the risk materializes.
Question 21: What type of action can the FTC take against companies violating privacy laws?
- Collect taxes
- Enact new laws
- File civil enforcement actions (Correct answer)
- Issue patents
Correct answer: File civil enforcement actions
The Federal Trade Commission (FTC) has significant enforcement powers to address violations of privacy laws and unfair or deceptive trade practices. These powers include filing civil enforcement actions in federal court, negotiating consent decrees with companies, and imposing monetary penalties or requiring specific remedial actions to protect consumers.
Question 22: Which federal agency enforces the Children's Online Privacy Protection Act (COPPA)?
- Department of Education
- Federal Trade Commission (Correct answer)
- Department of Health and Human Services
- Federal Communications Commission
Correct answer: Federal Trade Commission
The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law designed to protect the online privacy of children under 13. The Federal Trade Commission (FTC) is the primary agency responsible for enforcing COPPA, issuing rules and taking enforcement actions against companies that violate its provisions regarding the collection of personal information from children.
Question 23: Which state attorney general is often involved in privacy-related enforcement?
- Local police departments
- City council offices
- State attorneys general (Correct answer)
- Library boards
Correct answer: State attorneys general
State attorneys general play a significant role in privacy enforcement within their respective states. They have the authority to investigate and bring legal actions against companies that violate state consumer protection laws, including those related to data privacy and security. They often work in conjunction with federal agencies or lead multi-state investigations.
Question 24: Under the Electronic Communications Privacy Act (ECPA), which exception most commonly allows employers to monitor employee email on company systems?
- The law enforcement exception
- The business extension exception (Correct answer)
- The prior consent exception
- The national security exception
Correct answer: The business extension exception
The business extension exception under ECPA permits employers to monitor communications over equipment provided in the ordinary course of business.
Question 25: Under HIPAA, a 'business associate' is best described as:
- An employee of a covered entity who handles PHI
- A patient's authorized personal representative
- A person or entity that performs functions on behalf of a covered entity that involve the use or disclosure of PHI (Correct answer)
- A government health oversight agency
Correct answer: A person or entity that performs functions on behalf of a covered entity that involve the use or disclosure of PHI
A business associate is a person or organization that performs services for a covered entity that involve creating, receiving, maintaining, or transmitting PHI.
Question 26: Under the FCRA, consumer reporting agencies must investigate disputed information within:
- 10 business days
- 30 days (generally) (Correct answer)
- 60 days
- 90 days
Correct answer: 30 days (generally)
The FCRA generally requires consumer reporting agencies to complete reinvestigation of disputed information within 30 days of receiving the dispute.
Question 27: Which agency enforces HIPAA privacy regulations?
- Federal Trade Commission
- Securities and Exchange Commission
- Federal Communications Commission
- Office of Civil Rights (HHS) (Correct answer)
Correct answer: Office of Civil Rights (HHS)
The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting sensitive patient health information. The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) is the primary federal agency responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules, investigating complaints, and imposing penalties for violations.
Question 28: What is the appropriate action when discovering a colleague has violated professional standards?
- Handle it privately without documentation
- Post about it on social media
- Ignore it to maintain the relationship
- Report through proper channels as outlined in the code of ethics (Correct answer)
Correct answer: Report through proper channels as outlined in the code of ethics
Professional standards require reporting violations through proper channels to protect the public and maintain the integrity of the profession.
Question 29: Why is regular risk reassessment important?
- Because initial assessments are always wrong
- Because the risk landscape changes as conditions, activities, and environments evolve (Correct answer)
- Because regulators require it exactly once per year
- Because it provides work for risk management teams
Correct answer: Because the risk landscape changes as conditions, activities, and environments evolve
Regular risk reassessment is essential because risks are dynamic — new threats emerge, existing risks change in severity, and the effectiveness of controls may vary over time.
Question 30: Which of the following is the best practice when an employer wants to implement video surveillance of the workplace?
- Provide employees with advance notice of the surveillance through a written policy, avoiding placement in areas where employees have a heightened expectation of privacy such as restrooms (Correct answer)
- Install cameras in all areas including restrooms to deter theft
- Notify only senior management and security personnel to preserve the deterrent effect
- Obtain signed waivers from each employee consenting to 24-hour surveillance
Correct answer: Provide employees with advance notice of the surveillance through a written policy, avoiding placement in areas where employees have a heightened expectation of privacy such as restrooms
Best practice requires advance notice to employees and avoidance of locations (restrooms, changing rooms) where employees retain a reasonable expectation of privacy, balancing business interests with employee rights.
Question 31: What does a privacy notice typically include?
- A list of all employees
- Procedures for financial auditing
- Only the organization's mission
- Details about data collection and user rights (Correct answer)
Correct answer: Details about data collection and user rights
A privacy notice is a public statement explaining an organization's data handling practices. It typically informs individuals about what personal data is collected, the purposes for collection, how it will be used and shared, and the rights individuals have regarding their data, such as access or deletion. This transparency is fundamental for building trust and complying with privacy regulations.
Question 32: Under the Stored Communications Act (SCA), which of the following employer actions would most likely be permissible?
- Accessing an employee's personal Gmail account without consent
- Compelling a third-party cloud provider to disclose employee personal communications without legal process
- Accessing emails stored on the company's own email server without employee consent (Correct answer)
- Intercepting employee messages on a third-party messaging platform in real time
Correct answer: Accessing emails stored on the company's own email server without employee consent
The SCA generally permits system operators (including employers) to access communications stored on their own systems, as they are considered an authorized party.
Question 33: A company implements keystroke logging software on all employee computers. What is the most important step the company should take to limit privacy risk?
- Obtain a court order before deploying the software
- Limit monitoring to only remote workers
- Provide clear notice to employees through an acceptable use policy (Correct answer)
- Encrypt all logged keystrokes and never review them
Correct answer: Provide clear notice to employees through an acceptable use policy
Providing clear notice through an acceptable use or monitoring policy reduces privacy risk and supports the business extension exception under ECPA.
Question 34: Under the Family Educational Rights and Privacy Act (FERPA), educational records may generally be disclosed to third parties without student consent only when:
- The student has graduated
- The student's parents request the disclosure
- A recognized exception applies, such as a school official with a legitimate educational interest (Correct answer)
- The school has a written data sharing policy
Correct answer: A recognized exception applies, such as a school official with a legitimate educational interest
FERPA permits disclosure of educational records without consent in specific circumstances, including to school officials with legitimate educational interests.
Question 35: Under the FCRA, the statute of limitations for filing a civil lawsuit for a violation is generally:
- 10 years from the date of the violation
- 6 months from the date of the adverse action
- There is no statute of limitations for FCRA violations
- 2 years from discovery of the violation or 5 years from the date of the violation, whichever is earlier (Correct answer)
Correct answer: 2 years from discovery of the violation or 5 years from the date of the violation, whichever is earlier
FCRA civil actions must be brought within 2 years after the date of discovery of the violation, or within 5 years of the violation, whichever comes first.
Question 36: What is the primary purpose of an employee privacy notice under the California Consumer Privacy Act (CCPA) as amended by the CPRA?
- To satisfy FCRA's pre-adverse action disclosure obligations
- To comply with HIPAA's notice of privacy practices requirement
- To obtain employee consent before collecting any personal data
- To inform employees about the categories of personal information collected about them and the purposes for which it is used (Correct answer)
Correct answer: To inform employees about the categories of personal information collected about them and the purposes for which it is used
The CPRA requires employers to provide a privacy notice at or before collection informing California employees about the categories of personal information collected and the purposes of use.
Question 37: What defines a "best practice" in professional settings?
- Any procedure that is commonly used regardless of outcomes
- A method recommended by a single authority
- The most expensive approach available
- A method or technique that has consistently shown superior results through evidence (Correct answer)
Correct answer: A method or technique that has consistently shown superior results through evidence
Best practices are methods or techniques that have consistently demonstrated superior results through evidence, research, and widespread professional validation.
Question 38: What is active listening in a professional context?
- Simply waiting for your turn to speak
- Fully concentrating, understanding, responding, and remembering what is being said (Correct answer)
- Taking verbatim notes of everything said
- Agreeing with everything the speaker says
Correct answer: Fully concentrating, understanding, responding, and remembering what is being said
Active listening involves fully concentrating on the speaker, understanding the message, providing appropriate responses, and retaining the information communicated.
Question 39: Under HIPAA, 'Protected Health Information' (PHI) is defined as individually identifiable health information that is:
- Only information contained in a patient's medical chart
- Only information shared with insurance companies
- Only information stored in electronic format
- Held or transmitted by a covered entity or its business associate in any form or medium (Correct answer)
Correct answer: Held or transmitted by a covered entity or its business associate in any form or medium
PHI encompasses any individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate, regardless of format.
Question 40: Under the HIPAA Privacy Rule, patients have the right to do all of the following EXCEPT:
- Request an amendment to their PHI
- Prohibit all sharing of their PHI for treatment purposes (Correct answer)
- Request access to their PHI
- Receive an accounting of disclosures of their PHI
Correct answer: Prohibit all sharing of their PHI for treatment purposes
HIPAA does not give patients an absolute right to block all PHI disclosures for treatment; covered entities may share PHI for treatment, payment, and healthcare operations without patient authorization.
Question 41: Which federal law primarily governs online privacy protections for children in the United States?
- FERPA
- GLBA
- COPPA (Correct answer)
- HIPAA
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) is the primary federal law governing online data collection from children under 13.
Question 42: Why is continuous improvement important in quality management?
- Because existing processes are always fundamentally flawed
- Because regulators demand changes every year
- Because standards evolve, competitors improve, and customer expectations change (Correct answer)
- Because employees need new tasks to stay busy
Correct answer: Because standards evolve, competitors improve, and customer expectations change
Continuous improvement is essential because the competitive landscape, customer expectations, and industry standards are constantly evolving, requiring ongoing adaptation.
Question 43: HIPAA enforcement actions for civil violations are primarily handled by which agency?
- The Department of Justice (DOJ)
- The Department of Health and Human Services Office for Civil Rights (HHS OCR) (Correct answer)
- The Federal Trade Commission (FTC)
- State attorneys general exclusively
Correct answer: The Department of Health and Human Services Office for Civil Rights (HHS OCR)
HHS OCR is the primary federal enforcement body for HIPAA civil violations, including failure to safeguard PHI and improper disclosures.
Question 44: When a company uses a cloud service provider to process personal data on its behalf, the cloud provider is typically considered a:
- Service provider or data processor (Correct answer)
- Independent third party with no restrictions
- Regulatory authority
- Data controller
Correct answer: Service provider or data processor
A cloud provider processing data on behalf of a customer acts as a service provider or processor, bound by the customer's instructions and applicable contractual obligations.
Question 45: When applying core principles in practice, what should be the first consideration?
- Safety and compliance with established standards (Correct answer)
- Cost reduction opportunities
- Client entertainment preferences
- Timeline acceleration
Correct answer: Safety and compliance with established standards
Safety and compliance with established standards must always be the primary consideration when applying professional principles.
Question 46: The HITECH Act significantly strengthened HIPAA by making which of the following changes?
- Patient consent requirements for PHI disclosures were eliminated
- All PHI was made publicly accessible for research purposes
- Healthcare providers were permitted to share PHI without restrictions for treatment
- Business associates became directly liable for compliance with certain HIPAA provisions (Correct answer)
Correct answer: Business associates became directly liable for compliance with certain HIPAA provisions
The HITECH Act extended direct HIPAA liability to business associates, increased civil monetary penalties, and strengthened breach notification requirements.
Question 47: Which quality management tool is used to identify the most significant factors in a dataset?
- Organizational chart
- Flow chart
- Pareto chart (80/20 rule) (Correct answer)
- Gantt chart
Correct answer: Pareto chart (80/20 rule)
A Pareto chart applies the 80/20 principle to identify the vital few factors that account for the majority of effects, helping prioritize improvement efforts.
Question 48: What role do key performance indicators play in strategic implementation?
- They are optional reporting tools with no strategic value
- They provide measurable benchmarks to track progress toward strategic objectives (Correct answer)
- They replace the need for strategic planning entirely
- They are used only for employee salary decisions
Correct answer: They provide measurable benchmarks to track progress toward strategic objectives
KPIs serve as measurable benchmarks that enable organizations to track progress toward strategic objectives and make data-driven adjustments to implementation plans.
Question 49: Under the GLBA's opt-out provision, consumers may prevent financial institutions from doing which of the following?
- Sharing their nonpublic personal information with non-affiliated third parties for marketing purposes (Correct answer)
- Reporting them to credit bureaus
- Closing their accounts
- Collecting any financial data about them
Correct answer: Sharing their nonpublic personal information with non-affiliated third parties for marketing purposes
The GLBA's opt-out right allows consumers to prevent financial institutions from sharing their nonpublic personal information with non-affiliated third parties.
Question 50: Under the FCRA, how long before taking adverse employment action must an employer wait after providing the pre-adverse action notice?
- 30 calendar days
- A reasonable period of time (generally interpreted as at least 5 business days) (Correct answer)
- 72 hours
- No waiting period is required; the notice is purely informational
Correct answer: A reasonable period of time (generally interpreted as at least 5 business days)
FCRA requires a 'reasonable period of time' between the pre-adverse action notice and final adverse action, which the FTC has interpreted as approximately five business days.
Question 51: Which principle is essential in data classification under privacy regulations?
- Data minimization
- Data classification enables appropriate protection (Correct answer)
- Data portability
- Data duplication
Correct answer: Data classification enables appropriate protection
Data classification is an essential principle under privacy regulations because it enables organizations to assign appropriate levels of protection based on the sensitivity and value of the data. By categorizing data (e.g., public, internal, confidential, restricted), organizations can implement tailored security controls, access restrictions, and retention policies. This ensures that highly sensitive personal information receives the strongest safeguards, aligning with regulatory requirements and minimizing privacy risks.
Question 52: What is the role of a Data Governance Committee?
- To design hardware systems.
- To provide technical support.
- To govern data policies and ensure enterprise-wide accountability (Correct answer)
- To handle marketing strategy.
Correct answer: To govern data policies and ensure enterprise-wide accountability
A Data Governance Committee is a strategic body responsible for overseeing an organization's data governance framework. Its role includes establishing data policies, standards, and procedures, making decisions about data quality and security, and ensuring enterprise-wide accountability for data assets. This committee is crucial for maintaining data integrity, compliance, and strategic value.
Question 53: The CAN-SPAM Act requires commercial email senders to include which of the following in every message?
- Opt-in confirmation from each recipient
- End-to-end encryption of message content
- Prior written consent from all recipients
- A clear and conspicuous opt-out mechanism (Correct answer)
Correct answer: A clear and conspicuous opt-out mechanism
CAN-SPAM requires that all commercial emails include a functioning opt-out mechanism that must be honored within 10 business days.
Question 54: Which risk response strategy involves reducing the likelihood or impact of a risk?
- Risk transfer
- Risk mitigation (Correct answer)
- Risk escalation
- Risk acceptance
Correct answer: Risk mitigation
Risk mitigation involves taking proactive steps to reduce either the probability of a risk occurring or its potential impact if it does occur.
Question 55: What is a data inventory in the context of privacy governance?
- A list of data vendors only.
- A financial report.
- An archive for old emails.
- A catalog of personal data types and flows (Correct answer)
Correct answer: A catalog of personal data types and flows
A data inventory, in the context of privacy governance, is a comprehensive record or catalog of all personal data an organization collects, processes, and stores. It details the types of data, where it resides, who has access to it, and how it flows through the organization. This inventory is essential for understanding data assets, assessing privacy risks, and demonstrating compliance with data protection laws.
Question 56: What is the primary role of the FTC in privacy enforcement?
- Managing telecommunications policy
- Enforcing consumer protection and privacy laws (Correct answer)
- Drafting state legislation
- Providing healthcare services
Correct answer: Enforcing consumer protection and privacy laws
The Federal Trade Commission (FTC) serves as the primary federal agency for consumer protection in the United States. Its main role in privacy enforcement involves investigating and taking action against companies that engage in unfair or deceptive practices related to consumer data, including violations of privacy policies, data security failures, and non-compliance with specific privacy laws like COPPA.
Question 57: When an employer uses a third-party vendor to conduct social media screening of job applicants, the employer must be aware that this practice may trigger obligations under:
- The ECPA, because accessing social media constitutes electronic interception
- The ADA, because social media may reveal disability status
- HIPAA, because social media may contain protected health information
- The FCRA, if the vendor is considered a consumer reporting agency compiling consumer reports (Correct answer)
Correct answer: The FCRA, if the vendor is considered a consumer reporting agency compiling consumer reports
If a third-party vendor compiles social media information into a report used for employment decisions, it may constitute a consumer report under FCRA, triggering disclosure and adverse action requirements.
Question 58: Which role is typically responsible for managing an organization's privacy program?
- Chief Operations Officer
- Chief Marketing Officer
- Chief Privacy Officer (Correct answer)
- Chief Compliance Technician
Correct answer: Chief Privacy Officer
The Chief Privacy Officer (CPO) is a senior executive role responsible for developing, implementing, and overseeing an organization's privacy program and strategy. The CPO ensures compliance with privacy laws and regulations, manages privacy risks, and fosters a culture of privacy throughout the enterprise, making them central to privacy program management.
Question 59: Which of the following entities are classified as 'covered entities' under the HIPAA Privacy Rule?
- Any company that offers employee health benefits
- All businesses that store any health-related data
- Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically (Correct answer)
- Only hospitals and large health systems
Correct answer: Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically
HIPAA covered entities are specifically health plans, healthcare clearinghouses, and healthcare providers that conduct covered transactions electronically.
Question 60: What should be the first action when a new regulation is enacted that affects your practice?
- Delegate review to the newest team member
- Review the regulation, assess its impact, and develop an implementation plan (Correct answer)
- Assume existing procedures already comply
- Wait for enforcement before making changes
Correct answer: Review the regulation, assess its impact, and develop an implementation plan
When new regulations are enacted, professionals should promptly review them, assess their impact on current practices, and develop a structured implementation plan.
Question 61: Which concept requires minimizing the collection of personal data?
- Data minimization (Correct answer)
- Data storage
- Data localization
- Data portability
Correct answer: Data minimization
Data minimization is a core privacy principle that dictates organizations should only collect, process, and store the minimum amount of personal data necessary to achieve a specified purpose. This practice reduces the risk of data breaches and misuse, enhances privacy by design, and helps organizations comply with regulations like GDPR and CCPA.
Question 62: The Electronic Communications Privacy Act (ECPA) primarily regulates which of the following?
- Interception of wire, oral, and electronic communications (Correct answer)
- Sharing of financial information among affiliates
- Collection of children's online data
- Healthcare data breach notifications
Correct answer: Interception of wire, oral, and electronic communications
ECPA regulates government and private interception of wire, oral, and electronic communications, as well as access to stored electronic communications.
Question 63: Which of the following best describes the general legal standard for employee privacy expectations in the workplace?
- Employees and employers share equal privacy rights in the workplace
- Employers may never monitor employee communications without a court order
- Employees retain full Fourth Amendment protections in private workplaces
- Employees have a diminished expectation of privacy compared to the general public (Correct answer)
Correct answer: Employees have a diminished expectation of privacy compared to the general public
Courts generally recognize that employees have a reduced expectation of privacy in the workplace, particularly when using employer-owned equipment and systems.
Question 64: What is the purpose of a feedback mechanism in professional communication?
- To document complaints for legal purposes only
- To generate metrics for annual reports
- To evaluate employee performance
- To ensure messages are received, understood, and to identify areas for improvement (Correct answer)
Correct answer: To ensure messages are received, understood, and to identify areas for improvement
Feedback mechanisms verify that communication is effective by confirming messages are received and understood, while also identifying opportunities to improve communication processes.
Question 65: When communicating with diverse stakeholders, what approach is recommended?
- Minimize communication frequency to avoid overload
- Provide only positive information
- Adapt communication style and detail level to each stakeholder group (Correct answer)
- Use the same template for all stakeholders
Correct answer: Adapt communication style and detail level to each stakeholder group
Different stakeholders have different needs, interests, and levels of expertise, requiring adapted communication approaches for each group.
Question 66: IoT (Internet of Things) devices present heightened privacy risks primarily because:
- They are too expensive for most consumers to use securely
- They require government-issued licenses to operate
- They cannot be secured using standard encryption
- They continuously collect and transmit data, often without meaningful user notice or awareness (Correct answer)
Correct answer: They continuously collect and transmit data, often without meaningful user notice or awareness
IoT devices often collect sensitive data about users' behaviors and environments continuously and transmit it to manufacturers or third parties, frequently without prominent disclosure.
Question 67: What is the consequence of non-compliance with mandatory regulations?
- Reduced insurance premiums
- Penalties including fines, license revocation, and potential legal action (Correct answer)
- Automatic extension of compliance deadline
- A verbal warning with no further consequences
Correct answer: Penalties including fines, license revocation, and potential legal action
Non-compliance with mandatory regulations can result in serious consequences including financial penalties, loss of licensure, and legal proceedings.
Question 68: What does "informed consent" require in professional practice?
- Implied agreement through participation
- Verbal agreement without explanation
- Getting a signature on any available form
- Providing complete, understandable information so individuals can make voluntary decisions (Correct answer)
Correct answer: Providing complete, understandable information so individuals can make voluntary decisions
Informed consent requires that individuals receive complete, understandable information about procedures, risks, and alternatives to make truly voluntary decisions.
Question 69: Which federal law primarily governs the privacy of employee polygraph testing in the private sector?
- The Fair Labor Standards Act (FLSA)
- The Employee Polygraph Protection Act (EPPA) (Correct answer)
- The Privacy Act of 1974
- The National Labor Relations Act (NLRA)
Correct answer: The Employee Polygraph Protection Act (EPPA)
The Employee Polygraph Protection Act (EPPA) generally prohibits most private employers from using polygraph tests for pre-employment screening or during employment.
Question 70: How should best practices be adapted when applied to new situations?
- Apply them exactly as written regardless of circumstances
- Abandon them entirely and create new methods each time
- Use them only if specifically required by regulation
- Evaluate the specific context and modify as needed while maintaining core principles (Correct answer)
Correct answer: Evaluate the specific context and modify as needed while maintaining core principles
Best practices should be adapted to specific contexts and situations while maintaining their core principles and evidence-based foundations.
Question 71: What is the first step in the risk management process?
- Risk transfer — purchasing insurance immediately
- Risk avoidance — canceling all activities
- Risk identification — recognizing potential threats and vulnerabilities (Correct answer)
- Risk acceptance — deciding to live with all risks
Correct answer: Risk identification — recognizing potential threats and vulnerabilities
Risk identification is the critical first step in risk management, involving systematic recognition and documentation of potential threats and vulnerabilities.
Question 72: What is the role of benchmarking in establishing best practices?
- Matching exactly what competitors are doing
- Eliminating all practices that differ from the industry average
- Setting the lowest acceptable standard for performance
- Comparing performance against top performers to identify improvement opportunities (Correct answer)
Correct answer: Comparing performance against top performers to identify improvement opportunities
Benchmarking involves comparing your performance against top performers or industry leaders to identify gaps and opportunities for improvement.
Question 73: An employee notifies their manager of a disability and requests a reasonable accommodation. Under the ADA, the employer's privacy obligation regarding this disclosure is to:
- Keep the medical information confidential and share it only with those who have a specific need to know on a need-to-know basis (Correct answer)
- File it with the EEOC within 30 days
- Disclose it to HR and the employee's entire team to facilitate the accommodation
- Retain it in the general personnel file for documentation purposes
Correct answer: Keep the medical information confidential and share it only with those who have a specific need to know on a need-to-know basis
The ADA requires that medical information obtained through the accommodation process be kept confidential and disclosed only to those with a legitimate need to know.
Question 74: Social media platforms have COPPA obligations when they have:
- Advertising revenue exceeding a federal threshold
- Actual knowledge that a particular user is under 13 years of age (Correct answer)
- More than one million active users
- Offices in more than one U.S. state
Correct answer: Actual knowledge that a particular user is under 13 years of age
COPPA applies to general audience sites and apps when the operator has actual knowledge that a user is under 13, even if the platform is not directed at children.
Question 75: How often should compliance procedures be reviewed and updated?
- Only when an audit is scheduled
- Once at initial certification and never again
- Every ten years regardless of changes
- Regularly, and whenever regulations change or new risks are identified (Correct answer)
Correct answer: Regularly, and whenever regulations change or new risks are identified
Compliance procedures should be reviewed regularly and updated whenever regulations change, new risks emerge, or organizational changes occur.
Question 76: When should established methodologies be reconsidered?
- When evidence shows better alternatives exist or when outcomes decline (Correct answer)
- Whenever a new employee joins the organization
- Only during annual reviews regardless of performance
- Never, once established they should remain permanent
Correct answer: When evidence shows better alternatives exist or when outcomes decline
Established methodologies should be reconsidered when new evidence suggests better alternatives, when outcomes decline, or when the operating context changes significantly.
Question 77: What role does continuing education play in maintaining certification?
- It ensures professionals stay current with evolving standards and practices (Correct answer)
- It is required only for international practice
- It is purely optional with no impact on certification
- It only applies to entry-level professionals
Correct answer: It ensures professionals stay current with evolving standards and practices
Continuing education is essential to maintaining certification as it ensures professionals remain current with industry developments and evolving standards.
Question 78: What is the main objective of a data retention policy?
- To ensure infinite data storage.
- To comply with data storage and deletion timelines (Correct answer)
- To block user access to data.
- To increase file sizes.
Correct answer: To comply with data storage and deletion timelines
The main objective of a data retention policy is to define how long specific types of data should be kept and when they should be securely disposed of. This policy ensures compliance with legal, regulatory, and business requirements for data storage, minimizes the risk associated with holding excessive data, and supports efficient information lifecycle management.
Question 79: The California Consumer Privacy Act (CCPA) grants California consumers the right to do which of the following?
- Access all government databases containing their information
- Delete all data held by any company worldwide
- Know, delete, and opt out of the sale of their personal information (Correct answer)
- Prohibit any collection of personal data by businesses
Correct answer: Know, delete, and opt out of the sale of their personal information
The CCPA grants consumers the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale to third parties.
Question 80: An employer conducts an internal investigation of an employee suspected of misconduct. From a workplace privacy perspective, which approach best balances employer and employee interests?
- Delegating the investigation entirely to law enforcement to avoid privacy liability
- Conducting a broad investigation of all employee communications to ensure thoroughness
- Limiting the investigation to relevant evidence, informing only those with a need to know, and documenting the process to demonstrate proportionality (Correct answer)
- Publicizing the investigation to deter future misconduct by other employees
Correct answer: Limiting the investigation to relevant evidence, informing only those with a need to know, and documenting the process to demonstrate proportionality
A proportionate, confidential investigation that collects only relevant evidence and limits disclosure to those with a need to know minimizes privacy risk while serving legitimate business interests.
Question 81: What distinguishes quality assurance from quality control?
- QA is proactive and process-focused; QC is reactive and product-focused (Correct answer)
- There is no practical difference between them
- QA is more expensive; QC is free
- QA is performed by managers; QC is performed by workers
Correct answer: QA is proactive and process-focused; QC is reactive and product-focused
Quality assurance is a proactive approach focused on preventing defects through process improvement, while quality control is reactive, focused on identifying defects in products.
Question 82: What constitutes a conflict of interest in professional practice?
- When a client requests a service outside normal hours
- When two colleagues disagree on a procedure
- When multiple projects have the same deadline
- When personal interests could improperly influence professional judgment (Correct answer)
Correct answer: When personal interests could improperly influence professional judgment
A conflict of interest occurs when personal, financial, or other interests could compromise or appear to compromise professional objectivity and judgment.
Question 83: A multistate employer must navigate varying state workplace privacy laws. Which of the following is the most prudent compliance strategy?
- Comply only with the state where the corporate headquarters is located
- Apply only federal law uniformly across all states to ensure consistency
- Create entirely separate HR policies for every state with no cross-reference
- Adopt the most protective state standard as the baseline policy while documenting state-specific variations where required (Correct answer)
Correct answer: Adopt the most protective state standard as the baseline policy while documenting state-specific variations where required
Adopting the highest common denominator (most protective standard) as a baseline reduces compliance gaps across states while allowing state-specific addenda where local law imposes unique requirements.
Question 84: Why is it important to document and standardize best practices?
- To satisfy insurance requirements only
- To limit creativity and prevent any changes
- To ensure consistency, enable training, and facilitate continuous improvement (Correct answer)
- To reduce the number of employees needed
Correct answer: To ensure consistency, enable training, and facilitate continuous improvement
Documenting and standardizing best practices ensures consistency across operations, enables effective training, and provides a baseline for continuous improvement.
Question 85: Under the FCRA, what right does a consumer have when adverse action is taken based on information in a credit report?
- The right to a refund of any fees paid
- The right to sue the creditor immediately
- The right to have negative information immediately deleted
- The right to receive notice of the adverse action and the name of the consumer reporting agency that provided the report (Correct answer)
Correct answer: The right to receive notice of the adverse action and the name of the consumer reporting agency that provided the report
The FCRA requires that when adverse action is taken based on a consumer report, the consumer must be notified and given the name of the reporting agency so they can access and dispute the report.
Question 86: Which role typically owns the responsibility of data stewardship?
- Marketing Manager
- Data Steward ensures data quality and compliance (Correct answer)
- HR Representative
- Customer Support Agent
Correct answer: Data Steward ensures data quality and compliance
A Data Steward is a role within an organization responsible for the operational oversight and management of specific data assets. They ensure data quality, integrity, and compliance with established policies and regulations, acting as a liaison between data users and data governance bodies. This role is critical for maintaining trustworthy and compliant data.
Question 87: Under most U.S. state data breach notification laws, notification obligations are triggered when:
- A company experiences any cybersecurity incident regardless of data exposure
- Any employee accesses data outside normal hours
- Personal information of state residents is compromised by unauthorized access or acquisition (Correct answer)
- A federal agency independently discovers the breach
Correct answer: Personal information of state residents is compromised by unauthorized access or acquisition
State breach notification laws are generally triggered when personal information of state residents is acquired or accessed by an unauthorized party, creating a risk of harm.
Question 88: What is the role of documentation in regulatory compliance?
- It serves no practical purpose beyond record-keeping
- It is only necessary for international operations
- It is optional if verbal confirmation is available
- It provides verifiable evidence that standards are being met (Correct answer)
Correct answer: It provides verifiable evidence that standards are being met
Documentation provides verifiable evidence that regulatory requirements are being met and creates an audit trail for compliance verification.
Question 89: Which law requires businesses to implement reasonable security practices?
- FERPA
- GDPR
- CAN-SPAM
- CCPA (Correct answer)
Correct answer: CCPA
The California Consumer Privacy Act (CCPA) specifically requires businesses to implement and maintain reasonable security procedures and practices appropriate to the nature of the information they handle. This mandate aims to protect consumers' personal information from unauthorized access, destruction, use, modification, or disclosure. While other privacy laws also address security, CCPA explicitly outlines this requirement for businesses operating in California.
Question 90: What type of data is protected under the FCRA?
- Student records
- Employment history
- Medical records
- Credit report information (Correct answer)
Correct answer: Credit report information
The Fair Credit Reporting Act (FCRA) is a federal law that primarily protects the privacy and accuracy of information in consumer credit reports. It regulates how consumer reporting agencies collect, disseminate, and use consumer information, granting individuals rights such as accessing their credit files, disputing inaccuracies, and knowing when their credit report has been used. The FCRA aims to ensure fairness and accuracy in credit reporting practices.
Certified Information Privacy Professional/United States (CIPP/US) Exam
This exam certifies individuals in the comprehensive knowledge of privacy laws, regulations, and frameworks specific to the United States.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds