CIPP IAPP 2 ā Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), which threshold triggers a business's obligation to comply?
- Annual gross revenues exceeding $10 million
- Annual gross revenues exceeding $25 million, buying/selling data of 100,000+ consumers, or deriving 50%+ revenue from selling data (Correct answer)
- Having any California customer regardless of revenue
- Processing more than 500 records of California residents per year
Correct answer: Annual gross revenues exceeding $25 million, buying/selling data of 100,000+ consumers, or deriving 50%+ revenue from selling data
CCPA applies to for-profit businesses meeting at least one of three thresholds: $25M revenue, 100,000+ consumer records, or 50%+ revenue from selling personal information.
Question 2: Which federal law establishes a framework for protecting the privacy of student education records?
- COPPA
- FERPA (Correct answer)
- HIPAA
- GLBA
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records and grants parents and eligible students rights over those records.
Question 3: A company collects data for marketing and then uses it for fraud detection. Under FTC principles, this most likely violates which concept?
- Data minimization
- Purpose limitation (Correct answer)
- Data quality
- Individual participation
Correct answer: Purpose limitation
Purpose limitation requires that data collected for one stated purpose not be used for incompatible secondary purposes without notice and consent.
Question 4: Which US law requires financial institutions to explain their information-sharing practices and give customers the right to opt out of certain sharing?
- FCRA
- COPPA
- GLBA Privacy Rule (Correct answer)
- HIPAA Privacy Rule
Correct answer: GLBA Privacy Rule
The Gramm-Leach-Bliley Act (GLBA) Privacy Rule requires financial institutions to provide privacy notices and opt-out rights regarding nonpublic personal information sharing with non-affiliated third parties.
Question 5: The HIPAA minimum necessary standard requires covered entities to:
- Encrypt all PHI at all times
- Limit PHI access and disclosure to only what is needed for the intended purpose (Correct answer)
- Obtain written authorization for all PHI uses
- Delete PHI after 30 days if no longer needed
Correct answer: Limit PHI access and disclosure to only what is needed for the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the minimum needed to accomplish the intended purpose.
Question 6: Under COPPA, what is the age threshold below which verifiable parental consent is required before collecting personal information?
- 13 (Correct answer)
- 16
- 18
- Under 12 only
Correct answer: 13
COPPA requires verifiable parental consent before collecting personal information from children under 13 on commercial websites or online services directed to children.
Question 7: Which principle from the Fair Information Practice Principles (FIPPs) states that individuals should have a right to access and correct data about themselves?
- Collection Limitation
- Use Limitation
- Individual Participation (Correct answer)
- Accountability
Correct answer: Individual Participation
The Individual Participation principle holds that individuals should have the right to know what data is held about them and to correct or challenge inaccurate records.
Under the California Consumer Privacy Act (CCPA), which threshold triggers a business's obligation to comply?