CIPP IAPP 3 — Questions and Answers
Question 1: A data breach at a HIPAA-covered entity affects 600 individuals. What is the required notification timeline to HHS?
- Within 24 hours
- Within 72 hours
- Within 60 days of discovery (Correct answer)
- Within 60 days of end of calendar year
Correct answer: Within 60 days of discovery
For breaches affecting fewer than 500 individuals, HIPAA requires notification to HHS within 60 days of the end of the calendar year, but for 500+ it's 60 days of discovery; however the general rule for all is within 60 days of discovery.
Question 2: Which enforcement mechanism allows the FTC to take action against unfair or deceptive privacy practices?
- The FTC's rulemaking authority under the Privacy Act
- Section 5 of the FTC Act prohibiting unfair or deceptive acts or practices (Correct answer)
- The FTC's authority under HIPAA
- The Consumer Financial Protection Act
Correct answer: Section 5 of the FTC Act prohibiting unfair or deceptive acts or practices
Section 5 of the FTC Act is the primary enforcement tool that prohibits unfair or deceptive acts or practices, enabling the FTC to act against companies that fail to follow their privacy promises.
Question 3: Under the EU-US Data Privacy Framework (DPF), a US organization that self-certifies must do which of the following?
- Obtain EU adequacy status directly from each member state
- Annually re-certify with the US Department of Commerce (Correct answer)
- Appoint an EU Data Protection Authority as lead supervisory authority
- Use standard contractual clauses for all data transfers
Correct answer: Annually re-certify with the US Department of Commerce
Organizations self-certifying under the DPF must annually re-certify their compliance with the framework's principles through the US Department of Commerce.
Question 4: The concept of 'privacy by design' in US practice most closely aligns with which NIST Privacy Framework function?
- Detect-P
- Respond-P
- Govern-P
- Protect-P (Correct answer)
Correct answer: Protect-P
The Protect-P function in the NIST Privacy Framework covers developing and implementing data processing safeguards, which aligns with embedding privacy into system and product design.
Question 5: Under the CAN-SPAM Act, commercial email senders must:
- Obtain affirmative opt-in consent before sending any commercial email
- Honor opt-out requests within 10 business days and include a physical postal address (Correct answer)
- Limit commercial emails to existing customers only
- Register with the FTC before conducting email marketing campaigns
Correct answer: Honor opt-out requests within 10 business days and include a physical postal address
CAN-SPAM requires commercial email senders to honor unsubscribe requests within 10 business days and include a valid physical postal address in every message.
Question 6: A company's privacy notice states it will not sell data, but it later participates in a data broker arrangement sharing customer profiles. The FTC would most likely characterize this as:
- A permissible business practice under Section 5
- A deceptive practice because the company acted contrary to its privacy promises (Correct answer)
- An unfair practice only if consumers suffered financial harm
- Acceptable if disclosed in subsequent updated privacy notices
Correct answer: A deceptive practice because the company acted contrary to its privacy promises
Acting contrary to stated privacy promises is deceptive under FTC Section 5, as it misleads consumers who relied on those representations when sharing their data.
Question 7: Which US state law was the first comprehensive consumer privacy law passed in the United States?
- Illinois BIPA
- Vermont Data Broker Law
- California Consumer Privacy Act (CCPA) (Correct answer)
- California Online Privacy Protection Act (CalOPPA)
Correct answer: California Consumer Privacy Act (CCPA)
The CCPA, signed in 2018 and effective January 1, 2020, was the first comprehensive consumer privacy law in the United States, granting broad rights to California residents.
A data breach at a HIPAA-covered entity affects 600 individuals.
What is the required notification timeline to HHS?