CIPP IAPP 4 ā Questions and Answers
Question 1: Under FCRA, a consumer reporting agency must generally provide consumers with a free copy of their credit report:
- Only when they are denied credit
- Once every 12 months upon request, plus when adverse action is taken (Correct answer)
- At any time without limitation
- Only when a dispute is filed
Correct answer: Once every 12 months upon request, plus when adverse action is taken
FCRA entitles consumers to one free annual disclosure per CRA, plus an additional free report when adverse action is taken based on the report.
Question 2: The Illinois Biometric Information Privacy Act (BIPA) is notable among US privacy laws primarily because it:
- Requires opt-out consent for biometric data collection
- Provides a private right of action with statutory damages for biometric data violations (Correct answer)
- Applies only to government agencies
- Preempts all other state biometric laws
Correct answer: Provides a private right of action with statutory damages for biometric data violations
BIPA is unique because it grants individuals a private right of action with statutory damages of $1,000ā$5,000 per violation, without requiring proof of actual harm.
Question 3: Which of the following best describes a 'legitimate interest' basis for processing personal data under GDPR, which US multinationals must understand?
- Any business interest qualifies automatically without further analysis
- Processing that is necessary for the controller's interests, provided those interests are not overridden by data subject rights (Correct answer)
- Processing required by a court order
- Processing explicitly consented to by the data subject
Correct answer: Processing that is necessary for the controller's interests, provided those interests are not overridden by data subject rights
Legitimate interest under GDPR requires a three-part balancing test: the interest must be legitimate, processing must be necessary, and the interests must not override the data subject's rights and freedoms.
Question 4: A US company acting as a HIPAA Business Associate must sign a Business Associate Agreement (BAA) that:
- Transfers liability entirely from the covered entity to the business associate
- Specifies permissible uses and disclosures of PHI and obligates the BA to safeguard it (Correct answer)
- Allows the business associate to use PHI for its own marketing
- Replaces the need for a Notice of Privacy Practices
Correct answer: Specifies permissible uses and disclosures of PHI and obligates the BA to safeguard it
A BAA must specify the permitted and required uses and disclosures of PHI and require the business associate to implement appropriate safeguards and report breaches.
Question 5: Under the Privacy Act of 1974, which category of organization is directly regulated?
- All US corporations with more than 250 employees
- Federal government agencies maintaining systems of records (Correct answer)
- Any entity that processes Social Security Numbers
- State governments receiving federal funding
Correct answer: Federal government agencies maintaining systems of records
The Privacy Act of 1974 applies specifically to federal executive branch agencies that maintain systems of records about individuals, regulating how they collect, maintain, and use personal information.
Question 6: Which technique renders data outside the scope of HIPAA by replacing direct identifiers with a code, provided a re-identification key is not disclosed?
- Aggregation
- Anonymization
- Pseudonymization (Correct answer)
- Encryption
Correct answer: Pseudonymization
Pseudonymization (de-identification via the Expert Determination or Safe Harbor methods under HIPAA) can remove PHI status, but only pseudonymized data where re-identification keys are kept separately still qualifies.
Question 7: When must a CCPA-covered business provide a 'Do Not Sell or Share My Personal Information' opt-out link?
- Only if the business has sold data in the past 12 months
- On its homepage if it sells or shares personal information (Correct answer)
- Only upon written request from a California resident
- Only for businesses with more than 1,000 employees
Correct answer: On its homepage if it sells or shares personal information
Businesses that sell or share personal information must conspicuously post a 'Do Not Sell or Share My Personal Information' link on their homepage as required by CCPA as amended by CPRA.
Under FCRA, a consumer reporting agency must generally provide consumers with a free copy of their credit report: