CIPP IAPP 5 ā Questions and Answers
Question 1: A Privacy Impact Assessment (PIA) is primarily used to:
- Calculate the monetary cost of a data breach
- Identify and mitigate privacy risks before deploying a new system or process (Correct answer)
- Audit historical compliance with existing privacy policies
- Satisfy annual FTC reporting requirements
Correct answer: Identify and mitigate privacy risks before deploying a new system or process
A PIA proactively identifies privacy risks and impacts of a new project or system before implementation, enabling organizations to build in appropriate safeguards.
Question 2: Under CCPA/CPRA, the right to correct inaccurate personal information must be fulfilled by a business within:
- 30 days of receiving the request
- 45 days of receiving the request, extendable by another 45 days (Correct answer)
- 60 days of receiving the request
- 90 days of receiving the request
Correct answer: 45 days of receiving the request, extendable by another 45 days
CPRA requires businesses to respond to consumer requests to correct inaccurate personal information within 45 days, with a possible 45-day extension if reasonably necessary.
Question 3: Which concept describes the practice of ensuring that data collected is adequate, relevant, and limited to what is necessary for the specified purpose?
- Data accuracy
- Data minimization (Correct answer)
- Storage limitation
- Data portability
Correct answer: Data minimization
Data minimization is the principle that organizations should only collect personal data that is adequate, relevant, and necessary for the explicitly stated purpose.
Question 4: In the context of US employment privacy, which action by an employer is generally permissible without employee consent?
- Monitoring personal emails sent on a personal device
- Recording calls on company phone systems after providing notice (Correct answer)
- Accessing an employee's medical records from their personal doctor
- Installing keyloggers on personal home computers used for remote work
Correct answer: Recording calls on company phone systems after providing notice
Employers generally may monitor company-provided phone systems and communications after providing notice, as employees have a reduced expectation of privacy on employer systems.
Question 5: The FTC's enforcement action against a company for 'unfair' practices under Section 5 requires demonstrating that the practice:
- Caused any degree of consumer dissatisfaction
- Caused or was likely to cause substantial injury not reasonably avoidable by consumers and not outweighed by countervailing benefits (Correct answer)
- Violated a specific federal privacy statute
- Affected more than 10,000 consumers
Correct answer: Caused or was likely to cause substantial injury not reasonably avoidable by consumers and not outweighed by countervailing benefits
Unfairness under FTC Section 5 requires: substantial consumer injury, injury not reasonably avoidable by consumers, and injury not outweighed by benefits to consumers or competition.
Question 6: Which of the following is an example of sensitive personal information (SPI) under CPRA that triggers additional opt-out rights?
- A consumer's name and email address
- A consumer's ZIP code for weather services
- A consumer's Social Security Number and precise geolocation (Correct answer)
- A consumer's publicly available purchase history
Correct answer: A consumer's Social Security Number and precise geolocation
CPRA defines sensitive personal information to include government IDs like SSNs, precise geolocation, racial/ethnic origin, health data, and similar high-risk categories warranting additional controls.
Question 7: When a US organization transfers personal data from the EU under Standard Contractual Clauses (SCCs), it must also conduct a:
- Full GDPR audit of all EU data subjects
- Transfer Impact Assessment (TIA) to evaluate the receiving country's legal framework (Correct answer)
- Annual self-certification with the European Data Protection Board
- Notification to HHS before any transfer
Correct answer: Transfer Impact Assessment (TIA) to evaluate the receiving country's legal framework
Following the Schrems II ruling, organizations using SCCs must conduct a Transfer Impact Assessment to evaluate whether the destination country's law undermines the SCCs' protections.
A Privacy Impact Assessment (PIA) is primarily used to: