CIPP (US) 4 ā Questions and Answers
Question 1: An e-commerce company collects email addresses and later begins using them for SMS marketing without informing customers. Which privacy principle has most likely been violated?
- Data security
- Accountability
- Purpose limitation (Correct answer)
- Data minimization
Correct answer: Purpose limitation
Using data for a purpose (SMS marketing) beyond what was disclosed at collection violates the purpose limitation principle.
Question 2: Under HIPAA's Minimum Necessary standard, a nurse reviewing a patient's chart should access:
- All records in the system for thoroughness
- Only the PHI necessary to perform her specific job function (Correct answer)
- Any record requested by other care team members
- Records dating back five years for full context
Correct answer: Only the PHI necessary to perform her specific job function
The Minimum Necessary standard requires workforce members to access only the PHI needed to accomplish their intended purpose.
Question 3: Which sector-specific federal law requires telecommunications carriers to protect Customer Proprietary Network Information (CPNI)?
- CAN-SPAM Act
- Communications Act / FCC rules (Correct answer)
- Cable Communications Policy Act
- Telephone Consumer Protection Act
Correct answer: Communications Act / FCC rules
The Communications Act, enforced by the FCC, requires telecommunications carriers to protect CPNI and limits its use and disclosure.
Question 4: A company's privacy policy states it will never share data with third parties, but it later shares data with advertising partners. Under FTC enforcement theory, this is most likely:
- An unfair practice under Section 5
- A deceptive practice under Section 5 (Correct answer)
- Permissible if disclosed in terms of service
- Only actionable if consumers suffered financial harm
Correct answer: A deceptive practice under Section 5
Violating a material promise in a privacy policyāsharing data despite promising not toāconstitutes a deceptive practice under FTC Act Section 5.
Question 5: The Video Privacy Protection Act (VPPA) was enacted primarily in response to what event?
- The Sony Pictures data breach
- Disclosure of Supreme Court nominee Robert Bork's video rental records (Correct answer)
- Congress viewing a senator's streaming history
- A cable company selling viewing data to advertisers
Correct answer: Disclosure of Supreme Court nominee Robert Bork's video rental records
VPPA was passed after a newspaper published Supreme Court nominee Robert Bork's video rental records, revealing the sensitivity of such data.
Question 6: Under the Controlling the Assault of Non-Solicited Pornography And Marketing (CAN-SPAM) Act, which requirement applies to all commercial email messages?
- Opt-in consent must be obtained before sending
- A clear and conspicuous opt-out mechanism must be included (Correct answer)
- The email must be sent from a .com domain
- Recipients must be notified 30 days before the first email
Correct answer: A clear and conspicuous opt-out mechanism must be included
CAN-SPAM requires commercial emails to include a clear and conspicuous mechanism allowing recipients to opt-out of future messages.
Question 7: Which legal concept holds that individuals have diminished privacy expectations in information they voluntarily share with third parties, frequently cited by courts interpreting the Fourth Amendment?
- Reasonable expectation of privacy test
- Third-party doctrine (Correct answer)
- Mosaic theory
- Sectoral preemption doctrine
Correct answer: Third-party doctrine
The third-party doctrine holds that people lose Fourth Amendment protection over information voluntarily shared with third parties like banks or phone companies.
An e-commerce company collects email addresses and later begins using them for SMS marketing without informing customers.
Which privacy principle has most likely been violated?