CIPT Cheat Sheet 2026

The 30 highest-yield CIPT facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

90 questions
150 min time limit
70.00% to pass
  1. Which individual developed the Seven Principles of Privacy by Design? Ann Cavoukian
  2. Which attack re-identifies anonymized data by combining it with publicly available auxiliary datasets? Linkage attack
  3. When building a consent management platform, which engineering requirement is most critical from a Privacy by Design perspective? Granular, revocable consent with clear audit logs
  4. Which phase of the data lifecycle involves determining what data to collect, for what purpose, and under what legal basis? Data collection and creation
  5. Which data anonymization weakness occurs when a dataset has only a few records per combination of quasi-identifiers, making individuals easy to re-identify? Data sparsity re-identification
  6. An organization must delete a customer's data upon request. Which governance process ensures all copies — including backups — are identified and removed? Data mapping combined with a defined erasure workflow
  7. A company's privacy notice is written at a 16th-grade reading level. Which privacy principle does this most directly violate? Transparency (right to clear, intelligible information)
  8. Which concept describes building privacy protections directly into IT systems and business practices from the outset? Privacy by Design
  9. Which risk treatment option involves stopping a high-risk data processing activity because residual risk cannot be reduced to an acceptable level? Risk avoidance
  10. Under Virginia's Consumer Data Protection Act (VCDPA), which data processing activity requires a data protection assessment? Processing sensitive data or data for targeted advertising
  11. Under the CCPA/CPRA framework, which right allows California consumers to correct inaccurate personal information held by a business? Right to Correct
  12. Data protection regulations vary from country to country, but what is the underlying concept common to all? Keeping data safe while allowing authorized access
  13. A company maintains records of all its data processing activities including purposes, categories of data, and retention periods. What is this record called? Record of Processing Activities (RoPA)
  14. Under the Colorado Privacy Act (CPA), what is the maximum civil penalty per intentional violation? $7,500
  15. A developer implements a feature where users can download all their personal data in a machine-readable format. This satisfies which data subject right? Right to data portability
  16. Which element of the Privacy by Design framework highlights the significance of ensuring that decisions revolve around fulfilling the user's needs? Respect for User Privacy – Keep it User-Centric
  17. In Privacy by Design, what does the principle 'Proactive not Reactive' mean? Anticipate and prevent privacy-invasive events before they occur
  18. Which control requires that a minimum number of authorized personnel must cooperate to perform a sensitive operation, preventing unilateral action? Multi-party authorization (M-of-N control)
  19. What is the central objective of the Privacy by Design (PbD) framework? To embed privacy into development from the outset
  20. In the context of the ISO 29101 privacy architecture framework, what does the 'PII principal' refer to? The individual to whom the PII relates
  21. A privacy engineer proposes using 'k-anonymity' when publishing a dataset. What does this guarantee? Each record is indistinguishable from at least k-1 other records on quasi-identifiers
  22. Which element is generally NOT required in a breach notification sent directly to affected individuals? A list of all employees who handled the breached data internally
  23. An organization subject to the FTC Act engages in a data practice it did not disclose to consumers. The FTC considers this a violation under which authority? Section 5 prohibition on unfair or deceptive acts or practices
  24. Which data protection law in Canada enforces regulations on specific sectors and includes breach reporting requirements? Federal: PIPEDA
  25. An organization implements automated data expiry rules that delete personal records when their retention period ends. What governance benefit does this provide? Reduces risk of holding data beyond its legal or business justification
  26. An organization's privacy notice discloses that it shares data with 'partners for marketing purposes.' Under GDPR transparency requirements, what is missing? The specific identities or categories of third-party recipients
  27. Which principle requires that personal data not be kept longer than necessary for its stated purpose? Storage limitation
  28. A privacy team implements a process to handle user requests to access, correct, or delete their personal data. What is this process called? Data Subject Rights (DSR) or Data Subject Access Request (DSAR) fulfillment process
  29. Under GDPR Article 33, within how many hours must a personal data breach be reported to the supervisory authority? 72 hours
  30. Which term describes the risk that a machine learning model trained on sensitive data can inadvertently memorize and reveal specific training examples? Data leakage through overfitting
Turn these facts into recall:
Was this helpful?