CIPT Cheat Sheet 2026
The 30 highest-yield CIPT facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
90 questions
150 min time limit
70.00% to pass
- Which individual developed the Seven Principles of Privacy by Design? → Ann Cavoukian
- Which attack re-identifies anonymized data by combining it with publicly available auxiliary datasets? → Linkage attack
- When building a consent management platform, which engineering requirement is most critical from a Privacy by Design perspective? → Granular, revocable consent with clear audit logs
- Which phase of the data lifecycle involves determining what data to collect, for what purpose, and under what legal basis? → Data collection and creation
- Which data anonymization weakness occurs when a dataset has only a few records per combination of quasi-identifiers, making individuals easy to re-identify? → Data sparsity re-identification
- An organization must delete a customer's data upon request. Which governance process ensures all copies — including backups — are identified and removed? → Data mapping combined with a defined erasure workflow
- A company's privacy notice is written at a 16th-grade reading level. Which privacy principle does this most directly violate? → Transparency (right to clear, intelligible information)
- Which concept describes building privacy protections directly into IT systems and business practices from the outset? → Privacy by Design
- Which risk treatment option involves stopping a high-risk data processing activity because residual risk cannot be reduced to an acceptable level? → Risk avoidance
- Under Virginia's Consumer Data Protection Act (VCDPA), which data processing activity requires a data protection assessment? → Processing sensitive data or data for targeted advertising
- Under the CCPA/CPRA framework, which right allows California consumers to correct inaccurate personal information held by a business? → Right to Correct
- Data protection regulations vary from country to country, but what is the underlying concept common to all? → Keeping data safe while allowing authorized access
- A company maintains records of all its data processing activities including purposes, categories of data, and retention periods. What is this record called? → Record of Processing Activities (RoPA)
- Under the Colorado Privacy Act (CPA), what is the maximum civil penalty per intentional violation? → $7,500
- A developer implements a feature where users can download all their personal data in a machine-readable format. This satisfies which data subject right? → Right to data portability
- Which element of the Privacy by Design framework highlights the significance of ensuring that decisions revolve around fulfilling the user's needs? → Respect for User Privacy – Keep it User-Centric
- In Privacy by Design, what does the principle 'Proactive not Reactive' mean? → Anticipate and prevent privacy-invasive events before they occur
- Which control requires that a minimum number of authorized personnel must cooperate to perform a sensitive operation, preventing unilateral action? → Multi-party authorization (M-of-N control)
- What is the central objective of the Privacy by Design (PbD) framework? → To embed privacy into development from the outset
- In the context of the ISO 29101 privacy architecture framework, what does the 'PII principal' refer to? → The individual to whom the PII relates
- A privacy engineer proposes using 'k-anonymity' when publishing a dataset. What does this guarantee? → Each record is indistinguishable from at least k-1 other records on quasi-identifiers
- Which element is generally NOT required in a breach notification sent directly to affected individuals? → A list of all employees who handled the breached data internally
- An organization subject to the FTC Act engages in a data practice it did not disclose to consumers. The FTC considers this a violation under which authority? → Section 5 prohibition on unfair or deceptive acts or practices
- Which data protection law in Canada enforces regulations on specific sectors and includes breach reporting requirements? → Federal: PIPEDA
- An organization implements automated data expiry rules that delete personal records when their retention period ends. What governance benefit does this provide? → Reduces risk of holding data beyond its legal or business justification
- An organization's privacy notice discloses that it shares data with 'partners for marketing purposes.' Under GDPR transparency requirements, what is missing? → The specific identities or categories of third-party recipients
- Which principle requires that personal data not be kept longer than necessary for its stated purpose? → Storage limitation
- A privacy team implements a process to handle user requests to access, correct, or delete their personal data. What is this process called? → Data Subject Rights (DSR) or Data Subject Access Request (DSAR) fulfillment process
- Under GDPR Article 33, within how many hours must a personal data breach be reported to the supervisory authority? → 72 hours
- Which term describes the risk that a machine learning model trained on sensitive data can inadvertently memorize and reveal specific training examples? → Data leakage through overfitting
Turn these facts into recall:
Was this helpful?