Certified Information Privacy Technologist (CIPT) โ Questions and Answers
Question 1: What is 'residual risk' in the context of privacy risk management?
- The initial risk before any controls are considered
- The total financial exposure from a data breach
- The risk transferred to cyber insurance
- The remaining risk after controls and mitigations have been applied (Correct answer)
Correct answer: The remaining risk after controls and mitigations have been applied
Residual risk is what remains after all identified controls are implemented; it must be accepted, transferred, or reduced further if it exceeds the organization's risk tolerance.
Question 2: Which element is generally NOT required in a breach notification sent directly to affected individuals?
- A list of all employees who handled the breached data internally (Correct answer)
- Steps individuals can take to protect themselves from potential harm
- Contact information for the notifying organization
- Description of the types of personal information involved in the breach
Correct answer: A list of all employees who handled the breached data internally
Breach notifications must help individuals protect themselves but do not require disclosing internal personnel details, which would not aid the affected person.
Question 3: A data processor experiences a breach affecting EU residents' data. Under GDPR, within what timeframe must the processor notify the controller?
- Within 72 hours
- Within 24 hours
- Without undue delay (Correct answer)
- Within 7 business days
Correct answer: Without undue delay
Under GDPR Article 33(2), processors must notify controllers of a personal data breach without undue delay after becoming aware of it, without a specific hour limit for processor-to-controller notification.
Question 4: In the CIPT body of knowledge, which privacy-enhancing technology (PET) allows a verifier to confirm a fact about a user without learning the underlying data?
- Zero-knowledge proof (Correct answer)
- Transport Layer Security
- Symmetric encryption
- Role-based access control
Correct answer: Zero-knowledge proof
A zero-knowledge proof enables one party to prove knowledge of a value to another party without conveying any information beyond the validity of the statement.
Question 5: What is the key focus of the "Visibility and Transparency" principle?
- Limiting user control over data
- Concealing privacy practices from stakeholders
- Maximizing data collection
- Demonstrating accountability and making policies accessible (Correct answer)
Correct answer: Demonstrating accountability and making policies accessible
The "Visibility and Transparency" principle requires that organizations be open about their privacy practices and policies. It means that individuals should be informed about how their data is being collected, used, and shared, and that these practices should be verifiable. This fosters trust and allows for independent verification of privacy commitments, ensuring accountability.
Question 6: A privacy impact assessment (PIA) is most valuable when conducted at which stage of a project?
- After product launch
- During routine maintenance
- Early in the design phase (Correct answer)
- When a breach occurs
Correct answer: Early in the design phase
Conducting a PIA early in design allows privacy risks to be mitigated before costly system changes are required.
Question 7: A privacy governance framework assigns a Chief Privacy Officer (CPO). What is the CPO's primary organizational responsibility?
- Leading the organization's privacy strategy and ensuring enterprise-wide compliance (Correct answer)
- Conducting employee background checks
- Managing IT security incident response
- Drafting contracts with data processors
Correct answer: Leading the organization's privacy strategy and ensuring enterprise-wide compliance
The CPO sets privacy strategy, oversees compliance programs, advises leadership, and is ultimately accountable for the organization's privacy posture.
Question 8: In Privacy by Design, which foundational principle states that privacy must be proactive rather than reactive?
- Full functionality โ positive-sum not zero-sum
- Privacy as the default setting
- Privacy embedded into design
- Proactive not reactive; preventive not remedial (Correct answer)
Correct answer: Proactive not reactive; preventive not remedial
Ann Cavoukian's first principle of Privacy by Design emphasizes anticipating and preventing privacy issues before they occur.
Question 9: Which Privacy by Design principle ensures that privacy coexists with other legitimate system goals without trade-offs?
- End-to-End Security
- Visibility and Transparency
- User-Centric Design
- Full Functionality โ Positive-Sum, not Zero-Sum (Correct answer)
Correct answer: Full Functionality โ Positive-Sum, not Zero-Sum
Full Functionality rejects the notion that privacy must be sacrificed for functionality, seeking a win-win outcome instead.
Question 10: Which Privacy by Design principle emphasizes keeping systems open and verifiable so users can trust that stated privacy practices are actually being followed?
- Privacy as the Default Setting
- User-Centric Design
- Proactive not Reactive
- Visibility and Transparency (Correct answer)
Correct answer: Visibility and Transparency
Visibility and Transparency ensures that business practices and technologies are open to independent verification, building user trust.
Question 11: Which element of a privacy program ensures employees know how to recognize and escalate a potential personal data breach?
- Network segmentation controls
- Privacy incident reporting channel and training on what constitutes a reportable event (Correct answer)
- Automated data loss prevention (DLP) only
- Annual password rotation policy
Correct answer: Privacy incident reporting channel and training on what constitutes a reportable event
Effective breach response depends on employees recognizing privacy incidents and knowing how to report them promptly through a clear escalation path.
Question 12: Under the California Consumer Privacy Act (CCPA), which right allows consumers to prevent a business from selling their personal information?
- Right to opt-out of sale (Correct answer)
- Right to deletion
- Right to access
- Right to non-discrimination
Correct answer: Right to opt-out of sale
The CCPA gives California residents the right to opt out of the sale of their personal information to third parties.
Question 13: Which privacy threat category involves an attacker combining publicly available data from multiple sources to re-identify an anonymized individual?
- SQL injection
- Aggregation attack (Correct answer)
- Man-in-the-middle attack
- Phishing attack
Correct answer: Aggregation attack
An aggregation attack combines individually harmless data elements from multiple sources to reconstruct a person's identity or sensitive information.
Question 14: Which data governance artifact defines who can access specific datasets, under what conditions, and for what approved purposes?
- Privacy notice
- System security plan
- Data access policy (Correct answer)
- Data processing agreement
Correct answer: Data access policy
A data access policy specifies authorization rules, access conditions, and approved purposes for each data category, supporting both governance and privacy compliance.
Question 15: Which risk treatment option involves stopping a high-risk data processing activity because residual risk cannot be reduced to an acceptable level?
- Risk transfer
- Risk avoidance (Correct answer)
- Risk mitigation
- Risk acceptance
Correct answer: Risk avoidance
Risk avoidance means ceasing or not starting the processing activity entirely when the risk cannot be adequately controlled.
Question 16: Which type of architecture ensures that no single server or administrator can access a user's complete personal data, distributing trust across multiple parties?
- Monolithic database design
- Centralized identity management
- Distributed or decentralized privacy architecture (Correct answer)
- Single sign-on federation
Correct answer: Distributed or decentralized privacy architecture
Distributed privacy architectures split data across multiple parties so no single point of failure or insider can access all personal data.
Question 17: In a federated identity model, how does the approach support the privacy principle of data minimization?
- By storing biometric data locally at each service provider
- By eliminating authentication requirements entirely
- By sharing only necessary attributes rather than full identity records (Correct answer)
- By requiring central storage of all user credentials
Correct answer: By sharing only necessary attributes rather than full identity records
Federated identity allows a user's home organization to vouch for specific attributes, so relying parties receive only what they need rather than complete identity dossiers.
Question 18: A U.S. healthcare organization is evaluating privacy frameworks. Which framework is specifically designed for health information and mandates a Notice of Privacy Practices?
- FERPA
- CCPA
- HIPAA Privacy Rule (Correct answer)
- COPPA
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule requires covered entities to provide patients with a Notice of Privacy Practices describing how PHI is used and disclosed.
Question 19: Which approach involves transferring privacy risk to a third party, such as through cyber liability insurance or vendor contractual indemnification?
- Risk transfer (Correct answer)
- Risk avoidance
- Risk mitigation
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts financial or operational consequence of a privacy risk to another party but does not eliminate the underlying risk to data subjects.
Question 20: Which U.S. law requires federal agencies to publish notices in the Federal Register describing their systems of records?
- Federal Information Security Management Act (FISMA)
- E-Government Act
- Privacy Act of 1974 (Correct answer)
- Freedom of Information Act (FOIA)
Correct answer: Privacy Act of 1974
The Privacy Act of 1974 requires federal agencies to publish System of Records Notices (SORNs) in the Federal Register describing collections of personal information maintained in systems of records.
Question 21: An e-commerce company based in the U.S. sells goods to EU residents without any EU establishment. Does GDPR apply to this company?
- Only if annual revenue exceeds โฌ10 million
- Yes, because it offers goods to EU data subjects (Correct answer)
- Only if it processes sensitive personal data
- No, because the company has no EU establishment
Correct answer: Yes, because it offers goods to EU data subjects
GDPR Article 3(2) extends the regulation's territorial scope to controllers outside the EU that offer goods or services to data subjects in the EU, regardless of whether payment is required.
Question 22: A development team uses data minimization during system design so that only necessary personal data fields are collected. Which Privacy by Design principle does this best reflect?
- Visibility and Transparency
- Privacy Embedded into Design (Correct answer)
- Proactive not Reactive
- End-to-End Security
Correct answer: Privacy Embedded into Design
Privacy Embedded into Design requires integrating privacy controls โ including data minimization โ directly into the architecture of systems.
Question 23: A company automatically deletes personal data after a defined retention period using an automated policy engine. Which privacy principle does this technical control enforce?
- Storage limitation (Correct answer)
- Integrity and confidentiality
- Lawfulness of processing
- Purpose limitation
Correct answer: Storage limitation
Automated deletion enforces storage limitation by ensuring personal data is not kept longer than necessary for its stated purpose.
Question 24: During the data disposal phase, which method best ensures that magnetic hard drive data is unrecoverable?
- Standard file deletion
- Degaussing followed by physical destruction (Correct answer)
- Overwriting with zeros one time
- Formatting the drive once
Correct answer: Degaussing followed by physical destruction
Degaussing disrupts magnetic domains to erase data, and physical destruction ensures media cannot be reconstructed, together providing the highest assurance of unrecoverability.
Question 25: What is the function of 'privacy threat modeling' in system development?
- Writing user-facing privacy notices
- Systematically identifying privacy threats specific to a system's data flows and architecture (Correct answer)
- Encrypting all data fields in the database
- Documenting regulatory requirements applicable to the system
Correct answer: Systematically identifying privacy threats specific to a system's data flows and architecture
Privacy threat modeling (e.g., using LINDDUN) analyzes a system's data flow diagrams to surface privacy-specific threats such as linkability, identifiability, and disclosure.
Question 26: A privacy risk register documents identified risks, their scores, and assigned owners. What is the primary benefit of maintaining this register?
- Enables tracking of risk treatment progress and accountability over time (Correct answer)
- Provides legal immunity in case of a breach
- Satisfies all GDPR documentation requirements
- Replaces the need for technical security controls
Correct answer: Enables tracking of risk treatment progress and accountability over time
A risk register creates an auditable record of known risks, their status, and who is responsible for treatment, supporting continuous privacy risk management.
Question 27: When a privacy program is described as operating at a 'repeatable' maturity level, what does this mean?
- Privacy is handled ad-hoc with no consistent processes
- Privacy processes are documented and consistently followed, but not yet optimized or formally measured (Correct answer)
- Privacy is only addressed in response to regulatory audits
- Privacy processes are fully automated and continuously improved
Correct answer: Privacy processes are documented and consistently followed, but not yet optimized or formally measured
At the repeatable maturity level, privacy processes exist, are documented, and are followed consistently โ but advanced measurement, optimization, and automation are not yet in place.
Question 28: Which US federal rule requires financial institutions to notify the FTC and customers following certain data breaches affecting 500 or more customers?
- GLBA Safeguards Rule (Correct answer)
- COPPA Safe Harbor Rule
- FERPA Disclosure Rule
- CAN-SPAM Enforcement Rule
Correct answer: GLBA Safeguards Rule
The FTC's updated Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to report qualifying breaches affecting 500+ customers to the FTC.
Question 29: Which term describes the risk that a machine learning model trained on sensitive data can inadvertently memorize and reveal specific training examples?
- Data leakage through overfitting (Correct answer)
- Model poisoning
- Adversarial example attack
- Membership inference risk
Correct answer: Data leakage through overfitting
Overfitted models can memorize training data, allowing adversaries to extract sensitive records through carefully crafted queries.
Question 30: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals within how many days of discovering a breach?
- 90 calendar days
- 30 calendar days
- 60 calendar days (Correct answer)
- 45 calendar days
Correct answer: 60 calendar days
The HIPAA Breach Notification Rule requires notification to affected individuals without unreasonable delay and no later than 60 calendar days of breach discovery.
Question 31: What is the primary purpose of data minimization as a privacy engineering control?
- Minimize the number of database tables
- Collect only the data necessary for the specified purpose (Correct answer)
- Reduce storage costs by compressing files
- Delete all data older than 90 days
Correct answer: Collect only the data necessary for the specified purpose
Data minimization limits the collection of personal data to what is strictly necessary for a defined purpose, reducing privacy risk.
Question 32: Under the US HIPAA Breach Notification Rule, how quickly must covered entities notify affected individuals of an unsecured PHI breach?
- Within 14 days of discovery
- Within 24 hours of discovery
- Only after completing a full forensic investigation, with no time limit
- Without unreasonable delay and no later than 60 days after discovery (Correct answer)
Correct answer: Without unreasonable delay and no later than 60 days after discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and within 60 days of discovering a breach of unsecured PHI.
Question 33: Which software development practice integrates privacy requirements into each sprint or iteration of an Agile project?
- Privacy by Design in Agile (privacy user stories) (Correct answer)
- Annual privacy policy updates
- Waterfall privacy gate reviews
- Post-launch privacy audits
Correct answer: Privacy by Design in Agile (privacy user stories)
Writing privacy user stories and including privacy acceptance criteria in each sprint embeds Privacy by Design into Agile workflows.
Question 34: What is the role of "End-to-End Protection โ Lifecycle Security" within the Privacy by Design framework?
- To focus only on data collection and use
- To avoid any data processing
- To promote data sharing without restrictions
- To ensure security throughout the data lifecycle (Correct answer)
Correct answer: To ensure security throughout the data lifecycle
This principle emphasizes that privacy and security measures must be applied continuously throughout the entire lifecycle of personal data. From the moment data is collected to its eventual destruction, it must be securely handled and protected. This holistic approach ensures that data remains secure and private at every stage, preventing vulnerabilities at any point in its journey.
Question 35: What is the main goal of applying 'data separation' or 'compartmentalization' as a privacy engineering technique?
- Reducing cloud storage costs
- Speeding up database queries
- Encrypting data at rest
- Limiting the combination of data that could re-identify individuals (Correct answer)
Correct answer: Limiting the combination of data that could re-identify individuals
Data separation prevents linking datasets that together could re-identify individuals, limiting the risk of aggregation attacks.
Question 36: Which model explicitly uses 'contextual integrity' to evaluate whether information flows are appropriate?
- The OECD Privacy Guidelines model
- Helen Nissenbaum's privacy-as-contextual-integrity model (Correct answer)
- The EU adequacy decision model
- The NIST Cybersecurity Framework
Correct answer: Helen Nissenbaum's privacy-as-contextual-integrity model
Helen Nissenbaum's contextual integrity model holds that privacy is violated when information flows do not match the norms of the context in which data was shared.
Question 37: In a data governance program, what is the role of a 'data steward'?
- Responding to data subject access requests
- Processing personal data on behalf of the controller
- Managing day-to-day data quality, classification, and compliance for a specific dataset or domain (Correct answer)
- Setting organization-wide privacy strategy
Correct answer: Managing day-to-day data quality, classification, and compliance for a specific dataset or domain
Data stewards are operational custodians who enforce data governance policies, maintain data quality, and ensure day-to-day compliance within their assigned data domain.
Question 38: Under the GDPR, which role is responsible for processing personal data on behalf of the data controller?
- Supervisory authority
- Data subject
- Data processor (Correct answer)
- Data protection officer
Correct answer: Data processor
A data processor processes personal data only on the documented instructions of the data controller.
Question 39: What is the 'risk of harm' standard primarily used for in breach notification decisions?
- Establishing whether the severity of potential harm to individuals triggers mandatory notification (Correct answer)
- Setting the regulatory reporting timeline after a breach is discovered
- Determining the financial penalties owed to regulators after a breach
- Calculating compensation amounts owed to individual data subjects
Correct answer: Establishing whether the severity of potential harm to individuals triggers mandatory notification
The risk of harm standard acts as a threshold testโnotification is required only when a breach creates a sufficient risk of real harm to affected individuals.
Question 40: A company processes employee health data for workplace safety compliance. Under HIPAA, which entity type classification would typically apply?
- Hybrid entity (Correct answer)
- Business associate
- Covered entity
- Exempt entity
Correct answer: Hybrid entity
A hybrid entity is an organization that performs both covered and non-covered functions; it can designate only its healthcare components as subject to HIPAA requirements.
Question 41: Which threat model considers the scenario where a cloud provider's employees could access customer data stored on their platform?
- External attacker model
- Supply chain attack model
- Nation-state threat model
- Insider threat model (Correct answer)
Correct answer: Insider threat model
The insider threat model accounts for risks from individuals with legitimate system access, such as employees of a cloud or SaaS provider.
Question 42: An employee transfers to a new department. Which identity management process ensures their old access rights are removed and new ones are assigned?
- Multi-factor authentication enrollment
- Password reset
- Single sign-on configuration
- Access recertification or provisioning/deprovisioning workflow (Correct answer)
Correct answer: Access recertification or provisioning/deprovisioning workflow
A role-change provisioning workflow automatically deactivates the employee's previous role permissions and grants those appropriate to their new function.
Question 43: Which control requires that a minimum number of authorized personnel must cooperate to perform a sensitive operation, preventing unilateral action?
- Mandatory access control
- Multi-party authorization (M-of-N control) (Correct answer)
- Separation of duties
- Role-based access control
Correct answer: Multi-party authorization (M-of-N control)
M-of-N (multi-party authorization) requires M out of N designated individuals to approve an action, guarding against insider abuse.
Question 44: What is a 'privacy program maturity model' used for?
- Calculating GDPR fines based on violation severity
- Ranking countries by the strength of their privacy laws
- Grading individual employee privacy knowledge
- Measuring how advanced and effective an organization's privacy practices are across defined capability levels (Correct answer)
Correct answer: Measuring how advanced and effective an organization's privacy practices are across defined capability levels
A maturity model (e.g., AICPA Privacy Maturity Model, NIST Privacy Framework) benchmarks the current state of a privacy program and provides a roadmap for improvement.
Question 45: An organization applies different handling rules to 'confidential,' 'internal,' and 'public' data categories. What process created these distinctions?
- Data lineage tracking
- Data masking
- Data normalization
- Data classification (Correct answer)
Correct answer: Data classification
Data classification assigns sensitivity levels to data categories, enabling proportionate controls to be applied based on the level of privacy risk.
Question 46: Which data governance document formally describes what personal data an organization collects, how it is used, and with whom it is shared?
- Incident response plan
- Data retention schedule
- Cookie consent banner
- Records of processing activities (RoPA) (Correct answer)
Correct answer: Records of processing activities (RoPA)
A Records of Processing Activities (RoPA) documents all personal data processing operations and is required under GDPR Article 30.
Question 47: A privacy engineer proposes using 'k-anonymity' when publishing a dataset. What does this guarantee?
- Data is encrypted with k encryption keys
- Each record is indistinguishable from at least k-1 other records on quasi-identifiers (Correct answer)
- k users must consent before any data is published
- Each field is masked with k random characters
Correct answer: Each record is indistinguishable from at least k-1 other records on quasi-identifiers
k-anonymity ensures that any individual in a dataset cannot be uniquely identified because their quasi-identifier combination matches at least k-1 other individuals.
Question 48: After a breach is resolved, which activity is MOST important for preventing future incidents?
- Publishing a formal public apology statement acknowledging the breach
- Increasing the organization's marketing and public relations budget
- Conducting a root cause analysis and implementing corrective controls to address identified vulnerabilities (Correct answer)
- Replacing the entire IT or security department responsible for the systems
Correct answer: Conducting a root cause analysis and implementing corrective controls to address identified vulnerabilities
Root cause analysis identifies the specific weaknesses that enabled the breach, and targeted corrective controls directly address those gaps to prevent recurrence.
Question 49: When reporting a data breach to a supervisory authority under GDPR Article 33, what information must be included?
- The nature of the breach, categories of data affected, likely consequences, and measures taken (Correct answer)
- The full names of all data subjects whose data was affected
- A complete audit trail of all prior data processing activities
- Proof of active cyber insurance coverage at the time of the breach
Correct answer: The nature of the breach, categories of data affected, likely consequences, and measures taken
GDPR Article 33(3) specifies the notification must describe the breach nature, data categories, approximate number affected, likely consequences, and remediation measures.
Question 50: A data controller conducts profiling that produces legal or similarly significant effects on individuals. Under GDPR, what right do individuals have in this scenario?
- The right to data portability for all profiled data
- The right to access the source code of the profiling algorithm
- The right to erasure of all profile data within 24 hours
- The right not to be subject to solely automated decision-making (Correct answer)
Correct answer: The right not to be subject to solely automated decision-making
GDPR Article 22 gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, that produce significant effects.
Question 51: The concept of 'privacy by default' in GDPR Article 25 primarily requires that:
- Data is anonymized by default before any transfer
- Users must opt-in before any data processing begins
- The most privacy-protective settings are active without user action (Correct answer)
- All system features be disabled until the user enables them
Correct answer: The most privacy-protective settings are active without user action
Privacy by default means that, by default, only personal data necessary for each specific purpose is processed, without requiring action from the data subject.
Question 52: Which governance mechanism ensures that personal data collected for one purpose is not used for an incompatible second purpose?
- Data retention policies
- Role-based access control
- Purpose limitation controls (Correct answer)
- Encryption at rest
Correct answer: Purpose limitation controls
Purpose limitation controls โ including technical restrictions and policy enforcement โ prevent data from being repurposed beyond its original, consented-to use.
Question 53: What is Privacy by Design (PbD)?
- An approach to integrating privacy into development from the beginning (Correct answer)
- A process for addressing data breaches reactively
- A framework for building secure software
- A method of data encryption
Correct answer: An approach to integrating privacy into development from the beginning
Privacy by Design (PbD) is a proactive approach that embeds privacy considerations into the design and architecture of IT systems, business practices, and networked infrastructures from the outset. It emphasizes building privacy directly into the system, rather than treating it as an afterthought or an add-on. This ensures that privacy is a fundamental component of the system's operation, not just a compliance measure.
Question 54: What is the primary risk of 'data sprawl' from a privacy governance perspective?
- Increased storage costs
- Slower database query performance
- Difficulty in software version control
- Uncontrolled copies of personal data spread across systems, increasing breach surface and erasure complexity (Correct answer)
Correct answer: Uncontrolled copies of personal data spread across systems, increasing breach surface and erasure complexity
Data sprawl creates untracked copies of personal data that may not be covered by security controls or erasure workflows, elevating privacy risk.
Question 55: In Privacy by Design, what does the principle 'Proactive not Reactive' mean?
- Anticipate and prevent privacy-invasive events before they occur (Correct answer)
- React quickly when a data breach happens
- Comply with regulations after they are enacted
- Notify users after collecting their data
Correct answer: Anticipate and prevent privacy-invasive events before they occur
Proactive not Reactive means privacy is built in from the start, preventing incidents rather than remedying them after the fact.
Question 56: K-anonymity ensures that any individual in a dataset is indistinguishable from at least how many other individuals with respect to quasi-identifiers?
- k (Correct answer)
- 2k
- k-1
- k+1
Correct answer: k
In a k-anonymous dataset, every record shares the same quasi-identifier values with at least k-1 other records, making the group size at least k.
Question 57: Which data protection regulation applies specifically to websites targeted at children under 13 years of age?
- HIPAA
- FCRA
- GLBA
- COPPA (Correct answer)
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) is a US federal law that imposes specific requirements on operators of websites and online services directed to children under 13 years of age, or general audience sites that knowingly collect personal information from children under 13. It mandates parental consent for data collection and outlines how children's online privacy must be protected.
Question 58: Which principle from the Fair Information Practice Principles (FIPPs) requires that individuals be able to find out what personal information about them is on record?
- Security Safeguards
- Individual Participation (Correct answer)
- Openness
- Use Limitation
Correct answer: Individual Participation
The Individual Participation principle ensures that individuals have a right to know about and access personal information held about them, and can challenge inaccurate or incomplete data.
Question 59: Which risk management output formally documents an organization's decision to accept a specific privacy risk and who authorized that decision?
- Risk acceptance record (or risk acceptance sign-off) (Correct answer)
- Privacy policy update
- Vendor due diligence report
- Incident response plan
Correct answer: Risk acceptance record (or risk acceptance sign-off)
A risk acceptance record documents that the risk was reviewed, the residual risk level was understood, and a named accountable person formally approved accepting it.
Question 60: Which US state law, effective January 2020, grants California consumers the right to know what personal information is collected about them and to request its deletion?
- California Privacy Rights Act (CPRA)
- California Consumer Privacy Act (CCPA) (Correct answer)
- California Online Privacy Protection Act (CalOPPA)
- California Data Breach Notification Law (SB-1386)
Correct answer: California Consumer Privacy Act (CCPA)
The CCPA, effective January 1, 2020, established rights for California consumers including access, deletion, and opt-out of sale of personal information.
Question 61: An organization implements automated data expiry rules that delete personal records when their retention period ends. What governance benefit does this provide?
- Ensures HIPAA encryption requirements are met
- Reduces risk of holding data beyond its legal or business justification (Correct answer)
- Improves database query speed
- Reduces the need for user consent mechanisms
Correct answer: Reduces risk of holding data beyond its legal or business justification
Automated retention enforcement ensures data is not held longer than necessary, reducing regulatory exposure and minimizing the dataset affected in a breach.
Question 62: Which NIST Privacy Framework core function focuses on developing and implementing organizational activities to identify privacy risk?
- Protect-P
- Control-P
- Govern-P
- Identify-P (Correct answer)
Correct answer: Identify-P
The Identify-P function in the NIST Privacy Framework helps organizations develop an organizational understanding of privacy risk to individuals.
Question 63: A CIPT recommends conducting a privacy risk assessment before integrating a new third-party analytics SDK into a mobile app. Why is this timing important?
- Assessment timing does not affect remediation costs
- Post-launch assessments are required by law
- SDKs are always low-risk and only need review after user complaints
- Early assessment allows risks to be designed out before integration, reducing cost and rework (Correct answer)
Correct answer: Early assessment allows risks to be designed out before integration, reducing cost and rework
Identifying privacy risks before integration enables design-stage mitigations, which are far less costly than architectural changes after the SDK is live in production.
Question 64: What is the primary purpose of a 'privacy by default' operational setting in a product or service?
- Apply maximum data collection as the baseline
- Make all data publicly accessible unless users opt out
- Ensure the most privacy-protective settings are active without any user action required (Correct answer)
- Disable all non-essential features on launch
Correct answer: Ensure the most privacy-protective settings are active without any user action required
Privacy by default means that, out of the box, the most privacy-restrictive settings are applied, so users who take no action still receive strong privacy protection.
Question 65: A company collects biometric data in Illinois. Under the Illinois Biometric Information Privacy Act (BIPA), what must the company do BEFORE collection?
- Submit a privacy impact assessment to the Attorney General
- Anonymize the data before storage
- Obtain written release from the subject and publish a retention schedule (Correct answer)
- Notify state regulators within 30 days
Correct answer: Obtain written release from the subject and publish a retention schedule
BIPA requires companies to inform subjects in writing about the collection, its purpose, and duration; and obtain a written release before collecting biometric identifiers or information.
Question 66: A healthcare organization conducts quarterly 'access reviews' where managers certify which employees need continued access to patient records. What privacy risk does this address?
- Data breach notification delays
- Excessive data collection at point of entry
- Insecure data transmission protocols
- Privilege creep โ accumulation of unnecessary access rights over time (Correct answer)
Correct answer: Privilege creep โ accumulation of unnecessary access rights over time
Access reviews identify and remediate privilege creep, ensuring that only individuals with a current, legitimate need retain access to sensitive personal data.
Question 67: Which engineering technique adds statistical noise to datasets to protect individual privacy while preserving overall data utility?
- Access control lists
- Data tokenization
- Differential privacy (Correct answer)
- Homomorphic encryption
Correct answer: Differential privacy
Differential privacy injects calibrated noise into query results so that individual records cannot be inferred from aggregate outputs.
Question 68: What privacy risk does 'orphaned accounts' (accounts of former employees that were not deprovisioned) create?
- Unauthorized access to personal data by individuals who no longer have a legitimate need (Correct answer)
- Higher cloud storage costs
- Increased password reset ticket volume
- Degraded single sign-on performance
Correct answer: Unauthorized access to personal data by individuals who no longer have a legitimate need
Orphaned accounts can be used by former employees or attackers to access personal data without authorization, directly violating data access controls.
Question 69: When must an organization consult with the supervisory authority (e.g., a DPA) after completing a DPIA?
- After every DPIA regardless of the findings
- Only when a data breach has already occurred
- When processing data of fewer than 500 individuals
- When the DPIA indicates a high residual risk that the organization cannot sufficiently mitigate (Correct answer)
Correct answer: When the DPIA indicates a high residual risk that the organization cannot sufficiently mitigate
Prior consultation with the supervisory authority is required when the DPIA shows that high risks remain after the organization's mitigation efforts.
Question 70: Under the Colorado Privacy Act (CPA), what is the maximum civil penalty per intentional violation?
- $2,500
- $50,000
- $20,000
- $7,500 (Correct answer)
Correct answer: $7,500
The Colorado Privacy Act allows the Attorney General to seek civil penalties of up to $20,000 per violation, but enforcement is similar to other state laws with a 60-day cure period in some circumstances.
Question 71: What is the central objective of the Privacy by Design (PbD) framework?
- To embed privacy into development from the outset (Correct answer)
- To comply with security regulations
- To eliminate all data collection practices
- To prevent data breaches entirely
Correct answer: To embed privacy into development from the outset
The core objective of Privacy by Design is to proactively integrate privacy protections into the design and operation of information systems and business practices. Instead of addressing privacy as a reactive measure after a system is built, PbD ensures that privacy is a foundational element from the very beginning. This proactive approach aims to prevent privacy risks before they arise, making privacy an inherent part of the system's architecture.
Question 72: What is a data inventory (or data map) primarily used for in a privacy governance program?
- Documenting where personal data is collected, stored, processed, and shared (Correct answer)
- Managing software licenses
- Tracking server uptime and performance metrics
- Auditing user login activity
Correct answer: Documenting where personal data is collected, stored, processed, and shared
A data inventory catalogs all personal data assets, their locations, purposes, legal bases, and flows, forming the foundation for privacy compliance programs.
Question 73: A company maintains records of all its data processing activities including purposes, categories of data, and retention periods. What is this record called?
- Privacy impact assessment
- Information security policy
- Data breach register
- Record of Processing Activities (RoPA) (Correct answer)
Correct answer: Record of Processing Activities (RoPA)
A Record of Processing Activities (RoPA) is a documented inventory of all processing activities required by privacy regulations such as GDPR Article 30.
Question 74: What does 'remediation' mean in a privacy breach response context?
- Immediately deleting all data that was involved in or touched by the breach
- Paying financial compensation to all individuals whose data was involved in the breach
- Publicly disclosing all technical details of the breach to the media and general public
- Actions taken to fix the vulnerabilities, misconfigurations, or weaknesses that caused or enabled the breach (Correct answer)
Correct answer: Actions taken to fix the vulnerabilities, misconfigurations, or weaknesses that caused or enabled the breach
Remediation involves applying patches, reconfiguring systems, and implementing new controls to address the root causes of the breach and harden defenses against future incidents.
Question 75: Which privacy risk factor specifically relates to the harm an individual may suffer if their personal data is exposed or misused?
- Organizational reputational risk
- Impact to data subjects (Correct answer)
- Vulnerability severity
- Threat likelihood
Correct answer: Impact to data subjects
Privacy risk assessment must center on the potential harm to individuals โ including financial loss, discrimination, or reputational damage โ not just organizational risk.
Question 76: Under the California Consumer Privacy Act (CCPA), which threshold triggers the law's applicability to a for-profit business?
- Processing personal data of more than 50,000 consumers per year
- Having more than 100 employees in California
- Annual gross revenue exceeding $10 million
- Annual gross revenue exceeding $25 million (Correct answer)
Correct answer: Annual gross revenue exceeding $25 million
CCPA applies to for-profit businesses that meet at least one of three thresholds: annual gross revenue exceeding $25 million, buying/selling/receiving/sharing personal information of 100,000+ consumers/households annually, or deriving 50%+ of annual revenue from selling consumers' personal information.
Question 77: What does 'End-to-End Security โ Full Lifecycle Protection' require in Privacy by Design?
- Secure retention and deletion of data throughout its entire lifecycle (Correct answer)
- Applying security controls only during user authentication
- Encrypting only data in transit
- Securing only the database layer
Correct answer: Secure retention and deletion of data throughout its entire lifecycle
End-to-End Security means strong security measures protect data from collection through secure destruction at the end of its lifecycle.
Question 78: What is the purpose of conducting privacy awareness training for employees?
- Training employees to handle data breach litigation
- Ensuring staff understand their data handling obligations and can recognize privacy risks in their work (Correct answer)
- Satisfying a one-time regulatory checkbox requirement
- Replacing the need for technical privacy controls
Correct answer: Ensuring staff understand their data handling obligations and can recognize privacy risks in their work
Privacy training builds a culture of privacy by equipping employees to identify risks, follow procedures, and handle personal data responsibly in their daily tasks.
Question 79: Which document serves as the foundational governance instrument that describes an organization's privacy program scope, objectives, and senior management commitment?
- Privacy policy (internal) (Correct answer)
- Data processing agreement
- Privacy notice (external)
- Incident response plan
Correct answer: Privacy policy (internal)
An internal privacy policy establishes the organization's privacy program framework, assigns responsibilities, and documents management's commitment to privacy as an organizational value.
Question 80: Under Virginia's Consumer Data Protection Act (VCDPA), which data processing activity requires a data protection assessment?
- Processing sensitive data or data for targeted advertising (Correct answer)
- Processing publicly available information
- Processing data for order fulfillment
- Processing data for internal analytics
Correct answer: Processing sensitive data or data for targeted advertising
VCDPA requires data protection assessments for processing activities presenting heightened risk, including processing sensitive data, targeted advertising, profiling, and sale of personal data.
Question 81: What does 'data sovereignty' mean in the context of data governance?
- Data must be stored on on-premises servers only
- Users can export their data in any format they choose
- Data is subject to the laws of the country in which it is collected or stored (Correct answer)
- The organization owns all data it collects indefinitely
Correct answer: Data is subject to the laws of the country in which it is collected or stored
Data sovereignty means that data is governed by the legal and regulatory framework of the jurisdiction where it resides, affecting cross-border transfer decisions.
Question 82: A CIPT is reviewing a new mobile app. She recommends that the app request location permission only when a location-based feature is actively used. Which principle does this reflect?
- Data portability
- Full functionality
- End-to-end encryption
- Context-aware data collection (purpose limitation) (Correct answer)
Correct answer: Context-aware data collection (purpose limitation)
Context-aware data collection ensures personal data is gathered only when directly needed for a specific user action, limiting purpose and minimizing collection.
Question 83: What is 'substitute notice' in the context of breach notification laws?
- Using a third-party vendor to send breach notifications on behalf of the organization
- Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive (Correct answer)
- Notifying regulators in lieu of notifying affected individuals
- Sending a condensed summary notice rather than a full breach disclosure document
Correct answer: Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive
Substitute notice allows organizations to satisfy notification obligations via media notices or website postings when direct individual notification is infeasible due to cost or missing contact information.
Question 84: Which role is typically responsible for defining data classification levels and associated handling requirements in a data governance program?
- Data processor
- Data owner (Correct answer)
- Data subject
- Data custodian
Correct answer: Data owner
The data owner (usually a business unit leader) is accountable for data classification decisions and the rules governing how data at each level must be handled.
Question 85: A privacy engineer is asked to implement a technique that replaces real user identifiers with pseudonyms in a dataset. What technique is being used?
- Tokenization of payment data
- Anonymization
- Pseudonymization (Correct answer)
- Data masking for testing
Correct answer: Pseudonymization
Pseudonymization replaces direct identifiers with artificial identifiers (pseudonyms) so that data can no longer be attributed to a specific individual without additional information.
Question 86: Under GDPR Article 33, within how many hours must a personal data breach be reported to the supervisory authority?
- 48 hours
- 72 hours (Correct answer)
- 96 hours
- 24 hours
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of the breach, where feasible.
Question 87: Which concept describes tracking the origin, movement, and transformations of data across its entire lifecycle within an organization?
- Data provenance auditing
- Database versioning
- Data lineage (Correct answer)
- Change data capture
Correct answer: Data lineage
Data lineage documents where data comes from, how it moves through systems, and how it is transformed, enabling accountability and privacy compliance verification.
Question 88: Under HIPAA's Minimum Necessary standard, when does it NOT apply to a use or disclosure of PHI?
- Disclosures to the individual who is the subject of the PHI (Correct answer)
- Uses for treatment purposes by workforce members
- Disclosures to business associates
- Research uses with a waiver of authorization
Correct answer: Disclosures to the individual who is the subject of the PHI
The Minimum Necessary standard does not apply to disclosures made to or requested by the individual who is the subject of the information, as they have an inherent right to their own PHI.
Question 89: When building a consent management platform, which engineering requirement is most critical from a Privacy by Design perspective?
- Defaulting all marketing preferences to opted-in
- Granular, revocable consent with clear audit logs (Correct answer)
- Storing consent in the same table as behavioral analytics
- Requiring consent only for sensitive data categories
Correct answer: Granular, revocable consent with clear audit logs
A consent management platform must record granular per-purpose consent, allow withdrawal at any time, and maintain tamper-evident audit logs.
Question 90: A healthcare app encrypts data in transit using TLS but stores it in plaintext on the server. Which threat does this configuration leave unaddressed?
- Man-in-the-browser attacks
- Certificate spoofing
- Network eavesdropping
- Server-side data breach (Correct answer)
Correct answer: Server-side data breach
Encrypting only data in transit leaves stored data vulnerable to server compromise; encryption at rest is also required.
Certified Information Privacy Technologist (CIPT)
The CIPT certification, offered by IAPP, validates expertise in embedding privacy into technology systems and products. It covers privacy engineering, data lifecycle management, privacy risk management, privacy-enhancing technologies, and privacy by design principles.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds