Certified Information Privacy Technologist (CIPT) — Questions and Answers
Question 1: What is 'substitute notice' in the context of breach notification laws?
- Using a third-party vendor to send breach notifications on behalf of the organization
- Sending a condensed summary notice rather than a full breach disclosure document
- Notifying regulators in lieu of notifying affected individuals
- Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive (Correct answer)
Correct answer: Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive
Substitute notice allows organizations to satisfy notification obligations via media notices or website postings when direct individual notification is infeasible due to cost or missing contact information.
Question 2: Under Virginia's Consumer Data Protection Act (VCDPA), which data processing activity requires a data protection assessment?
- Processing data for order fulfillment
- Processing publicly available information
- Processing data for internal analytics
- Processing sensitive data or data for targeted advertising (Correct answer)
Correct answer: Processing sensitive data or data for targeted advertising
VCDPA requires data protection assessments for processing activities presenting heightened risk, including processing sensitive data, targeted advertising, profiling, and sale of personal data.
Question 3: What is 'residual risk' in the context of privacy risk management?
- The initial risk before any controls are considered
- The total financial exposure from a data breach
- The remaining risk after controls and mitigations have been applied (Correct answer)
- The risk transferred to cyber insurance
Correct answer: The remaining risk after controls and mitigations have been applied
Residual risk is what remains after all identified controls are implemented; it must be accepted, transferred, or reduced further if it exceeds the organization's risk tolerance.
Question 4: What is a data inventory (or data map) primarily used for in a privacy governance program?
- Auditing user login activity
- Managing software licenses
- Documenting where personal data is collected, stored, processed, and shared (Correct answer)
- Tracking server uptime and performance metrics
Correct answer: Documenting where personal data is collected, stored, processed, and shared
A data inventory catalogs all personal data assets, their locations, purposes, legal bases, and flows, forming the foundation for privacy compliance programs.
Question 5: A development team uses data minimization during system design so that only necessary personal data fields are collected. Which Privacy by Design principle does this best reflect?
- End-to-End Security
- Privacy Embedded into Design (Correct answer)
- Proactive not Reactive
- Visibility and Transparency
Correct answer: Privacy Embedded into Design
Privacy Embedded into Design requires integrating privacy controls — including data minimization — directly into the architecture of systems.
Question 6: Which US federal rule requires financial institutions to notify the FTC and customers following certain data breaches affecting 500 or more customers?
- COPPA Safe Harbor Rule
- GLBA Safeguards Rule (Correct answer)
- CAN-SPAM Enforcement Rule
- FERPA Disclosure Rule
Correct answer: GLBA Safeguards Rule
The FTC's updated Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to report qualifying breaches affecting 500+ customers to the FTC.
Question 7: Which U.S. law requires federal agencies to publish notices in the Federal Register describing their systems of records?
- Freedom of Information Act (FOIA)
- E-Government Act
- Privacy Act of 1974 (Correct answer)
- Federal Information Security Management Act (FISMA)
Correct answer: Privacy Act of 1974
The Privacy Act of 1974 requires federal agencies to publish System of Records Notices (SORNs) in the Federal Register describing collections of personal information maintained in systems of records.
Question 8: A CIPT is reviewing a new mobile app. She recommends that the app request location permission only when a location-based feature is actively used. Which principle does this reflect?
- End-to-end encryption
- Full functionality
- Context-aware data collection (purpose limitation) (Correct answer)
- Data portability
Correct answer: Context-aware data collection (purpose limitation)
Context-aware data collection ensures personal data is gathered only when directly needed for a specific user action, limiting purpose and minimizing collection.
Question 9: An organization must delete a customer's data upon request. Which governance process ensures all copies — including backups — are identified and removed?
- Deleting only the primary production record
- Issuing a SQL DELETE command on the main database
- Waiting for backup rotation to naturally overwrite data
- Data mapping combined with a defined erasure workflow (Correct answer)
Correct answer: Data mapping combined with a defined erasure workflow
Effective erasure requires a comprehensive data map to locate all copies — production, backup, archives, and third-party processors — followed by a documented deletion workflow.
Question 10: A privacy impact assessment (PIA) is most valuable when conducted at which stage of a project?
- Early in the design phase (Correct answer)
- After product launch
- During routine maintenance
- When a breach occurs
Correct answer: Early in the design phase
Conducting a PIA early in design allows privacy risks to be mitigated before costly system changes are required.
Question 11: During the data disposal phase, which method best ensures that magnetic hard drive data is unrecoverable?
- Formatting the drive once
- Overwriting with zeros one time
- Standard file deletion
- Degaussing followed by physical destruction (Correct answer)
Correct answer: Degaussing followed by physical destruction
Degaussing disrupts magnetic domains to erase data, and physical destruction ensures media cannot be reconstructed, together providing the highest assurance of unrecoverability.
Question 12: What is the 'principle of least privilege' as applied to personal data access?
- Administrators should have read-only access to all data
- Users and systems should only have access to the personal data required to perform their specific function (Correct answer)
- All employees should share a single account for simplicity
- Data should be accessible to anyone within the corporate network
Correct answer: Users and systems should only have access to the personal data required to perform their specific function
Least privilege minimizes the number of people and systems with access to personal data, reducing insider threat risk and limiting breach scope.
Question 13: Under GDPR Article 33, within how many hours must a personal data breach be reported to the supervisory authority?
- 96 hours
- 48 hours
- 24 hours
- 72 hours (Correct answer)
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of the breach, where feasible.
Question 14: What is Privacy by Design (PbD)?
- A method of data encryption
- A framework for building secure software
- An approach to integrating privacy into development from the beginning (Correct answer)
- A process for addressing data breaches reactively
Correct answer: An approach to integrating privacy into development from the beginning
Privacy by Design (PbD) is a proactive approach that embeds privacy considerations into the design and architecture of IT systems, business practices, and networked infrastructures from the outset. It emphasizes building privacy directly into the system, rather than treating it as an afterthought or an add-on. This ensures that privacy is a fundamental component of the system's operation, not just a compliance measure.
Question 15: Which US state law, effective January 2020, grants California consumers the right to know what personal information is collected about them and to request its deletion?
- California Data Breach Notification Law (SB-1386)
- California Consumer Privacy Act (CCPA) (Correct answer)
- California Online Privacy Protection Act (CalOPPA)
- California Privacy Rights Act (CPRA)
Correct answer: California Consumer Privacy Act (CCPA)
The CCPA, effective January 1, 2020, established rights for California consumers including access, deletion, and opt-out of sale of personal information.
Question 16: Which element must be included in a DPIA report according to GDPR Article 35?
- A list of all system vulnerabilities discovered during testing
- Only the names of the data subjects affected
- A description of the processing, necessity assessment, risk evaluation, and planned mitigation measures (Correct answer)
- The organization's annual privacy budget
Correct answer: A description of the processing, necessity assessment, risk evaluation, and planned mitigation measures
GDPR Article 35 specifies that a DPIA must include: a description of the processing, assessment of necessity and proportionality, risk assessment, and the measures to address risks.
Question 17: Which federated identity standard is widely used for delegating authorization to third-party applications without sharing user credentials?
- OAuth 2.0 (Correct answer)
- LDAP
- Kerberos
- SAML 1.1
Correct answer: OAuth 2.0
OAuth 2.0 provides an authorization framework allowing users to grant third-party apps limited access to their resources without exposing their passwords.
Question 18: Which document serves as the foundational governance instrument that describes an organization's privacy program scope, objectives, and senior management commitment?
- Privacy policy (internal) (Correct answer)
- Incident response plan
- Privacy notice (external)
- Data processing agreement
Correct answer: Privacy policy (internal)
An internal privacy policy establishes the organization's privacy program framework, assigns responsibilities, and documents management's commitment to privacy as an organizational value.
Question 19: An e-commerce platform stores customer purchase history indefinitely 'just in case it is useful later.' Which privacy principle does this most directly violate?
- Openness
- Security safeguards
- Individual participation
- Purpose specification (Correct answer)
Correct answer: Purpose specification
Purpose specification requires that the purposes for which data is collected be specified before collection; storing data for vague future use violates this.
Question 20: Which Privacy by Design principle ensures that privacy coexists with other legitimate system goals without trade-offs?
- Visibility and Transparency
- Full Functionality — Positive-Sum, not Zero-Sum (Correct answer)
- End-to-End Security
- User-Centric Design
Correct answer: Full Functionality — Positive-Sum, not Zero-Sum
Full Functionality rejects the notion that privacy must be sacrificed for functionality, seeking a win-win outcome instead.
Question 21: Which international standard provides guidance on privacy information management systems (PIMS) and is complementary to ISO/IEC 27001?
- ISO/IEC 27018
- ISO/IEC 27701 (Correct answer)
- ISO/IEC 29100
- ISO/IEC 29134
Correct answer: ISO/IEC 27701
ISO/IEC 27701 extends ISO 27001 by specifying requirements and guidance for establishing and continually improving a Privacy Information Management System (PIMS).
Question 22: In Privacy by Design, which foundational principle states that privacy must be proactive rather than reactive?
- Proactive not reactive; preventive not remedial (Correct answer)
- Privacy embedded into design
- Privacy as the default setting
- Full functionality — positive-sum not zero-sum
Correct answer: Proactive not reactive; preventive not remedial
Ann Cavoukian's first principle of Privacy by Design emphasizes anticipating and preventing privacy issues before they occur.
Question 23: Which concept describes designing systems so that a user's identity is not required to access a service when only a credential or attribute is needed?
- Multi-factor authentication
- Single sign-on
- Identity minimization (Correct answer)
- Zero-trust architecture
Correct answer: Identity minimization
Identity minimization (or attribute-based access) ensures systems request only the minimal identity information required rather than full identification.
Question 24: Which approach involves transferring privacy risk to a third party, such as through cyber liability insurance or vendor contractual indemnification?
- Risk mitigation
- Risk transfer (Correct answer)
- Risk avoidance
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts financial or operational consequence of a privacy risk to another party but does not eliminate the underlying risk to data subjects.
Question 25: A privacy 'tabletop exercise' in the context of incident response is best described as:
- An external audit of existing privacy and security controls by third-party reviewers
- A live penetration test executed against production organizational systems
- A simulated discussion-based scenario where stakeholders walk through a hypothetical breach response (Correct answer)
- A compliance training session on privacy regulations for newly hired employees
Correct answer: A simulated discussion-based scenario where stakeholders walk through a hypothetical breach response
Tabletop exercises are facilitated simulations where response teams verbally walk through a hypothetical incident scenario to test and refine their response plan without disrupting systems.
Question 26: A privacy risk assessment rates risks using 'likelihood' and 'impact'. What does the combination of these two factors produce?
- A data flow diagram
- A risk score or risk level (Correct answer)
- A breach notification timeline
- A compliance checklist
Correct answer: A risk score or risk level
Risk level = likelihood × impact; this score prioritizes which risks require immediate mitigation versus those that can be monitored.
Question 27: What does the principle of "Privacy as the Default Setting" suggest?
- Collecting as much data as possible for analysis
- Limiting data collection and retention to the minimum necessary (Correct answer)
- Disclosing personal information without consent
- Making privacy settings optional for users
Correct answer: Limiting data collection and retention to the minimum necessary
The "Privacy as the Default Setting" principle mandates that personal data should be automatically protected in any given system or business practice, without requiring individuals to take action. This means that data collection should be minimized to only what is essential for the specific purpose, and retained only for as long as necessary. It ensures that privacy is the default state for users, rather than an option they must actively select.
Question 28: Which risk management output formally documents an organization's decision to accept a specific privacy risk and who authorized that decision?
- Risk acceptance record (or risk acceptance sign-off) (Correct answer)
- Incident response plan
- Vendor due diligence report
- Privacy policy update
Correct answer: Risk acceptance record (or risk acceptance sign-off)
A risk acceptance record documents that the risk was reviewed, the residual risk level was understood, and a named accountable person formally approved accepting it.
Question 29: What does 'End-to-End Security — Full Lifecycle Protection' require in Privacy by Design?
- Applying security controls only during user authentication
- Securing only the database layer
- Encrypting only data in transit
- Secure retention and deletion of data throughout its entire lifecycle (Correct answer)
Correct answer: Secure retention and deletion of data throughout its entire lifecycle
End-to-End Security means strong security measures protect data from collection through secure destruction at the end of its lifecycle.
Question 30: Which of Ann Cavoukian's seven foundational principles of Privacy by Design states that privacy should be the default setting?
- Privacy as the Default Setting (Correct answer)
- Proactive not Reactive
- End-to-End Security
- Full Functionality
Correct answer: Privacy as the Default Setting
Privacy as the Default Setting means users automatically receive maximum privacy without any required action on their part.
Question 31: What is the primary risk of 'data sprawl' from a privacy governance perspective?
- Increased storage costs
- Slower database query performance
- Uncontrolled copies of personal data spread across systems, increasing breach surface and erasure complexity (Correct answer)
- Difficulty in software version control
Correct answer: Uncontrolled copies of personal data spread across systems, increasing breach surface and erasure complexity
Data sprawl creates untracked copies of personal data that may not be covered by security controls or erasure workflows, elevating privacy risk.
Question 32: A CIPT is creating a privacy incident response plan. Which event type specifically triggers privacy-related incident response (as opposed to a general IT incident)?
- An event involving unauthorized access to, loss of, or unlawful disclosure of personal data (Correct answer)
- Any unplanned server downtime
- An employee forgetting their password
- A failed software deployment
Correct answer: An event involving unauthorized access to, loss of, or unlawful disclosure of personal data
Privacy incidents involve personal data — their unauthorized access, loss, destruction, or disclosure — and trigger specific notification obligations under applicable privacy laws.
Certified Information Privacy Technologist (CIPT)
The CIPT certification, offered by IAPP, validates expertise in embedding privacy into technology systems and products. It covers privacy engineering, data lifecycle management, privacy risk management, privacy-enhancing technologies, and privacy by design principles.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds