IAPP CIPP-US Practice Test Questions and Exam Dumps Part1 Q1-20

View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.


Question 1. Which statement BEST describes the overall structure of privacy regulation in the United States?

  1. A single comprehensive federal privacy statute governs nearly all personal information
  2. Privacy is governed by a combination of federal sector-specific laws, state laws, and regulatory enforcement
  3. Only state governments regulate private-sector privacy
  4. Privacy protections apply only to information held by government agencies

Correct Answer: 2. Privacy is governed by a combination of federal sector-specific laws, state laws, and regulatory enforcement

Explanation:

The United States generally follows a sectoral approach to privacy regulation rather than relying on one comprehensive federal privacy statute covering all private-sector personal information. Different federal laws apply to areas such as health information, financial information, consumer reports, children’s online data, and commercial communications. States also impose privacy requirements, including comprehensive consumer privacy statutes such as California’s CCPA. In addition, the Federal Trade Commission uses its consumer-protection authority to address certain unfair or deceptive privacy and data-security practices. Understanding this overlapping framework is fundamental to the CIPP/US body of knowledge.

Question 2. Which federal agency frequently uses Section 5 of the FTC Act to address deceptive or unfair privacy practices?

  1. Department of Education
  2. Department of Labor
  3. Federal Communications Commission exclusively
  4. Federal Trade Commission

Correct Answer: 4. Federal Trade Commission

Explanation:

The Federal Trade Commission is a central U.S. privacy and consumer-protection regulator. Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in or affecting commerce. The FTC has used this authority in privacy and security matters where organizations misrepresented their data practices, failed to honor privacy promises, or engaged in conduct that caused substantial consumer injury. The FTC also enforces specific privacy statutes and rules, including COPPA and certain provisions affecting financial institutions. For CIPP/US preparation, it is important to distinguish the FTC’s broad consumer-protection role from agencies regulating particular industries.

Question 3. A company promises in its privacy notice that it never shares customer location data, but routinely sells that data to advertising partners. Which FTC concept is MOST directly implicated?

  1. Deception
  2. Data portability
  3. Federal preemption
  4. Public-record disclosure

Correct Answer: 1. Deception

Explanation:

A deceptive practice generally involves a material representation, omission, or practice that is likely to mislead consumers acting reasonably under the circumstances. If a company tells consumers that it does not share location data but actually sells that information, the discrepancy between the stated practice and actual conduct can form the basis of an FTC deception case. Privacy policies therefore create meaningful compliance obligations when companies make representations about collection, use, sharing, retention, or security. Organizations should ensure that public statements accurately reflect actual operations and that operational changes are reviewed against existing privacy commitments.

Question 4. Which organization is generally a HIPAA covered entity?

  1. An ordinary employer maintaining employee performance records
  2. A retail store collecting loyalty-card information
  3. A health plan
  4. A social media company merely discussing health topics

Correct Answer: 3. A health plan

Explanation:

The HIPAA Privacy Rule applies to specified covered entities: health plans, health care clearinghouses, and health care providers that conduct certain standardized electronic transactions. It does not automatically apply to every organization that possesses information related to health. For example, employers, life insurers, and many consumer applications may hold health-related information without becoming HIPAA covered entities solely for that reason. Correctly identifying whether an entity falls within HIPAA’s regulated categories is therefore a threshold compliance question. Covered entities must follow HIPAA requirements governing protected health information and individual privacy rights.

Question 5. Under HIPAA, what is a business associate?

  1. Any patient who conducts business with a hospital
  2. An organization performing certain functions or services for a covered entity involving protected health information
  3. Every employee of a covered entity
  4. Any insurer that sells property insurance

Correct Answer: 2. An organization performing certain functions or services for a covered entity involving protected health information

Explanation:

A business associate is generally a person or organization that performs certain functions or services for a HIPAA covered entity and needs access to protected health information in doing so. Covered entities typically must enter into written business associate agreements or other appropriate arrangements establishing permitted uses and required safeguards. Business associates are also directly liable for compliance with certain HIPAA provisions. Examples can include billing, data processing, legal, consulting, or technology services when the service involves protected health information. The concept extends HIPAA protections beyond the covered entity’s own workforce.

Question 6. Which individual is covered by COPPA’s core protections?

  1. A 17-year-old using an employment website
  2. A 14-year-old buying a product online
  3. A 12-year-old whose personal information is collected by a child-directed online service
  4. A 20-year-old using a gaming application

Correct Answer: 3. A 12-year-old whose personal information is collected by a child-directed online service

Explanation:

COPPA applies to operators of websites and online services directed to children under 13, as well as operators that have actual knowledge they are collecting personal information online from a child under 13. The rule imposes requirements concerning notice, parental involvement, data practices, and security. Age 13 is therefore an important threshold for COPPA analysis, although other laws or platform policies may protect teenagers as well. A privacy professional should not assume that COPPA broadly covers every minor under 18; its central federal framework focuses specifically on children younger than 13.

Question 7. Before collecting personal information online from a child covered by COPPA, an operator generally must do what?

  1. Provide required notice and obtain verifiable parental consent, subject to applicable exceptions
  2. Obtain approval from the child’s school principal
  3. Register the child with the Federal Trade Commission
  4. Publish the child’s information in a public privacy notice

Correct Answer: 1. Provide required notice and obtain verifiable parental consent, subject to applicable exceptions

Explanation:

A central COPPA requirement is parental involvement before covered online services collect, use, or disclose personal information from children under 13. Covered operators generally must provide required notice regarding their information practices and obtain verifiable parental consent before the collection occurs, subject to specific regulatory exceptions. The requirement reflects COPPA’s goal of giving parents meaningful control over young children’s online information. Privacy teams working with child-directed products should therefore build age screening, parental notice, consent, retention, security, and deletion considerations into the service’s design rather than attempting to address them only after collection begins.

Question 8. What is a major privacy requirement of the Gramm-Leach-Bliley Act (GLBA) for covered financial institutions?

  1. They must make all customer information publicly available
  2. They must delete all customer records after one year
  3. They must obtain a court order before processing financial data
  4. They must explain certain information-sharing practices and protect customer information

Correct Answer: 4. They must explain certain information-sharing practices and protect customer information

Explanation:

The GLBA applies to covered financial institutions and includes important privacy and security obligations. Financial institutions generally must provide required information about their information-sharing practices, while the Safeguards Rule requires covered organizations to develop and maintain an information security program containing appropriate administrative, technical, and physical safeguards. The law applies broadly to companies offering qualifying financial products or services, not merely traditional banks. Privacy professionals should therefore assess both whether an organization qualifies as a financial institution and which GLBA privacy, notice, sharing, and security obligations apply to its activities.

Question 9. What is the MAIN objective of the FTC Safeguards Rule under GLBA?

  1. To establish requirements for protecting covered customer information through an information security program
  2. To regulate children’s advertising
  3. To determine whether a credit report is accurate
  4. To control patient access to medical records

Correct Answer: 1. To establish requirements for protecting covered customer information through an information security program

Explanation:

The FTC Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program designed to protect customer information. The program includes administrative, technical, and physical safeguards appropriate to the organization and its risks. The rule complements GLBA privacy requirements concerning financial institutions’ handling of consumer information. A privacy professional should distinguish between privacy obligations governing collection, sharing, and notice and security obligations governing protection of data. Both areas are closely related, but satisfying a privacy-notice obligation alone does not establish that an organization has implemented an adequate security program.

Question 10. Which law primarily regulates information collected by consumer reporting agencies such as credit bureaus and tenant-screening companies?

  1. COPPA
  2. Fair Credit Reporting Act
  3. HIPAA
  4. CAN-SPAM Act

Correct Answer: 2. Fair Credit Reporting Act

Explanation:

The Fair Credit Reporting Act regulates consumer reporting agencies and the use of consumer reports. It applies to organizations such as credit bureaus, medical information companies, and tenant-screening services. Among other requirements, consumer-report information generally may be provided only for purposes permitted by the Act. Furnishers of information and users of consumer reports also have important obligations. The FCRA demonstrates the U.S. sectoral approach to privacy because it regulates specific information flows and decision-making contexts rather than functioning as a broad law governing all personal information held by every organization.

Question 11. An employer takes an adverse employment action based on information in a consumer report. Which federal law is particularly relevant?

  1. COPPA
  2. HIPAA Privacy Rule
  3. GLBA Safeguards Rule
  4. Fair Credit Reporting Act

Correct Answer: 4. Fair Credit Reporting Act

Explanation:

The FCRA regulates the use of consumer reports for several purposes, including employment. When an organization uses information from a consumer report in making certain adverse decisions, the Act imposes notification and related requirements. The FTC notes that users of consumer reports for credit, insurance, or employment purposes must notify consumers when adverse action is taken based on such reports. CIPP/US candidates should recognize that the FCRA applies far beyond traditional credit scores: background checks, tenant screening, and certain employment reports can fall within its framework when the statutory definitions and conditions are met.

Question 12. Which right is provided to California consumers under the CCPA, as amended by the CPRA?

  1. A right to force every business to stop collecting all information
  2. A right to automatic monetary compensation for every privacy violation
  3. A right to request correction of inaccurate personal information, subject to applicable requirements and exceptions
  4. A right to require all personal information to remain permanently in California

Correct Answer: 3. A right to request correction of inaccurate personal information, subject to applicable requirements and exceptions

Explanation:

The CPRA amended the CCPA and expanded California consumer privacy protections. Among the rights now reflected in California’s privacy framework are rights to know, delete, correct inaccurate personal information, opt out of certain sale or sharing, limit certain uses and disclosures of sensitive personal information, and receive equal treatment when exercising protected rights. These rights are subject to statutory definitions, conditions, and exceptions. CIPP/US candidates should understand that California’s framework is broader than a simple privacy-notice law and gives consumers several affirmative mechanisms for controlling how covered businesses handle personal information.

Question 13. Under the CCPA, what does the consumer right to opt out notably address?

  1. The sale or sharing of personal information, including sharing for cross-context behavioral advertising
  2. Every internal use of data by an employer
  3. All government access to public records
  4. Every processing operation performed by a nonprofit

Correct Answer: 1. The sale or sharing of personal information, including sharing for cross-context behavioral advertising

Explanation:

California consumers have a right to opt out of the sale of personal information and the sharing of personal information for cross-context behavioral advertising. California also recognizes mechanisms such as the Global Privacy Control in relevant contexts. This right does not amount to a universal ability to prohibit every use of personal information by every organization. The scope depends on the CCPA’s definitions, applicability rules, exemptions, and specific business practices. Privacy professionals should carefully analyze whether a transfer qualifies as a sale or sharing rather than assuming that any disclosure to another company automatically triggers identical obligations.

Question 14. Which statement BEST describes the CCPA right to non-discrimination?

  1. Businesses must provide every consumer with identical prices under all circumstances
  2. Consumers must disclose additional information before exercising privacy rights
  3. Businesses may deny services whenever a consumer requests deletion
  4. Covered businesses generally may not unlawfully discriminate against consumers for exercising CCPA rights

Correct Answer: 4. Covered businesses generally may not unlawfully discriminate against consumers for exercising CCPA rights

Explanation:

California’s privacy framework includes a right to equal treatment, meaning businesses generally may not unlawfully discriminate against consumers because they exercise CCPA rights. This prevents privacy rights from becoming meaningless because consumers fear automatic denial of service or other improper retaliation. The law contains nuances concerning financial incentives and differences reasonably related to the value of consumer data, so the principle should not be oversimplified into a rule requiring identical treatment in every conceivable circumstance. For exam preparation, the key concept is that exercising statutory privacy rights should not itself result in prohibited discriminatory treatment.

Question 15. What does the CAN-SPAM Act primarily regulate?

  1. Health records sent electronically
  2. Commercial email messages
  3. Credit reports used by lenders
  4. Children’s educational records

Correct Answer: 2. Commercial email messages

Explanation:

CAN-SPAM establishes requirements for commercial email. It applies to messages whose primary purpose is commercial advertising or promotion and is not limited to mass or bulk email. Among its core requirements are accurate header information, nondeceptive subject lines, appropriate identification, a valid physical postal address, a functioning opt-out mechanism, and timely honoring of opt-out requests. The law can also apply to business-to-business commercial email. Transactional or relationship messages are treated differently when their primary purpose fits the statutory categories. Privacy professionals should therefore classify message purpose before determining which CAN-SPAM requirements apply.

Question 16. Under CAN-SPAM, how quickly must a sender generally honor a recipient’s opt-out request?

  1. Within 24 hours
  2. Within 30 calendar days
  3. Within 10 business days
  4. At the sender’s next annual privacy review

Correct Answer: 3. Within 10 business days

Explanation:

CAN-SPAM requires covered senders to honor recipients’ opt-out requests within 10 business days. The opt-out mechanism must remain capable of processing requests for at least 30 days after the commercial message is sent. Organizations also cannot impose unreasonable requirements, such as charging a fee or demanding unrelated personal information, as a condition for honoring the request. Outsourcing email marketing does not eliminate the organization’s compliance responsibility. Consequently, privacy and marketing teams should maintain suppression processes that ensure opt-out requests are communicated to vendors and consistently honored across marketing systems.

Question 17. Which statement about CAN-SPAM and outsourced email marketing is correct?

  1. Hiring a third party completely transfers all legal responsibility to the vendor
  2. CAN-SPAM does not apply when an outside advertising agency sends the email
  3. Only the email recipient has compliance obligations
  4. A company generally cannot contract away its CAN-SPAM compliance responsibility simply by hiring another company to send marketing email

Correct Answer: 4. A company generally cannot contract away its CAN-SPAM compliance responsibility simply by hiring another company to send marketing email

Explanation:

The FTC makes clear that companies cannot simply outsource away responsibility for CAN-SPAM compliance. Both the organization whose product or service is promoted and the organization that sends the message may have legal responsibility depending on the circumstances. Businesses should therefore conduct vendor oversight, ensure required message elements are present, synchronize suppression lists, and monitor marketing partners. This principle is broader than email compliance: privacy programs frequently rely on third parties, but contractual delegation does not necessarily eliminate the original organization’s statutory or regulatory responsibilities. Vendor-management controls are therefore an important part of privacy governance.

Question 18. The FTC Health Breach Notification Rule primarily applies to which situation?

  1. Every HIPAA breach at a hospital
  2. A vendor of personal health records or certain related entities experiences a breach involving unsecured health information
  3. Any employee accidentally sends an internal email
  4. Every breach involving a credit card

Correct Answer: 1. A vendor of personal health records or certain related entities experiences a breach involving unsecured health information

Explanation:

The FTC Health Breach Notification Rule applies to vendors of personal health records and certain related entities that are outside or distinct from HIPAA’s traditional covered-entity framework. It requires notification following qualifying breaches involving unsecured health information. Service providers that experience a breach may have duties to notify the relevant vendor or entity, which in turn has consumer-notification responsibilities. Certain larger breaches may also trigger media notification. The rule is important because consumer health technologies can collect highly sensitive information even when the organization operating the application is not a HIPAA covered entity.

Question 19. A wellness application collects sensitive health information but is not a HIPAA covered entity or business associate. What is the BEST conclusion?

  1. No U.S. privacy or breach law can apply to the application
  2. The application automatically becomes a HIPAA covered entity
  3. Other laws, including FTC authority and potentially the Health Breach Notification Rule, may still apply
  4. Health information receives protection only when collected by a hospital

Correct Answer: 3. Other laws, including FTC authority and potentially the Health Breach Notification Rule, may still apply

Explanation:

Health-related information is not protected exclusively by HIPAA. HIPAA applies only when its coverage requirements are met, such as when information is handled by covered entities or applicable business associates. Consumer health applications and connected devices can fall outside HIPAA while still being subject to other privacy and consumer-protection requirements. The FTC can address certain unfair or deceptive privacy practices, and its Health Breach Notification Rule can impose notification obligations on qualifying personal health record vendors and related entities. Privacy analysis should therefore begin by identifying the organization, data, activity, and applicable legal regimes rather than assuming that “health information” automatically means HIPAA.

Question 20. A privacy professional is assessing a U.S. company’s obligations. What is the BEST first approach?

  1. Assume the strictest state privacy law automatically applies to every processing activity nationwide
  2. Identify the organization, the information involved, the individuals affected, the business purpose, and the potentially applicable federal and state laws
  3. Apply HIPAA to all personal information
  4. Review only the company’s privacy notice and ignore operational practices

Correct Answer: 2. Identify the organization, the information involved, the individuals affected, the business purpose, and the potentially applicable federal and state laws

Explanation:

U.S. privacy analysis is highly contextual because laws often depend on industry, information type, affected individuals, processing purpose, jurisdiction, and organizational characteristics. A sound assessment therefore begins with data mapping and applicability analysis: determine who is processing the information, what information is involved, whose information it is, how it is used or disclosed, and which federal or state requirements may apply. For example, health data may implicate HIPAA or other FTC rules depending on the entity, while financial or consumer-report data may trigger different statutes. Starting with facts prevents incorrect assumptions about legal coverage.