View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 21. What types of records are generally considered “education records” under FERPA?
- Only final academic transcripts
- Only records created by classroom teachers
- Records directly related to a student and maintained by an educational agency, institution, or party acting for it
- Every record created anywhere by a person who works for a school
Correct Answer: 3. Records directly related to a student and maintained by an educational agency, institution, or party acting for it
Explanation:
FERPA generally defines education records as records that are directly related to a student and maintained by an educational agency or institution, or by a party acting on its behalf. The definition is broad and can include grades, enrollment information, disciplinary records, and other identifiable student information, although FERPA contains important exclusions such as qualifying sole-possession records and certain law-enforcement-unit records. Determining whether information is an education record is a threshold step because FERPA’s access and disclosure requirements depend on that classification. Privacy professionals should therefore analyze both the content of the record and who maintains it.
Question 22. When does FERPA generally transfer privacy rights from a parent to the student?
- When the student turns 18 or attends a postsecondary institution at any age
- When the student reaches age 16
- When the student receives a driver’s license
- Only after the student graduates
Correct Answer: 1. When the student turns 18 or attends a postsecondary institution at any age
Explanation:
FERPA rights generally belong to parents while a student is a minor attending elementary or secondary school. Those rights transfer to the student when the student reaches 18 years of age or attends a postsecondary educational institution at any age. At that point, the student becomes an “eligible student” for FERPA purposes. The eligible student ordinarily exercises FERPA rights concerning access, amendment, and consent to disclosures. This distinction is important because the person legally entitled to exercise FERPA rights can change even though the educational records themselves remain protected.
Question 23. Which statement BEST describes FERPA’s general rule for disclosing personally identifiable information from education records?
- Schools may disclose it freely if the recipient promises confidentiality
- Disclosure is prohibited in every circumstance
- Only courts may authorize disclosure
- Prior written consent is generally required unless a FERPA exception applies
Correct Answer: 4. Prior written consent is generally required unless a FERPA exception applies
Explanation:
FERPA’s general rule is that personally identifiable information from education records should not be disclosed without prior written consent from the parent or eligible student. However, FERPA contains numerous exceptions, including qualifying disclosures to school officials, disclosures for certain studies or audits, specified directory information, and disclosures connected with actual health or safety emergencies. Because exceptions have conditions, an organization should not treat “educational purpose” as a blanket authorization. Privacy professionals must determine whether consent exists or whether the contemplated disclosure fits a specific regulatory exception and satisfies its requirements.
Question 24. What must a valid FERPA consent to disclose education records generally contain?
- Only the student’s name
- A signed and dated consent identifying the records, purpose, and recipient or class of recipients
- Only oral permission from a parent
- A notarized statement approved by the Department of Education
Correct Answer: 2. A signed and dated consent identifying the records, purpose, and recipient or class of recipients
Explanation:
A valid FERPA consent generally must be signed and dated, specify the records that may be disclosed, state the purpose of the disclosure, and identify the party or class of parties to whom the disclosure may be made. Oral consent does not satisfy these regulatory consent requirements. The specificity requirement helps ensure the parent or eligible student understands what information will be disclosed and why. Privacy professionals should therefore avoid using vague authorizations that merely state that a school may disclose “any information” without identifying the relevant records, purpose, and recipients.
Question 25. When may a school generally disclose properly designated “directory information” without prior FERPA consent?
- After providing required public notice and an opportunity for the parent or eligible student to restrict disclosure
- Whenever any employee requests it
- Only pursuant to a court order
- Only after the student graduates
Correct Answer: 1. After providing required public notice and an opportunity for the parent or eligible student to restrict disclosure
Explanation:
FERPA allows schools to disclose information properly designated as directory information without prior consent, but schools must follow the regulatory notice process. The institution must identify the types of information it designates as directory information, explain the right to restrict disclosure, and provide a period during which the parent or eligible student can opt out. Common examples may include a student’s name, participation in activities, or dates of attendance. Social Security numbers generally cannot simply be designated as directory information. A school should therefore not assume that information is freely disclosable merely because it seems non-sensitive.
Question 26. Which right does FERPA provide to parents and eligible students regarding education records?
- A right to require all education records to be destroyed annually
- A right to prohibit the school from maintaining any academic records
- A right to inspect and review applicable education records
- A right to obtain every school employee’s personnel file
Correct Answer: 3. A right to inspect and review applicable education records
Explanation:
A fundamental FERPA right is the ability of parents and eligible students to inspect and review the student’s education records. FERPA also provides mechanisms for seeking amendment of records believed to be inaccurate or otherwise problematic under the statute’s framework. The access right does not extend to every record maintained by a school; whether a document qualifies as an education record matters, and FERPA contains exclusions. Privacy professionals working in educational settings should understand the distinction between access rights to protected education records and unrelated institutional or employee information that does not fall within the student’s FERPA rights.
Question 27. Under the Privacy Act of 1974, what is a “system of records”?
- Every database used by a private company
- A group of federal agency records retrieved by an individual’s name or other identifying particular
- Any publicly available collection of documents
- Only classified national-security records
Correct Answer: 2. A group of federal agency records retrieved by an individual’s name or other identifying particular
Explanation:
The Privacy Act of 1974 applies to federal agency records maintained in a “system of records.” A system of records is generally a group of records under the control of a federal agency from which information is retrieved by an individual’s name or another identifying number, symbol, or particular assigned to that individual. The retrieval concept is important: not every federal database automatically becomes a Privacy Act system of records merely because it contains information about individuals. Federal agencies publish notices describing covered systems and the purposes and routine uses associated with them.
Question 28. What is the general Privacy Act rule concerning disclosure of records from a federal system of records?
- Records may always be sold to private companies
- Records may be disclosed whenever an agency employee requests them
- Disclosure is prohibited even with the individual’s consent
- Disclosure generally requires written consent unless a statutory exception applies
Correct Answer: 4. Disclosure generally requires written consent unless a statutory exception applies
Explanation:
The Privacy Act generally prohibits a federal agency from disclosing a record about an individual from a system of records without the individual’s written consent, unless one of the Act’s statutory exceptions authorizes the disclosure. The statute also provides individuals with mechanisms to seek access to and amendment of covered records and imposes recordkeeping obligations on federal agencies. This framework is distinct from private-sector privacy regulation because the Privacy Act principally governs federal agencies rather than ordinary commercial businesses. Candidates should therefore distinguish the Privacy Act of 1974 from similarly named state privacy statutes and private-sector consumer privacy laws.
Question 29. Which statement BEST describes the scope of the Telephone Consumer Protection Act (TCPA)?
- It applies only to postal advertisements
- It regulates only communications by federal agencies
- It regulates specified telephone calls and texts, including certain calls using automated technology or artificial or prerecorded voices
- It governs only consumer credit reports
Correct Answer: 3. It regulates specified telephone calls and texts, including certain calls using automated technology or artificial or prerecorded voices
Explanation:
The TCPA governs specified telephone communications and restricts certain calls made using an automatic telephone dialing system or an artificial or prerecorded voice. FCC interpretations also recognize text messages as calls for TCPA purposes in relevant circumstances. Different consent standards and regulatory exceptions can apply depending on the destination, technology used, and whether the communication contains advertising or telemarketing. Privacy professionals evaluating messaging campaigns should therefore examine the type of call or text, the number being contacted, the purpose of the communication, consent records, opt-out handling, and applicable FCC rules rather than treating every telephone communication identically.
Question 30. What consent standard generally applies under FCC TCPA rules to robocalls that contain advertising or telemarketing?
- Prior express written consent, subject to applicable rules and exceptions
- No consent is necessary if the company knows the consumer’s name
- Consent from any member of the consumer’s household
- Verbal consent from the company’s marketing agency
Correct Answer: 1. Prior express written consent, subject to applicable rules and exceptions
Explanation:
FCC TCPA rules generally require prior express written consent for covered robocalls that introduce advertisements or constitute telemarketing. The exact analysis depends on the technology, destination, communication type, and applicable regulatory provisions or exceptions. Consent management is therefore a central TCPA compliance issue. Organizations should be able to demonstrate how consent was obtained and should ensure marketing partners do not broaden consent beyond what the consumer actually authorized. FCC rules and orders also address how consent can be revoked and how opt-out requests should be handled, making lifecycle management important in addition to initial collection of consent.
Question 31. Under the TCPA framework, how are qualifying autodialed text messages generally treated?
- They are postal communications
- They are outside the TCPA because texts contain no voice
- They are treated exclusively as email
- A text message can constitute a “call” subject to TCPA requirements
Correct Answer: 4. A text message can constitute a “call” subject to TCPA requirements
Explanation:
The FCC has recognized that text messages sent using covered automated technology can constitute “calls” for purposes of the TCPA. Therefore, companies should not assume that switching a marketing campaign from voice calls to SMS automatically avoids telephone-consumer-protection requirements. Depending on the circumstances, consent and opt-out requirements may apply to robotexts just as they do to covered robocalls. Privacy and marketing teams should coordinate their compliance processes across communications channels so that a consumer’s revocation or opt-out instruction is handled consistently rather than remaining siloed within one messaging platform.
Question 32. What does the Video Privacy Protection Act (VPPA) primarily restrict?
- The sale of televisions to minors
- Certain disclosures of personally identifiable information concerning a consumer’s video viewing or obtaining of video materials or services
- Copyright infringement involving online video
- All advertising by streaming providers
Correct Answer: 2. Certain disclosures of personally identifiable information concerning a consumer’s video viewing or obtaining of video materials or services
Explanation:
The VPPA restricts knowing disclosure by covered video tape service providers of personally identifiable information concerning consumers, subject to statutory exceptions. The statute defines personally identifiable information to include information identifying a person as having requested or obtained specific video materials or services. Although enacted in the video-rental era, VPPA issues can arise in modern digital-video and streaming contexts when the statutory definitions are satisfied. Privacy professionals should analyze whether the entity is a covered provider, whether the individual qualifies as a consumer, what information is disclosed, and whether an exception or valid consent applies.
Question 33. Which statement correctly describes one form of consumer consent recognized by the VPPA for disclosures?
- Consent can never be obtained electronically
- Consent must always be renewed for every single video
- Consent may be informed and written, including electronically, and advance consent is subject to statutory limits
- A general website terms-of-service clause always satisfies the statute automatically
Correct Answer: 4. Consent may be informed and written, including electronically, and advance consent is subject to statutory limits
Explanation:
The VPPA permits certain disclosures when the consumer provides informed, written consent, including through electronic means. The statute imposes specific conditions on the consent process, including requirements concerning separation from other legal or financial obligations. It also permits advance consent for a limited period, subject to withdrawal by the consumer. A privacy professional should therefore avoid assuming that a broad bundled clause hidden inside general terms automatically satisfies the VPPA. The consent mechanism should be designed around the statute’s specific requirements and the disclosure actually contemplated by the video service provider.
Question 34. What conduct is principally prohibited by the Stored Communications Act provision in 18 U.S.C. § 2701?
- Intentionally accessing without authorization, or exceeding authorization to access, a facility providing electronic communication service and thereby accessing stored communications
- Sending a commercial email without a postal address
- Collecting education records without FERPA consent
- Creating a credit report without a credit score
Correct Answer: 1. Intentionally accessing without authorization, or exceeding authorization to access, a facility providing electronic communication service and thereby accessing stored communications
Explanation:
The Stored Communications Act, part of the broader Electronic Communications Privacy Act framework, addresses unauthorized access to certain electronic communications in storage. Section 2701 prohibits intentionally accessing without authorization, or intentionally exceeding authorization to access, a facility through which an electronic communication service is provided when doing so obtains, alters, or prevents authorized access to qualifying communications in electronic storage. The statute contains exceptions, so analysis depends on authorization, service-provider relationships, and the nature and status of the communications. Privacy professionals should distinguish stored-communication issues from interception of communications in transit, which involves related but separate electronic-communications provisions.
Question 35. What is true of U.S. state data-breach notification laws as of 2026?
- Only California and New York have breach-notification laws
- States use one uniform federal notification standard
- All 50 states, plus certain U.S. jurisdictions, have breach-notification laws, but their requirements vary
- Breach notification is required only for government databases
Correct Answer: 3. All 50 states, plus certain U.S. jurisdictions, have breach-notification laws, but their requirements vary
Explanation:
Every U.S. state has adopted a data-breach notification statute, and the District of Columbia, Guam, Puerto Rico, and the Virgin Islands also have breach-notification requirements. However, these laws are not identical. Important differences can include the definition of protected personal information, what constitutes a breach, risk-of-harm standards, timing requirements, regulator notifications, content requirements, and obligations involving consumer-reporting agencies. For multistate incidents, organizations therefore cannot safely assume that satisfying one state’s law satisfies all affected jurisdictions. Incident-response plans should include a mechanism for identifying where affected individuals reside and mapping the applicable notification rules.
Question 36. Why is the affected individual’s state of residence important when analyzing a U.S. multistate data breach?
- It determines whether federal criminal law exists
- State breach laws can impose different definitions, deadlines, and regulator-notification requirements
- Only residents of the company’s headquarters state can receive notification
- All states apply the law of the company’s incorporation
Correct Answer: 2. State breach laws can impose different definitions, deadlines, and regulator-notification requirements
Explanation:
State breach-notification requirements vary materially, so an organization’s obligations frequently depend on the states or territories where affected individuals reside. Some laws define personal information more broadly than others, some impose specific deadlines, and some require notice to an attorney general or another regulator when specified thresholds are met. Consequently, incident-response teams commonly perform a jurisdiction-by-jurisdiction assessment after determining the affected population. This variation is one reason U.S. breach compliance can become complex even when one security event affects all individuals in the same technical manner.
Question 37. What does the Illinois Biometric Information Privacy Act (BIPA) generally require before a private entity collects a person’s biometric identifier or biometric information?
- Written notice concerning collection and purpose, along with a written release
- Approval from the FTC
- A federal court order
- Only an internal privacy impact assessment
Correct Answer: 1. Written notice concerning collection and purpose, along with a written release
Explanation:
Illinois BIPA imposes specific requirements on private entities before collecting or otherwise obtaining biometric identifiers or biometric information. The entity must generally inform the person or legally authorized representative in writing that biometric information is being collected or stored, explain the specific purpose and length of time for which it will be collected, stored, and used, and obtain a written release. The statute also contains retention, destruction, disclosure, and security obligations. Because biometric identifiers can be difficult or impossible to replace after compromise, BIPA treats their collection as a particularly significant privacy event.
Question 38. Which statement about BIPA retention requirements is correct?
- Biometric data must always be retained permanently
- Only government agencies need a retention policy
- Retention is governed solely by the data subject’s employer contract
- Covered private entities must have a publicly available written retention schedule and destruction guidelines
Correct Answer: 4. Covered private entities must have a publicly available written retention schedule and destruction guidelines
Explanation:
BIPA requires a private entity in possession of biometric identifiers or biometric information to develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanent destruction. Generally, destruction is tied to satisfaction of the original purpose for collection or a statutory period following the individual’s last interaction with the entity, subject to the law’s terms. This requirement illustrates an important privacy principle: sensitive information should not simply be retained indefinitely because storage is technically inexpensive. Retention and destruction should instead be tied to a legitimate purpose and an established lifecycle.
Question 39. Which feature makes Illinois BIPA particularly significant from an enforcement-risk perspective?
- It can only be enforced by federal prosecutors
- It provides a statutory private right of action for persons aggrieved by violations
- It contains no potential monetary remedies
- It applies only to federal agencies
Correct Answer: 2. It provides a statutory private right of action for persons aggrieved by violations
Explanation:
BIPA expressly provides a right of action for persons aggrieved by violations of the statute. The law authorizes specified remedies, including liquidated or actual damages under applicable conditions, reasonable attorneys’ fees and costs, and other appropriate relief. Amendments have affected how repeated collection or disclosure involving the same biometric information is treated for recovery purposes, so current statutory text matters. The private right of action has made BIPA a prominent U.S. biometric privacy law and illustrates why privacy professionals must evaluate not only substantive obligations but also the enforcement mechanisms associated with a particular statute.
Question 40. A national company suffers a breach involving personal information of residents in several states. What is the BEST compliance approach?
- Notify only consumers in the state where company headquarters are located
- Apply whichever state’s law has the longest deadline and ignore the others
- Identify affected individuals and data types, analyze applicable state and sector-specific requirements, and coordinate notices according to the relevant laws
- Wait until every state attorney general independently contacts the company
Correct Answer: 3. Identify affected individuals and data types, analyze applicable state and sector-specific requirements, and coordinate notices according to the relevant laws
Explanation:
A multistate breach requires a structured legal and factual assessment. The organization should determine what happened, which individuals were affected, their jurisdictions, and what categories of information were involved. It can then evaluate state breach-notification requirements and any applicable federal or sector-specific rules. State laws can differ regarding covered information, timing, content, regulator notice, and other obligations, so applying a single state’s statute across the entire incident may be insufficient. Effective incident-response planning therefore combines technical investigation, data mapping, legal analysis, documentation, and coordinated communications rather than treating breach notification as a one-size-fits-all mailing exercise.