View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 141. Which consumer right is expressly provided by the Texas Data Privacy and Security Act (TDPSA)?
- The right to confirm whether a controller processes the consumer’s personal data and obtain access to that data
- The right to require every business to stop collecting all information immediately
- The right to sue any controller directly for statutory damages under the TDPSA
- The right to prevent businesses from complying with court orders
Correct Answer: 1. The right to confirm whether a controller processes the consumer’s personal data and obtain access to that data
Explanation:
The TDPSA gives Texas consumers several rights regarding personal data. These include confirming whether a controller processes their personal data, accessing that data, correcting inaccuracies, deleting qualifying personal data, obtaining portable copies, and opting out of certain targeted advertising, sales, and profiling. These rights are subject to statutory scope and exceptions. The law does not create an unrestricted ability to stop every type of processing or disclosure. A privacy program subject to Texas law should therefore establish procedures for authenticating consumers and responding to qualifying rights requests within the required timeframe.
Question 142. How long does a Texas controller generally have to respond substantively to an authenticated consumer request under the TDPSA?
- Seven days
- Ninety days with no extension
- 45 days, with a possible additional 45-day extension when reasonably necessary
- One year
Correct Answer: 3. 45 days, with a possible additional 45-day extension when reasonably necessary
Explanation:
Texas generally requires a controller to respond to an authenticated consumer privacy request without undue delay and no later than 45 days after receiving it. The controller can extend that period by another 45 days when reasonably necessary, but it must communicate the extension and reason within the original response period. This structure resembles several other U.S. state privacy laws, but organizations should still maintain jurisdiction-specific procedures. A national privacy-rights workflow should track the applicable state, authentication status, request type, deadline, extension rules, and response outcome instead of using an informal one-size-fits-all process.
Question 143. Under the TDPSA, what must a controller generally do before processing a consumer’s sensitive data?
- Publish the data in a privacy notice only
- Wait 30 days after collection
- Obtain approval from the FTC
- Obtain the consumer’s consent
Correct Answer: 4. Obtain the consumer’s consent
Explanation:
The Texas Data Privacy and Security Act prohibits controllers from processing sensitive data without first obtaining consumer consent. The statute also addresses data of known children, for which parental consent requirements apply. Sensitive-data treatment is therefore more restrictive than ordinary processing of nonsensitive personal data. Organizations should identify sensitive-data categories during data mapping and ensure consent is obtained before covered processing begins rather than attempting to rely solely on a general privacy notice after the fact. Texas enforcement has already focused on alleged collection and sale of sensitive precise-geolocation and driving information without adequate notice or consent.
Question 144. Which statement BEST describes private enforcement under the TDPSA?
- Every consumer automatically receives a private damages claim
- The TDPSA does not provide a private right of action; enforcement is handled by the Texas Attorney General
- Only federal prosecutors may enforce the law
- Consumers must bring claims exclusively before the FTC
Correct Answer: 2. The TDPSA does not provide a private right of action; enforcement is handled by the Texas Attorney General
Explanation:
The TDPSA does not create a general private right of action for individual consumers. Enforcement authority rests with the Texas Attorney General. This distinction is important because the existence of substantive consumer rights does not necessarily mean consumers can file direct lawsuits under the comprehensive privacy statute. Instead, consumers may submit complaints to the Attorney General, which can investigate and pursue violations. Privacy professionals should always analyze both substantive obligations and enforcement mechanisms because state privacy statutes differ regarding regulator authority, cure opportunities, penalties, and whether private litigation is available.
Question 145. What does the TDPSA require when a controller refuses a qualifying consumer privacy request?
- Nothing further is required
- The controller must automatically delete the consumer’s account
- The controller must provide the reason for denial and instructions for appealing the decision
- The controller must pay the consumer statutory damages immediately
Correct Answer: 3. The controller must provide the reason for denial and instructions for appealing the decision
Explanation:
Texas requires controllers that decline consumer requests to communicate the decision and provide a justification. The response must also explain how the consumer can appeal. Controllers therefore need an internal appeals process rather than treating the initial request decision as final. If an appeal is denied, consumers must receive information about how to submit a complaint to the Texas Attorney General. This procedural right reinforces accountability and provides consumers with another opportunity to challenge an incorrect request determination. Privacy operations teams should document both initial decisions and appeals so responses remain consistent and defensible.
Question 146. Which consumer right under the Oregon Consumer Privacy Act (OCPA) is broader than merely knowing categories of third-party recipients?
- The right to obtain a list of the specific third parties that received the consumer’s personal data or personal data from the controller
- The right to receive every third party’s internal financial statements
- The right to compel third parties to stop all business activity
- The right to obtain employee personnel records from every recipient
Correct Answer: 1. The right to obtain a list of the specific third parties that received the consumer’s personal data or personal data from the controller
Explanation:
Oregon consumers have a notable transparency right involving third-party disclosures. They may request a list of the specific third parties that received their personal data or personal data from the controller, rather than receiving only generalized categories of recipients. This requirement can create operational challenges because controllers need reliable records of downstream disclosures. Organizations subject to the OCPA should therefore maintain data inventories and sharing records detailed enough to respond accurately. Oregon also grants rights involving access, correction, deletion, data copies, and opt-outs from certain processing activities.
Question 147. What Oregon privacy rule became effective on January 1, 2026 concerning precise geolocation?
- Businesses may sell precise geolocation without restrictions
- Only children receive protection for precise geolocation
- Consumers must pay to prevent location-data sales
- The sale of precise geolocation data of Oregon consumers is prohibited**
Correct Answer: 2. The sale of precise geolocation data of Oregon consumers is prohibited
Explanation:
As of January 1, 2026, Oregon law prohibits the sale of precise geolocation data of Oregon consumers. Oregon describes precise geolocation using a radius of 1,750 feet and applies the protection to past as well as present location data. The prohibition applies to consumers generally rather than only minors. Precise location is considered particularly sensitive because it can reveal where people live, work, worship, obtain health care, or engage in private activities. Organizations operating location-based products in Oregon should therefore distinguish ordinary location functionality from prohibited sale of precise geolocation information.
Question 148. Beginning January 1, 2026, what must qualifying Oregon controllers do with recognized universal opt-out signals?
- Ignore them unless the consumer also sends a certified letter
- Treat them only as requests to correct data
- Honor qualifying signals as opt-out requests for covered sale or targeted-advertising processing
- Convert them into marketing consent
Correct Answer: 4. Honor qualifying signals as opt-out requests for covered sale or targeted-advertising processing
Explanation:
Beginning January 1, 2026, covered Oregon businesses and nonprofits must recognize qualifying universal opt-out mechanisms. These signals allow consumers to communicate a privacy preference through technology such as a browser rather than manually visiting each organization’s privacy interface. Global Privacy Control is one example identified by Oregon guidance. The signal can communicate an opt-out from sale or targeted advertising where the statute applies. Oregon still requires controllers to provide clear mechanisms on their own websites as well. Universal opt-out recognition is part of a broader movement toward machine-readable consumer privacy choices.
Question 149. When did the Oregon Consumer Privacy Act generally begin applying to qualifying nonprofit entities?
- July 1, 2025
- January 1, 2023
- July 1, 2030
- Nonprofits are permanently exempt from the OCPA
Correct Answer: 2. July 1, 2025
Explanation:
The OCPA initially applied to qualifying for-profit entities beginning July 1, 2024. Oregon extended coverage to qualifying nonprofit entities beginning July 1, 2025. This makes Oregon notable because several comprehensive state privacy statutes contain broad nonprofit exemptions. Applicability still depends on statutory thresholds and specific exemptions, so nonprofit status alone does not resolve the analysis. Privacy professionals should examine the organization’s activities, volume of Oregon consumer data, revenue characteristics where relevant, and any entity- or data-specific exemptions before determining whether OCPA requirements apply.
Question 150. As of January 1, 2026, what restriction applies under Oregon law to consumers under age 16?
- Their data must always be deleted within 24 hours
- They may never use social media
- Their data may be freely sold if the business posts notice
- Businesses may not sell their personal data or use it for targeted advertising or specified profiling as prohibited by the statute**
Correct Answer: 4. Businesses may not sell their personal data or use it for targeted advertising or specified profiling as prohibited by the statute
Explanation:
Oregon strengthened protections for children and teenagers effective January 1, 2026. Businesses may not sell the personal data of consumers known to be under 16 or use their information for targeted advertising or specified profiling in violation of the statute. For children under 13, parental or legal guardian consent is also required before covered collection or processing, and their data is treated as sensitive. These rules demonstrate how state privacy protections can extend beyond COPPA’s traditional under-13 scope. Privacy programs serving teenagers should therefore analyze state law in addition to federal COPPA requirements.
Question 151. Under the FTC’s 2025 COPPA Rule amendments, what additional consent is required for covered disclosure of children’s personal information to third parties for targeted advertising?
- A separate verifiable parental consent for that third-party disclosure
- Only the child’s click on an advertisement
- Consent from the advertising network alone
- No consent if the operator already collected the information lawfully
Correct Answer: 1. A separate verifiable parental consent for that third-party disclosure
Explanation:
The FTC’s 2025 amendments to the COPPA Rule strengthened protections concerning monetization and advertising. Covered operators must obtain separate verifiable parental consent before disclosing a child’s personal information to third parties for targeted advertising or other covered purposes. This separates consent to collect information needed for a service from consent to disclose that information externally for advertising-related uses. The amendment reflects the FTC’s concern that parents should not have to accept third-party commercial disclosure merely because their child uses an online service. Covered operators therefore need consent flows capable of distinguishing different processing purposes.
Question 152. What retention principle was added or reinforced by the FTC’s 2025 COPPA Rule amendments?
- Children’s personal information should be kept permanently for future analytics
- Children’s personal information may be retained only as long as reasonably necessary for the specific purpose for which it was collected
- All children’s information must be deleted after exactly 24 hours
- Retention is entirely unregulated once parental consent is obtained
Correct Answer: 3. Children’s personal information may be retained only as long as reasonably necessary for the specific purpose for which it was collected
Explanation:
The amended COPPA Rule limits retention of children’s personal information to the period reasonably necessary to fulfill the specific purpose for which the information was collected. The FTC expressly rejected indefinite retention merely because data might prove useful later. This approach links data lifecycle to purpose and reflects data-minimization principles increasingly visible across privacy regulation. Operators should therefore define retention periods, document legitimate purposes, and delete information when those purposes no longer justify retention. Parental consent to collection does not function as permission to retain children’s data forever.
Question 153. Which category was expressly added to COPPA’s definition of personal information by the 2025 amendments?
- Corporate revenue figures
- Product inventory numbers
- Anonymous aggregate statistics
- Biometric identifiers**
Correct Answer: 4. Biometric identifiers
Explanation:
The FTC’s 2025 COPPA amendments expanded the Rule’s definition of personal information to expressly include biometric identifiers, along with government-issued identifiers. Biometric identifiers can include information used to recognize or distinguish individuals based on physical or biological characteristics. The change reflects the increasing use of technologies such as facial, voice, fingerprint, and other biometric systems in children’s digital services. Operators need to consider whether these technologies collect personal information under COPPA and whether notice, consent, security, retention, and deletion obligations apply. The amendment modernizes the Rule to address technologies that were far less common when COPPA was originally adopted.
Question 154. What transparency obligation did the 2025 COPPA amendments add for FTC-approved Safe Harbor programs?
- They must disclose children’s individual browsing histories
- They must publicly disclose membership lists and provide additional reporting to the FTC
- They must publish every parent’s identity
- They must stop operating entirely
Correct Answer: 2. They must publicly disclose membership lists and provide additional reporting to the FTC
Explanation:
COPPA Safe Harbor programs are FTC-approved self-regulatory programs that implement protections consistent with the COPPA Rule. The 2025 amendments increased transparency and accountability by requiring these programs to publicly disclose membership lists and submit additional information to the FTC. Safe Harbor participation does not mean companies are exempt from protecting children’s personal information; rather, qualifying participants follow an approved set of guidelines. Enhanced transparency helps regulators, parents, and the public better understand which organizations participate and how Safe Harbor programs are administered.
Question 155. What does the FTC’s 2026 COPPA age-verification policy statement say operators should do with personal information collected solely to determine a user’s age?
- Use it freely for advertising once age is confirmed
- Sell it to identity-verification companies
- Retain it indefinitely for future product development
- Use it only for age verification and delete it promptly when no longer necessary for that purpose**
Correct Answer: 3. Use it only for age verification and delete it promptly when no longer necessary for that purpose
Explanation:
In February 2026, the FTC issued a COPPA policy statement intended to encourage privacy-protective age-verification technologies. Among its stated expectations, operators relying on the policy should not use or disclose information collected for age verification for unrelated purposes and should not retain it longer than necessary. The FTC also emphasized clear notice, reasonable security, and due diligence concerning third parties providing age-verification technology. This approach recognizes the privacy paradox of age assurance: collecting additional identity information to protect children can itself create new risks unless the data is tightly limited and promptly deleted.
Question 156. Which category of information is expressly excluded from the TDPSA’s ordinary consumer-data framework according to Texas guidance?
- Employment-related information covered by the statute’s exemptions
- Every online purchase made by a Texas resident
- All precise geolocation information
- Any information collected through a mobile application
Correct Answer: 1. Employment-related information covered by the statute’s exemptions
Explanation:
Texas guidance explains that the TDPSA contains both entity-level and data-level exemptions. Among the exempt categories is certain employment-related personal information. This means Texas does not necessarily give individuals acting in employment contexts the same rights they receive when acting as ordinary consumers. The distinction is similar to several other state comprehensive privacy laws and differs from California’s broader CCPA treatment of employees and job applicants. National employers should therefore avoid assuming that comprehensive privacy statutes define “consumer” identically across jurisdictions. The role in which the individual interacts with the organization can materially affect statutory coverage.
Question 157. How often must a Texas controller generally provide a consumer-rights response free of charge under the TDPSA before special circumstances such as excessive requests are considered?
- Once during the consumer’s lifetime
- Up to twice annually per consumer
- Once every five years
- Every request may automatically be charged a fee
Correct Answer: 2. Up to twice annually per consumer
Explanation:
Texas guidance states that a controller must generally respond to consumer requests free of charge up to twice each year per consumer. A reasonable administrative charge may be possible for requests that are unfounded, excessive, or repetitive. This differs from some other state laws that expressly guarantee fewer free requests in a 12-month period. National privacy-rights programs should therefore track request history and applicable state requirements before imposing a fee. An organization should never charge simply because responding to a valid privacy request requires ordinary compliance work.
Question 158. Under the OCPA, what kind of profiling may Oregon consumers opt out of?
- Any calculation performed by a spreadsheet
- Automated processing used to evaluate or predict characteristics for decisions producing legal or similarly significant effects
- Only advertising based on a single website visit
- Every internal fraud-detection activity automatically
Correct Answer: 1. Automated processing used to evaluate or predict characteristics for decisions producing legal or similarly significant effects
Explanation:
Oregon consumers can opt out of specified profiling involving automated processing that evaluates, analyzes, or predicts characteristics such as economic circumstances, health, preferences, behavior, location, or movements when used to support consequential decisions. Oregon guidance identifies examples involving financial services, housing, insurance, education, criminal justice, employment opportunities, health care, and access to essential goods or services. This right is narrower than an ability to prohibit every automated calculation. Privacy professionals should determine whether the profiling contributes to a decision with legally or similarly significant effects before applying the statutory opt-out framework.
Question 159. What must a Texas controller generally provide after denying a consumer’s appeal of an earlier rights-request decision?
- A free product or service
- A copy of every internal legal memorandum
- The personal telephone number of the company’s CEO
- Information explaining how the consumer can submit a complaint to the Texas Attorney General**
Correct Answer: 4. Information explaining how the consumer can submit a complaint to the Texas Attorney General
Explanation:
The TDPSA requires controllers to maintain an appeals process for consumers whose rights requests are denied. If the controller denies the appeal, it must provide information explaining how the consumer can submit a complaint to the Texas Attorney General. This creates an escalation path from internal request handling to the regulator with enforcement authority. Organizations should therefore document appeal outcomes carefully and ensure denial notices contain the required regulator information. A mature consumer-rights program should also use appeals as feedback: repeated reversals may reveal flaws in authentication, exception analysis, or request-processing procedures.
Question 160. A nationwide children’s application serves users in Texas and Oregon and shares children’s data with advertising partners. What is the BEST privacy-compliance approach in 2026?
- Follow only COPPA because federal law automatically eliminates state privacy requirements
- Apply only Oregon law because it is newer
- Map the user’s age, state, data categories, advertising disclosures, consent requirements, and applicable federal and state obligations before processing
- Rely on a general terms-of-service acceptance for all children’s data practices
Correct Answer: 3. Map the user’s age, state, data categories, advertising disclosures, consent requirements, and applicable federal and state obligations before processing
Explanation:
Children’s privacy compliance can involve overlapping federal and state requirements. COPPA governs covered online collection from children under 13 and now includes strengthened requirements for third-party advertising disclosures, retention, and biometric information. Oregon additionally imposes protections affecting children and teens, including restrictions on sale, targeted advertising, and profiling for consumers under 16 as of January 1, 2026. Texas also regulates sensitive and known-child data and requires consent in covered circumstances. A national application should therefore map age, jurisdiction, purpose, disclosures, and consent instead of assuming that one law universally resolves every requirement.