View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 181. What is a major requirement of New York’s SHIELD Act for businesses that maintain private information?
- They must make private information publicly searchable
- They must develop, implement, and maintain reasonable safeguards for the security, confidentiality, and integrity of private information
- They must delete all private information after 30 days
- They must obtain state approval before collecting any personal information
Correct Answer: 2. They must develop, implement, and maintain reasonable safeguards for the security, confidentiality, and integrity of private information
Explanation:
New York’s SHIELD Act strengthened the state’s information-security requirements by requiring persons and businesses that maintain private information to use reasonable safeguards. The statute identifies administrative, technical, and physical measures that can form part of an appropriate security program. Examples include designating personnel responsible for security, assessing foreseeable risks, training employees, selecting capable service providers, monitoring systems, protecting information during storage and disposal, and adjusting safeguards as circumstances change. The requirement is risk-based rather than a mandate to use one identical security architecture in every organization.
Question 182. How did New York’s SHIELD Act broaden the concept of a security breach?
- It limited breaches to theft of paper files
- It eliminated breach notification entirely
- It applies only when financial loss has already occurred
- It expanded breach coverage to include certain unauthorized access to computerized private information, not merely unauthorized acquisition
Correct Answer: 4. It expanded breach coverage to include certain unauthorized access to computerized private information, not merely unauthorized acquisition
Explanation:
Before the SHIELD Act amendments, New York’s breach law focused on unauthorized acquisition of computerized data containing private information. The SHIELD Act broadened the breach concept to include unauthorized access that compromises the confidentiality, security, or integrity of private information. This matters because an intruder may view or access sensitive information without clearly downloading or removing it. Organizations investigating incidents therefore need to consider evidence of unauthorized access rather than asking only whether files were conclusively copied. The change reflects the reality that exposure itself can create meaningful privacy and identity-theft risks.
Question 183. Which category was added to New York’s definition of private information by the SHIELD Act?
- Biometric information and certain online account credentials
- A consumer’s favorite color
- Publicly available weather information
- A company’s general product catalog
Correct Answer: 1. Biometric information and certain online account credentials
Explanation:
The SHIELD Act expanded New York’s definition of private information beyond traditional identifiers such as Social Security numbers, driver’s license numbers, and financial account information. The expanded definition includes biometric information and certain combinations of usernames or email addresses with passwords or security information that permit access to online accounts. These additions recognize that modern identity theft and account compromise are not limited to payment-card or government-identifier theft. Privacy and security teams should therefore include authentication credentials and biometric data in incident-response inventories rather than limiting breach analysis to older categories of financial identity information.
Question 184. Which categories of safeguards does the New York SHIELD Act identify as part of a reasonable security program?
- Legal, financial, and marketing safeguards
- Federal, state, and international safeguards
- Administrative, technical, and physical safeguards
- Advertising, sales, and customer-service safeguards
Correct Answer: 3. Administrative, technical, and physical safeguards
Explanation:
New York’s SHIELD Act describes reasonable safeguards in three broad categories: administrative, technical, and physical. Administrative measures include activities such as risk assessment, employee training, security-program oversight, and service-provider management. Technical measures include evaluating risks in networks and software, detecting attacks, and testing controls. Physical measures include protecting information during storage, transportation, destruction, and disposal and responding to physical intrusions. Together, these categories show that a security program cannot rely only on technology. Governance, people, contracts, physical security, and lifecycle management all contribute to protecting private information.
Question 185. Under the New York SHIELD Act, what must a business generally do if it determines that an inadvertent exposure is unlikely to result in misuse, financial harm, or applicable emotional harm and therefore does not notify consumers?
- Document the determination in writing and retain it for at least five years
- Delete all evidence of the incident
- Notify every U.S. attorney general
- Publish the determination in a newspaper
Correct Answer: 1. Document the determination in writing and retain it for at least five years
Explanation:
New York allows an exception to consumer breach notification in certain circumstances involving inadvertent disclosure by persons authorized to access the information when the organization reasonably determines the exposure is unlikely to result in misuse, financial harm, or specified emotional harm involving online credentials. The determination must be documented in writing and retained for at least five years. If more than 500 New York residents are affected, the written determination must also be provided to the Attorney General within the applicable timeframe. This requirement makes the decision not to notify an auditable compliance determination rather than an undocumented judgment.
Question 186. To whom does Massachusetts regulation 201 CMR 17.00 generally apply?
- Only Massachusetts state agencies
- Only banks headquartered in Massachusetts
- Only businesses with more than 500 employees
- Persons that own or license personal information about Massachusetts residents
Correct Answer: 4. Persons that own or license personal information about Massachusetts residents
Explanation:
Massachusetts regulation 201 CMR 17.00 establishes information-security standards for persons that own or license personal information about Massachusetts residents. Its scope is not limited to organizations physically headquartered in Massachusetts or to a single industry. The regulation is designed to protect personal information in both paper and electronic records against anticipated threats, unauthorized access, and uses that may create substantial harm or inconvenience. Businesses operating nationally should therefore consider the residence of individuals whose information they hold, not merely where the company maintains offices, when evaluating whether Massachusetts security requirements apply.
Question 187. What foundational security document does Massachusetts 201 CMR 17.00 require covered organizations to maintain?
- A public consumer advertising plan
- A comprehensive written information security program
- A federal privacy license
- A public employee directory
Correct Answer: 2. A comprehensive written information security program
Explanation:
Covered organizations must develop, implement, and maintain a comprehensive written information security program, commonly called a WISP. The program must contain administrative, technical, and physical safeguards appropriate to factors such as the organization’s size, resources, amount of stored data, and need for security and confidentiality. Required program elements include risk assessment, employee training, security policies, service-provider oversight, access controls, monitoring, disciplinary measures, and periodic review. Massachusetts therefore goes beyond a vague instruction to “use reasonable security” by specifying a structured written program through which organizations manage information-security risks.
Question 188. Under Massachusetts 201 CMR 17.00, what should an organization generally do with personal information transmitted across public networks, to the extent technically feasible?
- Print it before transmission
- Post it to a public website
- Encrypt it
- Convert it into marketing data
Correct Answer: 3. Encrypt it
Explanation:
Massachusetts’ computer-system security requirements generally call for encryption of personal information transmitted across public networks and information transmitted wirelessly, to the extent technically feasible. The regulation also calls for encryption of personal information stored on laptops and other portable devices, again within the regulation’s feasibility framework. Encryption reduces the risk that intercepted or stolen information can be readily used by unauthorized persons. Encryption is only one element of the Massachusetts framework, which also includes secure authentication, access controls, monitoring, firewall protection, malware protection, security patches, and employee training.
Question 189. What service-provider obligation is included in Massachusetts 201 CMR 17.00?
- Organizations should select capable service providers and contractually require appropriate safeguards
- Businesses may never outsource processing
- Service providers are automatically exempt from all security requirements
- Only federal agencies may evaluate service-provider security
Correct Answer: 4. Organizations should select capable service providers and contractually require appropriate safeguards
Explanation:
Massachusetts requires covered organizations to oversee third-party service providers that handle protected personal information. The organization must take reasonable steps to select and retain providers capable of maintaining appropriate safeguards and must require appropriate security measures by contract. This reflects a broader privacy principle that outsourcing data processing does not eliminate the need for vendor oversight. Organizations should perform appropriate due diligence, establish contractual requirements, and monitor relevant vendor risks rather than assuming a service provider’s possession of information transfers all security responsibility away from the original business.
Question 190. How often should a Massachusetts organization’s written information security program generally be reviewed?
- At least annually or when a material change in business practices may affect information security
- Only after a data breach
- Once every ten years
- Only when a regulator specifically requests review
Correct Answer: 1. At least annually or when a material change in business practices may affect information security
Explanation:
Massachusetts requires organizations to review the scope of their security measures at least annually and whenever a material change in business practices may reasonably affect the security or integrity of personal information. This requirement recognizes that security programs cannot remain static while technology, business processes, vendors, threats, and data holdings change. The regulation also requires organizations to document responsive actions following security incidents and conduct post-incident reviews to determine whether business practices should change. A WISP should therefore operate as a living governance program rather than a document created once and placed on a shelf.
Question 191. When did the Indiana Consumer Data Protection Act (CDPA) become effective?
- January 1, 2023
- July 1, 2024
- January 1, 2026
- January 1, 2030
Correct Answer: 3. January 1, 2026
Explanation:
Indiana’s Consumer Data Protection Act became effective on January 1, 2026. The law grants Indiana residents rights concerning personal data and imposes obligations on covered controllers and processors. Indiana’s Attorney General is responsible for enforcement. Because state comprehensive privacy laws have taken effect on different dates, national organizations need reliable jurisdictional tracking rather than assuming that every state’s obligations began simultaneously. As each law becomes effective, businesses must update privacy notices, request-handling procedures, vendor contracts, opt-out mechanisms, and other operational controls to reflect the state’s requirements.
Question 192. Which right is granted to Indiana consumers under the Indiana CDPA?
- The right to access, correct, delete, and obtain qualifying personal data, subject to statutory requirements
- The right to require all businesses to erase tax records
- The right to prevent every form of fraud monitoring
- The right to demand ownership of corporate databases
Correct Answer: 1. The right to access, correct, delete, and obtain qualifying personal data, subject to statutory requirements
Explanation:
Indiana’s CDPA gives qualifying consumers several rights over personal data. These include confirming whether a controller processes their personal data, accessing it, correcting inaccuracies in information they previously provided, requesting deletion, receiving qualifying data in a usable portable format, and opting out of processing for targeted advertising, sale, and profiling. Consumers also have an appeal right when a controller denies a request. These rights are subject to statutory definitions and exceptions, so they should not be interpreted as an unrestricted ability to erase every business or legally required record.
Question 193. How frequently does Indiana’s CDPA expressly provide a qualifying consumer a free copy or representative summary of personal data previously provided to a controller?
- Once a month
- Once every five years
- Only after filing a lawsuit
- Once per year
Correct Answer: 4. Once per year
Explanation:
Indiana’s Consumer Data Bill of Rights states that a consumer may obtain, once a year free of charge, a copy or representative summary of personal data the consumer previously provided to a controller. The state’s broader framework also provides portability-related rights so qualifying information can be transferred without undue hindrance. Request frequency matters operationally because privacy programs must track whether the consumer has already received the applicable free response within the relevant period. Organizations should nevertheless carefully review statutory rules before imposing charges or refusing additional requests, particularly when another applicable privacy law provides different requirements.
Question 194. A controller denies an Indiana consumer’s request to exercise a CDPA right. What additional consumer right applies?
- Immediate statutory damages from the controller
- The right to appeal the controller’s denial
- Automatic access to the controller’s legal advice
- Automatic suspension of the controller’s business license
Correct Answer: 2. The right to appeal the controller’s denial
Explanation:
Indiana consumers have the right to appeal a controller’s denial of a request to exercise rights under the CDPA. Appeal procedures provide an additional accountability mechanism when consumers believe the initial response was incorrect. Organizations subject to Indiana’s law should therefore design request-management workflows that include not only intake, authentication, search, exception review, and response, but also escalation and appeal handling. A privacy program that closes a case immediately after a denial without preserving a mechanism for appeal risks failing to implement the full consumer-rights process contemplated by the statute.
Question 195. When did the Tennessee Information Protection Act (TIPA) become effective?
- January 1, 2024
- January 1, 2026
- July 1, 2025
- July 1, 2030
Correct Answer: 2. July 1, 2025
Explanation:
The Tennessee Information Protection Act became effective on July 1, 2025. It establishes privacy rights for Tennessee consumers and obligations for qualifying controllers and processors. These include rights involving access, correction, deletion, portability, and opt-outs from certain sales, targeted advertising, and profiling. The law also requires covered entities to provide privacy notices and establish procedures for rights requests and appeals. National organizations should track Tennessee alongside other state comprehensive privacy statutes because differing effective dates, applicability thresholds, definitions, and enforcement provisions can affect when specific compliance controls need to become operational.
Question 196. Which business would MOST clearly satisfy one of Tennessee’s principal TIPA applicability pathways, assuming it does business in Tennessee and has annual revenue above $25 million?
- A company processing 500 Tennessee consumers’ data
- A company processing no personal data
- A company processing 175,000 Tennessee consumers’ personal information during a calendar year
- A company keeping only anonymous weather data
Correct Answer: 3. A company processing 175,000 Tennessee consumers’ personal information during a calendar year
Explanation:
TIPA generally applies when a business operates in Tennessee or targets Tennessee residents, earns more than $25 million in annual revenue, and meets one of specified data-processing thresholds. One pathway involves controlling or processing personal information of at least 175,000 Tennessee consumers during a calendar year. Another covers at least 25,000 consumers when the business also derives more than 50% of gross annual revenue from selling personal information. Organizations should evaluate all elements of applicability rather than looking only at company revenue or consumer counts in isolation.
Question 197. How quickly must an entity subject to TIPA generally respond to a consumer request to exercise privacy rights?
- 45 days after receipt of the request
- Seven days
- Six months
- One year
Correct Answer: 4. 45 days after receipt of the request
Explanation:
Tennessee’s Attorney General explains that an entity subject to TIPA must respond to a consumer’s request to exercise statutory privacy rights within 45 days of receiving the request. If the request is denied, the entity must explain why and provide a process through which the consumer can appeal the decision. This means covered businesses need a formal request-handling workflow capable of identifying Tennessee consumers, authenticating requests, locating responsive data, reviewing exceptions, and communicating within the required deadline. Delaying rights requests until a complaint is filed would not satisfy the law’s proactive operational requirements.
Question 198. What processing may a Tennessee consumer generally opt out of under TIPA?
- Every use of data needed to fulfill a purchase
- Sale of personal information, targeted advertising, and specified profiling
- All security monitoring
- Every legally required recordkeeping activity
Correct Answer: 2. Sale of personal information, targeted advertising, and specified profiling
Explanation:
TIPA gives Tennessee consumers the right to opt out of processing for three important categories: sale of personal information, targeted advertising, and profiling for covered purposes. Targeted advertising generally involves advertisements selected based on information derived from the consumer’s activities over time across websites or online applications. Profiling involves automated processing used to evaluate or predict specified personal characteristics. These opt-outs are not universal prohibitions on every use of personal information. Processing needed for requested services, security, legal compliance, and other statutory purposes may be treated differently under the law.
Question 199. Under TIPA, what is the difference between a controller and a processor?
- A controller determines why and how personal information is processed, while a processor handles it according to the controller’s instructions
- A processor always owns all data it receives
- A controller must be a government agency
- There is no legal difference
Correct Answer: 3. A controller determines why and how personal information is processed, while a processor handles it according to the controller’s instructions
Explanation:
TIPA distinguishes controllers from processors based on their roles in determining processing. The controller determines the purposes and means of processing personal information—essentially deciding why the processing occurs and how it should be carried out. A processor handles the information according to the controller’s instructions. This role-based structure helps allocate privacy obligations between businesses and their service providers. Organizations should examine actual decision-making rather than relying only on contract labels, because a vendor that independently determines purposes or uses personal information for its own objectives may no longer be acting solely as a processor.
Question 200. A national organization holds New York residents’ online credentials, Massachusetts residents’ identifying information, and consumer data covered by Indiana and Tennessee privacy laws. What is the BEST compliance strategy?
- Map the data and jurisdictions, apply applicable security requirements and state consumer-rights obligations, and maintain coordinated security, vendor, and rights-request processes
- Follow only the newest state privacy statute
- Apply Massachusetts security requirements only because security law replaces privacy law
- Wait for regulators to identify which controls should be implemented
Correct Answer: 1. Map the data and jurisdictions, apply applicable security requirements and state consumer-rights obligations, and maintain coordinated security, vendor, and rights-request processes
Explanation:
An organization can simultaneously be subject to different kinds of state privacy obligations. New York’s SHIELD Act focuses substantially on breach and reasonable security duties, while Massachusetts 201 CMR 17.00 imposes detailed information-security program requirements. Indiana and Tennessee add comprehensive consumer privacy rights and controller obligations. One statute does not automatically replace the others simply because it is broader or newer. A mature program should map residents, data categories, vendors, security controls, processing purposes, consumer rights, and applicable deadlines, then build common operational controls while preserving state-specific requirements where laws differ.