IAPP CIPP-US Practice Test Questions and Exam Dumps Part12 Q221-240

View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.


Question 221. What is a PRIMARY purpose of Washington’s My Health My Data Act?

  1. To replace HIPAA for hospitals and health plans
  2. To protect consumer health data that may fall outside the traditional scope of HIPAA
  3. To regulate only paper medical records maintained by physicians
  4. To create a federal health-record database

Correct Answer: 2. To protect consumer health data that may fall outside the traditional scope of HIPAA

Explanation:

Washington’s My Health My Data Act was designed specifically to protect consumer health information that can fall outside HIPAA’s traditional regulated-health-care framework. This can include information collected by health applications, websites, wearable technologies, and other entities that are not necessarily HIPAA covered entities or business associates. The law places requirements on collection, sharing, sale, deletion, privacy notices, and other handling of consumer health data. This makes it an important example of state legislation filling gaps that can exist when highly sensitive health-related information is collected outside conventional health care institutions.

Question 222. Under Washington’s My Health My Data Act, what must a regulated entity generally obtain before collecting or sharing consumer health data beyond applicable exceptions?

  1. Approval from HHS
  2. A court order
  3. Permission from the consumer’s physician
  4. The consumer’s consent

Correct Answer: 4. The consumer’s consent

Explanation:

Washington’s My Health My Data Act generally requires regulated entities to obtain consumer consent before collecting or sharing consumer health data, subject to statutory limitations and exceptions. The law is intended to give individuals meaningful control over sensitive information such as data revealing physical or mental health status and health-related decisions. Consent for collection and sharing is distinct from the more formal authorization required for selling consumer health data. Organizations should therefore identify which activity they are performing—collection, sharing, or sale—and use the correct legal mechanism rather than assuming one general privacy-policy disclosure satisfies every requirement.

Question 223. What does Washington’s My Health My Data Act generally require before consumer health data may be sold?

  1. A valid authorization from the consumer
  2. Only a general website privacy notice
  3. Approval from the FTC
  4. No special requirement if the purchaser promises confidentiality

Correct Answer: 1. A valid authorization from the consumer

Explanation:

Washington law imposes a particularly strong requirement on the sale of consumer health data. A person generally may not sell or offer to sell consumer health data without first obtaining a valid authorization from the consumer. This is stricter than merely placing the proposed sale in a general privacy notice. The Act also requires both the seller and purchaser to retain a copy of the valid authorization for the specified retention period. Privacy professionals should therefore distinguish ordinary consent for collection or sharing from the separate authorization requirements attached to selling consumer health information.

Question 224. A Washington consumer validly requests deletion of consumer health data. What is significant about the deletion right under the My Health My Data Act?

  1. It applies only to information less than one year old
  2. It applies only to information stored on the consumer’s device
  3. The deletion requirement extends to covered data in the regulated entity’s network, including archived or backup systems
  4. It applies only if the company has sold the information

Correct Answer: 3. The deletion requirement extends to covered data in the regulated entity’s network, including archived or backup systems

Explanation:

Washington’s My Health My Data Act gives consumers a meaningful deletion right extending beyond merely removing information from an active customer-facing database. The Attorney General’s guidance explains that consumers can request deletion of consumer health data from a regulated entity’s or small business’s network, including archived or backup systems. This makes deletion planning an architectural issue rather than simply a front-end account function. Organizations subject to the Act should know where consumer health data is stored, how copies propagate through systems, and how they can execute qualifying deletion requests throughout the applicable data environment.

Question 225. Which activity is specifically restricted by Washington’s My Health My Data Act?

  1. Geofencing around health care facilities for prohibited health-data-related purposes
  2. Providing consumers with maps to hospitals
  3. Allowing users to manually enter a ZIP code
  4. Publishing the address of a public pharmacy

Correct Answer: 1. Geofencing around health care facilities for prohibited health-data-related purposes

Explanation:

Washington’s My Health My Data Act specifically restricts geofencing around health care facilities for certain purposes, including identifying or tracking consumers seeking health care, collecting consumer health data, or sending messages or advertisements related to health data in prohibited circumstances. This provision reflects concern that precise location technology can expose deeply private health choices without requiring access to a traditional medical record. Privacy professionals should therefore recognize that health privacy can arise from location and behavioral information, not just diagnoses or clinical files. A geofence can reveal highly sensitive health activity even where HIPAA does not apply.

Question 226. Which statement BEST describes enforcement of Washington’s My Health My Data Act?

  1. Only HHS may enforce the Act
  2. The Washington Attorney General may enforce it, and the law also allows qualifying private civil actions
  3. Only the FTC may bring a case
  4. The Act contains no enforcement mechanism

Correct Answer: 2. The Washington Attorney General may enforce it, and the law also allows qualifying private civil actions

Explanation:

Washington’s My Health My Data Act is notable because it includes both governmental and private enforcement pathways. The Washington Attorney General can investigate and litigate violations, and the Act also provides a private right of action through Washington’s consumer-protection framework. This makes the law particularly important from a litigation-risk perspective compared with comprehensive privacy statutes that reserve enforcement exclusively to state attorneys general. Organizations handling consumer health data should therefore treat compliance as both a regulatory and civil-liability issue and should maintain documentation supporting consent, authorization, deletion, notice, and other required practices.

Question 227. How long must the seller and purchaser generally retain a valid authorization for sale of consumer health data under Washington’s My Health My Data Act?

  1. 30 days
  2. One year
  3. Three years
  4. Six years

Correct Answer: 4. Six years

Explanation:

Washington Attorney General guidance states that both the seller and purchaser of consumer health data must retain a copy of the consumer’s valid sale authorization for six years. This recordkeeping requirement allows organizations to demonstrate that a transaction involving sensitive health information was supported by legally sufficient authorization. Privacy compliance therefore requires more than simply displaying a consent interface at the moment of sale. Businesses must preserve evidence of authorization over time and ensure that their retention processes can retrieve that documentation if a regulator, consumer, or court later questions the transaction.

Question 228. What notice-related obligation does Washington’s My Health My Data Act impose on regulated entities?

  1. Publish only a generic company privacy policy
  2. Provide no notice if consumer consent is obtained
  3. Maintain a distinct consumer health data privacy policy describing relevant health-data practices
  4. Send every consumer a paper privacy notice each month

Correct Answer: 3. Maintain a distinct consumer health data privacy policy describing relevant health-data practices

Explanation:

Washington’s law requires entities covered by My Health My Data to provide a distinct consumer health data privacy policy. The policy is intended to explain how consumer health information is collected, used, shared, and otherwise processed and to provide transparency specific to this particularly sensitive category of information. A generic corporate privacy policy may not adequately satisfy the statute if it does not address the required health-data practices. Organizations should ensure that disclosures align with actual operations because inconsistencies between published notices and real practices can create both state-law and broader consumer-protection risk.

Question 229. When did the Delaware Personal Data Privacy Act (DPDPA) take effect?

  1. July 1, 2026
  2. January 1, 2025
  3. January 1, 2023
  4. January 1, 2030

Correct Answer: 2. January 1, 2025

Explanation:

The Delaware Personal Data Privacy Act took effect on January 1, 2025. The law provides Delaware residents with rights concerning access, correction, deletion, portability, opt-outs, and other handling of personal data. It also imposes controller obligations involving transparency, data minimization, security, sensitive-data consent, assessments for heightened-risk processing, and nondiscrimination. Because comprehensive state privacy laws became effective on different dates, national organizations need a reliable implementation calendar. A privacy program should not assume that all states followed California or became effective simultaneously.

Question 230. What must a Delaware controller generally obtain before processing a consumer’s sensitive personal data?

  1. The consumer’s consent
  2. Only an internal privacy assessment
  3. Permission from the consumer’s employer
  4. Approval from the Delaware legislature

Correct Answer: 1. The consumer’s consent

Explanation:

Delaware generally requires a controller to obtain consumer consent before processing sensitive data. Sensitive data includes categories such as racial or ethnic origin, religious beliefs, health conditions or diagnoses, sexual activity or orientation, citizenship or immigration status, genetic or biometric data used for identification, personal data of a child, and precise geolocation. Consent must therefore be built into relevant processing before the sensitive-data activity occurs. The Delaware framework also requires controllers to provide consumers with a mechanism to revoke consent and to stop the relevant processing within the period specified by the statute.

Question 231. How broad is the Delaware consumer right to deletion under the DPDPA?

  1. It applies only to data collected directly from the consumer
  2. It applies only to financial information
  3. It can include personal data provided by or obtained about the consumer, including data collected through third parties
  4. It applies only after an account has been closed

Correct Answer: 4. It can include personal data provided by or obtained about the consumer, including data collected through third parties

Explanation:

Delaware’s deletion right is comparatively broad. The DPDPA allows consumers to request deletion of personal data provided by or obtained about them, meaning the right is not limited solely to information the consumer directly typed into an organization’s website. Delaware’s consumer guidance specifically notes that deletion can extend to personal data collected through third parties. Controllers therefore need to map data provenance and cannot assume that externally sourced information is outside consumer-rights workflows. As with other privacy rights, statutory exemptions can still permit or require retention of certain information.

Question 232. Beginning January 1, 2026, what must Delaware controllers generally recognize as valid opt-out requests?

  1. Only postal letters
  2. Only telephone calls to customer service
  3. Only requests submitted while logged into an account
  4. Qualifying universal opt-out mechanisms

Correct Answer: 3. Qualifying universal opt-out mechanisms

Explanation:

Beginning January 1, 2026, the Delaware Personal Data Privacy Act requires controllers to recognize qualifying universal opt-out mechanisms as valid consumer requests. Universal opt-out signals allow consumers to express preferences across multiple websites through technology rather than repeatedly navigating individual business opt-out pages. Delaware still requires businesses to provide accessible mechanisms for consumers to exercise their rights directly. Universal opt-out recognition supplements those methods and reduces friction for consumers who wish to prevent sale or targeted-advertising processing across many services. Privacy technology implementations should therefore be capable of detecting and honoring recognized signals appropriately.

Question 233. Which statement about nonprofit organizations under the Delaware Personal Data Privacy Act is correct?

  1. The Act can apply to qualifying nonprofit organizations as well as for-profit businesses
  2. Every nonprofit is automatically exempt
  3. Only religious nonprofits are covered
  4. Nonprofits are regulated solely by HIPAA

Correct Answer: 1. The Act can apply to qualifying nonprofit organizations as well as for-profit businesses

Explanation:

Delaware’s privacy law is notable because it can apply to both for-profit and nonprofit organizations that meet the statutory scope requirements, rather than containing a broad exemption for nonprofit status. Delaware’s Attorney General specifically explains that both for-profit and nonprofit businesses can have obligations under the DPDPA. Entity-specific and data-specific exemptions still exist, so applicability requires a complete analysis. Privacy professionals should not assume that nonprofit status creates a universal exemption from comprehensive state privacy laws because states differ significantly on this issue.

Question 234. How long does a Delaware controller generally have to decide and respond to a consumer appeal after denying a privacy-rights request?

  1. 10 days
  2. 15 days
  3. One year
  4. No later than 60 days after receipt of the appeal

Correct Answer: 4. No later than 60 days after receipt of the appeal

Explanation:

The Delaware Personal Data Privacy Act requires controllers to establish an appeals process for consumers whose rights requests are denied. The process must be conspicuously available and similar to the ordinary rights-request mechanism. The controller generally must inform the consumer in writing of action taken or not taken on the appeal no later than 60 days after receiving it, together with an explanation. If the appeal remains denied, the controller must provide a mechanism through which the consumer can contact the Delaware Department of Justice to submit a complaint.

Question 235. When does the DPDPA require a controller to conduct a data protection assessment?

  1. Only after a data breach has occurred
  2. For processing activities presenting heightened risk, such as certain targeted advertising, sale, profiling, or sensitive-data processing
  3. Only when requested by the FTC
  4. Before collecting any publicly available information

Correct Answer: 2. For processing activities presenting heightened risk, such as certain targeted advertising, sale, profiling, or sensitive-data processing

Explanation:

Delaware requires data protection assessments before certain processing activities that present heightened risks to consumers. Delaware guidance identifies activities such as targeted advertising, sale of personal data, specified profiling, and processing of sensitive data as examples. The assessment is intended to identify privacy risks and evaluate whether safeguards and benefits justify the processing. This is a proactive accountability mechanism, not merely an incident-response exercise. Organizations should incorporate assessments into product and change-management workflows so higher-risk initiatives are reviewed before or as they are implemented, rather than waiting for consumer complaints or enforcement activity.

Question 236. Under Utah’s Government Data Privacy Act (GDPA), what must a governmental entity generally provide when it requests or collects personal data directly from an individual?

  1. A consumer credit report
  2. A HIPAA authorization
  3. A privacy notice
  4. A marketing consent form

Correct Answer: 3. A privacy notice

Explanation:

Utah’s Government Data Privacy Act requires governmental entities to provide a privacy notice when requesting or collecting personal data from individuals. The notice is designed to explain how the government entity intends to use and manage the information. Utah’s framework applies to governmental entities rather than serving as the state’s private-sector comprehensive consumer privacy law; private businesses are addressed separately by the Utah Consumer Privacy Act. This distinction is important because public-sector privacy rules can impose obligations that differ substantially from commercial privacy laws, even within the same state.

Question 237. Which information must Utah governmental entities generally disclose in a GDPA collection privacy notice?

  1. Intended uses of the data, consequences of refusing to provide it, relevant sharing or sale categories, and the record series containing the data
  2. Every employee’s salary
  3. Only the name of the software vendor storing the information
  4. The government’s complete cybersecurity architecture

Correct Answer: 1. Intended uses of the data, consequences of refusing to provide it, relevant sharing or sale categories, and the record series containing the data

Explanation:

Utah’s GDPA privacy-notice framework requires meaningful information about why the governmental entity is asking for personal data and what will happen to it. Utah guidance states that the notice must address intended purposes and uses, consequences of not providing the data, classes of persons and governmental entities with whom information is shared or to whom it is sold, and the record series in which the information is maintained. These requirements promote transparency at the point of collection and give individuals context for deciding whether and how to provide requested information.

Question 238. Which principle is expressly reflected in Utah’s Government Data Privacy Act?

  1. Governmental entities should collect every potentially useful data point
  2. Personal data should always be sold to offset public costs
  3. Governmental entities may process only the minimum amount of personal data reasonably necessary to efficiently achieve a specified purpose
  4. Personal information must be retained forever

Correct Answer: 3. Governmental entities may process only the minimum amount of personal data reasonably necessary to efficiently achieve a specified purpose

Explanation:

Utah’s GDPA expressly incorporates data minimization. Governmental entities should obtain and process only the minimum amount of personal data reasonably necessary to efficiently accomplish the specified purpose. Utah’s complaint materials demonstrate how this principle applies in practice—for example, questioning whether a website form really needs a person’s name or email address when the government can fulfill the underlying purpose without that information. This is an important privacy-by-design concept because minimizing collection reduces downstream risks involving misuse, breaches, retention, sharing, and unnecessary surveillance.

Question 239. What governance role must Utah governmental entities designate as part of implementing their privacy programs?

  1. A Chief Administrative Officer responsible for privacy-program implementation, who also appoints appropriate records officers or designated personnel
  2. A federal privacy judge
  3. A commercial data broker
  4. An outside marketing agency

Correct Answer: 4. A Chief Administrative Officer responsible for privacy-program implementation, who also appoints appropriate records officers or designated personnel

Explanation:

Utah’s governmental privacy framework requires organizational accountability. Governmental entities must designate a Chief Administrative Officer at the executive level who is responsible for implementing the entity’s privacy program and completing required privacy-program reporting. The CAO also appoints records officers or other designated employees responsible for implementing and maintaining associated privacy and records practices. This structure makes privacy ownership explicit instead of leaving responsibility dispersed informally among staff. Utah’s Office of Data Privacy provides frameworks, templates, training, and maturity tools to support governmental entities as they establish and improve these programs.

Question 240. An individual believes a Utah governmental entity has infringed the individual’s data privacy interests. What is an appropriate complaint path under the GDPA framework?

  1. File only with the FTC
  2. Submit the complaint to the governmental entity’s Chief Administrative Officer and, if unresolved, seek mediation through the Data Privacy Ombud
  3. Contact a consumer reporting agency
  4. File a HIPAA complaint with HHS regardless of the information involved

Correct Answer: 2. Submit the complaint to the governmental entity’s Chief Administrative Officer and, if unresolved, seek mediation through the Data Privacy Ombud

Explanation:

Utah’s Government Data Privacy Act provides a complaint process specifically tailored to governmental privacy practices. An individual with a concern about infringement of privacy interests can submit a complaint to the Chief Administrative Officer of the relevant governmental entity. If the CAO cannot resolve the complaint, the individual or governmental entity may ask Utah’s Data Privacy Ombud to mediate the dispute. This nonjudicial process is part of Utah’s broader effort to make governmental privacy governance accessible and accountable. Complaints involving private companies under Utah’s Consumer Privacy Act follow a different state process.