View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 301. Under GLBA Regulation P, when must a financial institution generally provide an initial privacy notice to a person who becomes its customer?
- Only after the customer requests the notice
- No later than when the customer relationship is established, subject to applicable exceptions
- Exactly 30 days after opening the account
- Only before the customer relationship ends
Correct Answer: 2. No later than when the customer relationship is established, subject to applicable exceptions
Explanation:
Regulation P generally requires a financial institution to provide a clear and conspicuous initial privacy notice to an individual who becomes a customer no later than when the customer relationship is established. The notice must accurately describe the institution’s privacy policies and practices. Different rules can apply to consumers who never establish continuing customer relationships, particularly when the institution does not disclose nonpublic personal information outside regulatory exceptions. Privacy professionals should therefore distinguish a “consumer” from a “customer” because the nature of the relationship affects which notice obligations apply and when the notice must be delivered.
Question 302. Which statement BEST describes the annual privacy notice requirement under Regulation P?
- Annual notices have been eliminated for every financial institution
- Annual notices are required once every five years
- Only former customers must receive annual notices
- Customers generally must receive an accurate privacy notice at least once every 12 months while the relationship continues, unless an exception applies**
Correct Answer: 4. Customers generally must receive an accurate privacy notice at least once every 12 months while the relationship continues, unless an exception applies
Explanation:
Regulation P generally requires covered financial institutions to provide customers with privacy notices at least annually during an ongoing customer relationship. “Annually” means at least once in any period of 12 consecutive months, although the institution can define the relevant 12-month cycle consistently. Current law contains exceptions that can relieve qualifying institutions from annual notice delivery in specified circumstances, so the obligation is not absolute for every institution. Privacy teams should understand both the default annual-notice rule and whether the institution satisfies an applicable exception before deciding to discontinue recurring notices.
Question 303. What must a GLBA opt-out notice generally provide when a financial institution intends to disclose nonpublic personal information to nonaffiliated third parties outside applicable exceptions?
- A clear explanation of the consumer’s opt-out right and a reasonable means to exercise it
- Only the financial institution’s postal address
- A requirement that consumers visit a branch in person
- A guarantee that the institution will never share information
Correct Answer: 1. A clear explanation of the consumer’s opt-out right and a reasonable means to exercise it
Explanation:
When Regulation P requires an opt-out notice, the notice must clearly and conspicuously explain that the institution discloses or reserves the right to disclose nonpublic personal information to nonaffiliated third parties, that the consumer has a right to opt out, and how the consumer can exercise that right. The institution must provide a reasonable means for opting out. The consumer must also receive a reasonable opportunity to opt out before the covered disclosure occurs. This framework is subject to important exceptions involving servicing transactions, fraud prevention, service providers, and other authorized disclosures.
Question 304. A bank previously disclosed only account-administration information to one category of nonaffiliated service providers. It now plans to disclose a new category of NPI to a new class of outside marketing companies. What should the bank generally consider under Regulation P?
- Nothing, because one privacy notice permanently covers all future practices
- Only whether the marketing company is profitable
- Providing a revised privacy notice and, where required, a new opt-out opportunity before the new disclosure
- Closing every customer account first
Correct Answer: 3. Providing a revised privacy notice and, where required, a new opt-out opportunity before the new disclosure
Explanation:
A financial institution generally may not begin materially broader disclosures of NPI to nonaffiliated third parties than those described in its existing notice unless it first satisfies Regulation P’s revised-notice requirements. These can include providing a clear revised privacy notice, providing a new opt-out notice where applicable, and giving consumers a reasonable opportunity to exercise the opt-out before disclosure. A revised notice can be required when an institution begins disclosing a new category of NPI or disclosing to a new category of nonaffiliated third party not adequately described previously.
Question 305. Which disclosure can qualify for Regulation P’s service-provider or joint-marketing exception to ordinary opt-out requirements?
- Disclosure to a nonaffiliated service provider under a contract restricting use and disclosure to the specified service purpose
- Sale of customer data to any advertiser without restrictions
- Public release of customer account balances
- Disclosure to a data broker for unrelated resale
Correct Answer: 1. Disclosure to a nonaffiliated service provider under a contract restricting use and disclosure to the specified service purpose
Explanation:
Regulation P provides an exception from ordinary opt-out requirements when a financial institution shares NPI with a nonaffiliated third party performing services on the institution’s behalf, including qualifying joint marketing. The institution must satisfy the applicable notice requirement and enter into a contractual agreement restricting the recipient’s use and disclosure of the information to carrying out the permitted purpose. This exception does not create a blanket authorization to give NPI to unrelated third parties for independent use or resale. The service relationship and contractual restrictions are important parts of the exception.
Question 306. A financial institution discloses NPI to process a payment transaction requested by the consumer. Which Regulation P concept is MOST relevant?
- The disclosure always requires a marketing opt-out
- The institution must terminate the customer relationship
- The disclosure is prohibited because the recipient is nonaffiliated
- Transaction-processing and servicing disclosures can qualify for an exception to notice and opt-out requirements**
Correct Answer: 4. Transaction-processing and servicing disclosures can qualify for an exception to notice and opt-out requirements
Explanation:
Regulation P contains exceptions permitting certain disclosures needed to effect, administer, or enforce transactions requested or authorized by consumers. Examples include processing a financial product or service, maintaining or servicing an account, or performing related transaction functions. These exceptions recognize that financial services cannot operate if consumers must separately opt out or consent every time information moves through ordinary payment or servicing infrastructure. The exception is purpose-specific, however. It should not be treated as authority to reuse transaction information for unrelated marketing or commercial activities outside the regulatory framework.
Question 307. Which Regulation P exception can permit disclosure of NPI without an ordinary opt-out when necessary to prevent fraud or unauthorized transactions?
- The annual-notice exception
- The fraud-prevention and security exception
- The affiliate-marketing rule
- The consumer-report dispute rule
Correct Answer: 2. The fraud-prevention and security exception
Explanation:
Regulation P recognizes several important exceptions to ordinary notice and opt-out requirements. Among them are disclosures necessary to protect the confidentiality or security of records, prevent actual or potential fraud and unauthorized transactions, perform required institutional risk control, or resolve consumer disputes. This allows financial institutions to share relevant information for legitimate security and fraud-prevention purposes without forcing consumers to approve each operational disclosure individually. The information should still be used within the scope of the applicable exception, and the exception should not be stretched to justify unrelated marketing or monetization practices.
Question 308. How must a Regulation P privacy or opt-out notice generally be delivered?
- Only through a social media post
- Only by certified mail
- In a manner reasonably expected to provide actual notice in writing or, with appropriate agreement, electronically
- Only by verbally reading the notice during a telephone call
Correct Answer: 3. In a manner reasonably expected to provide actual notice in writing or, with appropriate agreement, electronically
Explanation:
Regulation P requires covered notices to be delivered so the consumer can reasonably be expected to receive actual notice. Examples include hand delivery, mailing a printed copy to the consumer’s last known address, or qualifying electronic delivery where the consumer has agreed and the delivery mechanism satisfies the rule. Merely posting a privacy policy somewhere on a website without directing the consumer to it will not necessarily satisfy the delivery requirement. Privacy professionals should distinguish having a notice available from actually delivering a required notice in a legally sufficient manner.
Question 309. Under the ADA, may an employer disclose an employee’s medical information to a supervisor?
- Yes, when the supervisor needs the information to implement a reasonable accommodation or work restriction
- Yes, whenever coworkers ask why the employee has different working conditions
- Yes, for general workplace gossip
- No, disclosure is prohibited even when necessary to provide an accommodation
Correct Answer: 1. Yes, when the supervisor needs the information to implement a reasonable accommodation or work restriction
Explanation:
The ADA generally requires employers to keep applicant and employee medical information confidential, but it recognizes limited exceptions. Supervisors and managers may receive necessary information concerning an employee’s restrictions or reasonable accommodations when they need it to implement those arrangements. This does not mean they should receive the employee’s entire medical history or diagnosis when that information is unnecessary. Employers should apply a need-to-know approach and maintain medical information separately from ordinary personnel records. The exception enables accommodation administration without turning sensitive medical details into general workplace information.
Question 310. May an employer tell coworkers that another employee is receiving a reasonable accommodation because of a disability?
- Yes, whenever coworkers express curiosity
- Yes, if the accommodation changes the employee’s schedule
- Yes, because accommodation information is not medical information
- Generally no, because revealing that the person receives an ADA accommodation can disclose protected medical information**
Correct Answer: 4. Generally no, because revealing that the person receives an ADA accommodation can disclose protected medical information
Explanation:
The EEOC explains that an employer generally should not tell coworkers that an employee is receiving a reasonable accommodation because doing so effectively reveals that the employee has a disability or medical condition. An employer may need to explain workplace decisions in neutral terms—for example, that company policy allows different arrangements based on individual circumstances—without disclosing the medical reason. ADA confidentiality applies broadly to medical information learned about employees, including information contained in accommodation requests. Managers should therefore be trained not to answer coworkers’ questions by revealing protected health details.
Question 311. An employee requests a modified work schedule because of a disability. How should the employer generally treat the medical information contained in the accommodation request?
- Post it to the team calendar
- Treat it as confidential medical information and keep it separate from the regular personnel file
- Include it in performance evaluations
- Share it with all managers in the organization
Correct Answer: 2. Treat it as confidential medical information and keep it separate from the regular personnel file
Explanation:
The ADA confidentiality rule applies broadly to medical information an employer learns about an applicant or employee. An employee’s request for reasonable accommodation can itself reveal medical information and therefore should be protected, even if it contains no formal diagnosis or treatment records. The EEOC recommends storing medical information separately from general personnel files and using similar protections for electronic records. Access should generally be limited to officials who genuinely need the information for accommodation, emergency response, compliance investigation, workers’ compensation, or another recognized exception.
Question 312. Under the ADA, when may first aid or safety personnel receive otherwise confidential medical information about an employee?
- Whenever they want to learn about coworkers’ health
- Only after the employee resigns
- When the employee may need emergency treatment or assistance because of the medical condition
- Never under any circumstance
Correct Answer: 3. When the employee may need emergency treatment or assistance because of the medical condition
Explanation:
The ADA allows limited disclosure of confidential medical information to first aid and safety personnel when the employee may need emergency treatment or other assistance because of a medical condition. For example, safety personnel may need to know that an employee requires specific assistance during an evacuation. The purpose of the exception is practical safety, not general sharing of diagnosis information. Employers should disclose only what personnel need to perform the relevant emergency or safety function and should avoid unnecessarily distributing the employee’s complete medical records.
Question 313. What is the central requirement of the FTC Red Flags Rule for organizations within its scope?
- Maintain a written Identity Theft Prevention Program appropriate to the covered accounts and risks
- Report every fraud attempt to all customers
- Eliminate all online account access
- Require biometric authentication for every transaction
Correct Answer: 1. Maintain a written Identity Theft Prevention Program appropriate to the covered accounts and risks
Explanation:
The Red Flags Rule requires many covered organizations to implement a written Identity Theft Prevention Program designed to detect, prevent, and mitigate identity theft in connection with covered accounts. The program should identify relevant warning signs, establish methods for detecting them, define appropriate responses, and be updated as risks change. The Rule uses a risk-based approach rather than requiring one standardized list of red flags or one mandatory authentication technology. Organizations should tailor the program to their accounts, experiences with identity theft, methods of opening and accessing accounts, and evolving threat environment.
Question 314. Which type of activity should a Red Flags Rule program address AFTER a red flag has been detected?
- Only marketing opportunities
- Appropriate responses designed to prevent or mitigate identity theft
- Automatic deletion of every customer’s account
- Publication of the customer’s identity
Correct Answer: 4. Appropriate responses designed to prevent or mitigate identity theft
Explanation:
Detecting warning signs is only one component of a Red Flags Rule program. A covered organization must also establish appropriate responses when red flags are detected. Depending on the circumstances, those responses can involve monitoring an account, contacting the customer, changing passwords or security codes, refusing to open a new account, closing an existing account, notifying law enforcement, or determining that no response is warranted based on documented facts. The response should fit the degree of risk. A program that identifies suspicious activity but provides no process for acting on it would fail the Rule’s preventive purpose.
Question 315. Why must a Red Flags Rule Identity Theft Prevention Program be updated periodically?
- Identity-theft methods, account types, business practices, and risks can change over time
- The program automatically expires every 30 days
- The FTC requires a completely different program every year
- Written programs may never use the same controls twice
Correct Answer: 2. Identity-theft methods, account types, business practices, and risks can change over time
Explanation:
An effective identity-theft prevention program must evolve as threats and business practices change. New account-opening channels, changes in authentication, new products, fraud trends, security incidents, and emerging attack methods can create red flags that did not exist when the program was first drafted. The Red Flags Rule therefore requires periodic updates that reflect relevant changes in identity-theft risk. Regular reassessment keeps the program operationally meaningful rather than allowing it to become a static compliance document disconnected from the organization’s actual accounts and fraud environment.
Question 316. Which FCC-regulated entities were specifically reminded in 2026 of their annual CPNI certification obligations?
- Hospitals and pharmacies
- Consumer reporting agencies only
- Telecommunications carriers and interconnected VoIP providers
- Universities and schools
Correct Answer: 3. Telecommunications carriers and interconnected VoIP providers
Explanation:
In its 2026 enforcement advisory, the FCC reminded telecommunications carriers and interconnected Voice over Internet Protocol providers that they must file annual certifications documenting compliance with the Commission’s CPNI rules. CPNI can include highly sensitive information such as telephone numbers called and received, call timing, duration, location, and services purchased. The annual certification process is one way the FCC creates recurring accountability around customer-information protection. Organizations in these regulated communications sectors should therefore maintain CPNI policies, complaint data, and compliance documentation throughout the year rather than preparing only when the annual filing deadline approaches.
Question 317. Why does the FCC treat CPNI as particularly sensitive information?
- It can reveal detailed communications patterns, including who customers contact, when, how often, and sometimes where communications occur
- CPNI contains only public corporate addresses
- It contains no information about customer behavior
- It is limited exclusively to anonymous network statistics
Correct Answer: 4. It can reveal detailed communications patterns, including who customers contact, when, how often, and sometimes where communications occur
Explanation:
CPNI can reveal significant details about customers’ communications behavior. The FCC describes it as including telephone numbers of calls made and received, frequency, duration, timing, location, and purchased telecommunications features. Even where call contents are not included, these patterns can expose sensitive relationships, routines, and activities. The FCC therefore imposes safeguards, customer-authentication requirements, and annual compliance certification on covered carriers and interconnected VoIP providers. Privacy professionals should recognize that metadata can create serious privacy risks even where it does not contain the substantive contents of the underlying communication.
Question 318. A financial institution wants to disclose customer NPI to a nonaffiliated vendor solely to detect fraudulent transactions. Which conclusion is MOST appropriate under Regulation P?
- The disclosure always requires opt-in consent
- It may fall within a fraud-prevention exception to ordinary notice and opt-out requirements
- It is always prohibited
- The institution must first close the customer’s account
Correct Answer: 1. It may fall within a fraud-prevention exception to ordinary notice and opt-out requirements
Explanation:
Regulation P contains exceptions for disclosures made to protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability. A disclosure to a vendor for legitimate fraud-detection purposes may therefore be permitted without using the ordinary consumer opt-out process, assuming the arrangement fits the regulatory exception. This does not authorize the vendor to repurpose the information for independent marketing or resale. Privacy professionals should evaluate the purpose and scope of the vendor’s use and ensure contracts and operational controls align with the permitted fraud-prevention function.
Question 319. A bank discloses NPI to a vendor under Regulation P’s service-provider exception. What contractual restriction is especially important?
- The vendor must be free to sell the information to anyone
- The vendor must agree to use and disclose the information only as necessary for the specified service or another permitted exception
- The vendor must become an affiliate of the bank
- The vendor must delete the bank’s privacy notice
Correct Answer: 2. The vendor must agree to use and disclose the information only as necessary for the specified service or another permitted exception
Explanation:
The service-provider and joint-marketing exception depends in part on a contractual agreement restricting the third party’s use and disclosure of NPI. The recipient should use the information only to carry out the purposes for which it was disclosed, including permitted activity under other Regulation P exceptions in the ordinary course of performing that purpose. These restrictions prevent the exception from becoming an unrestricted data-transfer loophole. Financial institutions should therefore align vendor contracts, operational instructions, and oversight with the specific services the vendor performs.
Question 320. A national financial-services company employs workers with disabilities, uses fraud-monitoring vendors, maintains covered accounts, and shares customer NPI with service providers. What is the BEST privacy-compliance approach?
- Apply only the ADA because employee privacy overrides financial privacy requirements
- Apply only GLBA because financial regulation replaces employment law
- Map each activity separately and apply ADA medical confidentiality, Red Flags identity-theft controls, and Regulation P notice, opt-out, exception, and vendor requirements as appropriate
- Treat all data as governed by one general privacy notice
Correct Answer: 3. Map each activity separately and apply ADA medical confidentiality, Red Flags identity-theft controls, and Regulation P notice, opt-out, exception, and vendor requirements as appropriate
Explanation:
A large organization can simultaneously operate under several U.S. privacy and consumer-protection regimes. Employee medical information can trigger ADA confidentiality requirements, covered accounts can require an Identity Theft Prevention Program under the Red Flags Rule, and financial customer information may fall under GLBA Regulation P. Vendor disclosures may be permitted under service-provider, transaction-processing, fraud-prevention, or other exceptions, but only when the conditions for those exceptions are satisfied. A mature privacy program therefore maps data types, individuals, purposes, recipients, and legal roles and applies the correct controls to each activity instead of forcing all processing into one legal framework.