View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 241. What does Customer Proprietary Network Information (CPNI) generally include?
- Only a customer’s billing address
- Only information published in a telephone directory
- Certain information a telecommunications carrier obtains because of the customer-carrier relationship, such as numbers called and call timing, frequency, or duration
- Every item of information available on the public internet
Correct Answer: 3. Certain information a telecommunications carrier obtains because of the customer-carrier relationship, such as numbers called and call timing, frequency, or duration
Explanation:
CPNI is a category of telecommunications customer information protected by section 222 of the Communications Act and FCC rules. It can include highly sensitive details generated through the customer relationship, such as telephone numbers called, frequency of calls, duration, timing, and other call-detail information. Because telecommunications providers can obtain detailed information about customers’ communications patterns, FCC rules require carriers and certain interconnected VoIP providers to safeguard CPNI and limit unauthorized use or disclosure. CPNI should therefore be distinguished from information that happens to be publicly available independently of the carrier relationship.
Question 242. What must a telecommunications carrier generally do before disclosing CPNI during a customer-initiated telephone contact?
- Properly authenticate the customer according to FCC requirements
- Ask only for information readily available on the internet
- Require a court order in every case
- Publish the requested information online first
Correct Answer: 1. Properly authenticate the customer according to FCC requirements
Explanation:
FCC rules require telecommunications carriers to take reasonable measures to prevent unauthorized access to CPNI and to properly authenticate customers before disclosing protected information. For telephone access to call-detail information, the FCC adopted safeguards designed to prevent attackers from relying on easily obtainable biographical or account information. Depending on the circumstances, password authentication or other approved methods are required. The objective is to reduce pretexting and account takeover risks in which an unauthorized person impersonates the customer and obtains sensitive communication records. Authentication therefore serves as a core privacy safeguard under the CPNI framework.
Question 243. If a telecommunications customer changes an online account password or address of record, what do FCC CPNI rules generally require?
- The carrier must close the account immediately
- The carrier may wait until the annual privacy notice
- No notification is necessary
- The carrier must promptly notify the customer of specified account changes
Correct Answer: 4. The carrier must promptly notify the customer of specified account changes
Explanation:
FCC CPNI safeguards require carriers to notify customers when certain account credentials or account details are created or changed. Covered changes include passwords, backup authentication responses, online accounts, and addresses of record. This requirement is intended to alert customers quickly if an attacker changes security settings or account information without authorization. Account-change notices complement customer authentication rules by giving consumers another opportunity to detect account takeover. Telecommunications privacy therefore includes both restricting inappropriate disclosure and monitoring changes that could enable future unauthorized access.
Question 244. What annual FCC compliance requirement generally applies to companies subject to the CPNI rules?
- They must send all call records to the FCC
- They must file an annual certification documenting compliance with CPNI requirements
- They must delete all customer call information every year
- They must obtain new customer consent every January
Correct Answer: 2. They must file an annual certification documenting compliance with CPNI requirements
Explanation:
Companies subject to the FCC’s CPNI rules generally must file an annual certification documenting their compliance. The FCC’s certification process requires information concerning the company’s procedures, complaints about unauthorized CPNI release, and certain actions involving data brokers. The certifications are generally due by March 1 each year. This requirement gives the FCC a recurring compliance mechanism rather than relying solely on enforcement after a major privacy incident. Telecommunications providers should therefore maintain documented CPNI policies and complaint records throughout the year so they can support accurate annual certification.
Question 245. Under FCC CPNI rules, what approval is generally required before a carrier uses individually identifiable CPNI for purposes outside specified permitted uses or qualifying communications-related marketing?
- Approval from a credit bureau
- Approval from the consumer’s employer
- A judicial subpoena
- Customer opt-in approval, unless another rule or statutory exception permits the use**
Correct Answer: 4. Customer opt-in approval, unless another rule or statutory exception permits the use
Explanation:
FCC rules restrict carrier use and disclosure of individually identifiable CPNI. Certain uses connected with the telecommunications service or qualifying communications-related marketing can be handled under particular rules, including opt-out arrangements in some circumstances. Uses and disclosures outside those permitted categories generally require opt-in approval unless another exception applies. Privacy professionals should therefore identify the purpose of the proposed use, the recipient, and whether the activity fits a regulatory exception before deciding what consent is necessary. CPNI compliance involves purpose limitation in addition to security and authentication.
Question 246. What does the Protection of Pupil Rights Amendment (PPRA) primarily regulate?
- Certain student surveys, parental access to information, marketing-related data practices, and specified physical examinations
- Consumer credit reports
- Health insurance claims
- Telephone marketing campaigns
Correct Answer: 1. Certain student surveys, parental access to information, marketing-related data practices, and specified physical examinations
Explanation:
PPRA protects student and parental rights in several specific educational contexts. It governs certain surveys involving protected areas, parental inspection of survey and instructional materials, collection or use of student information for marketing, and specified nonemergency invasive physical examinations or screenings. PPRA applies to programs and activities of educational agencies and institutions receiving funds under programs administered by the U.S. Department of Education. It is separate from FERPA, although both are important federal student privacy laws. FERPA primarily focuses on education records, while PPRA focuses heavily on student participation, surveys, marketing, and related parental rights.
Question 247. Which topic is one of PPRA’s eight protected survey areas?
- A student’s favorite school subject
- Religious practices, affiliations, or beliefs of the student or the student’s parent
- The school’s lunch menu
- The student’s preferred sports team
Correct Answer: 2. Religious practices, affiliations, or beliefs of the student or the student’s parent
Explanation:
PPRA identifies eight protected categories that can trigger additional parental rights when surveys, analyses, or evaluations ask students about them. These include political affiliations, mental or psychological problems, sex behavior or attitudes, certain illegal or self-incriminating behavior, critical appraisals of close family members, privileged relationships, religious practices or beliefs, and income except in specified eligibility contexts. Because these topics involve highly sensitive personal or family matters, schools and other covered entities must follow PPRA’s notice, consent, inspection, or opt-out requirements as applicable.
Question 248. When must a school generally obtain written parental consent under PPRA for a protected-information survey?
- Whenever a student completes any voluntary classroom survey
- Only when the survey is anonymous
- When students are required, as part of a U.S. Department of Education-administered program, to participate in a survey concerning one or more protected areas
- Only after survey responses have already been collected
Correct Answer: 3. When students are required, as part of a U.S. Department of Education-administered program, to participate in a survey concerning one or more protected areas
Explanation:
PPRA requires active written parental consent before students are required, as part of a program administered by the Department of Education, to participate in surveys, analyses, or evaluations that concern one or more of the eight protected areas. Other protected-information surveys administered by a covered LEA may instead trigger notice and an opportunity for parents to opt their children out. The distinction between mandatory participation in a Department-funded or administered program and other survey scenarios is therefore important when determining whether affirmative consent or opt-out procedures apply.
Question 249. What inspection right does PPRA provide concerning third-party surveys administered to students?
- Parents may request to inspect the survey before it is administered or distributed to the student
- Parents may inspect the survey only after all students respond
- Only teachers may inspect third-party surveys
- Survey questions are never subject to parental inspection
Correct Answer: 1. Parents may request to inspect the survey before it is administered or distributed to the student
Explanation:
PPRA requires covered LEAs to develop policies protecting parents’ right to inspect qualifying third-party surveys before those surveys are administered or distributed to students. The school should provide reasonable access within a reasonable period after receiving the request. This right allows parents to understand what information their children may be asked to provide before participation occurs. PPRA also provides inspection rights concerning instructional materials and instruments used to collect personal information for certain marketing activities. These transparency requirements complement consent and opt-out protections.
Question 250. Which school activity may require PPRA notice and an opportunity for a parent to opt a child out?
- An ordinary math test
- A school lunch period
- A fire drill
- Collection of student personal information for certain marketing or sale purposes**
Correct Answer: 4. Collection of student personal information for certain marketing or sale purposes
Explanation:
PPRA addresses certain school activities involving collection, disclosure, or use of student personal information for marketing, selling that information, or otherwise providing it to others for marketing purposes. Covered LEAs must establish policies concerning these practices and, for relevant activities, provide notice and an opportunity for parents to opt students out. PPRA also provides parental inspection rights concerning the instruments used to collect the information. This framework recognizes that students should not become an unregulated source of marketing data merely because commercial data collection occurs through a school environment.
Question 251. When do PPRA rights generally transfer from a parent to a student?
- At age 13
- At age 16
- When the student turns 18 or becomes an emancipated minor under state law
- Only after college graduation
Correct Answer: 3. When the student turns 18 or becomes an emancipated minor under state law
Explanation:
Under PPRA, parental rights generally transfer to the student when the student reaches age 18 or becomes an emancipated minor under applicable state law. This transfer rule differs somewhat from FERPA, where rights transfer at age 18 or when a student attends a postsecondary institution at any age. CIPP/US candidates should therefore avoid assuming that every education privacy law uses the exact same trigger for transferring rights. Understanding the relevant statute’s definition of the rights holder is essential when determining who should receive notices, inspect materials, provide consent, or exercise opt-out rights.
Question 252. Under Maine’s broadband privacy law, what generally must an internet service provider obtain before using, disclosing, selling, or permitting access to customer personal information, unless an exception applies?
- A consumer credit report
- The customer’s express, affirmative consent
- Approval from the FTC
- Consent from any household member
Correct Answer: 2. The customer’s express, affirmative consent
Explanation:
Maine’s broadband privacy statute generally prohibits providers from using, disclosing, selling, or permitting access to customer personal information unless the customer provides express, affirmative consent or another statutory exception applies. The law covers a broad range of information, including browsing history, application usage, precise geolocation, financial and health information, information about children, device identifiers, communication contents, and IP-address information. The affirmative-consent framework reflects Maine’s choice to impose stronger privacy controls on broadband providers rather than relying solely on an opt-out model.
Question 253. Which information is expressly included within “customer personal information” under Maine’s broadband privacy law?
- Only a customer’s name
- Only billing records
- Only a Social Security number
- Web browsing history, application usage history, precise geolocation, and other specified information**
Correct Answer: 4. Web browsing history, application usage history, precise geolocation, and other specified information
Explanation:
Maine’s law defines broadband customer personal information broadly. It includes personally identifying information such as names, billing details, and Social Security numbers, as well as information generated through broadband use. The latter category expressly includes web browsing history, application usage, precise geolocation, health and financial information, information relating to children, device identifiers, communication contents, and origin and destination IP addresses. Because these data can reveal extensive details about a person’s behavior and interests, providers must apply the law’s consent, security, and notice rules carefully.
Question 254. Under Maine’s broadband privacy statute, may a provider refuse service because a customer declines to consent to optional use or disclosure of customer personal information?
- Yes, providers may always terminate nonconsenting customers
- Yes, if the provider offers a privacy notice
- No, the provider generally may not refuse service or penalize the customer for declining consent
- Only if the customer pays an additional privacy fee
Correct Answer: 3. No, the provider generally may not refuse service or penalize the customer for declining consent
Explanation:
Maine prohibits broadband providers from conditioning service on a customer’s willingness to provide consent for covered optional uses of personal information. The statute also prohibits charging a penalty or offering a discount based on the customer’s decision to give or withhold consent. This prevents providers from undermining the consent requirement through financial pressure or denial of basic broadband service. Consent therefore must function as a genuine choice rather than as a condition consumers must accept merely to receive the underlying service.
Question 255. Which use of customer personal information may Maine broadband providers generally perform without obtaining customer approval?
- Use necessary to provide, bill for, or protect the broadband service from fraudulent or unlawful use
- Sale to unrelated advertisers for any purpose
- Disclosure of browsing history to a data broker for behavioral advertising
- Public posting of communications content
Correct Answer: 1. Use necessary to provide, bill for, or protect the broadband service from fraudulent or unlawful use
Explanation:
Maine recognizes several operational exceptions to the general affirmative-consent rule. Providers may use customer personal information without approval when necessary to provide the service, bill and collect payment, protect users against fraudulent, abusive, or unlawful use, comply with lawful court orders, or provide specified emergency geolocation information. The law also permits certain marketing of the provider’s own communications-related services. These exceptions are purpose-specific and should not be interpreted as general permission to sell or disclose customer data for unrelated commercial activities.
Question 256. What security obligation does Maine impose on broadband providers concerning customer personal information?
- Providers have no security obligations if consent was obtained
- Providers must take reasonable measures to protect information from unauthorized use, disclosure, or access
- Only encryption is permitted as a security measure
- Providers must destroy all data every 24 hours
Correct Answer: 2. Providers must take reasonable measures to protect information from unauthorized use, disclosure, or access
Explanation:
Maine requires broadband providers to take reasonable measures to secure customer personal information. In determining appropriate safeguards, the statute directs providers to consider the nature and scope of their activities, the sensitivity of the collected information, the provider’s size, and the technical feasibility of security measures. This is a risk-based security approach rather than a mandate to use one specific technology. Consent to collect or use information does not eliminate the provider’s responsibility to protect it from unauthorized access or disclosure.
Question 257. Under Vermont’s data broker law, what type of business is generally considered a “data broker”?
- A business that knowingly collects and sells or licenses brokered personal information about consumers with whom it does not have a direct relationship
- Any business with a website
- Only a consumer reporting agency
- Any company selling products directly to its own customers
Correct Answer: 1. A business that knowingly collects and sells or licenses brokered personal information about consumers with whom it does not have a direct relationship
Explanation:
Vermont’s data broker law focuses on businesses whose business model involves collecting and selling or licensing personal information about consumers with whom the business does not have a direct relationship. Vermont guidance identifies direct relationships such as customers, users, employees, contractors, investors, or donors. The definition therefore distinguishes traditional direct-to-consumer businesses from businesses operating primarily in the background data ecosystem. Specific activities and statutory exclusions still need to be reviewed, so merely selling information does not automatically resolve the classification without considering the underlying relationship and activity.
Question 258. What recurring requirement does Vermont impose on covered data brokers?
- They must register annually with the Vermont Secretary of State
- They must send every consumer a monthly paper report
- They must become banks
- They must stop all data sales
Correct Answer: 1. They must register annually with the Vermont Secretary of State
Explanation:
Vermont was an early state to adopt specific data broker regulation. Covered data brokers must register annually with the Vermont Secretary of State and provide required information concerning their practices. Registration helps create transparency around businesses that collect and commercialize personal information without direct relationships with consumers. The Vermont Attorney General also provides compliance guidance to help businesses determine whether they fall within the law’s definition. Registration is only one component of the regulatory framework; Vermont also imposes minimum data-security requirements on covered brokers.
Question 259. In addition to annual registration, what does Vermont require covered data brokers to maintain?
- A federal banking charter
- Certain minimum data-security standards
- A health care license
- A COPPA Safe Harbor certification
Correct Answer: 2. Certain minimum data-security standards
Explanation:
Vermont’s data broker law has multiple components. In addition to annual registration, covered brokers must maintain specified minimum data-security standards. This reflects the significant risk created when organizations aggregate large volumes of personal information about people with whom they have no direct relationship. Vermont also regulates fraudulent acquisition of certain data and use of information for specified improper purposes. A privacy professional assessing a data broker should therefore consider transparency, security, acquisition practices, and downstream use—not merely whether the company filed its registration form.
Question 260. A company aggregates personal information about individuals it has never interacted with, licenses that data to third parties, and also provides broadband service to Maine residents. What is the BEST privacy-compliance approach?
- Follow only Vermont law because data-broker regulation is more specific
- Follow only Maine law because internet privacy law overrides all other statutes
- Analyze each business activity separately and apply Vermont data-broker obligations, Maine broadband privacy requirements, and any other applicable privacy laws
- Treat all collected information as public because it came from multiple sources
Correct Answer: 3. Analyze each business activity separately and apply Vermont data-broker obligations, Maine broadband privacy requirements, and any other applicable privacy laws
Explanation:
One company can be subject to different privacy regimes because separate business activities create distinct legal roles. Aggregating and licensing information about consumers with no direct relationship may trigger Vermont’s data broker requirements, while providing broadband service to Maine customers can trigger Maine’s affirmative-consent, security, and notice obligations. Neither law automatically eliminates the other. A mature privacy program maps each data flow, jurisdiction, customer relationship, purpose, disclosure, and business role and then applies the relevant requirements to each activity. This layered analysis is central to navigating the sectoral and state-based structure of U.S. privacy law.