View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 261. Which operator is generally subject to the California Online Privacy Protection Act (CalOPPA)?
- Only a company physically headquartered in California
- An operator of a commercial website or online service that collects personally identifiable information from California consumers
- Only federal government websites
- Only companies that sell personal information for money
Correct Answer: 2. An operator of a commercial website or online service that collects personally identifiable information from California consumers
Explanation:
CalOPPA applies broadly to operators of commercial websites and online services that collect personally identifiable information from California consumers. California’s Attorney General has explained that the operator does not need to be physically located in California for the law to apply. CalOPPA was the first U.S. state law to broadly require commercial online services to conspicuously post privacy policies. The law focuses heavily on transparency regarding online data practices rather than applying only when information is sold. Privacy professionals should therefore consider where users reside and what the service collects, not merely the company’s headquarters location.
Question 262. What must a privacy policy covered by CalOPPA generally disclose about personal information?
- Only the operator’s annual revenue
- Only whether cookies are used
- Only the name of the website’s hosting company
- Categories of personally identifiable information collected and categories of third parties with whom it may be shared**
Correct Answer: 4. Categories of personally identifiable information collected and categories of third parties with whom it may be shared
Explanation:
CalOPPA requires covered online operators to disclose important aspects of their privacy practices. California guidance identifies required disclosures including categories of personally identifiable information collected and categories of third parties with whom the operator may share that information. The policy must also include other required information, such as how changes are communicated and its effective date. The purpose is to allow consumers to understand meaningful aspects of online data handling before or while using a website or service. A vague statement that an organization “values privacy” would not substitute for the concrete disclosures contemplated by the statute.
Question 263. What did California’s 2013 amendments to CalOPPA add concerning online tracking?
- Covered privacy policies must disclose how the operator responds to Do Not Track signals or similar mechanisms and whether certain third parties may collect information across services
- All websites must technically honor every Do Not Track signal
- Tracking cookies became illegal in California
- California prohibited all behavioral advertising
Correct Answer: 1. Covered privacy policies must disclose how the operator responds to Do Not Track signals or similar mechanisms and whether certain third parties may collect information across services
Explanation:
California amended CalOPPA to increase transparency concerning online tracking. Covered privacy policies must explain how the operator responds to browser Do Not Track signals or other mechanisms that give consumers choices regarding collection of personally identifiable information over time and across online services. The policy must also address whether third parties may engage in such collection when consumers use the operator’s service. Importantly, CalOPPA’s tracking provisions primarily impose disclosure obligations; they do not simply ban online tracking or mandate that every website technically honor the original Do Not Track standard.
Question 264. Which statement BEST describes CalOPPA’s approach to privacy policies?
- Posting any privacy policy eliminates liability for actual practices
- Privacy policies are optional if an operator uses encryption
- Covered operators must conspicuously post a privacy policy and should comply with the practices they disclose
- A privacy policy is necessary only after a consumer files a complaint
Correct Answer: 3. Covered operators must conspicuously post a privacy policy and should comply with the practices they disclose
Explanation:
CalOPPA requires covered operators to conspicuously post their privacy policies. California’s Attorney General has summarized the principle as requiring operators to explain what they do and then follow those stated practices. A privacy notice therefore is not merely decorative legal text. Inaccurate disclosures can create additional consumer-protection risk if actual practices differ materially from what consumers were told. Privacy teams should coordinate with engineering, advertising, analytics, and product groups so published policies reflect actual collection, use, sharing, tracking, and retention practices. Maintaining accurate notices also requires reviewing them when business practices materially change.
Question 265. Which fact should ordinarily appear in a CalOPPA-compliant privacy policy?
- The names of every employee with database access
- The company’s complete cybersecurity architecture
- The personal addresses of all corporate officers
- The effective date of the privacy policy**
Correct Answer: 4. The effective date of the privacy policy
Explanation:
California guidance identifies the effective date as one of the items a covered CalOPPA privacy policy must include. The policy should also explain categories of personal information collected, categories of third parties with whom information may be shared, and required information concerning review or changes and online tracking. An effective date helps consumers and regulators understand which version of a privacy policy applies to a particular period. Version control is especially important where an operator’s tracking, analytics, advertising, or sharing practices change over time. Privacy teams should preserve prior versions internally so historical representations can be reconstructed if necessary.
Question 266. Under Nevada’s online privacy law, what must a covered operator establish for consumers wishing to direct the operator not to sell qualifying covered information?
- A physical office in every Nevada county
- A designated request address
- A federal consumer-reporting account
- A mandatory paid privacy subscription
Correct Answer: 2. A designated request address
Explanation:
Nevada requires covered operators to establish a designated request address through which consumers can submit verified requests directing the operator not to make qualifying sales of covered information. The statute defines a designated request address to include an email address, toll-free telephone number, or internet website established for this purpose. The request must be reasonably verified using commercially reasonable means. This requirement gives consumers a defined mechanism for exercising Nevada’s sale opt-out rather than forcing them to find an informal customer-service route. Data brokers subject to the Nevada framework also have designated-request obligations.
Question 267. Under Nevada’s online privacy statute, how is “sale” generally defined for purposes of the consumer opt-out right?
- Every disclosure to a service provider
- Every transfer occurring during a merger
- Exchange of covered information for monetary consideration to another person for that person to license or sell it onward, subject to statutory exclusions
- Any disclosure made at a consumer’s direction
Correct Answer: 3. Exchange of covered information for monetary consideration to another person for that person to license or sell it onward, subject to statutory exclusions
Explanation:
Nevada’s sale definition is narrower than the definitions used in some other state privacy laws. In general, it focuses on exchanging covered information for monetary consideration to another person for that person to license or sell the information to additional persons. Nevada expressly excludes various transfers, including disclosures to processors, certain direct-relationship service providers, affiliates, and qualifying transfers in mergers or acquisitions. Privacy professionals should therefore avoid importing California’s or another state’s definition of “sale” into a Nevada analysis. The precise statutory definition determines whether Nevada’s opt-out right applies.
Question 268. How quickly must a Nevada operator generally respond to a verified request not to sell covered information?
- Within 60 days, with a possible extension of up to 30 additional days when reasonably necessary
- Within 24 hours with no extension
- Within one year
- Only after the Attorney General approves the request
Correct Answer: 1. Within 60 days, with a possible extension of up to 30 additional days when reasonably necessary
Explanation:
Nevada requires an operator receiving a verified opt-out request to respond within 60 days. If an extension is reasonably necessary, the operator may extend the period by no more than 30 additional days and must notify the consumer of the extension. Similar timing rules apply to covered data brokers under Nevada’s framework. This timing differs from the 45-day response periods found in many newer state comprehensive privacy statutes. A national rights-management program should therefore track the consumer’s jurisdiction and apply the correct deadline rather than assuming all state privacy requests share one timeframe.
Question 269. Which item is expressly included within Nevada’s definition of “covered information”?
- Only biometric templates
- Only health diagnoses
- Only data purchased from government agencies
- An email address collected from a consumer through the operator’s website or online service**
Correct Answer: 4. An email address collected from a consumer through the operator’s website or online service
Explanation:
Nevada’s definition of covered information includes several familiar identifiers collected through an operator’s website or online service and maintained in accessible form. Examples include first and last name, physical address, email address, telephone number, Social Security number, identifiers allowing a person to be contacted, and other information combined with identifiers so it becomes personally identifiable. The definition is tied to Nevada’s specific statutory framework and is not identical to the broad “personal data” definitions found in newer comprehensive state privacy statutes. Correct classification is therefore essential before applying the Nevada opt-out provisions.
Question 270. Which information must Nevada’s online privacy notice generally address?
- Only the operator’s tax filings
- Categories of covered information collected and categories of third parties with whom the operator may share it
- Only the operator’s advertising budget
- Names of all individual customers
Correct Answer: 2. Categories of covered information collected and categories of third parties with whom the operator may share it
Explanation:
Nevada requires covered operators to provide an accessible notice describing specified privacy practices. Among the required disclosures are categories of covered information the operator collects and categories of third parties with whom the operator may share such information. The notice also addresses processes for consumer review or changes where available, how material changes are communicated, whether third parties collect information across services over time, and the notice’s effective date. This transparency framework preceded many modern comprehensive state privacy laws but continues to impose specific online notice requirements on covered Nevada operators.
Question 271. When did the Maryland Online Data Privacy Act (MODPA) take effect?
- October 1, 2025
- January 1, 2023
- July 1, 2027
- January 1, 2030
Correct Answer: 1. October 1, 2025
Explanation:
Maryland’s Online Data Privacy Act took effect on October 1, 2025. MODPA gives Maryland residents privacy rights and establishes obligations for qualifying controllers and processors. The law includes rights involving knowledge, correction, deletion, opt-outs, limitations on certain processing, and equal treatment. For businesses, Maryland imposes obligations involving data minimization, sensitive data, consumer request handling, security, and assessments for processing that presents heightened risk. Its effective date matters because national privacy programs must track when each state law becomes operational rather than assuming all comprehensive privacy statutes became effective at the same time.
Question 272. What data-minimization standard does MODPA impose on controllers?
- Collect any data that could potentially become commercially valuable
- Retain all data indefinitely once collected
- Limit collection to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer
- Collect all sensitive data before determining whether it is needed
Correct Answer: 3. Limit collection to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer
Explanation:
Maryland adopts a relatively strong data-minimization approach. Controllers must limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain the specific product or service requested by the consumer. This differs from approaches that primarily rely on notice and consumer opt-out after broad collection has already occurred. Data minimization requires product teams to ask whether each requested data element is actually needed for the consumer-facing purpose. Collecting information merely because it may become useful later can increase security exposure and may conflict with MODPA’s statutory requirements.
Question 273. Which statement BEST describes MODPA’s treatment of sensitive data?
- Controllers may sell sensitive data whenever consumers are given an opt-out
- Sensitive data is excluded from MODPA
- Sensitive data may always be used for unrelated advertising
- Controllers may not sell sensitive data and generally may collect, process, or share it only where strictly necessary to provide or maintain a specific requested product or service**
Correct Answer: 4. Controllers may not sell sensitive data and generally may collect, process, or share it only where strictly necessary to provide or maintain a specific requested product or service
Explanation:
MODPA imposes strong restrictions on sensitive data. Maryland’s Attorney General states that controllers may not sell sensitive data and may collect, process, or share sensitive data only where doing so is strictly necessary to provide or maintain a specific product or service requested by the consumer. Sensitive data includes categories such as health information, biometric or genetic data, precise geolocation, data of children, and information revealing specified personal characteristics. This model goes beyond a simple consent-based framework and places substantive limits on processing even where a controller might prefer broader secondary uses.
Question 274. Which processing activity can trigger a MODPA data protection assessment?
- Processing personal data for targeted advertising or selling personal data
- Printing an ordinary receipt
- Publishing a company’s office hours
- Maintaining anonymous statistical information only
Correct Answer: 1. Processing personal data for targeted advertising or selling personal data
Explanation:
MODPA requires data protection assessments before certain processing activities that present heightened risks to consumers. Maryland specifically identifies targeted advertising, sale of personal data, sensitive-data processing, and certain forms of profiling with reasonably foreseeable risks as activities requiring assessments. The purpose is to force organizations to evaluate risks and safeguards before or while undertaking higher-risk data practices rather than waiting for harm to occur. Privacy professionals should integrate these assessments with product review and change-management processes, particularly when new advertising technologies, sensitive-data programs, or automated decision-making systems are introduced.
Question 275. Does MODPA generally protect an individual acting in an employment context?
- Yes, all employees automatically qualify as consumers
- No, its consumer protections generally apply to individuals acting in an individual or household context, not an employment context
- Yes, but only executives
- Only employees of data brokers are excluded
Correct Answer: 2. No, its consumer protections generally apply to individuals acting in an individual or household context, not an employment context
Explanation:
Maryland’s comprehensive privacy law protects consumers acting in an individual or household context. Maryland’s Attorney General explains that an individual acting in an employment context is not covered by MODPA’s consumer definition in the same way. This distinction matters for national companies because California’s CCPA, for example, does extend privacy rights to employees and job applicants. State comprehensive privacy laws use different definitions and exclusions, so privacy professionals should identify the role in which an individual interacts with the organization before determining what rights and obligations apply.
Question 276. When did the New Jersey Data Privacy Law (NJDPL) take effect?
- January 15, 2025
- January 1, 2027
- July 1, 2023
- January 1, 2030
Correct Answer: 3. January 15, 2025
Explanation:
The New Jersey Data Privacy Law took effect on January 15, 2025. It grants New Jersey consumers rights regarding their personal data and imposes responsibilities on covered controllers. The law addresses matters such as access, correction, deletion, portability, opt-outs, sensitive data, notices, security, and controller-processor relationships. As with other state privacy statutes, its effective date is important when implementing national compliance programs. New Jersey also continued to amend its privacy framework in 2026, making current legal tracking particularly important for organizations subject to the state’s requirements.
Question 277. Who can bring an enforcement action under the New Jersey Data Privacy Law?
- Every consumer through an automatic private right of action
- Only the FTC
- Local school districts
- The New Jersey Attorney General; the law does not provide consumers a general private right of action**
Correct Answer: 4. The New Jersey Attorney General; the law does not provide consumers a general private right of action
Explanation:
New Jersey’s Office of the Attorney General enforces the NJDPL. State guidance expressly states that consumers cannot bring lawsuits on their own behalf under the comprehensive privacy statute, although they can submit complaints to the Division of Consumer Affairs. The Attorney General may seek court orders stopping violations, compensation for victims, and civil penalties. This illustrates why enforcement structure must be analyzed separately from consumer rights: a statute can give consumers substantial access, deletion, or opt-out rights without giving each consumer a direct private damages claim under the law itself.
Question 278. What civil penalty can the New Jersey Attorney General seek for a later NJDPL offense according to state guidance?
- No monetary penalty is available
- Up to $20,000 for later offenses
- Exactly $500 in every case
- Only restitution, never civil penalties
Correct Answer: 2. Up to $20,000 for later offenses
Explanation:
New Jersey’s consumer-protection guidance states that the Attorney General may seek penalties of up to $10,000 for an initial offense and up to $20,000 for subsequent offenses under the state’s privacy framework. The Attorney General may also seek relief such as stopping violations and obtaining compensation for victims. Monetary exposure therefore can escalate for organizations that continue noncompliant practices after earlier enforcement. Privacy teams should not treat a first enforcement matter as an isolated cost of doing business; repeated violations can produce greater penalties and demonstrate weaknesses in the organization’s compliance program.
Question 279. Which principle is expressly included in New Jersey’s 2026 amended controller obligations?
- Limit collection to personal data that is adequate, relevant, and reasonably necessary for disclosed processing purposes
- Collect every available data point for future innovation
- Keep personal data permanently
- Sell data whenever the controller cannot identify an immediate use
Correct Answer: 1. Limit collection to personal data that is adequate, relevant, and reasonably necessary for disclosed processing purposes
Explanation:
New Jersey’s 2026 amendments reinforce data minimization by requiring controllers to limit collection to personal data that is adequate, relevant, and reasonably necessary in relation to disclosed processing purposes. They also restrict incompatible secondary processing unless the controller obtains consumer consent and require reasonable administrative, technical, and physical security measures. These requirements reflect a broader trend in state privacy law toward substantive limitations on collection and use instead of relying exclusively on privacy notices and opt-outs. Product teams should therefore identify legitimate purposes before collecting information and reassess whether each data element is needed.
Question 280. A nationwide online company operates websites covered by CalOPPA, serves Nevada consumers, and processes Maryland and New Jersey residents’ personal data. What is the BEST compliance strategy?
- Follow only California law because it was enacted first
- Apply one identical definition of “sale” in every state
- Map each jurisdiction’s scope, notices, consumer rights, opt-outs, sensitive-data restrictions, minimization rules, and enforcement requirements, then build common controls with state-specific variations
- Wait for each attorney general to contact the company before implementing controls
Correct Answer: 3. Map each jurisdiction’s scope, notices, consumer rights, opt-outs, sensitive-data restrictions, minimization rules, and enforcement requirements, then build common controls with state-specific variations
Explanation:
State privacy laws increasingly share common concepts, but important differences remain. CalOPPA focuses heavily on online privacy-policy transparency, Nevada uses a relatively narrow monetary-consideration definition of sale, Maryland imposes stringent minimization and sensitive-data restrictions, and New Jersey has its own rights, enforcement, and updated controller duties. A national organization should therefore map jurisdictions and data practices, identify where requirements overlap, and implement reusable enterprise controls while preserving state-specific logic when definitions, deadlines, rights, or substantive processing restrictions differ. Assuming that compliance with one state’s statute automatically satisfies the others creates avoidable regulatory risk.