View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 381. Which organization is covered by the SEC’s amended Regulation S-P requirements?
- Every private employer in the United States
- A registered investment adviser subject to SEC Regulation S-P
- Only commercial banks regulated by the FDIC
- Only health insurance companies
Correct Answer: 2. A registered investment adviser subject to SEC Regulation S-P
Explanation:
The SEC’s amended Regulation S-P applies to specified financial institutions within the SEC’s regulatory framework. Covered institutions include broker-dealers, including funding portals, investment companies, SEC-registered investment advisers, and qualifying transfer agents. The 2024 amendments modernized requirements for protecting customer financial information in light of increased reliance on technology and the growing impact of data breaches. Regulation S-P should not be confused with the FTC’s Safeguards Rule, which applies to different categories of non-bank financial institutions under FTC jurisdiction. Privacy professionals must first identify the regulator and regulated entity before determining which financial privacy requirements apply.
Question 382. What do the 2024 amendments to SEC Regulation S-P require covered institutions to maintain regarding security incidents?
- Only an annual marketing review
- A verbal cybersecurity procedure with no documentation
- A public list of every cybersecurity vulnerability
- Written policies and procedures for an incident response program designed to detect, respond to, and recover from unauthorized access to or use of customer information**
Correct Answer: 4. Written policies and procedures for an incident response program designed to detect, respond to, and recover from unauthorized access to or use of customer information
Explanation:
The amended Regulation S-P requires covered institutions to develop, implement, and maintain written incident-response policies and procedures. The program must be reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. It also must support investigation of the nature and scope of incidents, containment, control, and appropriate notification of affected individuals when the rule’s requirements are satisfied. The amendments reflect the SEC’s recognition that financial institutions need formal, documented processes capable of addressing modern cybersecurity incidents rather than relying on informal or purely reactive responses.
Question 383. Under amended Regulation S-P, how quickly must a covered institution generally notify affected individuals after becoming aware that unauthorized access to or use of customer information occurred or is reasonably likely to have occurred?
- As soon as practicable, but generally no later than 30 days
- Within 90 business days
- Only after the SEC completes an investigation
- At the end of the calendar year
Correct Answer: 1. As soon as practicable, but generally no later than 30 days
Explanation:
The Regulation S-P amendments establish a federal customer-notification standard for covered institutions. Subject to specified exceptions, notice must generally be provided as soon as practicable and no later than 30 days after the covered institution becomes aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The notice must provide information about the incident and help affected individuals respond appropriately. This requirement means firms need procedures capable of quickly determining incident scope, affected information, likely unauthorized use, and the population requiring notification.
Question 384. Which statement BEST describes another significant effect of the 2024 Regulation S-P amendments?
- They eliminated safeguards requirements for financial firms
- They limited the rule to paper customer records
- They broadened the information covered by safeguards and disposal requirements and extended certain safeguards obligations to transfer agents
- They replaced every state breach-notification law
Correct Answer: 3. They broadened the information covered by safeguards and disposal requirements and extended certain safeguards obligations to transfer agents
Explanation:
The SEC’s amendments did more than create a breach-notification requirement. They broadened the scope of customer information subject to safeguarding obligations, expanded proper-disposal requirements, and extended relevant safeguards requirements to qualifying transfer agents. The amendments also introduced written recordkeeping obligations designed to demonstrate compliance. These changes respond to the increased amount of financial information handled electronically and the expanded use of third-party technology. Regulation S-P establishes important federal protections but does not automatically eliminate other applicable federal or state privacy, cybersecurity, or breach-notification requirements.
Question 385. What responsibility does amended Regulation S-P place on covered institutions regarding third-party service providers?
- They must maintain reasonable oversight, including due diligence and monitoring, so service-provider incidents are appropriately addressed and required customer notices occur
- They may transfer all compliance responsibility to the service provider
- They must avoid using service providers entirely
- They need only evaluate vendors after a confirmed breach
Correct Answer: 1. They must maintain reasonable oversight, including due diligence and monitoring, so service-provider incidents are appropriately addressed and required customer notices occur
Explanation:
The Regulation S-P amendments expressly address third-party service-provider risk. Covered institutions must establish written policies and procedures reasonably designed to provide appropriate oversight through measures such as due diligence and monitoring. An institution may outsource operational activities, but it cannot simply outsource its ultimate Regulation S-P responsibilities. The incident-response framework should therefore address how vendors communicate security incidents, how the institution assesses whether customer information was affected, and how required notifications will be made. Vendor-management processes should align contractual obligations with the institution’s regulatory response deadlines.
Question 386. When did the SEC require larger and smaller covered institutions, respectively, to comply with the 2024 Regulation S-P amendments?
- January 1, 2025 and January 1, 2027
- August 2, 2024 for both groups
- December 3, 2026 and June 3, 2027
- December 3, 2025 for larger entities and June 3, 2026 for smaller entities**
Correct Answer: 4. December 3, 2025 for larger entities and June 3, 2026 for smaller entities
Explanation:
The SEC adopted a tiered compliance schedule for the Regulation S-P amendments. Larger covered institutions were required to comply by December 3, 2025, while smaller entities received additional preparation time until June 3, 2026. The amendments themselves became effective earlier, on August 2, 2024, but the compliance dates gave firms time to update policies, incident-response procedures, vendor oversight, notification processes, and recordkeeping. As of September 2026, both large and small covered institutions should therefore already be operating under the amended requirements.
Question 387. What type of incident generally triggers notification to the FTC under the amended GLBA Safeguards Rule?
- Every attempted phishing email
- Unauthorized acquisition of unencrypted customer information involving at least 500 consumers
- Any temporary system outage
- Every employee password reset
Correct Answer: 2. Unauthorized acquisition of unencrypted customer information involving at least 500 consumers
Explanation:
The FTC Safeguards Rule requires covered financial institutions to report a “notification event” involving the unauthorized acquisition of at least 500 consumers’ unencrypted customer information. For purposes of the rule, encrypted information can be treated as unencrypted when an unauthorized person also gains access to the encryption key. The reporting requirement became effective in May 2024 and adds a federal regulatory-notification obligation to the Safeguards Rule’s existing information-security requirements. Organizations should still analyze whether separate state breach laws or other federal rules also impose notification duties.
Question 388. How soon must a covered financial institution report a Safeguards Rule notification event to the FTC?
- Within one year
- Within 60 business days
- As soon as possible and no later than 30 days after discovery
- Only after notifying every consumer
Correct Answer: 3. As soon as possible and no later than 30 days after discovery
Explanation:
The Safeguards Rule requires covered institutions to notify the FTC as soon as possible and no later than 30 days after discovering a qualifying notification event. The institution submits the report through the FTC’s online reporting mechanism and provides information such as the number of consumers affected or potentially affected, the types of information involved, and a summary of the incident. This FTC deadline is distinct from notification timelines that may apply under state laws or other federal regimes, making coordinated incident-response tracking particularly important for financial institutions.
Question 389. Under the FTC Safeguards Rule notification requirement, when can encrypted customer information be treated as “unencrypted”?
- Whenever the organization uses cloud storage
- Whenever more than 100 consumers are involved
- Whenever an employee accesses the data
- When an unauthorized person also accessed the encryption key**
Correct Answer: 4. When an unauthorized person also accessed the encryption key
Explanation:
Encryption can significantly reduce breach risk, but its effectiveness depends on protecting the corresponding encryption keys. The FTC Safeguards Rule therefore treats encrypted customer information as unencrypted for notification purposes when an unauthorized person also gains access to the encryption key. This prevents organizations from relying on nominal encryption where an attacker obtained everything needed to decrypt the information. Incident-response investigations should determine not only whether customer data was encrypted, but also whether relevant keys, credentials, or other mechanisms enabling decryption were compromised during the incident.
Question 390. Under the Safeguards Rule notification provision, how is unauthorized access to unencrypted customer information generally treated when assessing unauthorized acquisition?
- Unauthorized acquisition is presumed unless reliable evidence shows there was not, or could not reasonably have been, unauthorized acquisition
- Unauthorized access can never trigger reporting
- Acquisition must always be proved by video evidence
- Access matters only if the attacker publicly posts the information
Correct Answer: 1. Unauthorized acquisition is presumed unless reliable evidence shows there was not, or could not reasonably have been, unauthorized acquisition
Explanation:
The FTC’s Safeguards Rule does not require an institution to prove through direct evidence that an attacker downloaded customer information in every case. Unauthorized access to unencrypted customer information is presumed to involve unauthorized acquisition unless reliable evidence demonstrates that acquisition did not occur or could not reasonably have occurred. This approach places importance on forensic evidence and careful documentation. Organizations investigating incidents should preserve logs, system information, access records, and other evidence capable of supporting or rebutting the presumption rather than assuming lack of confirmed exfiltration automatically eliminates reporting obligations.
Question 391. When did the Iowa Consumer Data Protection Act become effective?
- January 1, 2023
- July 1, 2026
- January 1, 2025
- January 1, 2030
Correct Answer: 3. January 1, 2025
Explanation:
Iowa’s Consumer Data Protection Act became effective on January 1, 2025. The statute applies to qualifying businesses meeting specified processing thresholds and provides Iowa consumers with rights involving access, deletion of personal data provided by the consumer, portability, and opting out of sale. The law also imposes controller and processor duties involving privacy notices, security practices, sensitive data, vendor contracts, and nondiscrimination. Iowa’s definitions and rights do not match every other state privacy statute, so national organizations should avoid assuming a single state-law template automatically satisfies Iowa’s specific requirements.
Question 392. How long does an Iowa controller generally have to respond to an authenticated consumer request?
- 30 days
- 90 days, with a possible one-time 45-day extension when reasonably necessary
- 45 days with no extension
- One year
Correct Answer: 2. 90 days, with a possible one-time 45-day extension when reasonably necessary
Explanation:
Iowa differs from many comprehensive state privacy laws by giving controllers a comparatively long initial response period. A controller generally must respond without undue delay and within 90 days of receiving an authenticated request. The period may be extended once by an additional 45 days when reasonably necessary because of the complexity or number of requests, provided the consumer is informed during the original period and receives the reason for the extension. Privacy-rights systems serving multiple states should therefore calculate deadlines according to the applicable jurisdiction rather than using a universal 45-day assumption.
Question 393. What does Iowa law generally require before a controller processes sensitive data for a nonexempt purpose?
- Approval from the Iowa legislature
- Prior written consent in every case
- A court order
- Clear notice and an opportunity for the consumer to opt out, with known-child data handled consistently with COPPA**
Correct Answer: 4. Clear notice and an opportunity for the consumer to opt out, with known-child data handled consistently with COPPA
Explanation:
Iowa’s approach to sensitive data differs from states that require affirmative opt-in consent for all covered sensitive-data processing. Iowa generally requires clear notice and an opportunity for the consumer to opt out before sensitive data is processed for a nonexempt purpose. For sensitive personal data concerning a known child, processing must be handled in accordance with COPPA. Iowa’s sensitive-data definition includes information involving racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, immigration or citizenship status, qualifying biometric and genetic information, known-child data, and precise geolocation.
Question 394. Who has enforcement authority under the Iowa Consumer Data Protection Act?
- The Iowa Attorney General, which has exclusive enforcement authority; the statute does not create a private right of action
- Every consumer through automatic statutory damages
- Only the Federal Trade Commission
- Individual county governments
Correct Answer: 1. The Iowa Attorney General, which has exclusive enforcement authority; the statute does not create a private right of action
Explanation:
The Iowa Attorney General has exclusive authority to enforce the state’s comprehensive privacy statute. Before initiating an action, the Attorney General generally provides 90 days’ written notice identifying the alleged violation. If the controller or processor cures the violation and provides the required written statement, an enforcement action will not proceed on that basis. If the violation continues or the organization breaches its written cure statement, civil penalties of up to $7,500 per violation may be sought. Iowa expressly states that the law does not create a private right of action.
Question 395. Which processing threshold can bring a New Hampshire business within the state’s comprehensive privacy law?
- Processing data of any single New Hampshire consumer
- Processing 1,000 consumers regardless of business activity
- Processing at least 35,000 unique consumers, excluding data processed solely to complete payment transactions, or meeting the alternative statutory threshold
- Having any employee in New Hampshire
Correct Answer: 3. Processing at least 35,000 unique consumers, excluding data processed solely to complete payment transactions, or meeting the alternative statutory threshold
Explanation:
New Hampshire’s privacy law applies to businesses that meet specified processing thresholds. One pathway covers entities that control or process personal data of at least 35,000 unique consumers during a one-year period, excluding personal data processed solely for payment transactions. Another pathway covers entities processing at least 10,000 unique consumers while deriving more than 25% of gross revenue from the sale of personal data. Applicability also depends on conducting business in New Hampshire or producing products or services targeted to state residents, and statutory exclusions must also be considered.
Question 396. How quickly must a New Hampshire controller generally respond to a consumer’s appeal after refusing a privacy-rights request?
- Seven days
- No later than 60 days after receiving the appeal
- One year
- Only after the Attorney General requests a response
Correct Answer: 2. No later than 60 days after receiving the appeal
Explanation:
New Hampshire requires controllers to provide consumers with a process for appealing refusals to take action on privacy-rights requests. The appeals process must be conspicuously available and generally similar to the method used for initial rights requests. No later than 60 days after receiving the appeal, the controller must provide a written response explaining the action taken or not taken and the reasons. If the appeal remains denied, the controller must also provide a mechanism through which the consumer can contact the New Hampshire Attorney General to submit a complaint.
Question 397. Beginning January 1, 2026, what is true of cure opportunities before New Hampshire privacy enforcement?
- Every controller is automatically guaranteed a permanent 60-day cure period
- Cure periods were completely prohibited
- Only consumers may decide whether a cure is available
- The Attorney General may decide whether to provide a cure opportunity based on statutory factors such as the number of violations, business complexity, and likelihood of public injury**
Correct Answer: 4. The Attorney General may decide whether to provide a cure opportunity based on statutory factors such as the number of violations, business complexity, and likelihood of public injury
Explanation:
During 2025, New Hampshire generally required the Attorney General to provide notice and a 60-day opportunity to cure when the violation was considered curable. Beginning January 1, 2026, that guaranteed structure changed. The Attorney General may now consider factors including the number of violations, the size and complexity of the controller or processor, processing activities, likelihood of public injury, safety concerns, and whether the problem resulted from human or technical error when deciding whether to offer an opportunity to cure. The Attorney General retains exclusive enforcement authority.
Question 398. Which right is provided to Nebraska consumers under the Nebraska Data Privacy Act?
- A right to require every business to disclose trade secrets
- A right to opt out of targeted advertising, sale of personal data, and specified profiling
- A right to demand deletion of every legally required record
- A right to prevent all cybersecurity processing
Correct Answer: 2. A right to opt out of targeted advertising, sale of personal data, and specified profiling
Explanation:
Nebraska’s Data Privacy Act became effective January 1, 2025 and gives consumers several rights over qualifying personal data. These include confirming whether a controller processes or has access to personal data, correction, deletion, certain portable copies, and opt-outs from targeted advertising, sale, and profiling based on personal data. The statute’s consumer definition generally covers Nebraska residents acting in individual or household contexts and excludes employment or commercial contexts. Consumers generally must first use the controller’s request and appeal process before escalating a complaint to the Nebraska Attorney General.
Question 399. When did the Rhode Island Data Transparency and Privacy Protection Act become effective?
- January 1, 2026
- January 1, 2024
- July 1, 2027
- January 1, 2030
Correct Answer: 1. January 1, 2026
Explanation:
Rhode Island’s Data Transparency and Privacy Protection Act became effective January 1, 2026. The statute establishes customer privacy rights and controller and processor responsibilities for qualifying businesses. Its main consumer-rights provisions generally apply to for-profit entities that meet specified processing thresholds, such as controlling or processing personal data of at least 35,000 customers or processing at least 10,000 customers while deriving more than 20% of gross revenue from personal-data sales. The law also contains exclusions for categories such as financial institutions and data subject to GLBA, HIPAA information, and certain tax-exempt organizations.
Question 400. A financial technology company is an SEC-registered investment adviser, is also subject to Iowa and Nebraska consumer privacy laws for separate activities, and experiences a vendor-related data incident. What is the BEST compliance approach?
- Follow only Regulation S-P because federal securities rules automatically preempt all state privacy laws
- Notify only the vendor and take no independent action
- Map the company’s legal roles, incident scope, affected customers and consumers, and applicable federal and state duties, then coordinate Regulation S-P incident response and notification with any state-law privacy and breach obligations
- Wait until a regulator identifies which law should apply
Correct Answer: 3. Map the company’s legal roles, incident scope, affected customers and consumers, and applicable federal and state duties, then coordinate Regulation S-P incident response and notification with any state-law privacy and breach obligations
Explanation:
Privacy obligations can overlap even within one organization. An SEC-registered investment adviser may be subject to Regulation S-P’s incident-response, customer-notification, vendor-oversight, and recordkeeping requirements. Separate consumer-facing activities can also create obligations under applicable state comprehensive privacy laws, and a security incident may trigger additional state breach-notification statutes. Outsourcing systems to a vendor does not eliminate the regulated institution’s responsibilities. A mature response therefore identifies which information and individuals were affected, which regulatory roles the company holds, which deadlines apply, and how notifications and remediation can be coordinated without assuming one law automatically displaces all others.