View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 81. Under the FTC Act, when is a practice generally considered “unfair”?
- Whenever a consumer dislikes the practice
- Whenever a business earns a profit from consumer information
- Whenever the practice is not specifically described in a privacy notice
- When it causes or is likely to cause substantial consumer injury that is not reasonably avoidable and is not outweighed by countervailing benefits
Correct Answer: 4. When it causes or is likely to cause substantial consumer injury that is not reasonably avoidable and is not outweighed by countervailing benefits
Explanation:
The FTC’s unfairness framework focuses principally on consumer injury. A practice may be considered unfair when it causes or is likely to cause substantial injury to consumers, the injury is not reasonably avoidable by consumers themselves, and the harm is not outweighed by countervailing benefits to consumers or competition. A trivial or merely speculative harm will not ordinarily satisfy the substantial-injury requirement. Privacy and security practices can therefore create unfairness concerns even when a company has not made an explicitly false promise, provided the statutory injury-based requirements are satisfied.
Question 82. Which factor would make an FTC unfairness claim LESS likely?
- Consumers could not understand or avoid the harm before it occurred
- Consumers could reasonably avoid the alleged injury through an informed and meaningful choice
- The practice caused substantial financial loss
- The practice provided no offsetting consumer benefit
Correct Answer: 2. Consumers could reasonably avoid the alleged injury through an informed and meaningful choice
Explanation:
One element of the FTC unfairness standard asks whether consumers could reasonably avoid the injury. If consumers have meaningful information and a practical opportunity to make a choice that prevents the harm, an unfairness theory may be more difficult to establish. By contrast, consumers may be unable to reasonably avoid harm when a company withholds important information, changes practices after the transaction, or creates risks that consumers cannot realistically detect or prevent. The FTC evaluates this element along with substantial injury and countervailing benefits rather than treating consumer choice as an isolated factor.
Question 83. Under the FTC deception standard, why is “materiality” important?
- A representation or omission is material when it is likely to affect a consumer’s conduct or decision regarding a product or service
- Materiality means the statement must be written on paper
- Only statements involving more than $500 are material
- A deceptive statement must always involve physical injury
Correct Answer: 1. A representation or omission is material when it is likely to affect a consumer’s conduct or decision regarding a product or service
Explanation:
The FTC considers materiality when determining whether a representation, omission, or practice is deceptive. A matter is material when it is likely to affect the consumer’s choice or conduct concerning a product or service. Certain claims may be presumed material because of their nature, while other situations require evidence showing that consumers would likely have behaved differently if the truth had been known. In privacy matters, representations about sensitive-data collection, sharing, security, or confidentiality can be significant because they may influence whether consumers choose to use a service or disclose information.
Question 84. When determining whether a practice is deceptive, from whose perspective does the FTC generally evaluate whether it is likely to mislead?
- Only the company’s legal department
- The company’s most sophisticated customer
- A consumer acting reasonably under the circumstances, including the relevant target audience when appropriate
- Only a federal judge
Correct Answer: 3. A consumer acting reasonably under the circumstances, including the relevant target audience when appropriate
Explanation:
The FTC deception analysis considers how a consumer acting reasonably under the circumstances would understand the representation, omission, or practice. When a claim is aimed primarily at a particular audience, the Commission evaluates reasonableness from the perspective of that group. This prevents businesses from defending misleading practices merely because an unusually sophisticated person might discover their true meaning. Context matters: wording, placement, disclosures, audience characteristics, and the overall impression can all affect the analysis. The FTC also requires that the misleading matter be material before treating the conduct as deceptive.
Question 85. What is the PRIMARY objective of the federal Freedom of Information Act (FOIA)?
- To give private companies ownership of federal agency records
- To increase public access to federal government agency information, subject to statutory exemptions
- To prevent individuals from requesting records about themselves
- To regulate private-sector privacy notices
Correct Answer: 2. To increase public access to federal government agency information, subject to statutory exemptions
Explanation:
FOIA is fundamentally a government-transparency statute. It provides a mechanism for members of the public to request federal agency records, subject to nine statutory exemptions and other limitations. DOJ guidance contrasts FOIA’s disclosure-oriented purpose with the Privacy Act, which focuses more specifically on federal agencies’ collection, maintenance, use, disclosure, and individual access regarding records about people. FOIA does not mean every federal record must be released. Agencies may withhold information protected by exemptions involving matters such as personal privacy, national security, confidential business information, privileged communications, and law-enforcement interests.
Question 86. Which information is MOST directly addressed by FOIA Exemption 6?
- Every confidential business trade secret
- Classified military information
- Geological information concerning wells
- Personnel, medical, and similar files whose disclosure would constitute a clearly unwarranted invasion of personal privacy
Correct Answer: 4. Personnel, medical, and similar files whose disclosure would constitute a clearly unwarranted invasion of personal privacy
Explanation:
FOIA Exemption 6 protects personal privacy in personnel, medical, and similar files when disclosure would constitute a clearly unwarranted invasion of personal privacy. Application of the exemption generally involves identifying the individual’s privacy interest and balancing it against the public interest in disclosure. The relevant FOIA public interest centers on shedding light on government activities rather than satisfying curiosity about private individuals. Exemption 6 is distinct from exemptions protecting classified information, trade secrets, law-enforcement methods, or financial-institution examination materials, each of which has its own statutory basis.
Question 87. What distinguishes FOIA Exemption 7(C) from Exemption 6?
- Exemption 7(C) specifically applies to information compiled for law-enforcement purposes and protects against unwarranted invasions of personal privacy
- Exemption 7(C) applies only to corporate trade secrets
- Exemption 7(C) protects every record held by a private employer
- Exemption 7(C) applies only to medical records
Correct Answer: 1. Exemption 7(C) specifically applies to information compiled for law-enforcement purposes and protects against unwarranted invasions of personal privacy
Explanation:
Exemption 7(C) is the principal FOIA privacy exemption for qualifying law-enforcement records. It permits withholding information compiled for law-enforcement purposes when disclosure could reasonably be expected to constitute an unwarranted invasion of personal privacy. Exemption 6, by comparison, applies to personnel, medical, and similar files and uses the “clearly unwarranted” privacy standard. Law-enforcement records can create substantial privacy interests because identifying someone in an investigation may expose that person to stigma, harassment, retaliation, or unsupported assumptions about involvement in wrongdoing.
Question 88. Which statement BEST describes who may generally submit a FOIA request compared with who receives Privacy Act access rights?
- Only U.S. citizens can use either statute
- Only government employees can use FOIA
- FOIA generally allows any person to request agency records, while Privacy Act access rights generally apply to U.S. citizens and lawful permanent residents covered by its definition of “individual”
- The Privacy Act gives access rights only to corporations
Correct Answer: 3. FOIA generally allows any person to request agency records, while Privacy Act access rights generally apply to U.S. citizens and lawful permanent residents covered by its definition of “individual”
Explanation:
FOIA and the Privacy Act have overlapping but different access structures. Under FOIA, a request for agency records can generally be made by any person, including organizations and individuals who are not U.S. citizens. Privacy Act access rights are narrower because the statute’s definition of “individual” generally covers U.S. citizens and lawful permanent residents. When someone seeks records about themselves from a federal agency, both statutes can sometimes be relevant, and agencies may need to analyze access under each. Understanding the distinction helps privacy professionals avoid treating FOIA and the Privacy Act as interchangeable federal records laws.
Question 89. Why is Griswold v. Connecticut important to U.S. privacy law?
- The Supreme Court recognized an implied constitutional privacy right in invalidating a law restricting contraceptive use by married couples
- The Court created the FTC
- The Court enacted the Privacy Act of 1974
- The Court established the Fair Credit Reporting Act
Correct Answer: 1. The Supreme Court recognized an implied constitutional privacy right in invalidating a law restricting contraceptive use by married couples
Explanation:
Griswold v. Connecticut is a foundational constitutional privacy case. The Supreme Court invalidated a Connecticut restriction on contraceptive use by married couples and reasoned that protections contained in several constitutional amendments created implied zones or “penumbras” of privacy. The Constitution does not expressly contain a general textual right labeled “privacy,” so Griswold became significant for recognizing privacy through constitutional structure and precedent. Constitutional privacy doctrine has evolved through later decisions and remains legally contested in some areas, so privacy professionals should distinguish constitutional rights from statutory private-sector privacy protections such as HIPAA or the FCRA.
Question 90. What is central to the reasonable-expectation-of-privacy test associated with Katz v. United States?
- Whether a company published a privacy policy
- Whether a person has both an actual expectation of privacy and an expectation society recognizes as reasonable
- Whether information is encrypted
- Whether the government owns the property being searched
Correct Answer: 4. Whether a person has both an actual expectation of privacy and an expectation society recognizes as reasonable
Explanation:
The reasonable-expectation-of-privacy framework associated with Katz became central to Fourth Amendment analysis. The familiar formulation asks whether the person exhibited an actual, subjective expectation of privacy and whether that expectation is one society is prepared to recognize as reasonable. Katz also helped move Fourth Amendment analysis beyond rigid dependence on physical trespass or property ownership, reinforcing the principle that the Amendment protects people rather than simply places. The doctrine concerns governmental searches and seizures, making it fundamentally different from many statutory privacy duties imposed on private companies.
Question 91. Which scenario BEST illustrates the privacy tort of intrusion upon seclusion?
- A newspaper accurately reports a public court decision
- Someone intentionally installs unauthorized surveillance to observe another person in a setting where that person reasonably expects privacy
- A company uses someone’s photograph with the person’s permission
- A government agency releases a properly redacted FOIA record
Correct Answer: 2. Someone intentionally installs unauthorized surveillance to observe another person in a setting where that person reasonably expects privacy
Explanation:
Intrusion upon seclusion concerns intentional intrusion into another person’s private affairs or solitude in a manner that would be offensive to a reasonable person. Examples can include unauthorized electronic surveillance, wiretapping, eavesdropping, physical intrusion, or exceeding the scope of consent to obtain private information. Importantly, the plaintiff need not necessarily show that the information obtained was later published to others; the offensive intrusion itself can support the claim. State law governs privacy torts, so precise elements can vary by jurisdiction, but intentional invasion of a genuinely private matter is central to the concept.
Question 92. Which fact is LEAST necessary for an intrusion-upon-seclusion claim?
- Intentional intrusion into a private matter
- A reasonable expectation of privacy
- Publication of the obtained information to the general public
- An intrusion offensive to a reasonable person
Correct Answer: 3. Publication of the obtained information to the general public
Explanation:
Intrusion upon seclusion focuses on the act of invading a person’s private affairs, not on subsequent publication. An unauthorized wiretap or hidden-camera recording can potentially constitute intrusion even if the defendant never distributes the resulting information. The claim generally considers whether the plaintiff had a reasonable expectation of privacy, whether the defendant intentionally invaded a private matter without authorization, and whether the intrusion would be offensive to a reasonable person. This distinguishes intrusion from other privacy tort theories that focus more directly on public disclosure or misuse of personal identity.
Question 93. Which conduct MOST closely describes the privacy tort of appropriation?
- Using another person’s name or likeness without permission for commercial advantage
- Correcting an inaccurate consumer report
- Obtaining a properly issued search warrant
- Destroying personal information according to a retention schedule
Correct Answer: 4. Using another person’s name or likeness without permission for commercial advantage
Explanation:
Appropriation is a privacy tort involving unauthorized use of another person’s name, likeness, or image for commercial benefit or another advantage. A typical claim examines whether the defendant used the plaintiff’s identity without consent and obtained a commercial benefit while causing legally recognized harm. The doctrine overlaps in some jurisdictions with rights of publicity, though precise legal elements differ. Newsworthy and other protected uses may raise defenses. Appropriation is conceptually different from data-access statutes because it addresses exploitation of an individual’s identity rather than ordinary collection, storage, or security of personal information.
Question 94. Under FACTA’s credit-card receipt truncation requirement, what may generally appear on an electronically printed customer receipt?
- The complete card number and expiration date
- No more than the last five digits of the card number, with the expiration date removed
- The first ten digits of the card number
- The complete card number if the merchant prints a privacy notice
Correct Answer: 1. No more than the last five digits of the card number, with the expiration date removed
Explanation:
FACTA includes a receipt-truncation requirement designed to reduce identity-theft risks associated with discarded payment receipts. For electronically printed receipts provided to customers, businesses generally may print no more than the final five digits of the credit or debit card number and must omit the expiration date. The requirement concerns electronically printed customer receipts rather than handwritten or manually imprinted receipts and does not apply identically to the merchant’s own retained records. The rule limits the sensitive payment information available to someone who finds or steals a discarded receipt.
Question 95. What important consumer right did FACTA add to the Fair Credit Reporting Act framework?
- Unlimited deletion of accurate credit information
- A right to prevent lenders from ever reviewing credit information
- A right to one free credit report every year from each nationwide consumer reporting company
- Automatic forgiveness of identity-theft debt
Correct Answer: 3. A right to one free credit report every year from each nationwide consumer reporting company
Explanation:
FACTA amended the FCRA and added several consumer protections, including a statutory right to obtain one free credit report every 12 months from each nationwide credit reporting company. FACTA also introduced or strengthened provisions addressing identity theft, fraud alerts, accuracy, risk-based pricing, and other credit-reporting concerns. Reviewing credit reports allows consumers to identify inaccurate accounts, unfamiliar inquiries, or signs of possible identity theft. The statutory right concerns credit reports rather than automatic removal of accurate negative information or guaranteed changes to credit scores.
Question 96. How long does an initial fraud alert generally remain on a consumer’s credit report?
- Seven years
- Ninety days
- Permanently
- One year
Correct Answer: 2. One year
Explanation:
An initial fraud alert generally lasts for one year and can be renewed. It tells businesses evaluating a new credit account that they should take steps to verify the consumer’s identity before opening the account. An initial fraud alert does not block companies from accessing the credit report in the way a credit freeze can. A person who believes they may be affected by identity theft can place an initial alert, and contacting one of the three nationwide credit bureaus is sufficient because that bureau must notify the other two. Fraud alerts are free.
Question 97. How long does an extended fraud alert generally last for an eligible identity-theft victim?
- Seven years
- One year
- Six months
- Until the next credit application
Correct Answer: 1. Seven years
Explanation:
An extended fraud alert generally remains on a consumer’s credit report for seven years. It is available to individuals who have experienced identity theft and provide the required identity-theft documentation, such as an FTC Identity Theft Report or qualifying police report. Like an initial alert, it instructs businesses to take additional steps to verify identity before granting new credit. An extended alert also provides additional protections, including removal from certain unsolicited credit and insurance marketing lists for five years unless the consumer chooses otherwise. The alert can be renewed with appropriate documentation.
Question 98. What is a major difference between a credit freeze and a fraud alert?
- A fraud alert completely prevents anyone from accessing a credit report
- A credit freeze restricts access to the credit file, while a fraud alert generally permits access but tells businesses to verify the consumer’s identity
- Credit freezes are available only after a court judgment
- Fraud alerts always last longer than freezes
Correct Answer: 4. A credit freeze restricts access to the credit file, while a fraud alert generally permits access but tells businesses to verify the consumer’s identity
Explanation:
A credit freeze and a fraud alert are both identity-theft tools, but they work differently. A freeze restricts prospective creditors and others from accessing the credit file for new-account purposes until the consumer lifts or removes the freeze, subject to legal exceptions. A fraud alert does not block report access; instead, it tells businesses that they should verify the consumer’s identity before extending new credit. The appropriate option depends on the consumer’s circumstances. Both are available without charge, and fraud alerts are offered in initial and extended forms with different durations.
Question 99. A person asks a federal agency for records about themselves that may be covered by both FOIA and the Privacy Act. What should the agency generally recognize?
- The requester must choose one statute and permanently waive the other
- Only FOIA can ever apply to first-party records requests
- The agency may need to evaluate the individual’s access rights under both statutes
- The Privacy Act automatically eliminates FOIA rights
Correct Answer: 2. The agency may need to evaluate the individual’s access rights under both statutes
Explanation:
FOIA and the Privacy Act have distinct but overlapping access provisions. When an individual seeks federal agency records about themselves, the records may qualify for access analysis under both statutes. DOJ guidance explains that agencies processing these first-party requests often need to consider both frameworks rather than requiring the requester to elect only one. The statutes differ in their definitions, exemptions, requester eligibility, and purposes. FOIA emphasizes public access to government records, while the Privacy Act focuses on agency handling of identifiable records about individuals and provides access rights to qualifying individuals.
Question 100. A privacy team is assessing a federal-facing service that makes consumer representations, handles credit-report data, and responds to government-record requests. What is the BEST compliance approach?
- Apply only the FTC Act because it overrides every other privacy law
- Treat all records as public once a federal agency is involved
- Ignore consumer-report rules if the company has a privacy policy
- Map each activity separately and apply the relevant FTC, FCRA/FACTA, FOIA, Privacy Act, and constitutional or other rules according to the actor and information involved
Correct Answer: 3. Map each activity separately and apply the relevant FTC, FCRA/FACTA, FOIA, Privacy Act, and constitutional or other rules according to the actor and information involved
Explanation:
U.S. privacy obligations often depend on the actor, information, purpose, and legal context. Consumer-facing representations may raise FTC deception or unfairness concerns, credit-report information can trigger FCRA and FACTA requirements, and federal records requests may require analysis under FOIA and the Privacy Act. Constitutional privacy protections generally address government action rather than functioning as ordinary private-sector notice rules. A mature privacy program therefore maps information flows and legal roles before deciding which requirements apply. Relying on one statute or one privacy notice across all activities can miss obligations created by the United States’ overlapping privacy framework.