IAPP CIPP-US Practice Test Questions and Exam Dumps Part6 Q101-120

View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.


Question 101. Which California resident is generally within the scope of CCPA consumer privacy rights?

  1. Only individuals purchasing products for household use
  2. A California employee or job applicant whose personal information is handled by a covered business
  3. Only individuals who have created an online account
  4. Only consumers who purchase more than $500 of goods annually

Correct Answer: 2. A California employee or job applicant whose personal information is handled by a covered business

Explanation:

The CCPA provides privacy rights to California residents, and current California guidance confirms that this includes residents acting as employees or job applicants, as well as contacts for business customers, vendors, and independent contractors. This is broader than some other state comprehensive privacy laws, which commonly define “consumer” to exclude individuals acting in employment contexts. Covered California businesses therefore need to consider CCPA obligations across several personal-information populations rather than focusing only on retail customers. Applicability still depends on whether the organization itself satisfies the CCPA’s coverage requirements and whether another statutory exemption applies.

Question 102. Which item is specifically identified as sensitive personal information under the CCPA?

  1. A consumer’s favorite movie
  2. A publicly listed business telephone number
  3. An ordinary product SKU
  4. A consumer’s precise geolocation

Correct Answer: 4. A consumer’s precise geolocation

Explanation:

California treats certain categories of personal information as sensitive personal information. Examples include Social Security and driver’s license numbers, precise geolocation, certain financial account credentials, genetic data, biometric information used for identification, contents of certain communications, and information revealing matters such as health, sexual orientation, racial or ethnic origin, religious beliefs, or union membership. The distinction matters because California consumers may have a right to limit particular uses and disclosures of sensitive personal information. Privacy professionals should therefore classify data carefully instead of treating all personal information as subject to identical operational requirements.

Question 103. What is the purpose of an opt-out preference signal under the CCPA?

  1. To automatically communicate a consumer’s choice to opt out of sale or sharing through a technical signal
  2. To authorize every website to collect sensitive information
  3. To create a consumer account with every business visited
  4. To request deletion of all government records

Correct Answer: 1. To automatically communicate a consumer’s choice to opt out of sale or sharing through a technical signal

Explanation:

An opt-out preference signal allows a consumer to communicate an opt-out choice automatically through technology such as a browser setting or extension. California recognizes such signals as a way for consumers to exercise their right to opt out of the sale or sharing of personal information. Global Privacy Control is a common example. This reduces the need for consumers to locate and use a separate opt-out interface on every website. Businesses subject to the relevant CCPA requirements must process valid signals in accordance with the statute and regulations rather than simply ignoring the technical expression of the consumer’s preference.

Question 104. What does the CCPA right to limit primarily allow a consumer to do?

  1. Require a business to stop all processing of every category of information
  2. Force deletion of every legally required business record
  3. Direct a covered business to restrict certain uses and disclosures of sensitive personal information
  4. Prevent a business from responding to law-enforcement requests

Correct Answer: 3. Direct a covered business to restrict certain uses and disclosures of sensitive personal information

Explanation:

California’s right to limit applies to sensitive personal information when a business uses or discloses that information for purposes beyond specified permitted uses. Covered businesses may need to provide consumers with a clear method to exercise this right, such as a “Limit the Use of My Sensitive Personal Information” or combined privacy-choices link. The right does not amount to an unrestricted ability to prohibit every use of sensitive data. Certain uses necessary to provide requested goods or services, maintain security, or satisfy other recognized purposes may remain permitted under the CCPA framework.

Question 105. A business denies part of a California consumer’s deletion request because a statutory exception applies. What should the business generally do with the remaining information not covered by the exception?

  1. Keep all information because any partial denial defeats the whole request
  2. Sell the remaining information before deleting it
  3. Require the consumer to submit a completely new request
  4. Delete the information that is not subject to the exception and explain the basis for the partial denial

Correct Answer: 4. Delete the information that is not subject to the exception and explain the basis for the partial denial

Explanation:

California regulations contemplate partial denial of deletion requests. When a valid exception applies to some information, the business should explain the basis for the denial and still delete personal information that is not covered by that exception. The retained information should not be repurposed beyond what the exception permits. Businesses should also appropriately instruct service providers and contractors regarding deletion of information not subject to the exception. This illustrates an important privacy-practice principle: a valid basis to retain one category of information does not automatically justify retaining all personal information associated with the consumer.

Question 106. Which right is expressly provided to Colorado consumers under the Colorado Privacy Act (CPA)?

  1. The right to access, correct, and delete qualifying personal data
  2. The right to require every company to stop operating in Colorado
  3. The right to demand unlimited free copies of all company records
  4. The right to prohibit all fraud-prevention processing

Correct Answer: 1. The right to access, correct, and delete qualifying personal data

Explanation:

The Colorado Privacy Act gives qualifying Colorado consumers several rights over their personal data. These include rights to access, correct, delete, and obtain data in a portable form, along with rights to opt out of the sale of personal data, targeted advertising, and certain forms of profiling. The rights are subject to statutory scope, exceptions, authentication, and other requirements. Colorado’s law also places obligations on controllers, including privacy notices, safeguards, data protection assessments in specified circumstances, and consent requirements for sensitive data. The CPA took effect on July 1, 2023.

Question 107. Does the Colorado Privacy Act generally treat an employee acting in an employment context as a “consumer”?

  1. Yes, every worker automatically receives CPA consumer rights against their employer
  2. No, the CPA consumer definition generally excludes individuals acting in an employment context
  3. Yes, but only if the employee works remotely
  4. Only if the employee has been employed for more than one year

Correct Answer: 2. No, the CPA consumer definition generally excludes individuals acting in an employment context

Explanation:

Colorado’s CPA protects residents acting in an individual or household context and generally excludes individuals acting in employment contexts, such as employees and job applicants. Colorado’s Attorney General also explains that data maintained for employment-record purposes is outside the CPA’s ordinary consumer framework. This is an important contrast with California, where CCPA privacy rights extend to California employees and job applicants. CIPP/US candidates should avoid assuming that comprehensive state privacy laws use the same definition of “consumer.” Comparing exclusions and covered relationships is often critical when an organization operates across multiple states.

Question 108. Before processing a Colorado consumer’s sensitive personal data, what must a controller generally obtain?

  1. Approval from the FTC
  2. A federal court order
  3. The consumer’s valid consent
  4. Permission from any unrelated third party

Correct Answer: 3. The consumer’s valid consent

Explanation:

The Colorado Privacy Act generally requires affirmative consent before a controller processes sensitive personal data. Colorado’s privacy rules emphasize that valid consent should be affirmative, freely given, specific, informed, and unambiguous. Broad acceptance of general terms, passive interaction with a webpage, or consent obtained through deceptive interface design does not necessarily satisfy the CPA standard. Colorado also requires consent in certain situations involving secondary uses of personal information or renewed processing after a consumer has opted out of targeted advertising or sale. Controllers should therefore design consent as a meaningful choice rather than as a hidden contractual formality.

Question 109. Which universal opt-out mechanism is currently recognized by the Colorado Department of Law for CPA enforcement purposes?

  1. Global Privacy Control (GPC)
  2. Do Not Track exclusively
  3. A handwritten letter sent to every website
  4. A credit freeze

Correct Answer: 1. Global Privacy Control (GPC)

Explanation:

Colorado recognizes Global Privacy Control as a valid universal opt-out mechanism under the CPA and its implementing rules. GPC sends a browser-based privacy signal communicating that the consumer wishes to opt out of qualifying sale of personal data or processing for targeted advertising. Since July 1, 2024, covered controllers have been required to accept qualifying universal opt-out requests. Colorado’s framework aims to reduce the burden of requiring consumers to visit each controller individually to exercise the same preference. The Department may update its list of recognized mechanisms over time, so organizations should monitor current regulatory guidance.

Question 110. Why does the Colorado Privacy Act require data protection assessments for certain processing activities?

  1. To automatically transfer ownership of personal data to the consumer
  2. To replace every organization’s information security program
  3. To permit businesses to avoid all consumer requests
  4. To evaluate and document privacy risks associated with higher-risk processing activities

Correct Answer: 4. To evaluate and document privacy risks associated with higher-risk processing activities

Explanation:

Colorado requires data protection assessments for certain processing activities presenting heightened risk to consumers. Relevant activities can include sensitive-data processing, targeted advertising, sale of personal data, and specified profiling. The assessment process helps controllers identify potential harms, consider safeguards, evaluate benefits, and document whether processing should proceed as designed. Colorado was an early state to issue detailed rules governing these assessments under a comprehensive state privacy law. Assessments are therefore a proactive accountability mechanism rather than merely a response to a complaint or enforcement action after harm occurs.

Question 111. Under the Connecticut Data Privacy Act (CTDPA), what primarily distinguishes a controller from a processor?

  1. A controller must always be larger than a processor
  2. A processor must be a nonprofit organization
  3. A controller determines purposes and means of processing, while a processor acts on the controller’s direction
  4. A processor owns all personal information it handles

Correct Answer: 3. A controller determines purposes and means of processing, while a processor acts on the controller’s direction

Explanation:

The distinction between controllers and processors centers on decision-making authority. Under Connecticut’s law, a controller determines why and how personal data is processed, while a processor handles personal data at the direction of a controller and is contractually bound by those instructions. A processor that begins independently determining processing purposes or means may become a controller for that activity and assume corresponding legal obligations. This controller-processor structure appears in several state comprehensive privacy laws and helps allocate responsibility between organizations that make substantive decisions about personal data and vendors performing services on their behalf.

Question 112. How long does a Connecticut controller generally have to respond to a consumer rights request under the CTDPA?

  1. 10 days
  2. 45 days, with a possible additional 45-day extension under specified conditions
  3. 180 days with no extensions
  4. One year

Correct Answer: 2. 45 days, with a possible additional 45-day extension under specified conditions

Explanation:

The CTDPA generally requires controllers to respond to qualifying consumer-rights requests within 45 days after receiving them. Under certain conditions, the controller can extend the response period by an additional 45 days. Request-response procedures are a major operational component of comprehensive state privacy laws, requiring businesses to authenticate requests, locate responsive personal data, apply exceptions, and communicate results within statutory timelines. Privacy teams should build repeatable request-management workflows rather than handling each access, deletion, correction, or portability request informally. Connecticut generally permits a consumer to make certain information requests free of charge once every 12 months.

Question 113. A Connecticut controller denies a consumer’s privacy-rights request. What additional right does the CTDPA provide to the consumer?

  1. Automatic statutory damages
  2. Immediate access to the controller’s internal legal advice
  3. Automatic deletion of all data
  4. A right to appeal the controller’s decision

Correct Answer: 4. A right to appeal the controller’s decision

Explanation:

Connecticut consumers may appeal a controller’s refusal to honor a privacy-rights request. The controller generally must respond to the appeal within 60 days and explain the actions taken or reasons for continuing to deny the request. If the controller denies the appeal, it must provide information explaining how the consumer can contact the Connecticut Attorney General to submit a complaint. The appeals mechanism gives consumers a structured way to challenge a controller’s initial decision without immediately relying on litigation. State privacy laws differ in their request and appeals procedures, so organizations should configure workflows according to each applicable jurisdiction.

Question 114. Who has enforcement authority under the Connecticut Data Privacy Act?

  1. Every individual consumer through a general private right of action
  2. The Connecticut Attorney General, with no general private cause of action under the CTDPA
  3. Only the Federal Trade Commission
  4. Only local city governments

Correct Answer: 2. The Connecticut Attorney General, with no general private cause of action under the CTDPA

Explanation:

The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA. The statute does not create a general private cause of action allowing individual consumers to sue directly for violations of the comprehensive privacy law itself. Connecticut indicates that violations may result in civil penalties under the state’s unfair trade practices framework, along with remedies such as injunctive relief, restitution, or disgorgement. This enforcement structure is important for exam purposes because state comprehensive privacy laws differ in available remedies and enforcement mechanisms. A consumer right does not necessarily imply an individual right to bring a private lawsuit.

Question 115. Under the CTDPA, what is generally required before a controller sells the personal data of a consumer under 16 or processes it for targeted advertising?

  1. Opt-in consent
  2. Only a privacy-policy update
  3. No special requirement applies to minors
  4. Consent from the controller’s advertising partner

Correct Answer: 1. Opt-in consent

Explanation:

Connecticut provides enhanced protections for younger consumers. The Attorney General’s guidance explains that controllers must obtain opt-in consent before selling personal data or processing personal data for targeted advertising when the consumer is under 16. Separate COPPA obligations also apply when a child under 13 is involved and the federal law’s coverage requirements are satisfied. Connecticut additionally provides protections for minors under 18 interacting with online services, products, or features. Privacy teams serving teenagers should therefore not assume that COPPA’s under-13 threshold is the only age-related rule relevant to online data practices.

Question 116. Which CTDPA obligation BEST reflects the privacy principle of data minimization?

  1. Keep every category of personal information indefinitely
  2. Sell unused information to offset storage costs
  3. Limit collection to personal data that is adequate, relevant, and reasonably necessary for the specified processing purposes
  4. Collect all potentially useful information before deciding why it is needed

Correct Answer: 3. Limit collection to personal data that is adequate, relevant, and reasonably necessary for the specified processing purposes

Explanation:

The CTDPA requires controllers to limit personal-data collection to information that is adequate, relevant, and reasonably necessary for the purposes for which the information is processed. This reflects the privacy principle commonly known as data minimization. Collecting information “just in case” it might someday be useful can increase privacy and security risk and may conflict with statutory purpose limitations. Connecticut also restricts processing for materially new purposes that are neither reasonably necessary to nor compatible with the disclosed purpose unless appropriate consent is obtained. Data minimization should therefore be incorporated into product and system design rather than treated only as a retention issue.

Question 117. Under the Virginia Consumer Data Protection Act (VCDPA), what is generally required before a controller processes a consumer’s sensitive data?

  1. The consumer’s consent
  2. Approval from the Virginia legislature
  3. A credit report
  4. Only an internal manager’s authorization

Correct Answer: 2. The consumer’s consent

Explanation:

Virginia’s VCDPA requires controllers to obtain consumer consent before processing sensitive personal data. Virginia’s definition includes categories such as racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, certain genetic or biometric data used for unique identification, precise geolocation, and personal data collected from a known child. These categories receive additional protection because misuse can create particularly serious privacy risks. Controllers should therefore identify sensitive data in their inventories and ensure that consent processes occur before covered processing begins instead of merely describing sensitive-data practices after collection.

Question 118. How quickly must a Virginia controller generally respond to a consumer request under the VCDPA?

  1. 45 days, with a possible additional 45-day extension when appropriate
  2. Seven days without extension
  3. Six months
  4. Only after the consumer files a lawsuit

Correct Answer: 1. 45 days, with a possible additional 45-day extension when appropriate

Explanation:

Virginia controllers generally must respond to consumer privacy-rights requests within 45 days. When reasonably necessary, the response period can be extended by an additional 45 days, with appropriate notice to the consumer. Virginia consumers can exercise rights such as accessing, correcting, deleting, and obtaining certain personal data, as well as opting out of certain processing. Controllers may also need additional information to authenticate the consumer or request. Because request deadlines can vary by jurisdiction, national organizations should use structured case-management procedures capable of applying the correct timing rules to each consumer request.

Question 119. What enforcement consequence can follow an uncured VCDPA violation?

  1. Automatic imprisonment of the company’s privacy officer
  2. Permanent revocation of every business license in the United States
  3. Automatic deletion of the controller’s databases
  4. The Virginia Attorney General may seek civil penalties of up to $7,500 for each violation

Correct Answer: 4. The Virginia Attorney General may seek civil penalties of up to $7,500 for each violation

Explanation:

The Virginia Attorney General enforces the VCDPA. Current Virginia guidance states that when the Attorney General notifies a controller or processor of a violation, the entity has 30 days to provide written confirmation that the violation has been cured. If the organization fails to cure the violation within the applicable period, the Attorney General may bring an enforcement action and seek civil penalties of up to $7,500 per violation, in addition to other available relief. Privacy professionals should therefore treat consumer-rights operations and sensitive-data requirements as enforceable legal duties rather than voluntary best practices.

Question 120. A national online retailer serves consumers in California, Colorado, Connecticut, and Virginia. What is the BEST approach to state comprehensive privacy-law compliance?

  1. Apply only California law because it was enacted first
  2. Assume every state law has exactly the same definitions, rights, exclusions, and consent rules
  3. Map applicable jurisdictions and data practices, then build a privacy program that satisfies the relevant rights, opt-outs, consent requirements, assessments, notices, and state-specific differences
  4. Wait until each state attorney general issues an enforcement letter before implementing privacy controls

Correct Answer: 3. Map applicable jurisdictions and data practices, then build a privacy program that satisfies the relevant rights, opt-outs, consent requirements, assessments, notices, and state-specific differences

Explanation:

State comprehensive privacy laws share many concepts, but they are not identical. California includes employees and job applicants within its consumer rights framework, while Colorado and Connecticut generally exclude employment contexts. Consent rules, universal opt-out requirements, response procedures, enforcement mechanisms, and sensitive-data definitions can also differ. A national business should therefore map where consumers reside, what data it processes, its purposes and disclosures, and which statutes apply. It can then build common controls where laws overlap while preserving jurisdiction-specific logic where necessary. Treating every state statute as identical risks both under-compliance and unnecessary operational restrictions.