{"id":20824,"date":"2026-09-24T07:51:47","date_gmt":"2026-09-24T07:51:47","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20824"},"modified":"2026-09-24T07:51:47","modified_gmt":"2026-09-24T07:51:47","slug":"iapp-cipp-us-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-us-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"IAPP CIPP-US Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-us-exam-dumps\"><b>IAPP CIPP-US Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 101. Which California resident is generally within the scope of CCPA consumer privacy rights?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only individuals purchasing products for household use<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A California employee or job applicant whose personal information is handled by a covered business<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only individuals who have created an online account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only consumers who purchase more than $500 of goods annually<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A California employee or job applicant whose personal information is handled by a covered business<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The CCPA provides privacy rights to California residents, and current California guidance confirms that this includes residents acting as employees or job applicants, as well as contacts for business customers, vendors, and independent contractors. This is broader than some other state comprehensive privacy laws, which commonly define \u201cconsumer\u201d to exclude individuals acting in employment contexts. Covered California businesses therefore need to consider CCPA obligations across several personal-information populations rather than focusing only on retail customers. Applicability still depends on whether the organization itself satisfies the CCPA&#8217;s coverage requirements and whether another statutory exemption applies.<\/span><\/p>\n<p><b>Question 102. Which item is specifically identified as sensitive personal information under the CCPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A consumer&#8217;s favorite movie<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A publicly listed business telephone number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An ordinary product SKU<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A consumer&#8217;s precise geolocation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A consumer&#8217;s precise geolocation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">California treats certain categories of personal information as sensitive personal information. Examples include Social Security and driver&#8217;s license numbers, precise geolocation, certain financial account credentials, genetic data, biometric information used for identification, contents of certain communications, and information revealing matters such as health, sexual orientation, racial or ethnic origin, religious beliefs, or union membership. The distinction matters because California consumers may have a right to limit particular uses and disclosures of sensitive personal information. Privacy professionals should therefore classify data carefully instead of treating all personal information as subject to identical operational requirements.<\/span><\/p>\n<p><b>Question 103. What is the purpose of an opt-out preference signal under the CCPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To automatically communicate a consumer&#8217;s choice to opt out of sale or sharing through a technical signal<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To authorize every website to collect sensitive information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create a consumer account with every business visited<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To request deletion of all government records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To automatically communicate a consumer&#8217;s choice to opt out of sale or sharing through a technical signal<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An opt-out preference signal allows a consumer to communicate an opt-out choice automatically through technology such as a browser setting or extension. California recognizes such signals as a way for consumers to exercise their right to opt out of the sale or sharing of personal information. Global Privacy Control is a common example. This reduces the need for consumers to locate and use a separate opt-out interface on every website. Businesses subject to the relevant CCPA requirements must process valid signals in accordance with the statute and regulations rather than simply ignoring the technical expression of the consumer&#8217;s preference.<\/span><\/p>\n<p><b>Question 104. What does the CCPA right to limit primarily allow a consumer to do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require a business to stop all processing of every category of information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Force deletion of every legally required business record<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct a covered business to restrict certain uses and disclosures of sensitive personal information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent a business from responding to law-enforcement requests<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Direct a covered business to restrict certain uses and disclosures of sensitive personal information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">California&#8217;s right to limit applies to sensitive personal information when a business uses or discloses that information for purposes beyond specified permitted uses. Covered businesses may need to provide consumers with a clear method to exercise this right, such as a \u201cLimit the Use of My Sensitive Personal Information\u201d or combined privacy-choices link. The right does not amount to an unrestricted ability to prohibit every use of sensitive data. Certain uses necessary to provide requested goods or services, maintain security, or satisfy other recognized purposes may remain permitted under the CCPA framework.<\/span><\/p>\n<p><b>Question 105. A business denies part of a California consumer&#8217;s deletion request because a statutory exception applies. What should the business generally do with the remaining information not covered by the exception?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep all information because any partial denial defeats the whole request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sell the remaining information before deleting it<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require the consumer to submit a completely new request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the information that is not subject to the exception and explain the basis for the partial denial<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Delete the information that is not subject to the exception and explain the basis for the partial denial<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">California regulations contemplate partial denial of deletion requests. When a valid exception applies to some information, the business should explain the basis for the denial and still delete personal information that is not covered by that exception. The retained information should not be repurposed beyond what the exception permits. Businesses should also appropriately instruct service providers and contractors regarding deletion of information not subject to the exception. This illustrates an important privacy-practice principle: a valid basis to retain one category of information does not automatically justify retaining all personal information associated with the consumer.<\/span><\/p>\n<p><b>Question 106. Which right is expressly provided to Colorado consumers under the Colorado Privacy Act (CPA)?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to access, correct, and delete qualifying personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to require every company to stop operating in Colorado<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to demand unlimited free copies of all company records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to prohibit all fraud-prevention processing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The right to access, correct, and delete qualifying personal data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Colorado Privacy Act gives qualifying Colorado consumers several rights over their personal data. These include rights to access, correct, delete, and obtain data in a portable form, along with rights to opt out of the sale of personal data, targeted advertising, and certain forms of profiling. The rights are subject to statutory scope, exceptions, authentication, and other requirements. Colorado&#8217;s law also places obligations on controllers, including privacy notices, safeguards, data protection assessments in specified circumstances, and consent requirements for sensitive data. The CPA took effect on July 1, 2023.<\/span><\/p>\n<p><b>Question 107. Does the Colorado Privacy Act generally treat an employee acting in an employment context as a \u201cconsumer\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Yes, every worker automatically receives CPA consumer rights against their employer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No, the CPA consumer definition generally excludes individuals acting in an employment context<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Yes, but only if the employee works remotely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only if the employee has been employed for more than one year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. No, the CPA consumer definition generally excludes individuals acting in an employment context<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Colorado&#8217;s CPA protects residents acting in an individual or household context and generally excludes individuals acting in employment contexts, such as employees and job applicants. Colorado&#8217;s Attorney General also explains that data maintained for employment-record purposes is outside the CPA&#8217;s ordinary consumer framework. This is an important contrast with California, where CCPA privacy rights extend to California employees and job applicants. CIPP\/US candidates should avoid assuming that comprehensive state privacy laws use the same definition of \u201cconsumer.\u201d Comparing exclusions and covered relationships is often critical when an organization operates across multiple states.<\/span><\/p>\n<p><b>Question 108. Before processing a Colorado consumer&#8217;s sensitive personal data, what must a controller generally obtain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approval from the FTC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A federal court order<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The consumer&#8217;s valid consent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permission from any unrelated third party<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The consumer&#8217;s valid consent<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Colorado Privacy Act generally requires affirmative consent before a controller processes sensitive personal data. Colorado&#8217;s privacy rules emphasize that valid consent should be affirmative, freely given, specific, informed, and unambiguous. Broad acceptance of general terms, passive interaction with a webpage, or consent obtained through deceptive interface design does not necessarily satisfy the CPA standard. Colorado also requires consent in certain situations involving secondary uses of personal information or renewed processing after a consumer has opted out of targeted advertising or sale. Controllers should therefore design consent as a meaningful choice rather than as a hidden contractual formality.<\/span><\/p>\n<p><b>Question 109. Which universal opt-out mechanism is currently recognized by the Colorado Department of Law for CPA enforcement purposes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Global Privacy Control (GPC)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Do Not Track exclusively<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A handwritten letter sent to every website<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A credit freeze<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Global Privacy Control (GPC)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Colorado recognizes Global Privacy Control as a valid universal opt-out mechanism under the CPA and its implementing rules. GPC sends a browser-based privacy signal communicating that the consumer wishes to opt out of qualifying sale of personal data or processing for targeted advertising. Since July 1, 2024, covered controllers have been required to accept qualifying universal opt-out requests. Colorado&#8217;s framework aims to reduce the burden of requiring consumers to visit each controller individually to exercise the same preference. The Department may update its list of recognized mechanisms over time, so organizations should monitor current regulatory guidance.<\/span><\/p>\n<p><b>Question 110. Why does the Colorado Privacy Act require data protection assessments for certain processing activities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To automatically transfer ownership of personal data to the consumer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace every organization&#8217;s information security program<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To permit businesses to avoid all consumer requests<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To evaluate and document privacy risks associated with higher-risk processing activities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. To evaluate and document privacy risks associated with higher-risk processing activities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Colorado requires data protection assessments for certain processing activities presenting heightened risk to consumers. Relevant activities can include sensitive-data processing, targeted advertising, sale of personal data, and specified profiling. The assessment process helps controllers identify potential harms, consider safeguards, evaluate benefits, and document whether processing should proceed as designed. Colorado was an early state to issue detailed rules governing these assessments under a comprehensive state privacy law. Assessments are therefore a proactive accountability mechanism rather than merely a response to a complaint or enforcement action after harm occurs.<\/span><\/p>\n<p><b>Question 111. Under the Connecticut Data Privacy Act (CTDPA), what primarily distinguishes a controller from a processor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller must always be larger than a processor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A processor must be a nonprofit organization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller determines purposes and means of processing, while a processor acts on the controller&#8217;s direction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A processor owns all personal information it handles<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A controller determines purposes and means of processing, while a processor acts on the controller&#8217;s direction<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The distinction between controllers and processors centers on decision-making authority. Under Connecticut&#8217;s law, a controller determines why and how personal data is processed, while a processor handles personal data at the direction of a controller and is contractually bound by those instructions. A processor that begins independently determining processing purposes or means may become a controller for that activity and assume corresponding legal obligations. This controller-processor structure appears in several state comprehensive privacy laws and helps allocate responsibility between organizations that make substantive decisions about personal data and vendors performing services on their behalf.<\/span><\/p>\n<p><b>Question 112. How long does a Connecticut controller generally have to respond to a consumer rights request under the CTDPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 10 days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 45 days, with a possible additional 45-day extension under specified conditions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 180 days with no extensions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. 45 days, with a possible additional 45-day extension under specified conditions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The CTDPA generally requires controllers to respond to qualifying consumer-rights requests within 45 days after receiving them. Under certain conditions, the controller can extend the response period by an additional 45 days. Request-response procedures are a major operational component of comprehensive state privacy laws, requiring businesses to authenticate requests, locate responsive personal data, apply exceptions, and communicate results within statutory timelines. Privacy teams should build repeatable request-management workflows rather than handling each access, deletion, correction, or portability request informally. Connecticut generally permits a consumer to make certain information requests free of charge once every 12 months.<\/span><\/p>\n<p><b>Question 113. A Connecticut controller denies a consumer&#8217;s privacy-rights request. What additional right does the CTDPA provide to the consumer?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic statutory damages<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Immediate access to the controller&#8217;s internal legal advice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic deletion of all data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A right to appeal the controller&#8217;s decision<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A right to appeal the controller&#8217;s decision<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connecticut consumers may appeal a controller&#8217;s refusal to honor a privacy-rights request. The controller generally must respond to the appeal within 60 days and explain the actions taken or reasons for continuing to deny the request. If the controller denies the appeal, it must provide information explaining how the consumer can contact the Connecticut Attorney General to submit a complaint. The appeals mechanism gives consumers a structured way to challenge a controller&#8217;s initial decision without immediately relying on litigation. State privacy laws differ in their request and appeals procedures, so organizations should configure workflows according to each applicable jurisdiction.<\/span><\/p>\n<p><b>Question 114. Who has enforcement authority under the Connecticut Data Privacy Act?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every individual consumer through a general private right of action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The Connecticut Attorney General, with no general private cause of action under the CTDPA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the Federal Trade Commission<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only local city governments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The Connecticut Attorney General, with no general private cause of action under the CTDPA<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA. The statute does not create a general private cause of action allowing individual consumers to sue directly for violations of the comprehensive privacy law itself. Connecticut indicates that violations may result in civil penalties under the state&#8217;s unfair trade practices framework, along with remedies such as injunctive relief, restitution, or disgorgement. This enforcement structure is important for exam purposes because state comprehensive privacy laws differ in available remedies and enforcement mechanisms. A consumer right does not necessarily imply an individual right to bring a private lawsuit.<\/span><\/p>\n<p><b>Question 115. Under the CTDPA, what is generally required before a controller sells the personal data of a consumer under 16 or processes it for targeted advertising?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Opt-in consent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a privacy-policy update<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No special requirement applies to minors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent from the controller&#8217;s advertising partner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Opt-in consent<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connecticut provides enhanced protections for younger consumers. The Attorney General&#8217;s guidance explains that controllers must obtain opt-in consent before selling personal data or processing personal data for targeted advertising when the consumer is under 16. Separate COPPA obligations also apply when a child under 13 is involved and the federal law&#8217;s coverage requirements are satisfied. Connecticut additionally provides protections for minors under 18 interacting with online services, products, or features. Privacy teams serving teenagers should therefore not assume that COPPA&#8217;s under-13 threshold is the only age-related rule relevant to online data practices.<\/span><\/p>\n<p><b>Question 116. Which CTDPA obligation BEST reflects the privacy principle of data minimization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep every category of personal information indefinitely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sell unused information to offset storage costs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Limit collection to personal data that is adequate, relevant, and reasonably necessary for the specified processing purposes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collect all potentially useful information before deciding why it is needed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Limit collection to personal data that is adequate, relevant, and reasonably necessary for the specified processing purposes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The CTDPA requires controllers to limit personal-data collection to information that is adequate, relevant, and reasonably necessary for the purposes for which the information is processed. This reflects the privacy principle commonly known as data minimization. Collecting information \u201cjust in case\u201d it might someday be useful can increase privacy and security risk and may conflict with statutory purpose limitations. Connecticut also restricts processing for materially new purposes that are neither reasonably necessary to nor compatible with the disclosed purpose unless appropriate consent is obtained. Data minimization should therefore be incorporated into product and system design rather than treated only as a retention issue.<\/span><\/p>\n<p><b>Question 117. Under the Virginia Consumer Data Protection Act (VCDPA), what is generally required before a controller processes a consumer&#8217;s sensitive data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The consumer&#8217;s consent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approval from the Virginia legislature<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A credit report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only an internal manager&#8217;s authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The consumer&#8217;s consent<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Virginia&#8217;s VCDPA requires controllers to obtain consumer consent before processing sensitive personal data. Virginia&#8217;s definition includes categories such as racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, certain genetic or biometric data used for unique identification, precise geolocation, and personal data collected from a known child. These categories receive additional protection because misuse can create particularly serious privacy risks. Controllers should therefore identify sensitive data in their inventories and ensure that consent processes occur before covered processing begins instead of merely describing sensitive-data practices after collection.<\/span><\/p>\n<p><b>Question 118. How quickly must a Virginia controller generally respond to a consumer request under the VCDPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 45 days, with a possible additional 45-day extension when appropriate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Seven days without extension<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Six months<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after the consumer files a lawsuit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. 45 days, with a possible additional 45-day extension when appropriate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Virginia controllers generally must respond to consumer privacy-rights requests within 45 days. When reasonably necessary, the response period can be extended by an additional 45 days, with appropriate notice to the consumer. Virginia consumers can exercise rights such as accessing, correcting, deleting, and obtaining certain personal data, as well as opting out of certain processing. Controllers may also need additional information to authenticate the consumer or request. Because request deadlines can vary by jurisdiction, national organizations should use structured case-management procedures capable of applying the correct timing rules to each consumer request.<\/span><\/p>\n<p><b>Question 119. What enforcement consequence can follow an uncured VCDPA violation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic imprisonment of the company&#8217;s privacy officer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanent revocation of every business license in the United States<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic deletion of the controller&#8217;s databases<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The Virginia Attorney General may seek civil penalties of up to $7,500 for each violation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The Virginia Attorney General may seek civil penalties of up to $7,500 for each violation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Virginia Attorney General enforces the VCDPA. Current Virginia guidance states that when the Attorney General notifies a controller or processor of a violation, the entity has 30 days to provide written confirmation that the violation has been cured. If the organization fails to cure the violation within the applicable period, the Attorney General may bring an enforcement action and seek civil penalties of up to $7,500 per violation, in addition to other available relief. Privacy professionals should therefore treat consumer-rights operations and sensitive-data requirements as enforceable legal duties rather than voluntary best practices.<\/span><\/p>\n<p><b>Question 120. A national online retailer serves consumers in California, Colorado, Connecticut, and Virginia. What is the BEST approach to state comprehensive privacy-law compliance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply only California law because it was enacted first<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume every state law has exactly the same definitions, rights, exclusions, and consent rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Map applicable jurisdictions and data practices, then build a privacy program that satisfies the relevant rights, opt-outs, consent requirements, assessments, notices, and state-specific differences<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Wait until each state attorney general issues an enforcement letter before implementing privacy controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Map applicable jurisdictions and data practices, then build a privacy program that satisfies the relevant rights, opt-outs, consent requirements, assessments, notices, and state-specific differences<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">State comprehensive privacy laws share many concepts, but they are not identical. California includes employees and job applicants within its consumer rights framework, while Colorado and Connecticut generally exclude employment contexts. Consent rules, universal opt-out requirements, response procedures, enforcement mechanisms, and sensitive-data definitions can also differ. A national business should therefore map where consumers reside, what data it processes, its purposes and disclosures, and which statutes apply. It can then build common controls where laws overlap while preserving jurisdiction-specific logic where necessary. Treating every state statute as identical risks both under-compliance and unnecessary operational restrictions.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps. Question 101. Which California resident is generally within the scope of CCPA consumer privacy rights? Only individuals purchasing products for household use A California employee or job applicant whose personal information is handled by a covered business Only individuals who have created an online account [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20824"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20824"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20824\/revisions"}],"predecessor-version":[{"id":20825,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20824\/revisions\/20825"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}