{"id":20826,"date":"2026-09-24T07:52:18","date_gmt":"2026-09-24T07:52:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20826"},"modified":"2026-09-24T07:52:18","modified_gmt":"2026-09-24T07:52:18","slug":"iapp-cipp-us-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-us-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"IAPP CIPP-US Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-us-exam-dumps\"><b>IAPP CIPP-US Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 121. What does the federal Wiretap Act generally prohibit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every storage of an email after delivery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only government monitoring of telephone calls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any company use of customer contact information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Intentional interception of wire, oral, or electronic communications unless an exception applies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Intentional interception of wire, oral, or electronic communications unless an exception applies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The federal Wiretap Act, which forms part of the Electronic Communications Privacy Act framework, generally prohibits intentionally intercepting wire, oral, or electronic communications, as well as certain uses or disclosures of unlawfully intercepted communications. The statute contains important exceptions, including specified provider activities, qualifying law-enforcement activity, and consent in appropriate circumstances. \u201cInterception\u201d generally concerns acquisition during communication rather than ordinary access to communications already stored, which can implicate the Stored Communications Act instead. Privacy professionals therefore need to determine both the type of communication and when and how access occurred before deciding which ECPA provision is relevant.<\/span><\/p>\n<p><b>Question 122. Under the federal Wiretap Act, what level of consent generally permits a private party to record a communication, assuming the recording is not for a criminal or tortious purpose?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent of one party to the communication can generally be sufficient under federal law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent of every person in the United States is required<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a federal judge can authorize recording<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent is never relevant to interception law<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Consent of one party to the communication can generally be sufficient under federal law<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federal law generally permits a private person to intercept a wire, oral, or electronic communication when that person is a party to the communication or when one party has given prior consent, unless the interception is undertaken for the purpose of committing a criminal or tortious act. This is commonly described as a federal one-party consent rule. However, state interception and recording statutes may impose stricter requirements, so a national organization should not rely solely on the federal rule when recording calls involving participants in multiple jurisdictions. Applicable state law must also be considered.<\/span><\/p>\n<p><b>Question 123. A person participates in a telephone conversation and secretly records it specifically to facilitate a separate criminal act. Which statement BEST describes the federal one-party consent exception?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It always protects the recording because the recorder participated in the call<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It applies only to government officials<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The exception may not apply when interception is undertaken for the purpose of committing a criminal or tortious act<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The Wiretap Act never addresses the recorder&#8217;s purpose<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The exception may not apply when interception is undertaken for the purpose of committing a criminal or tortious act<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Although federal interception law generally recognizes consent from one party to a communication, the private-party exception contains an important limitation. The interception is not protected by that exception when it is performed for the purpose of committing a criminal or tortious act in violation of federal or state law or the Constitution. Therefore, participation in a conversation does not necessarily provide absolute immunity for every recording. Privacy professionals evaluating recording practices should consider consent, the purpose of the interception, and any stricter state laws that may independently regulate the conduct.<\/span><\/p>\n<p><b>Question 124. Why is the distinction between interception and stored communications important under ECPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stored communications are never protected by federal law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Real-time interception and access to stored communications are generally governed by different statutory provisions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only telephone calls can ever be intercepted<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECPA applies only after a communication has been deleted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Real-time interception and access to stored communications are generally governed by different statutory provisions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ECPA contains separate legal frameworks addressing communications at different stages. The Wiretap Act generally addresses interception of communications, while the Stored Communications Act regulates specified access to and disclosure of communications and subscriber information held by electronic communication and remote computing services. This distinction can change the applicable authorization, consent, and government-process rules. For example, accessing a stored email from a service provider raises different statutory questions from capturing the same communication while it is being transmitted. Correctly classifying the activity is therefore an essential first step in electronic communications privacy analysis.<\/span><\/p>\n<p><b>Question 125. Under the Stored Communications Act, when may a qualifying service provider disclose the contents of a communication based on consent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> When lawful consent is provided by the originator, addressee, intended recipient, or other statutorily recognized party as applicable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after the communication becomes one year old<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when every employee of the provider agrees<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Never, because stored communications cannot be disclosed voluntarily<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. When lawful consent is provided by the originator, addressee, intended recipient, or other statutorily recognized party as applicable<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Stored Communications Act generally restricts voluntary disclosure by providers of qualifying communications services, but it contains several exceptions. One permits disclosure of communication contents with the lawful consent of specified parties, including an originator or an addressee or intended recipient, with additional rules for remote computing services. Other exceptions cover matters such as forwarding communications, protecting provider rights or property, and disclosures otherwise authorized by law. The presence of a consent exception does not eliminate the need to determine who is legally capable of giving valid consent under the specific provision.<\/span><\/p>\n<p><b>Question 126. Which Stored Communications Act exception can permit a service provider to access or disclose communication contents when reasonably necessary to provide its service?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A blanket advertising exception<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A public-record exception<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A consumer-report exception<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An exception for activity necessarily incident to providing the service or protecting the provider&#8217;s rights or property<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. An exception for activity necessarily incident to providing the service or protecting the provider&#8217;s rights or property<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Stored Communications Act contains an exception permitting a provider to disclose communication contents as may be necessarily incident to rendering the service or protecting the provider&#8217;s rights or property. This recognizes that communications providers need limited operational access for activities such as delivering messages, maintaining systems, and protecting services against abuse. The exception is not a general authorization to inspect customer communications for unrelated commercial purposes. Privacy professionals should therefore distinguish operational necessity from secondary uses that are not genuinely required to deliver or protect the communications service.<\/span><\/p>\n<p><b>Question 127. A government entity sends a qualifying preservation request to an electronic communications provider under 18 U.S.C. \u00a7 2703(f). How long must the provider initially preserve the records?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 90 days, with a possible additional 90-day extension upon renewed request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Seven days only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One year automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Indefinitely without any further request<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. 90 days, with a possible additional 90-day extension upon renewed request<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Under the Stored Communications Act, a provider receiving a qualifying governmental preservation request must preserve specified records and other evidence in its possession pending issuance of appropriate legal process. The initial preservation period is 90 days, and a renewed request can extend that period for another 90 days. A preservation request does not itself necessarily authorize disclosure of all preserved information; the government must still use the legal process required for the information it ultimately seeks. Privacy and legal teams should distinguish preservation obligations from disclosure authorization.<\/span><\/p>\n<p><b>Question 128. What information is a government-authorized pen register or trap-and-trace device generally intended to capture?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The complete contents of every telephone conversation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stored email attachments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dialing, routing, addressing, and signaling information rather than communication contents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Medical records stored by a hospital<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Dialing, routing, addressing, and signaling information rather than communication contents<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federal law distinguishes pen register and trap-and-trace information from the contents of communications. Government use of the relevant technology must, where reasonably available, be configured so it captures dialing, routing, addressing, and signaling information without recording or decoding communication contents. This distinction reflects different legal treatment for transactional or routing information compared with the substantive content of communications. Privacy professionals should recognize that metadata can still be highly revealing, even though it is legally categorized differently from communication content under the relevant statutory framework.<\/span><\/p>\n<p><b>Question 129. Under the Privacy Act of 1974, what is a \u201croutine use\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any disclosure a federal employee finds convenient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any disclosure made at least once per year<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any disclosure to a private company<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A use of a record compatible with the purpose for which the record was collected and properly described as a routine use<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A use of a record compatible with the purpose for which the record was collected and properly described as a routine use<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Privacy Act defines a routine use as a use of a record for a purpose compatible with the purpose for which the information was collected. Before relying on the routine-use disclosure exception, the agency must publish the routine use in the Federal Register as part of the applicable system-of-records notice, including relevant categories of users and purposes. The actual disclosure also must fall within the published scope. Routine use is therefore not a blanket label allowing agencies to repurpose personal information whenever convenient; compatibility and notice are core requirements.<\/span><\/p>\n<p><b>Question 130. Which Privacy Act disclosure generally does NOT require an individual&#8217;s prior written consent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disclosure to agency officers or employees who need the record to perform their official duties<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sale of the record to an advertiser<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public posting of the record for convenience<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disclosure to any private business that requests it<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Disclosure to agency officers or employees who need the record to perform their official duties<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Privacy Act contains several statutory exceptions to its general prohibition on disclosing records from a system of records without consent. One exception allows disclosure to officers and employees of the agency maintaining the record when they have a need for the record in performing their duties. This is often described as the need-to-know exception. It does not mean every employee of the agency can browse personal records freely; the employee&#8217;s official responsibilities must justify access. Federal agencies should therefore use access controls that align information availability with legitimate job functions.<\/span><\/p>\n<p><b>Question 131. What must a federal agency generally publish concerning a Privacy Act system of records?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A System of Records Notice in the Federal Register<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every record contained in the system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every employee password used to access the system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the database vendor&#8217;s name<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A System of Records Notice in the Federal Register<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Privacy Act requires federal agencies to provide public notice of their systems of records through publication in the Federal Register. A System of Records Notice, commonly called a SORN, describes matters such as the categories of individuals and records maintained, system purposes, routine uses, and relevant recordkeeping practices. Publication promotes transparency by informing individuals and the public about how identifiable records are maintained and used. A SORN is not a publication of the underlying personal records themselves; rather, it describes the system and its authorized purposes and disclosures.<\/span><\/p>\n<p><b>Question 132. Under the Computer Matching and Privacy Protection Act provisions, what is generally required before a federal agency discloses records for use in a covered matching program?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only an oral agreement between analysts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A written matching agreement between the relevant source and recipient entities, subject to statutory requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approval from every individual contained in both databases<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A commercial data-broker license<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A written matching agreement between the relevant source and recipient entities, subject to statutory requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Computer Matching and Privacy Protection Act amended the Privacy Act to add procedural safeguards around certain computerized matching programs. Subject to applicable exceptions, records from a system of records generally may not be disclosed for use in a covered matching program without a written agreement between the source agency and recipient agency or qualifying nonfederal entity. Agreements address issues such as purpose, verification, retention, security, redisclosure, and destruction. These requirements help ensure that large-scale government data comparisons operate under documented controls rather than informal data-sharing arrangements.<\/span><\/p>\n<p><b>Question 133. Why did the Computer Matching and Privacy Protection Act add procedural protections before adverse benefit decisions based on matching data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure agencies can automatically terminate benefits without review<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To give affected individuals notice and an opportunity to contest or refute adverse information in qualifying circumstances<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate federal benefits programs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prohibit agencies from using computers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To give affected individuals notice and an opportunity to contest or refute adverse information in qualifying circumstances<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Computer matching can identify apparent inconsistencies that may affect eligibility for benefits, employment, or other government determinations, but automated matches can contain errors or incomplete information. The Computer Matching and Privacy Protection Act added due-process-oriented safeguards requiring procedures for verification and, in qualifying contexts, opportunities for affected individuals to receive notice and refute adverse information before benefits are denied or terminated based solely on a match. These safeguards reflect the risks created when automated comparisons of large databases influence important decisions about identifiable individuals.<\/span><\/p>\n<p><b>Question 134. What governance mechanism does the Computer Matching and Privacy Protection Act require participating federal agencies to establish?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Advertising review committees<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Credit bureaus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data Protection Boards to oversee matching activities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Private arbitration panels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Data Protection Boards to oversee matching activities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Computer Matching and Privacy Protection Act requires federal agencies engaged in covered matching programs to establish Data Protection Boards. These boards provide oversight of matching activities and help ensure compliance with the procedural requirements added to the Privacy Act. The statute also introduced matching agreements, notice requirements, verification processes, and protections allowing individuals to challenge adverse information. These mechanisms illustrate an early form of privacy governance for automated governmental data processing, anticipating modern concerns about using large datasets to make consequential decisions about individuals.<\/span><\/p>\n<p><b>Question 135. What does the Privacy Act generally say about a federal agency selling or renting an individual&#8217;s name and address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is generally prohibited unless specifically authorized by law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is always permitted if the agency needs revenue<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is mandatory for marketing purposes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is permitted whenever a private company requests the list<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It is generally prohibited unless specifically authorized by law<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Privacy Act includes a specific provision concerning mailing lists. An individual&#8217;s name and address generally may not be sold or rented by a federal agency unless the activity is specifically authorized by law. The provision does not independently require withholding information that is otherwise legally available to the public, but it restricts agencies from commercializing mailing lists simply because they maintain those records. This requirement demonstrates that the Privacy Act addresses not only access and amendment rights but also particular forms of government dissemination and secondary use of personal information.<\/span><\/p>\n<p><b>Question 136. Why has the FTC treated precise geolocation information as particularly sensitive?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Location information can reveal movements and visits to sensitive places such as medical facilities and places of worship<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation can only identify a consumer&#8217;s country<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Location information cannot be connected to mobile devices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation data has no commercial value<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Location information can reveal movements and visits to sensitive places such as medical facilities and places of worship<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FTC enforcement actions have emphasized that precise location information can reveal deeply private aspects of a person&#8217;s life, including visits to medical and reproductive health facilities, houses of worship, domestic-abuse shelters, and other sensitive locations. In its 2026 Kochava settlement, the FTC alleged that consumers could be harmed when location data from hundreds of millions of devices was collected and disclosed without adequate awareness or consent. The agency&#8217;s recent location-data cases demonstrate that the sensitivity of information can depend not only on the individual data point, but also on the inferences and behavioral patterns created by repeated tracking.<\/span><\/p>\n<p><b>Question 137. What was a significant requirement in the FTC&#8217;s finalized 2026 General Motors and OnStar order regarding connected vehicle data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> GM was required to make all location data public<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consumers lost the ability to request deletion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> GM was prohibited from allowing emergency first responders to receive location information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> GM generally must obtain affirmative express consent before collecting, using, or sharing covered connected vehicle data, subject to limited exceptions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. GM generally must obtain affirmative express consent before collecting, using, or sharing covered connected vehicle data, subject to limited exceptions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In January 2026, the FTC finalized an order settling allegations that GM and OnStar collected, used, and sold consumers&#8217; precise geolocation and driving-behavior data without adequate notice and consent. Among other requirements, the order generally requires affirmative express consumer consent before covered connected vehicle data is collected, used, or shared, with limited exceptions such as certain emergency-response uses. The order also requires mechanisms for accessing and deleting data and includes restrictions on disclosure to consumer reporting agencies. The case illustrates the FTC&#8217;s continuing focus on transparency and consumer choice involving highly sensitive connected-device information.<\/span><\/p>\n<p><b>Question 138. In its location-data enforcement actions, why has the FTC emphasized downstream-use controls for data brokers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data brokers are prohibited from having any customers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Selling sensitive location data without appropriate safeguards can expose consumers to harms that occur after the original transfer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Location data cannot be copied by customers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FTC requires every customer to become a federal agency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Selling sensitive location data without appropriate safeguards can expose consumers to harms that occur after the original transfer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FTC actions involving location-data companies have criticized not only initial collection and disclosure practices but also failures to control downstream uses of sensitive data. The X-Mode\/Outlogic matter alleged inadequate safeguards concerning third parties receiving precise location information, creating risks of discrimination, physical violence, emotional distress, and other harms. Vendor and customer controls therefore can be important where a company&#8217;s product enables recipients to infer visits to highly sensitive locations. A privacy program should consider what recipients can do with data after transfer instead of treating the organization&#8217;s responsibility as ending when the dataset leaves its systems.<\/span><\/p>\n<p><b>Question 139. Which location-data practice has recently attracted significant FTC scrutiny?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Displaying a city name in a weather application after a user requests it<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Selling or sharing precise location information capable of identifying visits to sensitive places without appropriate notice, consent, or safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printing a company&#8217;s office address on its website<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing employees to choose a meeting location<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Selling or sharing precise location information capable of identifying visits to sensitive places without appropriate notice, consent, or safeguards<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recent FTC cases have focused on businesses that collect, sell, or share precise geolocation information in ways consumers may not reasonably expect. Actions involving X-Mode, InMarket, Kochava, and connected-vehicle data demonstrate regulatory concern where datasets can reveal sensitive movements and visits and where consumers lack meaningful transparency or control. The exact remedy differs by case, but FTC orders have included prohibitions on selling sensitive location data, consent requirements, deletion mechanisms, restrictions on downstream disclosure, and privacy-program obligations. Privacy professionals should therefore treat precise location information as a high-risk data category requiring careful governance.<\/span><\/p>\n<p><b>Question 140. A company provides electronic communications services, records some calls, responds to government requests, and sells precise mobile-location analytics. What is the BEST U.S. privacy-law approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply only the Wiretap Act because communications law preempts every other privacy requirement<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat all information as unregulated because customers use the service voluntarily<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyze each activity separately under applicable interception, stored-communications, government-access, consumer-protection, and state privacy requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rely entirely on a general privacy policy regardless of actual practices<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Analyze each activity separately under applicable interception, stored-communications, government-access, consumer-protection, and state privacy requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Different data practices can trigger different legal frameworks even within one organization. Recording calls may implicate federal and state interception laws; storing communications can raise Stored Communications Act issues; government demands require analysis of applicable legal process; and precise-location analytics may create FTC and state privacy obligations. Consent may operate differently under each regime. A mature privacy program therefore maps data flows and identifies the legal role, purpose, technology, and jurisdiction associated with each processing activity. A single privacy notice or one communications statute does not automatically resolve every obligation created by the company&#8217;s broader information ecosystem.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps. Question 121. What does the federal Wiretap Act generally prohibit? Every storage of an email after delivery Only government monitoring of telephone calls Any company use of customer contact information Intentional interception of wire, oral, or electronic communications unless an exception applies Correct Answer: 4. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20826"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20826"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20826\/revisions"}],"predecessor-version":[{"id":20827,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20826\/revisions\/20827"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}