{"id":20828,"date":"2026-09-24T07:52:39","date_gmt":"2026-09-24T07:52:39","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20828"},"modified":"2026-09-24T07:52:39","modified_gmt":"2026-09-24T07:52:39","slug":"iapp-cipp-us-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-us-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"IAPP CIPP-US Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-us-exam-dumps\"><b>IAPP CIPP-US Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 141. Which consumer right is expressly provided by the Texas Data Privacy and Security Act (TDPSA)?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to confirm whether a controller processes the consumer&#8217;s personal data and obtain access to that data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to require every business to stop collecting all information immediately<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to sue any controller directly for statutory damages under the TDPSA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to prevent businesses from complying with court orders<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The right to confirm whether a controller processes the consumer&#8217;s personal data and obtain access to that data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The TDPSA gives Texas consumers several rights regarding personal data. These include confirming whether a controller processes their personal data, accessing that data, correcting inaccuracies, deleting qualifying personal data, obtaining portable copies, and opting out of certain targeted advertising, sales, and profiling. These rights are subject to statutory scope and exceptions. The law does not create an unrestricted ability to stop every type of processing or disclosure. A privacy program subject to Texas law should therefore establish procedures for authenticating consumers and responding to qualifying rights requests within the required timeframe.<\/span><\/p>\n<p><b>Question 142. How long does a Texas controller generally have to respond substantively to an authenticated consumer request under the TDPSA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Seven days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ninety days with no extension<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 45 days, with a possible additional 45-day extension when reasonably necessary<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. 45 days, with a possible additional 45-day extension when reasonably necessary<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Texas generally requires a controller to respond to an authenticated consumer privacy request without undue delay and no later than 45 days after receiving it. The controller can extend that period by another 45 days when reasonably necessary, but it must communicate the extension and reason within the original response period. This structure resembles several other U.S. state privacy laws, but organizations should still maintain jurisdiction-specific procedures. A national privacy-rights workflow should track the applicable state, authentication status, request type, deadline, extension rules, and response outcome instead of using an informal one-size-fits-all process.<\/span><\/p>\n<p><b>Question 143. Under the TDPSA, what must a controller generally do before processing a consumer&#8217;s sensitive data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publish the data in a privacy notice only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Wait 30 days after collection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Obtain approval from the FTC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Obtain the consumer&#8217;s consent<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Obtain the consumer&#8217;s consent<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Texas Data Privacy and Security Act prohibits controllers from processing sensitive data without first obtaining consumer consent. The statute also addresses data of known children, for which parental consent requirements apply. Sensitive-data treatment is therefore more restrictive than ordinary processing of nonsensitive personal data. Organizations should identify sensitive-data categories during data mapping and ensure consent is obtained before covered processing begins rather than attempting to rely solely on a general privacy notice after the fact. Texas enforcement has already focused on alleged collection and sale of sensitive precise-geolocation and driving information without adequate notice or consent.<\/span><\/p>\n<p><b>Question 144. Which statement BEST describes private enforcement under the TDPSA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every consumer automatically receives a private damages claim<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The TDPSA does not provide a private right of action; enforcement is handled by the Texas Attorney General<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only federal prosecutors may enforce the law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consumers must bring claims exclusively before the FTC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The TDPSA does not provide a private right of action; enforcement is handled by the Texas Attorney General<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The TDPSA does not create a general private right of action for individual consumers. Enforcement authority rests with the Texas Attorney General. This distinction is important because the existence of substantive consumer rights does not necessarily mean consumers can file direct lawsuits under the comprehensive privacy statute. Instead, consumers may submit complaints to the Attorney General, which can investigate and pursue violations. Privacy professionals should always analyze both substantive obligations and enforcement mechanisms because state privacy statutes differ regarding regulator authority, cure opportunities, penalties, and whether private litigation is available.<\/span><\/p>\n<p><b>Question 145. What does the TDPSA require when a controller refuses a qualifying consumer privacy request?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Nothing further is required<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller must automatically delete the consumer&#8217;s account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller must provide the reason for denial and instructions for appealing the decision<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller must pay the consumer statutory damages immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The controller must provide the reason for denial and instructions for appealing the decision<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Texas requires controllers that decline consumer requests to communicate the decision and provide a justification. The response must also explain how the consumer can appeal. Controllers therefore need an internal appeals process rather than treating the initial request decision as final. If an appeal is denied, consumers must receive information about how to submit a complaint to the Texas Attorney General. This procedural right reinforces accountability and provides consumers with another opportunity to challenge an incorrect request determination. Privacy operations teams should document both initial decisions and appeals so responses remain consistent and defensible.<\/span><\/p>\n<p><b>Question 146. Which consumer right under the Oregon Consumer Privacy Act (OCPA) is broader than merely knowing categories of third-party recipients?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to obtain a list of the specific third parties that received the consumer&#8217;s personal data or personal data from the controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to receive every third party&#8217;s internal financial statements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to compel third parties to stop all business activity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to obtain employee personnel records from every recipient<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The right to obtain a list of the specific third parties that received the consumer&#8217;s personal data or personal data from the controller<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Oregon consumers have a notable transparency right involving third-party disclosures. They may request a list of the specific third parties that received their personal data or personal data from the controller, rather than receiving only generalized categories of recipients. This requirement can create operational challenges because controllers need reliable records of downstream disclosures. Organizations subject to the OCPA should therefore maintain data inventories and sharing records detailed enough to respond accurately. Oregon also grants rights involving access, correction, deletion, data copies, and opt-outs from certain processing activities.<\/span><\/p>\n<p><b>Question 147. What Oregon privacy rule became effective on January 1, 2026 concerning precise geolocation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Businesses may sell precise geolocation without restrictions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only children receive protection for precise geolocation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consumers must pay to prevent location-data sales<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The sale of precise geolocation data of Oregon consumers is prohibited**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The sale of precise geolocation data of Oregon consumers is prohibited<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">As of January 1, 2026, Oregon law prohibits the sale of precise geolocation data of Oregon consumers. Oregon describes precise geolocation using a radius of 1,750 feet and applies the protection to past as well as present location data. The prohibition applies to consumers generally rather than only minors. Precise location is considered particularly sensitive because it can reveal where people live, work, worship, obtain health care, or engage in private activities. Organizations operating location-based products in Oregon should therefore distinguish ordinary location functionality from prohibited sale of precise geolocation information.<\/span><\/p>\n<p><b>Question 148. Beginning January 1, 2026, what must qualifying Oregon controllers do with recognized universal opt-out signals?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore them unless the consumer also sends a certified letter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat them only as requests to correct data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Honor qualifying signals as opt-out requests for covered sale or targeted-advertising processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Convert them into marketing consent<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Honor qualifying signals as opt-out requests for covered sale or targeted-advertising processing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Beginning January 1, 2026, covered Oregon businesses and nonprofits must recognize qualifying universal opt-out mechanisms. These signals allow consumers to communicate a privacy preference through technology such as a browser rather than manually visiting each organization&#8217;s privacy interface. Global Privacy Control is one example identified by Oregon guidance. The signal can communicate an opt-out from sale or targeted advertising where the statute applies. Oregon still requires controllers to provide clear mechanisms on their own websites as well. Universal opt-out recognition is part of a broader movement toward machine-readable consumer privacy choices.<\/span><\/p>\n<p><b>Question 149. When did the Oregon Consumer Privacy Act generally begin applying to qualifying nonprofit entities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> July 1, 2025<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2023<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> July 1, 2030<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Nonprofits are permanently exempt from the OCPA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. July 1, 2025<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The OCPA initially applied to qualifying for-profit entities beginning July 1, 2024. Oregon extended coverage to qualifying nonprofit entities beginning July 1, 2025. This makes Oregon notable because several comprehensive state privacy statutes contain broad nonprofit exemptions. Applicability still depends on statutory thresholds and specific exemptions, so nonprofit status alone does not resolve the analysis. Privacy professionals should examine the organization&#8217;s activities, volume of Oregon consumer data, revenue characteristics where relevant, and any entity- or data-specific exemptions before determining whether OCPA requirements apply.<\/span><\/p>\n<p><b>Question 150. As of January 1, 2026, what restriction applies under Oregon law to consumers under age 16?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Their data must always be deleted within 24 hours<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They may never use social media<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Their data may be freely sold if the business posts notice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Businesses may not sell their personal data or use it for targeted advertising or specified profiling as prohibited by the statute**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Businesses may not sell their personal data or use it for targeted advertising or specified profiling as prohibited by the statute<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Oregon strengthened protections for children and teenagers effective January 1, 2026. Businesses may not sell the personal data of consumers known to be under 16 or use their information for targeted advertising or specified profiling in violation of the statute. For children under 13, parental or legal guardian consent is also required before covered collection or processing, and their data is treated as sensitive. These rules demonstrate how state privacy protections can extend beyond COPPA&#8217;s traditional under-13 scope. Privacy programs serving teenagers should therefore analyze state law in addition to federal COPPA requirements.<\/span><\/p>\n<p><b>Question 151. Under the FTC&#8217;s 2025 COPPA Rule amendments, what additional consent is required for covered disclosure of children&#8217;s personal information to third parties for targeted advertising?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A separate verifiable parental consent for that third-party disclosure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the child&#8217;s click on an advertisement<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent from the advertising network alone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No consent if the operator already collected the information lawfully<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A separate verifiable parental consent for that third-party disclosure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The FTC&#8217;s 2025 amendments to the COPPA Rule strengthened protections concerning monetization and advertising. Covered operators must obtain separate verifiable parental consent before disclosing a child&#8217;s personal information to third parties for targeted advertising or other covered purposes. This separates consent to collect information needed for a service from consent to disclose that information externally for advertising-related uses. The amendment reflects the FTC&#8217;s concern that parents should not have to accept third-party commercial disclosure merely because their child uses an online service. Covered operators therefore need consent flows capable of distinguishing different processing purposes.<\/span><\/p>\n<p><b>Question 152. What retention principle was added or reinforced by the FTC&#8217;s 2025 COPPA Rule amendments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Children&#8217;s personal information should be kept permanently for future analytics<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Children&#8217;s personal information may be retained only as long as reasonably necessary for the specific purpose for which it was collected<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All children&#8217;s information must be deleted after exactly 24 hours<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retention is entirely unregulated once parental consent is obtained<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Children&#8217;s personal information may be retained only as long as reasonably necessary for the specific purpose for which it was collected<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The amended COPPA Rule limits retention of children&#8217;s personal information to the period reasonably necessary to fulfill the specific purpose for which the information was collected. The FTC expressly rejected indefinite retention merely because data might prove useful later. This approach links data lifecycle to purpose and reflects data-minimization principles increasingly visible across privacy regulation. Operators should therefore define retention periods, document legitimate purposes, and delete information when those purposes no longer justify retention. Parental consent to collection does not function as permission to retain children&#8217;s data forever.<\/span><\/p>\n<p><b>Question 153. Which category was expressly added to COPPA&#8217;s definition of personal information by the 2025 amendments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Corporate revenue figures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Product inventory numbers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anonymous aggregate statistics<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Biometric identifiers**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Biometric identifiers<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The FTC&#8217;s 2025 COPPA amendments expanded the Rule&#8217;s definition of personal information to expressly include biometric identifiers, along with government-issued identifiers. Biometric identifiers can include information used to recognize or distinguish individuals based on physical or biological characteristics. The change reflects the increasing use of technologies such as facial, voice, fingerprint, and other biometric systems in children&#8217;s digital services. Operators need to consider whether these technologies collect personal information under COPPA and whether notice, consent, security, retention, and deletion obligations apply. The amendment modernizes the Rule to address technologies that were far less common when COPPA was originally adopted.<\/span><\/p>\n<p><b>Question 154. What transparency obligation did the 2025 COPPA amendments add for FTC-approved Safe Harbor programs?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must disclose children&#8217;s individual browsing histories<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must publicly disclose membership lists and provide additional reporting to the FTC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must publish every parent&#8217;s identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must stop operating entirely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. They must publicly disclose membership lists and provide additional reporting to the FTC<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">COPPA Safe Harbor programs are FTC-approved self-regulatory programs that implement protections consistent with the COPPA Rule. The 2025 amendments increased transparency and accountability by requiring these programs to publicly disclose membership lists and submit additional information to the FTC. Safe Harbor participation does not mean companies are exempt from protecting children&#8217;s personal information; rather, qualifying participants follow an approved set of guidelines. Enhanced transparency helps regulators, parents, and the public better understand which organizations participate and how Safe Harbor programs are administered.<\/span><\/p>\n<p><b>Question 155. What does the FTC&#8217;s 2026 COPPA age-verification policy statement say operators should do with personal information collected solely to determine a user&#8217;s age?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use it freely for advertising once age is confirmed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sell it to identity-verification companies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retain it indefinitely for future product development<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use it only for age verification and delete it promptly when no longer necessary for that purpose**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use it only for age verification and delete it promptly when no longer necessary for that purpose<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In February 2026, the FTC issued a COPPA policy statement intended to encourage privacy-protective age-verification technologies. Among its stated expectations, operators relying on the policy should not use or disclose information collected for age verification for unrelated purposes and should not retain it longer than necessary. The FTC also emphasized clear notice, reasonable security, and due diligence concerning third parties providing age-verification technology. This approach recognizes the privacy paradox of age assurance: collecting additional identity information to protect children can itself create new risks unless the data is tightly limited and promptly deleted.<\/span><\/p>\n<p><b>Question 156. Which category of information is expressly excluded from the TDPSA&#8217;s ordinary consumer-data framework according to Texas guidance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Employment-related information covered by the statute&#8217;s exemptions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every online purchase made by a Texas resident<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All precise geolocation information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any information collected through a mobile application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Employment-related information covered by the statute&#8217;s exemptions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Texas guidance explains that the TDPSA contains both entity-level and data-level exemptions. Among the exempt categories is certain employment-related personal information. This means Texas does not necessarily give individuals acting in employment contexts the same rights they receive when acting as ordinary consumers. The distinction is similar to several other state comprehensive privacy laws and differs from California&#8217;s broader CCPA treatment of employees and job applicants. National employers should therefore avoid assuming that comprehensive privacy statutes define \u201cconsumer\u201d identically across jurisdictions. The role in which the individual interacts with the organization can materially affect statutory coverage.<\/span><\/p>\n<p><b>Question 157. How often must a Texas controller generally provide a consumer-rights response free of charge under the TDPSA before special circumstances such as excessive requests are considered?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Once during the consumer&#8217;s lifetime<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Up to twice annually per consumer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Once every five years<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every request may automatically be charged a fee<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Up to twice annually per consumer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Texas guidance states that a controller must generally respond to consumer requests free of charge up to twice each year per consumer. A reasonable administrative charge may be possible for requests that are unfounded, excessive, or repetitive. This differs from some other state laws that expressly guarantee fewer free requests in a 12-month period. National privacy-rights programs should therefore track request history and applicable state requirements before imposing a fee. An organization should never charge simply because responding to a valid privacy request requires ordinary compliance work.<\/span><\/p>\n<p><b>Question 158. Under the OCPA, what kind of profiling may Oregon consumers opt out of?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any calculation performed by a spreadsheet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automated processing used to evaluate or predict characteristics for decisions producing legal or similarly significant effects<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only advertising based on a single website visit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every internal fraud-detection activity automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Automated processing used to evaluate or predict characteristics for decisions producing legal or similarly significant effects<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Oregon consumers can opt out of specified profiling involving automated processing that evaluates, analyzes, or predicts characteristics such as economic circumstances, health, preferences, behavior, location, or movements when used to support consequential decisions. Oregon guidance identifies examples involving financial services, housing, insurance, education, criminal justice, employment opportunities, health care, and access to essential goods or services. This right is narrower than an ability to prohibit every automated calculation. Privacy professionals should determine whether the profiling contributes to a decision with legally or similarly significant effects before applying the statutory opt-out framework.<\/span><\/p>\n<p><b>Question 159. What must a Texas controller generally provide after denying a consumer&#8217;s appeal of an earlier rights-request decision?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A free product or service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A copy of every internal legal memorandum<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The personal telephone number of the company&#8217;s CEO<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Information explaining how the consumer can submit a complaint to the Texas Attorney General**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Information explaining how the consumer can submit a complaint to the Texas Attorney General<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The TDPSA requires controllers to maintain an appeals process for consumers whose rights requests are denied. If the controller denies the appeal, it must provide information explaining how the consumer can submit a complaint to the Texas Attorney General. This creates an escalation path from internal request handling to the regulator with enforcement authority. Organizations should therefore document appeal outcomes carefully and ensure denial notices contain the required regulator information. A mature consumer-rights program should also use appeals as feedback: repeated reversals may reveal flaws in authentication, exception analysis, or request-processing procedures.<\/span><\/p>\n<p><b>Question 160. A nationwide children&#8217;s application serves users in Texas and Oregon and shares children&#8217;s data with advertising partners. What is the BEST privacy-compliance approach in 2026?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Follow only COPPA because federal law automatically eliminates state privacy requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply only Oregon law because it is newer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Map the user&#8217;s age, state, data categories, advertising disclosures, consent requirements, and applicable federal and state obligations before processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rely on a general terms-of-service acceptance for all children&#8217;s data practices<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Map the user&#8217;s age, state, data categories, advertising disclosures, consent requirements, and applicable federal and state obligations before processing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Children&#8217;s privacy compliance can involve overlapping federal and state requirements. COPPA governs covered online collection from children under 13 and now includes strengthened requirements for third-party advertising disclosures, retention, and biometric information. Oregon additionally imposes protections affecting children and teens, including restrictions on sale, targeted advertising, and profiling for consumers under 16 as of January 1, 2026. Texas also regulates sensitive and known-child data and requires consent in covered circumstances. A national application should therefore map age, jurisdiction, purpose, disclosures, and consent instead of assuming that one law universally resolves every requirement.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps. Question 141. Which consumer right is expressly provided by the Texas Data Privacy and Security Act (TDPSA)? The right to confirm whether a controller processes the consumer&#8217;s personal data and obtain access to that data The right to require every business to stop collecting all [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20828"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20828"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20828\/revisions"}],"predecessor-version":[{"id":20829,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20828\/revisions\/20829"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20828"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}