{"id":20832,"date":"2026-09-24T07:53:21","date_gmt":"2026-09-24T07:53:21","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20832"},"modified":"2026-09-24T07:53:21","modified_gmt":"2026-09-24T07:53:21","slug":"iapp-cipp-us-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-us-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"IAPP CIPP-US Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-us-exam-dumps\"><b>IAPP CIPP-US Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 181. What is a major requirement of New York&#8217;s SHIELD Act for businesses that maintain private information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must make private information publicly searchable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must develop, implement, and maintain reasonable safeguards for the security, confidentiality, and integrity of private information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must delete all private information after 30 days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must obtain state approval before collecting any personal information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. They must develop, implement, and maintain reasonable safeguards for the security, confidentiality, and integrity of private information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">New York&#8217;s SHIELD Act strengthened the state&#8217;s information-security requirements by requiring persons and businesses that maintain private information to use reasonable safeguards. The statute identifies administrative, technical, and physical measures that can form part of an appropriate security program. Examples include designating personnel responsible for security, assessing foreseeable risks, training employees, selecting capable service providers, monitoring systems, protecting information during storage and disposal, and adjusting safeguards as circumstances change. The requirement is risk-based rather than a mandate to use one identical security architecture in every organization.<\/span><\/p>\n<p><b>Question 182. How did New York&#8217;s SHIELD Act broaden the concept of a security breach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It limited breaches to theft of paper files<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminated breach notification entirely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It applies only when financial loss has already occurred<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It expanded breach coverage to include certain unauthorized access to computerized private information, not merely unauthorized acquisition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. It expanded breach coverage to include certain unauthorized access to computerized private information, not merely unauthorized acquisition<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before the SHIELD Act amendments, New York&#8217;s breach law focused on unauthorized acquisition of computerized data containing private information. The SHIELD Act broadened the breach concept to include unauthorized access that compromises the confidentiality, security, or integrity of private information. This matters because an intruder may view or access sensitive information without clearly downloading or removing it. Organizations investigating incidents therefore need to consider evidence of unauthorized access rather than asking only whether files were conclusively copied. The change reflects the reality that exposure itself can create meaningful privacy and identity-theft risks.<\/span><\/p>\n<p><b>Question 183. Which category was added to New York&#8217;s definition of private information by the SHIELD Act?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Biometric information and certain online account credentials<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A consumer&#8217;s favorite color<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publicly available weather information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A company&#8217;s general product catalog<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Biometric information and certain online account credentials<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The SHIELD Act expanded New York&#8217;s definition of private information beyond traditional identifiers such as Social Security numbers, driver&#8217;s license numbers, and financial account information. The expanded definition includes biometric information and certain combinations of usernames or email addresses with passwords or security information that permit access to online accounts. These additions recognize that modern identity theft and account compromise are not limited to payment-card or government-identifier theft. Privacy and security teams should therefore include authentication credentials and biometric data in incident-response inventories rather than limiting breach analysis to older categories of financial identity information.<\/span><\/p>\n<p><b>Question 184. Which categories of safeguards does the New York SHIELD Act identify as part of a reasonable security program?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Legal, financial, and marketing safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Federal, state, and international safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrative, technical, and physical safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Advertising, sales, and customer-service safeguards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Administrative, technical, and physical safeguards<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">New York&#8217;s SHIELD Act describes reasonable safeguards in three broad categories: administrative, technical, and physical. Administrative measures include activities such as risk assessment, employee training, security-program oversight, and service-provider management. Technical measures include evaluating risks in networks and software, detecting attacks, and testing controls. Physical measures include protecting information during storage, transportation, destruction, and disposal and responding to physical intrusions. Together, these categories show that a security program cannot rely only on technology. Governance, people, contracts, physical security, and lifecycle management all contribute to protecting private information.<\/span><\/p>\n<p><b>Question 185. Under the New York SHIELD Act, what must a business generally do if it determines that an inadvertent exposure is unlikely to result in misuse, financial harm, or applicable emotional harm and therefore does not notify consumers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Document the determination in writing and retain it for at least five years<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete all evidence of the incident<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Notify every U.S. attorney general<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publish the determination in a newspaper<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Document the determination in writing and retain it for at least five years<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">New York allows an exception to consumer breach notification in certain circumstances involving inadvertent disclosure by persons authorized to access the information when the organization reasonably determines the exposure is unlikely to result in misuse, financial harm, or specified emotional harm involving online credentials. The determination must be documented in writing and retained for at least five years. If more than 500 New York residents are affected, the written determination must also be provided to the Attorney General within the applicable timeframe. This requirement makes the decision not to notify an auditable compliance determination rather than an undocumented judgment.<\/span><\/p>\n<p><b>Question 186. To whom does Massachusetts regulation 201 CMR 17.00 generally apply?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only Massachusetts state agencies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only banks headquartered in Massachusetts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only businesses with more than 500 employees<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persons that own or license personal information about Massachusetts residents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Persons that own or license personal information about Massachusetts residents<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Massachusetts regulation 201 CMR 17.00 establishes information-security standards for persons that own or license personal information about Massachusetts residents. Its scope is not limited to organizations physically headquartered in Massachusetts or to a single industry. The regulation is designed to protect personal information in both paper and electronic records against anticipated threats, unauthorized access, and uses that may create substantial harm or inconvenience. Businesses operating nationally should therefore consider the residence of individuals whose information they hold, not merely where the company maintains offices, when evaluating whether Massachusetts security requirements apply.<\/span><\/p>\n<p><b>Question 187. What foundational security document does Massachusetts 201 CMR 17.00 require covered organizations to maintain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A public consumer advertising plan<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A comprehensive written information security program<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A federal privacy license<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A public employee directory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A comprehensive written information security program<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Covered organizations must develop, implement, and maintain a comprehensive written information security program, commonly called a WISP. The program must contain administrative, technical, and physical safeguards appropriate to factors such as the organization&#8217;s size, resources, amount of stored data, and need for security and confidentiality. Required program elements include risk assessment, employee training, security policies, service-provider oversight, access controls, monitoring, disciplinary measures, and periodic review. Massachusetts therefore goes beyond a vague instruction to \u201cuse reasonable security\u201d by specifying a structured written program through which organizations manage information-security risks.<\/span><\/p>\n<p><b>Question 188. Under Massachusetts 201 CMR 17.00, what should an organization generally do with personal information transmitted across public networks, to the extent technically feasible?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Print it before transmission<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Post it to a public website<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt it<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Convert it into marketing data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Encrypt it<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Massachusetts&#8217; computer-system security requirements generally call for encryption of personal information transmitted across public networks and information transmitted wirelessly, to the extent technically feasible. The regulation also calls for encryption of personal information stored on laptops and other portable devices, again within the regulation&#8217;s feasibility framework. Encryption reduces the risk that intercepted or stolen information can be readily used by unauthorized persons. Encryption is only one element of the Massachusetts framework, which also includes secure authentication, access controls, monitoring, firewall protection, malware protection, security patches, and employee training.<\/span><\/p>\n<p><b>Question 189. What service-provider obligation is included in Massachusetts 201 CMR 17.00?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Organizations should select capable service providers and contractually require appropriate safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Businesses may never outsource processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service providers are automatically exempt from all security requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only federal agencies may evaluate service-provider security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Organizations should select capable service providers and contractually require appropriate safeguards<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Massachusetts requires covered organizations to oversee third-party service providers that handle protected personal information. The organization must take reasonable steps to select and retain providers capable of maintaining appropriate safeguards and must require appropriate security measures by contract. This reflects a broader privacy principle that outsourcing data processing does not eliminate the need for vendor oversight. Organizations should perform appropriate due diligence, establish contractual requirements, and monitor relevant vendor risks rather than assuming a service provider&#8217;s possession of information transfers all security responsibility away from the original business.<\/span><\/p>\n<p><b>Question 190. How often should a Massachusetts organization&#8217;s written information security program generally be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> At least annually or when a material change in business practices may affect information security<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after a data breach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Once every ten years<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when a regulator specifically requests review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. At least annually or when a material change in business practices may affect information security<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Massachusetts requires organizations to review the scope of their security measures at least annually and whenever a material change in business practices may reasonably affect the security or integrity of personal information. This requirement recognizes that security programs cannot remain static while technology, business processes, vendors, threats, and data holdings change. The regulation also requires organizations to document responsive actions following security incidents and conduct post-incident reviews to determine whether business practices should change. A WISP should therefore operate as a living governance program rather than a document created once and placed on a shelf.<\/span><\/p>\n<p><b>Question 191. When did the Indiana Consumer Data Protection Act (CDPA) become effective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2023<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> July 1, 2024<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2026<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2030<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. January 1, 2026<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Indiana&#8217;s Consumer Data Protection Act became effective on January 1, 2026. The law grants Indiana residents rights concerning personal data and imposes obligations on covered controllers and processors. Indiana&#8217;s Attorney General is responsible for enforcement. Because state comprehensive privacy laws have taken effect on different dates, national organizations need reliable jurisdictional tracking rather than assuming that every state&#8217;s obligations began simultaneously. As each law becomes effective, businesses must update privacy notices, request-handling procedures, vendor contracts, opt-out mechanisms, and other operational controls to reflect the state&#8217;s requirements.<\/span><\/p>\n<p><b>Question 192. Which right is granted to Indiana consumers under the Indiana CDPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to access, correct, delete, and obtain qualifying personal data, subject to statutory requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to require all businesses to erase tax records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to prevent every form of fraud monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to demand ownership of corporate databases<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The right to access, correct, delete, and obtain qualifying personal data, subject to statutory requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Indiana&#8217;s CDPA gives qualifying consumers several rights over personal data. These include confirming whether a controller processes their personal data, accessing it, correcting inaccuracies in information they previously provided, requesting deletion, receiving qualifying data in a usable portable format, and opting out of processing for targeted advertising, sale, and profiling. Consumers also have an appeal right when a controller denies a request. These rights are subject to statutory definitions and exceptions, so they should not be interpreted as an unrestricted ability to erase every business or legally required record.<\/span><\/p>\n<p><b>Question 193. How frequently does Indiana&#8217;s CDPA expressly provide a qualifying consumer a free copy or representative summary of personal data previously provided to a controller?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Once a month<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Once every five years<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after filing a lawsuit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Once per year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Once per year<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Indiana&#8217;s Consumer Data Bill of Rights states that a consumer may obtain, once a year free of charge, a copy or representative summary of personal data the consumer previously provided to a controller. The state&#8217;s broader framework also provides portability-related rights so qualifying information can be transferred without undue hindrance. Request frequency matters operationally because privacy programs must track whether the consumer has already received the applicable free response within the relevant period. Organizations should nevertheless carefully review statutory rules before imposing charges or refusing additional requests, particularly when another applicable privacy law provides different requirements.<\/span><\/p>\n<p><b>Question 194. A controller denies an Indiana consumer&#8217;s request to exercise a CDPA right. What additional consumer right applies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Immediate statutory damages from the controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to appeal the controller&#8217;s denial<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic access to the controller&#8217;s legal advice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic suspension of the controller&#8217;s business license<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The right to appeal the controller&#8217;s denial<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Indiana consumers have the right to appeal a controller&#8217;s denial of a request to exercise rights under the CDPA. Appeal procedures provide an additional accountability mechanism when consumers believe the initial response was incorrect. Organizations subject to Indiana&#8217;s law should therefore design request-management workflows that include not only intake, authentication, search, exception review, and response, but also escalation and appeal handling. A privacy program that closes a case immediately after a denial without preserving a mechanism for appeal risks failing to implement the full consumer-rights process contemplated by the statute.<\/span><\/p>\n<p><b>Question 195. When did the Tennessee Information Protection Act (TIPA) become effective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2024<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2026<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> July 1, 2025<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> July 1, 2030<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. July 1, 2025<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Tennessee Information Protection Act became effective on July 1, 2025. It establishes privacy rights for Tennessee consumers and obligations for qualifying controllers and processors. These include rights involving access, correction, deletion, portability, and opt-outs from certain sales, targeted advertising, and profiling. The law also requires covered entities to provide privacy notices and establish procedures for rights requests and appeals. National organizations should track Tennessee alongside other state comprehensive privacy statutes because differing effective dates, applicability thresholds, definitions, and enforcement provisions can affect when specific compliance controls need to become operational.<\/span><\/p>\n<p><b>Question 196. Which business would MOST clearly satisfy one of Tennessee&#8217;s principal TIPA applicability pathways, assuming it does business in Tennessee and has annual revenue above $25 million?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A company processing 500 Tennessee consumers&#8217; data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A company processing no personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A company processing 175,000 Tennessee consumers&#8217; personal information during a calendar year<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A company keeping only anonymous weather data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A company processing 175,000 Tennessee consumers&#8217; personal information during a calendar year<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TIPA generally applies when a business operates in Tennessee or targets Tennessee residents, earns more than $25 million in annual revenue, and meets one of specified data-processing thresholds. One pathway involves controlling or processing personal information of at least 175,000 Tennessee consumers during a calendar year. Another covers at least 25,000 consumers when the business also derives more than 50% of gross annual revenue from selling personal information. Organizations should evaluate all elements of applicability rather than looking only at company revenue or consumer counts in isolation.<\/span><\/p>\n<p><b>Question 197. How quickly must an entity subject to TIPA generally respond to a consumer request to exercise privacy rights?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 45 days after receipt of the request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Seven days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Six months<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One year<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. 45 days after receipt of the request<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tennessee&#8217;s Attorney General explains that an entity subject to TIPA must respond to a consumer&#8217;s request to exercise statutory privacy rights within 45 days of receiving the request. If the request is denied, the entity must explain why and provide a process through which the consumer can appeal the decision. This means covered businesses need a formal request-handling workflow capable of identifying Tennessee consumers, authenticating requests, locating responsive data, reviewing exceptions, and communicating within the required deadline. Delaying rights requests until a complaint is filed would not satisfy the law&#8217;s proactive operational requirements.<\/span><\/p>\n<p><b>Question 198. What processing may a Tennessee consumer generally opt out of under TIPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every use of data needed to fulfill a purchase<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sale of personal information, targeted advertising, and specified profiling<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All security monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every legally required recordkeeping activity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Sale of personal information, targeted advertising, and specified profiling<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TIPA gives Tennessee consumers the right to opt out of processing for three important categories: sale of personal information, targeted advertising, and profiling for covered purposes. Targeted advertising generally involves advertisements selected based on information derived from the consumer&#8217;s activities over time across websites or online applications. Profiling involves automated processing used to evaluate or predict specified personal characteristics. These opt-outs are not universal prohibitions on every use of personal information. Processing needed for requested services, security, legal compliance, and other statutory purposes may be treated differently under the law.<\/span><\/p>\n<p><b>Question 199. Under TIPA, what is the difference between a controller and a processor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller determines why and how personal information is processed, while a processor handles it according to the controller&#8217;s instructions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A processor always owns all data it receives<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controller must be a government agency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> There is no legal difference<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A controller determines why and how personal information is processed, while a processor handles it according to the controller&#8217;s instructions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TIPA distinguishes controllers from processors based on their roles in determining processing. The controller determines the purposes and means of processing personal information\u2014essentially deciding why the processing occurs and how it should be carried out. A processor handles the information according to the controller&#8217;s instructions. This role-based structure helps allocate privacy obligations between businesses and their service providers. Organizations should examine actual decision-making rather than relying only on contract labels, because a vendor that independently determines purposes or uses personal information for its own objectives may no longer be acting solely as a processor.<\/span><\/p>\n<p><b>Question 200. A national organization holds New York residents&#8217; online credentials, Massachusetts residents&#8217; identifying information, and consumer data covered by Indiana and Tennessee privacy laws. What is the BEST compliance strategy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Map the data and jurisdictions, apply applicable security requirements and state consumer-rights obligations, and maintain coordinated security, vendor, and rights-request processes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Follow only the newest state privacy statute<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply Massachusetts security requirements only because security law replaces privacy law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Wait for regulators to identify which controls should be implemented<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Map the data and jurisdictions, apply applicable security requirements and state consumer-rights obligations, and maintain coordinated security, vendor, and rights-request processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An organization can simultaneously be subject to different kinds of state privacy obligations. New York&#8217;s SHIELD Act focuses substantially on breach and reasonable security duties, while Massachusetts 201 CMR 17.00 imposes detailed information-security program requirements. Indiana and Tennessee add comprehensive consumer privacy rights and controller obligations. One statute does not automatically replace the others simply because it is broader or newer. A mature program should map residents, data categories, vendors, security controls, processing purposes, consumer rights, and applicable deadlines, then build common operational controls while preserving state-specific requirements where laws differ.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps. Question 181. What is a major requirement of New York&#8217;s SHIELD Act for businesses that maintain private information? They must make private information publicly searchable They must develop, implement, and maintain reasonable safeguards for the security, confidentiality, and integrity of private information They must delete [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20832"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20832"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20832\/revisions"}],"predecessor-version":[{"id":20833,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20832\/revisions\/20833"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}