{"id":20838,"date":"2026-09-24T07:55:16","date_gmt":"2026-09-24T07:55:16","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20838"},"modified":"2026-09-24T07:55:16","modified_gmt":"2026-09-24T07:55:16","slug":"iapp-cipp-us-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-us-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"IAPP CIPP-US Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-us-exam-dumps\"><b>IAPP CIPP-US Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 241. What does Customer Proprietary Network Information (CPNI) generally include?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a customer&#8217;s billing address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only information published in a telephone directory<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Certain information a telecommunications carrier obtains because of the customer-carrier relationship, such as numbers called and call timing, frequency, or duration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every item of information available on the public internet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Certain information a telecommunications carrier obtains because of the customer-carrier relationship, such as numbers called and call timing, frequency, or duration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CPNI is a category of telecommunications customer information protected by section 222 of the Communications Act and FCC rules. It can include highly sensitive details generated through the customer relationship, such as telephone numbers called, frequency of calls, duration, timing, and other call-detail information. Because telecommunications providers can obtain detailed information about customers&#8217; communications patterns, FCC rules require carriers and certain interconnected VoIP providers to safeguard CPNI and limit unauthorized use or disclosure. CPNI should therefore be distinguished from information that happens to be publicly available independently of the carrier relationship.<\/span><\/p>\n<p><b>Question 242. What must a telecommunications carrier generally do before disclosing CPNI during a customer-initiated telephone contact?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Properly authenticate the customer according to FCC requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ask only for information readily available on the internet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require a court order in every case<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publish the requested information online first<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Properly authenticate the customer according to FCC requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FCC rules require telecommunications carriers to take reasonable measures to prevent unauthorized access to CPNI and to properly authenticate customers before disclosing protected information. For telephone access to call-detail information, the FCC adopted safeguards designed to prevent attackers from relying on easily obtainable biographical or account information. Depending on the circumstances, password authentication or other approved methods are required. The objective is to reduce pretexting and account takeover risks in which an unauthorized person impersonates the customer and obtains sensitive communication records. Authentication therefore serves as a core privacy safeguard under the CPNI framework.<\/span><\/p>\n<p><b>Question 243. If a telecommunications customer changes an online account password or address of record, what do FCC CPNI rules generally require?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The carrier must close the account immediately<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The carrier may wait until the annual privacy notice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No notification is necessary<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The carrier must promptly notify the customer of specified account changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The carrier must promptly notify the customer of specified account changes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FCC CPNI safeguards require carriers to notify customers when certain account credentials or account details are created or changed. Covered changes include passwords, backup authentication responses, online accounts, and addresses of record. This requirement is intended to alert customers quickly if an attacker changes security settings or account information without authorization. Account-change notices complement customer authentication rules by giving consumers another opportunity to detect account takeover. Telecommunications privacy therefore includes both restricting inappropriate disclosure and monitoring changes that could enable future unauthorized access.<\/span><\/p>\n<p><b>Question 244. What annual FCC compliance requirement generally applies to companies subject to the CPNI rules?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must send all call records to the FCC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must file an annual certification documenting compliance with CPNI requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must delete all customer call information every year<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must obtain new customer consent every January<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. They must file an annual certification documenting compliance with CPNI requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Companies subject to the FCC&#8217;s CPNI rules generally must file an annual certification documenting their compliance. The FCC&#8217;s certification process requires information concerning the company&#8217;s procedures, complaints about unauthorized CPNI release, and certain actions involving data brokers. The certifications are generally due by March 1 each year. This requirement gives the FCC a recurring compliance mechanism rather than relying solely on enforcement after a major privacy incident. Telecommunications providers should therefore maintain documented CPNI policies and complaint records throughout the year so they can support accurate annual certification.<\/span><\/p>\n<p><b>Question 245. Under FCC CPNI rules, what approval is generally required before a carrier uses individually identifiable CPNI for purposes outside specified permitted uses or qualifying communications-related marketing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approval from a credit bureau<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approval from the consumer&#8217;s employer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A judicial subpoena<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Customer opt-in approval, unless another rule or statutory exception permits the use**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Customer opt-in approval, unless another rule or statutory exception permits the use<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FCC rules restrict carrier use and disclosure of individually identifiable CPNI. Certain uses connected with the telecommunications service or qualifying communications-related marketing can be handled under particular rules, including opt-out arrangements in some circumstances. Uses and disclosures outside those permitted categories generally require opt-in approval unless another exception applies. Privacy professionals should therefore identify the purpose of the proposed use, the recipient, and whether the activity fits a regulatory exception before deciding what consent is necessary. CPNI compliance involves purpose limitation in addition to security and authentication.<\/span><\/p>\n<p><b>Question 246. What does the Protection of Pupil Rights Amendment (PPRA) primarily regulate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Certain student surveys, parental access to information, marketing-related data practices, and specified physical examinations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consumer credit reports<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Health insurance claims<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Telephone marketing campaigns<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Certain student surveys, parental access to information, marketing-related data practices, and specified physical examinations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PPRA protects student and parental rights in several specific educational contexts. It governs certain surveys involving protected areas, parental inspection of survey and instructional materials, collection or use of student information for marketing, and specified nonemergency invasive physical examinations or screenings. PPRA applies to programs and activities of educational agencies and institutions receiving funds under programs administered by the U.S. Department of Education. It is separate from FERPA, although both are important federal student privacy laws. FERPA primarily focuses on education records, while PPRA focuses heavily on student participation, surveys, marketing, and related parental rights.<\/span><\/p>\n<p><b>Question 247. Which topic is one of PPRA&#8217;s eight protected survey areas?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A student&#8217;s favorite school subject<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Religious practices, affiliations, or beliefs of the student or the student&#8217;s parent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The school&#8217;s lunch menu<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The student&#8217;s preferred sports team<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Religious practices, affiliations, or beliefs of the student or the student&#8217;s parent<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PPRA identifies eight protected categories that can trigger additional parental rights when surveys, analyses, or evaluations ask students about them. These include political affiliations, mental or psychological problems, sex behavior or attitudes, certain illegal or self-incriminating behavior, critical appraisals of close family members, privileged relationships, religious practices or beliefs, and income except in specified eligibility contexts. Because these topics involve highly sensitive personal or family matters, schools and other covered entities must follow PPRA&#8217;s notice, consent, inspection, or opt-out requirements as applicable.<\/span><\/p>\n<p><b>Question 248. When must a school generally obtain written parental consent under PPRA for a protected-information survey?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever a student completes any voluntary classroom survey<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when the survey is anonymous<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> When students are required, as part of a U.S. Department of Education-administered program, to participate in a survey concerning one or more protected areas<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after survey responses have already been collected<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. When students are required, as part of a U.S. Department of Education-administered program, to participate in a survey concerning one or more protected areas<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PPRA requires active written parental consent before students are required, as part of a program administered by the Department of Education, to participate in surveys, analyses, or evaluations that concern one or more of the eight protected areas. Other protected-information surveys administered by a covered LEA may instead trigger notice and an opportunity for parents to opt their children out. The distinction between mandatory participation in a Department-funded or administered program and other survey scenarios is therefore important when determining whether affirmative consent or opt-out procedures apply.<\/span><\/p>\n<p><b>Question 249. What inspection right does PPRA provide concerning third-party surveys administered to students?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parents may request to inspect the survey before it is administered or distributed to the student<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parents may inspect the survey only after all students respond<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only teachers may inspect third-party surveys<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Survey questions are never subject to parental inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Parents may request to inspect the survey before it is administered or distributed to the student<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PPRA requires covered LEAs to develop policies protecting parents&#8217; right to inspect qualifying third-party surveys before those surveys are administered or distributed to students. The school should provide reasonable access within a reasonable period after receiving the request. This right allows parents to understand what information their children may be asked to provide before participation occurs. PPRA also provides inspection rights concerning instructional materials and instruments used to collect personal information for certain marketing activities. These transparency requirements complement consent and opt-out protections.<\/span><\/p>\n<p><b>Question 250. Which school activity may require PPRA notice and an opportunity for a parent to opt a child out?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An ordinary math test<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A school lunch period<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A fire drill<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collection of student personal information for certain marketing or sale purposes**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Collection of student personal information for certain marketing or sale purposes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PPRA addresses certain school activities involving collection, disclosure, or use of student personal information for marketing, selling that information, or otherwise providing it to others for marketing purposes. Covered LEAs must establish policies concerning these practices and, for relevant activities, provide notice and an opportunity for parents to opt students out. PPRA also provides parental inspection rights concerning the instruments used to collect the information. This framework recognizes that students should not become an unregulated source of marketing data merely because commercial data collection occurs through a school environment.<\/span><\/p>\n<p><b>Question 251. When do PPRA rights generally transfer from a parent to a student?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> At age 13<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> At age 16<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> When the student turns 18 or becomes an emancipated minor under state law<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after college graduation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. When the student turns 18 or becomes an emancipated minor under state law<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Under PPRA, parental rights generally transfer to the student when the student reaches age 18 or becomes an emancipated minor under applicable state law. This transfer rule differs somewhat from FERPA, where rights transfer at age 18 or when a student attends a postsecondary institution at any age. CIPP\/US candidates should therefore avoid assuming that every education privacy law uses the exact same trigger for transferring rights. Understanding the relevant statute&#8217;s definition of the rights holder is essential when determining who should receive notices, inspect materials, provide consent, or exercise opt-out rights.<\/span><\/p>\n<p><b>Question 252. Under Maine&#8217;s broadband privacy law, what generally must an internet service provider obtain before using, disclosing, selling, or permitting access to customer personal information, unless an exception applies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A consumer credit report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The customer&#8217;s express, affirmative consent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approval from the FTC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consent from any household member<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The customer&#8217;s express, affirmative consent<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Maine&#8217;s broadband privacy statute generally prohibits providers from using, disclosing, selling, or permitting access to customer personal information unless the customer provides express, affirmative consent or another statutory exception applies. The law covers a broad range of information, including browsing history, application usage, precise geolocation, financial and health information, information about children, device identifiers, communication contents, and IP-address information. The affirmative-consent framework reflects Maine&#8217;s choice to impose stronger privacy controls on broadband providers rather than relying solely on an opt-out model.<\/span><\/p>\n<p><b>Question 253. Which information is expressly included within \u201ccustomer personal information\u201d under Maine&#8217;s broadband privacy law?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a customer&#8217;s name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only billing records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a Social Security number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web browsing history, application usage history, precise geolocation, and other specified information**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Web browsing history, application usage history, precise geolocation, and other specified information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Maine&#8217;s law defines broadband customer personal information broadly. It includes personally identifying information such as names, billing details, and Social Security numbers, as well as information generated through broadband use. The latter category expressly includes web browsing history, application usage, precise geolocation, health and financial information, information relating to children, device identifiers, communication contents, and origin and destination IP addresses. Because these data can reveal extensive details about a person&#8217;s behavior and interests, providers must apply the law&#8217;s consent, security, and notice rules carefully.<\/span><\/p>\n<p><b>Question 254. Under Maine&#8217;s broadband privacy statute, may a provider refuse service because a customer declines to consent to optional use or disclosure of customer personal information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Yes, providers may always terminate nonconsenting customers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Yes, if the provider offers a privacy notice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No, the provider generally may not refuse service or penalize the customer for declining consent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only if the customer pays an additional privacy fee<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. No, the provider generally may not refuse service or penalize the customer for declining consent<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Maine prohibits broadband providers from conditioning service on a customer&#8217;s willingness to provide consent for covered optional uses of personal information. The statute also prohibits charging a penalty or offering a discount based on the customer&#8217;s decision to give or withhold consent. This prevents providers from undermining the consent requirement through financial pressure or denial of basic broadband service. Consent therefore must function as a genuine choice rather than as a condition consumers must accept merely to receive the underlying service.<\/span><\/p>\n<p><b>Question 255. Which use of customer personal information may Maine broadband providers generally perform without obtaining customer approval?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use necessary to provide, bill for, or protect the broadband service from fraudulent or unlawful use<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sale to unrelated advertisers for any purpose<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disclosure of browsing history to a data broker for behavioral advertising<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public posting of communications content<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Use necessary to provide, bill for, or protect the broadband service from fraudulent or unlawful use<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Maine recognizes several operational exceptions to the general affirmative-consent rule. Providers may use customer personal information without approval when necessary to provide the service, bill and collect payment, protect users against fraudulent, abusive, or unlawful use, comply with lawful court orders, or provide specified emergency geolocation information. The law also permits certain marketing of the provider&#8217;s own communications-related services. These exceptions are purpose-specific and should not be interpreted as general permission to sell or disclose customer data for unrelated commercial activities.<\/span><\/p>\n<p><b>Question 256. What security obligation does Maine impose on broadband providers concerning customer personal information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Providers have no security obligations if consent was obtained<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Providers must take reasonable measures to protect information from unauthorized use, disclosure, or access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only encryption is permitted as a security measure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Providers must destroy all data every 24 hours<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Providers must take reasonable measures to protect information from unauthorized use, disclosure, or access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Maine requires broadband providers to take reasonable measures to secure customer personal information. In determining appropriate safeguards, the statute directs providers to consider the nature and scope of their activities, the sensitivity of the collected information, the provider&#8217;s size, and the technical feasibility of security measures. This is a risk-based security approach rather than a mandate to use one specific technology. Consent to collect or use information does not eliminate the provider&#8217;s responsibility to protect it from unauthorized access or disclosure.<\/span><\/p>\n<p><b>Question 257. Under Vermont&#8217;s data broker law, what type of business is generally considered a \u201cdata broker\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A business that knowingly collects and sells or licenses brokered personal information about consumers with whom it does not have a direct relationship<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any business with a website<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a consumer reporting agency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any company selling products directly to its own customers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A business that knowingly collects and sells or licenses brokered personal information about consumers with whom it does not have a direct relationship<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vermont&#8217;s data broker law focuses on businesses whose business model involves collecting and selling or licensing personal information about consumers with whom the business does not have a direct relationship. Vermont guidance identifies direct relationships such as customers, users, employees, contractors, investors, or donors. The definition therefore distinguishes traditional direct-to-consumer businesses from businesses operating primarily in the background data ecosystem. Specific activities and statutory exclusions still need to be reviewed, so merely selling information does not automatically resolve the classification without considering the underlying relationship and activity.<\/span><\/p>\n<p><b>Question 258. What recurring requirement does Vermont impose on covered data brokers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must register annually with the Vermont Secretary of State<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must send every consumer a monthly paper report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must become banks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They must stop all data sales<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. They must register annually with the Vermont Secretary of State<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vermont was an early state to adopt specific data broker regulation. Covered data brokers must register annually with the Vermont Secretary of State and provide required information concerning their practices. Registration helps create transparency around businesses that collect and commercialize personal information without direct relationships with consumers. The Vermont Attorney General also provides compliance guidance to help businesses determine whether they fall within the law&#8217;s definition. Registration is only one component of the regulatory framework; Vermont also imposes minimum data-security requirements on covered brokers.<\/span><\/p>\n<p><b>Question 259. In addition to annual registration, what does Vermont require covered data brokers to maintain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A federal banking charter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Certain minimum data-security standards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A health care license<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A COPPA Safe Harbor certification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Certain minimum data-security standards<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vermont&#8217;s data broker law has multiple components. In addition to annual registration, covered brokers must maintain specified minimum data-security standards. This reflects the significant risk created when organizations aggregate large volumes of personal information about people with whom they have no direct relationship. Vermont also regulates fraudulent acquisition of certain data and use of information for specified improper purposes. A privacy professional assessing a data broker should therefore consider transparency, security, acquisition practices, and downstream use\u2014not merely whether the company filed its registration form.<\/span><\/p>\n<p><b>Question 260. A company aggregates personal information about individuals it has never interacted with, licenses that data to third parties, and also provides broadband service to Maine residents. What is the BEST privacy-compliance approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Follow only Vermont law because data-broker regulation is more specific<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Follow only Maine law because internet privacy law overrides all other statutes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyze each business activity separately and apply Vermont data-broker obligations, Maine broadband privacy requirements, and any other applicable privacy laws<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat all collected information as public because it came from multiple sources<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Analyze each business activity separately and apply Vermont data-broker obligations, Maine broadband privacy requirements, and any other applicable privacy laws<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">One company can be subject to different privacy regimes because separate business activities create distinct legal roles. Aggregating and licensing information about consumers with no direct relationship may trigger Vermont&#8217;s data broker requirements, while providing broadband service to Maine customers can trigger Maine&#8217;s affirmative-consent, security, and notice obligations. Neither law automatically eliminates the other. A mature privacy program maps each data flow, jurisdiction, customer relationship, purpose, disclosure, and business role and then applies the relevant requirements to each activity. This layered analysis is central to navigating the sectoral and state-based structure of U.S. privacy law.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps. Question 241. What does Customer Proprietary Network Information (CPNI) generally include? Only a customer&#8217;s billing address Only information published in a telephone directory Certain information a telecommunications carrier obtains because of the customer-carrier relationship, such as numbers called and call timing, frequency, or duration Every [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20838"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20838"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20838\/revisions"}],"predecessor-version":[{"id":20839,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20838\/revisions\/20839"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20838"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20838"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20838"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}