
Buy Latest Mar 21, 2025 CIPP-US Exam Q&A PDF - One Year Free Update
Download the Latest CIPP-US Dump - 2025 CIPP-US Exam Questions
The CIPP-US certification exam covers a wide range of topics, including the United States' federal and state privacy laws, regulations, and industry best practices. Professionals who hold this certification are well-equipped to navigate the complex regulatory environment and ensure compliance with data protection laws. Additionally, they are recognized as experts in their field, which can enhance their career prospects.
NEW QUESTION # 40
The Video Privacy Protection Act of 1988 restricted which of the following?
- A. When downloading of copyrighted audio visual materials is allowed
- B. Which purchase records of audio visual materials may be disclosed
- C. When a user's viewing of online video content can be monitored
- D. Who advertisements for videos and video games may target
Answer: B
Explanation:
Explanation/Reference: https://searchcompliance.techtarget.com/definition/Video-Privacy-Protection-Act-of-1988
NEW QUESTION # 41
Which of the following is most likely to provide privacy protection to private-sector employees in the United States?
- A. The Federal Trade Commission Act (FTC Act)
- B. The U.S. Department of Health and Human Services (HHS)
- C. Amendments one, four, and five of the U.S. Constitution
- D. State law, contract law, and tort law
Answer: D
Explanation:
Unlike many other countries, the United States does not have a comprehensive federal law that regulates the privacy of private-sector employees. Instead, the privacy protection of employees depends largely on state law, contract law, and tort law. State law may provide specific rights and remedies for employees regarding issues such as drug testing, background checks, electronic monitoring, social media access, and genetic information.
Contract law may create obligations and expectations for employers and employees based on written or implied agreements, such as employment contracts, employee handbooks, or collective bargaining agreements.
Tort law may allow employees to sue their employers for invasion of privacy, such as intrusion upon seclusion, public disclosure of private facts, false light, or appropriation of name or likeness. The other options are less likely to provide privacy protection to private-sector employees in the United States. The FTC Act primarily regulates the privacy practices of businesses that collect and use consumer data, not employee data.
The U.S. Constitution only protects individuals from unreasonable searches and seizures by the government, not by private employers. The HHS only enforces the HIPAA Privacy Rule, which applies to covered entities and business associates that handle protected health information, not to all private-sector employers. References:
* IAPP CIPP/US Study Guide, Chapter 6: Workplace Privacy
* Privacy Rights of Employees Using Workplace Computers in the United States
* Employee Privacy Laws
NEW QUESTION # 42
Which of the following statements is most accurate in regard to data breach notifications under federal and state laws:
- A. The only obligations to provide data breach notification are under state law because currently there is no federal law or regulation requiring notice for the breach of personal information.
- B. When providing an individual with required notice of a data breach, you must identify what personal information was actually or likely compromised.
- C. You must notify the Federal Trade Commission (FTC) in addition to affected individuals if over 500 individuals are receiving notice.
- D. When you are required to provide an individual with notice of a data breach under any state's law, you must provide the individual with an offer for free credit monitoring.
Answer: B
NEW QUESTION # 43
SCENARIO -
Please use the following to answer the next question:
Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to the U.S. Department of Defense and other U.S. federal agencies. Jane's manager, Patrick, is a French citizen who has been living in California for over a decade. Patrick has recently begun to suspect that Jane is an insider secretly transmitting trade secrets to foreign intelligence. Unbeknownst to Patrick, the FBI has already received a hint from anonymous whistleblower, and jointly with the National Security Agency is investigating Jane's possible implication in a sophisticated foreign espionage campaign.
Ever since the pandemic, Jane has been working from home. To complete her daily tasks she uses her corporate laptop, which after each login conspicuously provides notice that the equipment belongs to Jones Labs and may be monitored according to the enacted privacy policy and employment handbook. Jane also has a corporate mobile phone that she uses strictly for business, the terms of which are defined in her employment contract and elaborated upon in her employee handbook. Both the privacy policy and the employee handbook are revised annually by a reputable California law firm specializing in privacy law. Jane also has a personal iPhone that she uses for private purposes only.
Jones Labs has its primary data center in San Francisco, which is managed internally by Jones Labs engineers. The secondary data center, managed by Amazon AWS, is physically located in the UK for disaster recovery purposes. Jones Labs' mobile devices backup is managed by a mid-sized mobile defense company located in Denver, which physically stores the data in Canada to reduce costs. Jones Labs MS Office documents are securely stored in a Microsoft Office 365 data center based in Ireland. Manufacturing data of Jones Labs is stored in Taiwan and managed by a local supplier that has no presence in the U.S.
Before inspecting any GPS geolocation data from Jane's corporate mobile phone, Patrick should first do what?
- A. Revise emerging workplace privacy best practices with a reputable advocacy organization.
- B. Ensure that such activity is permitted under Jane's employment contract or the company's employee privacy policy.
- C. Obtain a subpoena from law enforcement, or a court order, directing Jones Labs to collect the GPS geolocation data.
- D. Obtain prior consent from Jane pursuant to the Telephone Consumer Protection Act
Answer: B
Explanation:
"In California, it is legal to track employees during work hours. However, Californians have a constitutional right to privacy. Therefore, if you plan to track employees, make sure it's not in violation of any union agreements and that there's a documented tracking policy in place. " https://www.workyard.com/employee-time-tracking/gps-tracking-employees-laws
NEW QUESTION # 44
What does the Massachusetts Personal Information Security Regulation require as it relates to encryption of personal information?
- A. The encryption of all personal information of Massachusetts residents when all equipment is located in Massachusetts.
- B. The encryption of personal information stored in Massachusetts-based companies when stored on portable devices.
- C. The encryption of all personal information of Massachusetts residents when stored on portable devices.
- D. The encryption of all personal information stored in Massachusetts-based companies when all equipment is located in Massachusetts.
Answer: C
NEW QUESTION # 45
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
- A. Vermont.
- B. New York.
- C. Washington.
- D. California.
Answer: A
Explanation:
Explanation
Explanation/Reference: https://www.natlawreview.com/article/ringing-2019-new-state-privacy-and-data-security-laws- impacting-data-brokers-and
NEW QUESTION # 46
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal dat a. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Upon review, the data privacy leader discovers that the Company's documented data inventory is obsolete. What is the data privacy leader's next best source of information to aid the investigation?
- A. Reports on recent purchase histories
- B. Interviews with key marketing personnel
- C. Lists of all customers, sorted by country
- D. Database schemas held by the retailer
Answer: C
NEW QUESTION # 47
Who has rulemaking authority for the Fair Credit Reporting Act (FCRA) and the Fair and Accurate Credit Transactions Act (FACTA)?
- A. The Department of Commerce
- B. The Federal Trade Commission
- C. State Attorneys General
- D. The Consumer Financial Protection Bureau
Answer: D
Explanation:
Explanation/Reference: https://www.ftc.gov/enforcement/statutes/fair-accurate-credit-transactions-act-2003
NEW QUESTION # 48
What information did the Red Flag Program Clarification Act of 2010 add to the original Red Flags rule?
- A. The components of an identity theft detection program.
- B. The process for proper disposal of sensitive data.
- C. The most common methods of identity theft.
- D. The definition of what constitutes a creditor.
Answer: D
Explanation:
The Red Flag Program Clarification Act of 2010 amended the original Red Flags rule, which required certain financial institutions and creditors to develop and implement a written identity theft prevention program. The Clarification Act narrowed the definition of creditor to include only those who regularly and in the ordinary course of business advance funds to or on behalf of a person, based on an obligation of the person to repay the funds or repayable from specific property pledged by or on behalf of the person12. This excludes creditors who advance funds for expenses incidental to a service provided by the creditor to that person3. References:
* CIPP/US Practice Questions (Sample Questions), Question 133, Answer B, Explanation B.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 4, Section 4.3, p. 108-
109.
* Red Flag Program Clarification Act of 2010, Section 2, Subsection (b).
NEW QUESTION # 49
Which of the following accurately describes the purpose of a particular federal enforcement agency?
- A. The National Institute of Standards and Technology (NIST) has established mandatory privacy standards that can then be enforced against all for-profit organizations by the Department of Justice (DOJ).
- B. The Federal Trade Commission (FTC) is typically recognized as having the broadest authority under the FTC Act to address unfair or deceptive privacy practices.
- C. The Federal Communications Commission (FCC) regulates privacy practices on the internet and enforces violations relating to websites' posted privacy disclosures.
- D. The Cybersecurity and Infrastructure Security Agency (CISA) is authorized to bring civil enforcement actions against organizations whose website or other online service fails to adequately secure personal information.
Answer: B
Explanation:
The FTC is the primary federal agency responsible for enforcing privacy and data security laws in the United States. The FTC has broad jurisdiction over most commercial entities that collect, use, or share personal information from consumers. The FTC Act prohibits unfair or deceptive acts or practices in or affecting commerce, which includes unfair or deceptive privacy practices. The FTC can bring enforcement actions against companies that violate their own privacy policies, fail to provide adequate notice or choice to consumers, engage in unfair or harmful data practices, or breach consumers' reasonable expectations of privacy. The FTC can also issue rules, guidelines, and reports on privacy and data security issues, as well as conduct investigations, workshops, and educational campaigns. References:
* IAPP CIPP/US Body of Knowledge, Section I.A.1.a
* IAPP CIPP/US Textbook, Chapter 1, pp. 9-12
* FTC Privacy and Security Enforcement
NEW QUESTION # 50
Once a breach has been definitively established, which task should be prioritized next?
- A. Implementing remedial measures and evaluating how to prevent future breaches.
- B. Providing notice to the affected parties so they can take precautionary measures.
- C. Involving law enforcement and state Attorneys General.
- D. Determining what was responsible for the breach and neutralizing the threat.
Answer: B
Explanation:
According to the IAPP CIPP/US study guide, the first priority after a breach has been confirmed is to notify the affected individuals, regulators, and other stakeholders as required by law or contract. This is to allow them to take steps to protect themselves from potential harm, such as identity theft, fraud, or reputational damage. Providing timely and accurate notice also helps to mitigate legal liability, preserve customer trust, and comply with applicable laws and regulations. The other tasks are also important, but they are not the immediate priority after a breach has been established. References: IAPP CIPP/US study guide, Chapter 6, Section 6.4.2, page 211.
NEW QUESTION # 51
Which of the following describes the most likely risk for a company developing a privacy policy with standards that are much higher than its competitors?
- A. Attracting skepticism from auditors
- B. Having a security system failure
- C. Getting accused of discriminatory practices
- D. Being more closely scrutinized for any breaches of policy
Answer: D
NEW QUESTION # 52
More than half of U.S. states require telemarketers to?
- A. Provide written contracts for customer transactions
- B. Obtain written consent from potential customers
- C. Identify themselves at the beginning of a call
- D. Register with the state before conducting business
Answer: D
Explanation:
According to the IAPP CIPP/US Study Guide, more than half of U.S. states require telemarketers to register with the state before conducting business within the state. This registration requirement may involve paying a fee, posting a bond, or providing information about the telemarketer's identity, location, and business practices. The purpose of this requirement is to protect consumers from fraudulent or deceptive telemarketing calls and to facilitate the enforcement of state laws and regulations. The other options are not required by most states, although some states may have additional rules or guidelines for telemarketers regarding identification, consent, or contracts. References:
* IAPP CIPP/US Study Guide, Chapter 7: Marketing and Advertising
* State Telemarketing Registration Requirements
NEW QUESTION # 53
In which situation is a company operating under the assumption of implied consent?
- A. A landlord uses the information on a completed rental application to run a credit report
- B. A retail clerk asks a customer to provide a zip code at the check-out counter
- C. An online retailer subscribes new customers to an e-mail list by default
- D. An employer contacts the professional references provided on an applicant's resume
Answer: D
Explanation:
* Implied consent is a form of consent that is inferred from the actions or inactions of the data subject, rather than explicitly expressed by the data subject1.
* Implied consent is generally considered a valid basis for processing personal data under certain circumstances, such as when the processing is necessary for the performance of a contract, the legitimate interests of the data controller, or the reasonable expectations of the data subject2.
* However, implied consent may not be sufficient for processing sensitive personal data, such as health, biometric, or genetic data, or for sending marketing communications, depending on the applicable laws and regulations2.
* In the U.S., there is no comprehensive federal privacy law that regulates the use of implied consent for data processing, but there are sector-specific laws and state laws that may impose different requirements and limitations3.
* Based on the scenarios given in the question, the situation that is most likely to involve a company operating under the assumption of implied consent is A. An employer contacts the professional references provided on an applicant's resume.
* This is because the employer may reasonably infer that the applicant has consented to the contact of the references by voluntarily providing their information on the resume, and that the contact is necessary for the legitimate interest of the employer to verify the applicant's qualifications and suitability for the job4.
* The other situations may not involve implied consent, but rather require explicit consent or provide opt- out options for the data subjects, depending on the type and purpose of the data processing and the relevant laws and regulations5 . For example:
* B. An online retailer subscribes new customers to an e-mail list by default. This may violate the CAN-SPAM Act, which requires online marketers to obtain affirmative consent from the recipients before sending commercial e-mail messages, and to provide a clear and conspicuous opt-out mechanism in every message5.
* C. A landlord uses the information on a completed rental application to run a credit report. This may violate the Fair Credit Reporting Act, which requires landlords to obtain written authorization from the applicants before obtaining their consumer reports, and to provide them with a copy of the report and a summary of their rights if they take any adverse action based on the report.
* D. A retail clerk asks a customer to provide a zip code at the check-out counter. This may violate the California Song-Beverly Credit Card Act, which prohibits retailers from requesting and recording personal identification information from customers who pay with a credit card, unless the information is necessary for a special purpose, such as shipping or fraud prevention.
References: 1: Implied Consent 2: Consent 3: U.S. Private-Sector Privacy (CIPP/US) 4: [Reference Checks:
Tips for Job Applicants and Employers] 5: [CAN-SPAM Act: A Compliance Guide for Business] : [Using Consumer Reports: What Landlords Need to Know] : [California Song-Beverly Credit Card Act] : [Reference Checks: Tips for Job Applicants and Employers] : [CAN-SPAM Act: A Compliance Guide for Business] :
[Using Consumer Reports: What Landlords Need to Know] : [California Song-Beverly Credit Card Act]
NEW QUESTION # 54
A law enforcement subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?
- A. CALEA
- B. USA Freedom Act
- C. ECPA
- D. SCA
Answer: A
Explanation:
The law that ACME violated by designing the service to prevent access to the information by a law enforcement agency is the Communications Assistance for Law Enforcement Act (CALEA)1. CALEA is a federal law that requires telecommunications carriers and manufacturers of telecommunications equipment to design their equipment, facilities, and services to ensure that they have the necessary surveillance capabilities to comply with legal requests for interception of communications2. CALEA applies to all commercial messages, including text messages, and gives law enforcement agencies the authority to subpoena the records of such communications from the service providers3. By encrypting its text message records so that only the suspect could access this data, ACME violated CALEA's duty to cooperate in the interception of communications for law enforcement purposes. References: 1: Communications Assistance for Law Enforcement Act - Wikipedia2: Home | CALEA | The Commission on Accreditation for Law Enforcement Agencies, Inc.3: Communications Assistance for Law Enforcement Act : IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 6: Law Enforcement and National Security Access, p.
177
NEW QUESTION # 55
......
IAPP CIPP-US (Certified Information Privacy Professional/United States (CIPP/US)) certification exam is designed for professionals who are interested in enhancing their knowledge and skills in the field of privacy and data protection. Certified Information Privacy Professional/United States (CIPP/US) certification is highly recognized in the industry and is ideal for individuals who work with personal data in the United States, such as privacy officers, lawyers, compliance officers, and consultants. Certified Information Privacy Professional/United States (CIPP/US) certification exam covers various topics, including the legal framework for privacy in the United States, data protection regulations, and privacy management practices.
IAPP CIPP-US (Certified Information Privacy Professional/United States) Exam is a highly recognized and sought-after certification for individuals seeking to enhance their privacy knowledge and skills. Certified Information Privacy Professional/United States (CIPP/US) certification is designed to help professionals gain a thorough understanding of U.S. privacy laws, regulations, and practices, and apply that knowledge in real-world scenarios.
Verified CIPP-US Dumps Q&As - 1 Year Free & Quickly Updates: https://www.trainingdump.com/IAPP/CIPP-US-practice-exam-dumps.html
Latest IAPP CIPP-US Certification Practice Test Questions: https://drive.google.com/open?id=1k5DcG2HnVFbWWi76K-39NKF3fyc_QNAq