
Free CIPP-US Exam Study Guide for the NEW [Aug-2026] Dumps Test Engine
CIPP-US PDF Dumps Extremely Quick Way Of Preparation
IAPP CIPP-US (Certified Information Privacy Professional/United States) Exam is a certification exam that is designed to test the knowledge and skills required for individuals who are involved in the management and protection of personal data in the United States. CIPP-US exam is created and administered by the International Association of Privacy Professionals (IAPP), which is the largest and most respected privacy organization in the world. Passing the CIPP-US exam is a key step for professionals who want to demonstrate their expertise in privacy laws and regulations in the United States.
NEW QUESTION # 47
Lawrence works for a healthcare provider, which of the following healthcare entities covered by HIPAA (prior to HITECH) includes third-party organizations that host, handle, or process medical information?
- A. Healthcare Plans
- B. Healthcare Controllers
- C. Business Associates
- D. Healthcare Clearinghouses
Answer: D
Explanation:
Healthcare Clearinghouses are third-party organizations that host, handle, or process medical information. These are HIPAA covered entities now.
NEW QUESTION # 48
What is the main reason some supporters of the European approach to privacy are skeptical about self- regulation of privacy practices?
- A. Human rights may be disregarded for the sake of privacy
- B. Industries may not be strict enough in the creation and enforcement of rules
- C. A large amount of money may have to be sent on improved technology and security
- D. A new business owner may not understand the regulations
Answer: B
Explanation:
The European approach to privacy is based on the recognition of privacy as a fundamental human right that requires strong legal protection and oversight. The EU has adopted comprehensive and binding privacy laws, such as the General Data Protection Regulation (GDPR) and the ePrivacy Directive, that apply to all sectors and activities involving personal data. The EU also has independent data protection authorities (DPAs) that monitor and enforce compliance with the privacy laws, and a European Data Protection Board (EDPB) that issues guidance and opinions on privacy matters. The EU also requires adequate levels of privacy protection for personal data transferred to third countries or international organizations.
In contrast, the U.S. approach to privacy is based on a sectoral and self-regulatory model that relies on a combination of federal and state laws, industry codes of conduct, consumer education, and market forces. The
U.S. does not have a single, comprehensive, and enforceable federal privacy law that covers all sectors and activities involving personal data. Instead, the U.S. has a patchwork of federal and state laws that address specific issues or sectors, such as health, financial, children's, and electronic communications privacy. The U.
S. also has various federal and state agencies that share jurisdiction over privacy matters, such as the Federal Trade Commission (FTC), the Federal Communications Commission (FCC), and the Department of Health and Human Services (HHS). The U.S. also relies on self-regulation by industries that develop and adhere to voluntary codes of conduct, standards, and best practices for privacy. The U.S. also allows personal data to be transferred to third countries or international organizations without requiring adequate levels of privacy protection, as long as the data subjects have given their consent or the transfer is covered by a mechanism such as the Privacy Shield or the Standard Contractual Clauses.
Some supporters of the European approach to privacy are skeptical about self-regulation of privacy practices because they believe that self-regulation is not effective, consistent, or accountable enough to protect the rights and interests of data subjects. They argue that self-regulation may not provide sufficient incentives or sanctions for industries to comply with privacy rules, or to adopt privacy-enhancing technologies and practices. They also contend that self-regulation may not reflect the views and expectations of data subjects, or address the emerging and complex privacy challenges posed by new technologies and business models.
They also question the transparency and legitimacy of self-regulation, and the ability of data subjects to exercise their rights and seek redress for privacy violations. References:
* IAPP CIPP/US Study Guide, Chapter 1: Introduction to the U.S. Privacy Environment, pp. 9-10, 16-17
* IAPP website, CIPP/US Certification
* NICCS website, Certified Information Privacy Professional/United States (CIPP/US) Training
NEW QUESTION # 49
SCENARIO
Please use the following to answer the next question :
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most effective kind of training CloudHealth could have given its employees to help prevent this type of data breach?
- A. Training on the terms of the contractual agreement with HealthCo
- B. Training on techniques for identifying phishing attempts
- C. Training on CloudHealth's HR policy regarding the role of employees involved data breaches
- D. Training on the difference between confidential and non-public information
Answer: B
NEW QUESTION # 50
California's SB 1386 was the first law of its type in the United States to do what?
- A. Require encryption of sensitive information stored on servers that are Internet connected
- B. Require commercial entities to disclose a security data breach concerning personal information about the state's residents
- C. Require state attorney general enforcement of federal regulations against unfair and deceptive trade practices
- D. Require notification of non-California residents of a breach that occurred in California
Answer: B
NEW QUESTION # 51
SCENARIO
Please use the following to answer the next question:
Larry has become increasingly dissatisfied with his telemarketing position at SunriseLynx, and particularly with his supervisor, Evan. Just last week, he overheard Evan mocking the state's Do Not Call list, as well as the people on it. "If they were really serious about not being bothered," Evan said, "They'd be on the national DNC list. That's the only one we're required to follow. At SunriseLynx, we call until they ask us not to." Bizarrely, Evan requires telemarketers to keep records of recipients who ask them to call "another time." This, to Larry, is a clear indication that they don't want to be called at all. Evan doesn't see it that way.
Larry believes that Evan's arrogance also affects the way he treats employees. The U.S.
Constitution protects American workers, and Larry believes that the rights of those at SunriseLynx are violated regularly. At first Evan seemed friendly, even connecting with employees on social media. However, following Evan's political posts, it became clear to Larry that employees with similar affiliations were the only ones offered promotions.
Further, Larry occasionally has packages containing personal-use items mailed to work. Several times, these have come to him already opened, even though this name was clearly marked. Larry thinks the opening of personal mail is common at SunriseLynx, and that Fourth Amendment rights are being trampled under Evan's leadership.
Larry has also been dismayed to overhear discussions about his coworker, Sadie. Telemarketing calls are regularly recorded for quality assurance, and although Sadie is always professional during business, her personal conversations sometimes contain sexual comments. This too is something Larry has heard Evan laughing about. When he mentioned this to a coworker, his concern was met with a shrug. It was the coworker's belief that employees agreed to be monitored when they signed on. Although personal devices are left alone, phone calls, emails and browsing histories are all subject to surveillance. In fact, Larry knows of one case in which an employee was fired after an undercover investigation by an outside firm turned up evidence of misconduct. Although the employee may have stolen from the company, Evan could have simply contacted the authorities when he first suspected something amiss.
Larry wants to take action, but is uncertain how to proceed.
Which act would authorize Evan's undercover investigation?
- A. The National Labor Relations Act (NLRA)
- B. The Whistleblower Protection Act
- C. The Stored Communications Act (SCA)
- D. The Fair and Accurate Credit Transactions Act (FACTA)
Answer: C
Explanation:
The Stored Communications Act (SCA) is a federal law that regulates the privacy of electronic communications that are stored by third-party service providers, such as email providers, cloud storage providers, or social media platforms. The SCA prohibits unauthorized access to or disclosure of such communications, unless authorized by law or by the consent of the user or the service provider . The SCA also provides exceptions for certain types of access or disclosure, such as those made for law enforcement purposes, for the protection of the service provider's rights or property, or for the consent of the subscriber or customer .
One of the exceptions to the SCA is where the service provider gives consent to the access or disclosure of the stored communications. This means that if a third-party service provider agrees to cooperate with an investigation or a request for information, the access or disclosure is lawful under the SCA. Consent can be express or implied, depending on the circumstances and the terms of service of the provider. For example, if a service provider has a policy that allows it to disclose user information to third parties for legitimate purposes, the provider has impliedly consented to the access or disclosure of the stored communications. However, if a service provider has a policy that prohibits such disclosure, the provider has not consented to the access or disclosure of the stored communications.
In the scenario, Evan's undercover investigation may have been authorized by the SCA if he obtained the consent of the third-party service provider that stored the electronic communications of the employee who was suspected of misconduct. For instance, if the employee used a company email account or a cloud storage service that had a policy that allowed the service provider to disclose user information to the employer or to law enforcement, Evan may have been able to access or disclose the stored communications with the consent of the service provider.
However, if the employee used a personal email account or a cloud storage service that had a policy that protected user privacy and prohibited such disclosure, Evan may have violated the SCA by accessing or disclosing the stored communications without the consent of the service provider.
NEW QUESTION # 52
In March 2012, the FTC released a privacy report that outlined three core principles for companies handling consumer dat a. Which was NOT one of these principles?
- A. Providing greater transparency.
- B. Simplifying consumer choice.
- C. Enhancing security measures.
- D. Practicing Privacy by Design.
Answer: C
NEW QUESTION # 53
What consumer protection did the Fair and Accurate Credit Transactions Act (FACTA) require?
- A. The ability for the consumer to correct inaccurate credit report information
- B. Consumer notice when third-party data is used to make an adverse decision
- C. The truncation of account numbers on credit card receipts
- D. The right to request removal from e-mail lists
Answer: A
NEW QUESTION # 54
Which of the following became the first state to pass a law specifically regulating the collection of biometric data?
- A. California.
- B. Washington.
- C. Illinois.
- D. Texas.
Answer: C
NEW QUESTION # 55
Which of the following laws is NOT involved in the regulation of employee background checks?
- A. The Civil Rights Act.
- B. The California Investigative Consumer Reporting Agencies Act (ICRAA).
- C. The U.S. Fair Credit Reporting Act (FCRA).
- D. The Gramm-Leach-Bliley Act (GLBA).
Answer: D
Explanation:
The law that is not involved in the regulation of employee background checks is B. The Gramm-Leach-Bliley Act (GLBA). The GLBA is a federal law that regulates the privacy and security of financial information collected, used, or shared by financial institutions, such as banks, insurance companies, or securities firms. The GLBA does not apply to employee background checks, unless the employer is a financial institution that obtains financial information from a consumer reporting agency for employment purposes. In that case, the employer must comply with the GLBA's notice and opt-out requirements, as well as the FCRA's requirements for using consumer reports. References:
* [IAPP CIPP/US Study Guide], Chapter 4: Workplace Privacy, pp. 113-114.
* IAPP CIPP/US Body of Knowledge, Section IV: Workplace Privacy, Subsection A: Employee Privacy Expectations, Topic 3: Background Checks.
* IAPP CIPP/US Practice Questions, Question 150.
NEW QUESTION # 56
Which of the following best describes how federal anti-discrimination laws protect the privacy of private-sector employees in the United States?
- A. They prescribe working environments that are safe and comfortable.
- B. They promote a workforce of employees with diverse skills and interests.
- C. They limit the types of information that employers can collect about employees.
- D. They limit the amount of time a potential employee can be interviewed.
Answer: C
Explanation:
Federal anti-discrimination laws, such as Title VII of the Civil Rights Act of 1964, the Equal Pay Act of 1963, the Age Discrimination in Employment Act of 1967, and the Americans with Disabilities Act of 1990, prohibit employers from discriminating against employees or applicants based on certain protected characteristics, such as race, color, religion, sex, national origin, age, disability, and genetic information. These laws also limit the types of information that employers can collect, use, disclose, or retain about employees or applicants,in order to prevent discrimination or invasion of privacy. For example, employers cannot ask about an applicant's medical history, disability status, genetic information, or religious beliefs, unless they are relevant to the job or a bona fide occupational qualification. Employers also cannot use such information to make adverse employment decisions, such as hiring, firing, promotion, or compensation, unless they are justified by a legitimate business necessity or a reasonable accommodation. Employers must also safeguard the confidentiality of such information and dispose of it properly when it is no longer needed. References:
* Federal Laws Prohibiting Job Discrimination Questions And Answers
* Laws Enforced by EEOC
* Employment and Anti-Discrimination Laws in the Workplace
* Protections Against Discrimination and Other Prohibited Practices
* 3. Who is protected from employment discrimination?
NEW QUESTION # 57
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?
- A. The ability to investigate incidents of identity theft.
- B. The ability to appeal negative credit-based decisions.
- C. The ability to receive reports from multiple credit reporting agencies.
- D. The ability to correct inaccurate credit information.
Answer: D
Explanation:
The Fair Credit Reporting Act (FCRA) was originally intended to provide consumers with the ability to correct inaccurate credit information that could affect their access to credit, employment, insurance, and other benefits. The FCRA gives consumers the right to access their credit reports from the three major credit reporting agencies (Equifax, Experian, and TransUnion) for free once every 12 months, and to dispute any errors or inaccuracies with the credit reporting agencies or the information furnishers (such as lenders, creditors, or debt collectors). The FCRA also requires the credit reporting agencies and the information furnishers to investigate and resolve the disputes within 30 days, and to delete or correct any information that is found to be inaccurate, incomplete, or outdated. The FCRA also provides consumers with the right to place fraud alerts or security freezes on their credit reports if they are victims or potential victims of identity theft, and to receive notifications from users of their credit reports (such as employers or insurers) if any adverse action is taken based on their credit information.
NEW QUESTION # 58
Global Manufacturing Co's Human Resources department recently purchased a new software tool. This tool helps evaluate future candidates for executive roles by scanning emails to see what those candidates say and what is said about them. This provides the HR department with an automated "360 review" that lets them know how the candidate thinks and operates, what their peers and direct reports say about them, and how well they interact with each other.
What is the most important step for the Human Resources Department to take when implementing this new software?
- A. Confirming that employees have read and signed the employee handbook where they have been advised that they have no right to privacy as long as they are using the organization's systems, regardless of the protected group or laws enforced by EEOC.
- B. Making sure that the software does not unintentionally discriminate against protected groups.
- C. Providing notice to employees that their emails will be scanned by the software and creating automated profiles.
- D. Ensuring that the software contains a privacy notice explaining that employees have no right to privacy as long as they are running this software on organization systems to scan email systems.
Answer: C
Explanation:
The most important step for the HR department to take when implementing this new software is to provide notice to employees that their emails will be scanned by the software and creating automated profiles. This is because the software involves the collection and use of personal information from employees, which may implicate their privacy rights and expectations. By providing notice, the HR department can inform employees about the purpose, scope, and consequences of the software, as well as their choices and rights regarding their data. Notice is also a key element of transparency and accountability, which are essential principles of privacy management. Providing notice can also help the HR department comply with various privacy laws and regulations that may apply to the software, such as the Electronic Communications Privacy Act (ECPA), the Stored Communications Act (SCA), the Fair Credit Reporting Act (FCRA), and state privacy laws. Notice can also help the HR department avoid potential legal risks and liabilities that may arise from the software, such as claims of invasion of privacy, breach of contract, or violation of employee rights. References:
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 4, Section 4.2.1, pp. 97-98.
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 5, Section 5.2.1, pp. 125-126.
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 6, Section 6.2.1, pp. 153-154.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide by Mike Chapple and Joe Shelley, Chapter 4, Section 4.1, pp. 113-114.
NEW QUESTION # 59
Which federal law or regulation preempts state law?
- A. Health Insurance Portability and Accountability Act
- B. Electronic Communications Privacy Act of 1986
- C. Controlling the Assault of Non-Solicited Pornography and Marketing Act
- D. Telemarketing Sales Rule
Answer: C
NEW QUESTION # 60
SCENARIO
Please use the following to answer the next question:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in statea.
HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo.
CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals ?ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most significant reason that the U.S. Department of Health and Human Services (HHS) might impose a penalty on HealthCo?
- A. Because HealthCo did not require CloudHealth to implement appropriate physical and administrative measures to safeguard the ePHI
- B. Because HIPAA requires the imposition of a fine if a data breach of this magnitude has occurred
- C. Because HealthCo did not conduct due diligence to verify or monitor CloudHealth's security measures
- D. Because CloudHealth violated its contract with HealthCo by not encrypting the ePHI
Answer: C
Explanation:
According to the HIPAA Security Rule, covered entities are responsible for ensuring that their business associates comply with the security standards and safeguards required by the rule. This includes conducting due diligence to assess the business associate's security capabilities and practices, and monitoring their performance and compliance. Failure to do so may result in a violation of the rule and a penalty by the HHS. In this scenario, HealthCo did not perform due diligence on CloudHealth before entering the contract, and did not conduct audits of CloudHealth's security measures. This is the most significant reason why HHS might impose a penalty on HealthCo, as it indicates a lack of oversight and accountability for the protection of ePHI.
NEW QUESTION # 61
The Video Privacy Protection Act of 1988 restricted which of the following?
- A. Who advertisements for videos and video games may target
- B. When a user's viewing of online video content can be monitored
- C. When downloading of copyrighted audio visual materials is allowed
- D. Which purchase records of audio visual materials may be disclosed
Answer: D
Explanation:
Explanation/Reference: https://searchcompliance.techtarget.com/definition/Video-Privacy-Protection-Act-of-1988
NEW QUESTION # 62
Although an employer may have a strong incentive or legal obligation to monitor employees' conduct or behavior, some excessive monitoring may be considered an intrusion on employees' privacy? Which of the following is the strongest example of excessive monitoring by the employer?
- A. An employer who installs data loss prevention software on all employee computers to limit transmission of confidential company information.
- B. An employer who installs a video monitor in physical locations, such as a warehouse, to ensure employees are performing tasks in a safe manner and environment.
- C. An employer who installs video monitors in physical locations, such as a changing room, to reduce the risk of sexual harassment.
- D. An employer who records all employee phone calls that involve financial transactions with customers completed over the phone.
Answer: C
Explanation:
The strongest example of excessive monitoring by the employer is C. An employer who installs video monitors in physical locations, such as a changing room, to reduce the risk of sexual harassment. This would be considered an unreasonable invasion of employees' privacy, as it would violate their legitimate expectation of privacy in a place where they change their clothes. Such monitoring would also likely violate the Electronic Communications Privacy Act (ECPA), which prohibits the interception of oral communications without consent or authorization. Moreover, such monitoring would not be justified by a legitimate business interest, as there are less intrusive ways to prevent or address sexual harassment, such as policies, training, and reporting mechanisms. References:
* [IAPP CIPP/US Study Guide], Chapter 4: Workplace Privacy, pp. 109-110.
* IAPP CIPP/US Body of Knowledge, Section IV: Workplace Privacy, Subsection A: Employee Privacy Expectations, Topic 1: Employee Monitoring.
* IAPP CIPP/US Practice Questions, Question 134.
NEW QUESTION # 63
Once a breach has been definitively established, which task should be prioritized next?
- A. Implementing remedial measures and evaluating how to prevent future breaches.
- B. Determining what was responsible for the breach and neutralizing the threat.
- C. Providing notice to the affected parties so they can take precautionary measures.
- D. Involving law enforcement and state Attorneys General.
Answer: B
Explanation:
IAPP Book, Section 7.4, second step. Forward looking changes are in the fourth step
NEW QUESTION # 64
According to FERPA, when can a school disclose records without a student's consent?
- A. If the disclosure is to practitioners who are involved in a student's health care
- B. If the disclosure would not reveal a student's student identification number
- C. If the disclosure is to provide transcripts to a school where a student intends to enroll
- D. If the disclosure is not to be conducted through email to the third party
Answer: C
Explanation:
According to FERPA, a school may disclose personally identifiable information (PII) from an eligible student's education records without consent if the disclosure meets one of the exceptions in 34 CFR § 99.31.
One of these exceptions is for disclosures to other schools to which a student seeks or intends to enroll, or is already enrolled if the disclosure is for purposes related to the student's enrollment or transfer (34 CFR §
99.31(a)(2)). This exception allows schools to disclose transcripts, recommendations, or other information that may facilitate the student's admission or enrollment at another school. However, the school must make a reasonable attempt to notify the student of the disclosure, unless the student initiated the disclosure, and must provide the student with a copy of the records that were disclosed upon request (34 CFR § 99.34(a) (1)). References: https://studentprivacy.ed.gov/ferpa
https://studentprivacy.ed.gov/ferpa
NEW QUESTION # 65
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the best reason for Cheryl to follow Janice's suggestion about classifying customer data?
- A. It will increase the security of customers' personal information (PI)
- B. It will help the company meet a federal mandate
- C. It will help employees stay better organized
- D. It will prevent the company from collecting too much personal information (PI)
Answer: A
NEW QUESTION # 66
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
- A. California.
- B. Washington.
- C. New York.
- D. Vermont.
Answer: D
Explanation:
Explanation
Explanation/Reference: https://www.natlawreview.com/article/ringing-2019-new-state-privacy-and-data-security-laws- impacting-data-brokers-and
NEW QUESTION # 67
Which of the following is NOT one of three broad categories of products offered by data brokers, as identified by the U.S. Federal Trade Commission (FTC)?
- A. Location of individuals (such as identifying an individual from partial information).
- B. Research (such as information for understanding consumer trends).
- C. Marketing (such as appending data to customer information that a marketing company already has).
- D. Risk mitigation (such as information that may reduce the risk of fraud).
Answer: A
Explanation:
Data brokers are companies that collect, analyze, and share personal information about consumers for various purposes, such as marketing, risk mitigation, and research. The U.S. Federal Trade Commission (FTC) conducted a study of nine data brokers in 2012 and published a report in 2014, titled "Data Brokers: A Call for Transparency and Accountability". In the report, the FTC identified three broad categories of products offered by data brokers, based on the primary purposes for which the products are used by their customers. The three categories are: 12
* Marketing products: These products help customers target potential customers, tailor marketing offers, measure the effectiveness of marketing campaigns, and improve customer relationships. Marketing products include data elements, segments, scores, lists, and analytics that are derived from consumer data. Data brokers may provide marketing products through direct marketing (such as postal mail, e- mail, or phone), online marketing (such as online display ads, social media, or mobile apps), or marketing analytics (such as measuring consumer behavior, preferences, and trends)12
* Risk mitigation products: These products help customers verify and authenticate consumers' identities, prevent fraud, and comply with legal obligations. Risk mitigation products include identity verification, identity authentication, fraud prevention, and compliance products that are based on consumer data. Data brokers may provide risk mitigation products through various methods, such as matching consumer-provided information with data broker records, generating questions or challenges based on consumer data, or providing scores or indicators of fraud risk or compliance status12
* Research products: These products help customers understand consumer behavior, preferences, and trends, as well as market conditions, industry developments, and economic factors. Research products include reports, studies, statistics, and insights that are derived from consumer data. Data brokers may provide research products through various formats, such as online portals, dashboards, newsletters, or custom reports12 The FTC report did not include location of individuals as one of the three broad categories of products offered by data brokers. Location of individuals may be a specific type of product or service that some data brokers provide, but it is not a primary purpose for which data brokers use consumer data. Therefore, the correct answer is C. Location of individuals (such as identifying an individual from partial information).
References:
* Data Brokers: A Call For Transparency and Accountability: A Report of the Federal Trade Commission (May 2014)
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 5: State Privacy Laws, Section 5.3: Data Broker Laws
NEW QUESTION # 68
What is the primary purpose of the HIPAA Security Rule?
- A. Establish a secure manner of payment processing for insurance claims.
- B. Establish minimum security requirement for medical facilities following the 2001 terrorist attacks.
- C. Establish minimum security requirements for PHI collected in electronic form.
- D. Establish minimum security requirements for PHI collected in any form.
Answer: C
Explanation:
The Security Rule establishes minimum security requirements for PHI that a covered entity receives, creates, maintains, or transmits in electronic form.
NEW QUESTION # 69
Within what time period must a commercial message sender remove a recipient's address once they have asked to stop receiving future e-mail?
- A. 15 days
- B. 7 days
- C. 10 days
- D. 21 days
Answer: C
NEW QUESTION # 70
......
Enhance your career with CIPP-US PDF Dumps - True IAPP Exam Questions: https://www.itexamdownload.com/CIPP-US-valid-questions.html
Download CIPP-US Dumps (2026) - Free PDF Exam Demo: https://drive.google.com/open?id=1Qbvq36yKmiC_ccIRxbI5vthbkWBqJ1pP