
Use Real IAPP Achieve the CIPP-US Dumps - 100% Exam Passing Guarantee
Verified CIPP-US Q&As - Pass Guarantee CIPP-US Exam Dumps
NEW QUESTION # 23
All of the following are tasks in the "Discover" phase of building an information management program EXCEPT?
- A. Developing a process for review and update of privacy policies
- B. Deciding how aggressive to be in the use of personal information
- C. Facilitating participation across departments and levels
- D. Understanding the laws that regulate a company's collection of information
Answer: A
Explanation:
The "Discover" phase of building an information management program is the first step in the process of creating a privacy framework. It involves identifying the types, sources, and flows of personal information within an organization, as well as the legal, regulatory, and contractual obligations that apply to it. The tasks in this phase include:
* Conducting a data inventory and mapping exercise to document what personal information is collected, used, shared, and stored by the organization, and how it is protected.
* Assessing the current state of privacy compliance and risk by reviewing existing policies, procedures, and practices, and identifying any gaps or weaknesses.
* Understanding the laws that regulate a company's collection of information, such as the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), the Health Insurance Portability and Accountability Act (HIPAA), and the California Consumer Privacy Act (CCPA).
* Facilitating participation across departments and levels to ensure that all stakeholders are involved and informed of the privacy goals and objectives, and to foster a culture of privacy awareness and accountability.
Developing a process for review and update of privacy policies is not a task in the "Discover" phase, but rather in the "Implement" phase, which is the third step in the process of creating a privacy framework. It involves putting the privacy policies and procedures into action, and ensuring that they are effective and compliant. The tasks in this phase include:
* Developing a process for review and update of privacy policies to reflect changes in the business environment, legal requirements, and best practices, and to incorporate feedback from internal and external audits and assessments.
* Implementing privacy training and awareness programs to educate employees and other relevant parties on their roles and responsibilities regarding privacy, and to promote a privacy-by-design approach.
* Establishing privacy governance and oversight mechanisms to monitor and measure the performance and outcomes of the privacy program, and to ensure accountability and transparency.
* Developing a process for responding to privacy incidents and requests from data subjects, regulators, and other parties, and to mitigate and remediate any privacy risks or harms.
References:
* IAPP CIPP/US Body of Knowledge, Domain I: Information Management from a U.S. Perspective, Section A: Building a Privacy Program
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 1: Information Management from a U.S. Perspective, Section 1.1: Building a Privacy Program
* Practice Exam - International Association of Privacy Professionals
NEW QUESTION # 24
Which of the following is NOT one of three broad categories of products offered by data brokers, as identified by the U.S. Federal Trade Commission (FTC)?
- A. Risk mitigation (such as information that may reduce the risk of fraud).
- B. Location of individuals (such as identifying an individual from partial information).
- C. Research (such as information for understanding consumer trends).
- D. Marketing (such as appending data to customer information that a marketing company already has).
Answer: B
NEW QUESTION # 25
Sarah lives in San Francisco, Californi
a. Based on a dramatic increase in unsolicited commercial emails, Sarah believes that a major social media platform with over 50 million users has collected a lot of personal information about her. The company that runs the platform is based in New York and France.
Why is Sarah entitled to ask the social media platform to delete the personal information they have collected about her?
- A. The California Consumer Privacy Act entitles Sarah to request deletion of her personal information.
- B. Any company with a presence in Europe must comply with the General Data Protection Regulation globally, including in response to data subject deletion requests.
- C. The New York "Stop Hacks and Improve Electronic Data Security" (SHIELD) Act requires that businesses under New York's jurisdiction must delete customers' personal information upon request.
- D. Under Section 5 of the FTC Act, the Federal Trade Commission has held that refusing to delete an individual's personal information upon request constitutes an unfair practice.
Answer: A
NEW QUESTION # 26
In which situation would a policy of "no consumer choice" or "no option" be expected?
- A. When a customer's street address is shared with a shipping company
- B. When a customer's financial information is requested by the government
- C. When a patient's health record is made available to a pharmaceutical company
- D. When a job applicant's credit report is provided to an employer
Answer: A
NEW QUESTION # 27
Which of the following is NOT a principle found in the APEC Privacy Framework?
- A. Integrity of Personal Information.
- B. Preventing Harm.
- C. Access and Correction.
- D. Privacy by Design.
Answer: D
NEW QUESTION # 28
What information did the Red Flag Program Clarification Act of 2010 add to the original Red Flags rule?
- A. The definition of what constitutes a creditor.
- B. The components of an identity theft detection program.
- C. The most common methods of identity theft.
- D. The process for proper disposal of sensitive data.
Answer: A
Explanation:
The Red Flag Program Clarification Act of 2010 amended the original Red Flags rule, which required certain financial institutions and creditors to develop and implement a written identity theft prevention program. The Clarification Act narrowed the definition of creditor to include only those who regularly and in the ordinary course of business advance funds to or on behalf of a person, based on an obligation of the person to repay the funds or repayable from specific property pledged by or on behalf of the person12. This excludes creditors who advance funds for expenses incidental to a service provided by the creditor to that person3. References:
* CIPP/US Practice Questions (Sample Questions), Question 133, Answer B, Explanation B.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 4, Section 4.3, p. 108-
109.
* Red Flag Program Clarification Act of 2010, Section 2, Subsection (b).
NEW QUESTION # 29
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-basedretailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Upon review, the data privacy leader discovers that the Company's documented data inventory is obsolete.
What is the data privacy leader's next best source of information to aid the investigation?
- A. Interviews with key marketing personnel
- B. Database schemas held by the retailer
- C. Lists of all customers, sorted by country
- D. Reports on recent purchase histories
Answer: A
Explanation:
The data privacy leader needs to identify all the personal data that the Company has received from the retailer, as well as the purposes, retention periods, and sharing practices of such data. Since the data inventory is obsolete, the data privacy leader cannot rely on it to provide accurate and complete information. Therefore, the next best source of information is to interview the key marketing personnel who are responsible for the partnership with the retailer and the use of the personal data. The marketing personnel can provide insights into the data flows, the data categories, the data processing activities, and the data protection measures that the Company has implemented. They can also help the data privacy leader to locate the relevant documents, contracts, and records that can support the investigation. References: [IAPP CIPP/US Study Guide], Chapter 5:
Data Management, p. 97-98; IAPP Privacy Tech Vendor Report, Data Mapping and Inventory, p. 9-10.
NEW QUESTION # 30
What practice do courts commonly require in order to protect certain personal information on documents, whether paper or electronic, that is involved in litigation?
- A. Hashing
- B. Redaction
- C. Deletion
- D. Encryption
Answer: B
Explanation:
Redaction is the permanent removal of sensitive data-the digital equivalent of "blacking out" text in printed material. Redaction can be accomplished by simply deleting characters from a file or database record, or by replacing characters with asterisks or other placeholders. Redaction is often used to protect personal information, such as names, addresses, social security numbers, or financial data, on documents that are disclosed in litigation, such as pleadings, exhibits, or discovery responses. Redaction is required by courts to comply with privacy laws and rules, such as the Federal Rules of Civil Procedure (FRCP), which mandate that parties must redact certain types of personal information from documents filed with the court or produced to the other party. Redaction is also a best practice to minimize the risk of unauthorized access, identity theft, or reputational harm that may result from exposing personal information in litigation. References:
* When to redact, or not, disclosable documents in litigation - Stewarts
* The approach to redaction - High Court guidance - Lexology
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 3: Federal Privacy Laws and Regulations, Section 3.2: Federal Rules of Civil Procedure (FRCP).
NEW QUESTION # 31
The U.S. Supreme Court has recognized an individual's right to privacy over personal issues, such as contraception, by acknowledging which of the following?
- A. A "penumbra" of unenumerated constitutional rights as well as more general protections of due process of law.
- B. Federal preemption of state constitutions that expressly recognize an individual right to privacy.
- C. An interpretation of the U.S. Constitution's explicit definition of privacy that extends to personal issues.
- D. The doctrine of stare decisis, which allows the U.S. Supreme Court to follow the precedent of previously decided case law.
Answer: A
Explanation:
The U.S. Supreme Court has recognized an individual's right to privacy over personal issues, such as contraception, by acknowledging a "penumbra" of unenumerated constitutional rights as well as more general protections of due process of law. This means that the right to privacy is not explicitly stated in the Constitution, but it is implied from other rights that are explicitly stated, such as the First Amendment rights of speech and assembly, the Third Amendment right to be free from quartering of soldiers, the Fourth Amendment right to be secure from unreasonable searches and seizures, the Fifth Amendment right to be free from self-incrimination, and the Ninth Amendment right to retain other rights not enumerated in the Constitution. These rights create a
"zone of privacy" that protects individuals from undue government interference in their personal affairs. The Supreme Court first articulated this concept of privacy in Griswold v. Connecticut (1965), where it struck down a state law that prohibited the use of contraceptives by married couples. The Court also relied on the due process clause of the Fourteenth Amendment, which prohibits states from depriving any person of life, liberty, or property without due process of law.
The Court interpreted this clause to include a substantive component that protects certain fundamental rights from state regulation, unless there is a compelling state interest and the regulation is narrowly tailored to achieve that interest. The Court has applied this due process analysis to other privacy issues, such as abortion, marriage, and sexual orientation.
NEW QUESTION # 32
Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?
- A. The entity must have employees in the state
- B. The entity must be an information broker
- C. The entity must conduct business in the state
- D. The entity must be registered in the state
Answer: C
NEW QUESTION # 33
Which power was NOT granted to the California Privacy Protection Agency by the California Privacy Rights Act (CPRA)?
- A. Imposing administrative fines for violations of the CCPA
- B. Investigating possible violations of the CCPA on the agency's own initiative.
- C. Overriding decisions of the Attorney General regarding CCPA enforcement
- D. Adopting and updating CCPA regulations
Answer: C
Explanation:
The California Privacy Rights Act (CPRA), which amends the California Consumer Privacy Act (CCPA), created the California Privacy Protection Agency (CPPA). This agency has been granted significant authority to regulate and enforce California privacy laws, but it does not have the authority to override decisions made by the California Attorney General regarding CCPA enforcement.
Powers Granted to the CPPA by the CPRA:
Adopting and Updating CCPA Regulations:
The CPPA has rulemaking authority, meaning it can adopt, amend, and update CCPA regulations to clarify obligations under the law.
This is explicitly stated in the CPRA.
Investigating Violations:
The CPPA can independently investigate potential violations of the CCPA, even without a complaint from a consumer.
Imposing Administrative Fines:
The CPPA has the authority to impose administrative fines for violations of the CCPA, which is critical for enforcing compliance.
NEW QUESTION # 34
Global Manufacturing Co's Human Resources department recently purchased a new software tool. This tool helps evaluate future candidates for executive roles by scanning emails to see what those candidates say and what is said about them. This provides the HR department with an automated "360 review" that lets them know how the candidate thinks and operates, what their peers and direct reports say about them, and how well they interact with each other.
What is the most important step for the Human Resources Department to take when implementing this new software?
- A. Providing notice to employees that their emails will be scanned by the software and creating automated profiles.
- B. Ensuring that the software contains a privacy notice explaining that employees have no right to privacy as long as they are running this software on organization systems to scan email systems.
- C. Confirming that employees have read and signed the employee handbook where they have been advised that they have no right to privacy as long as they are using the organization's systems, regardless of the protected group or laws enforced by EEOC.
- D. Making sure that the software does not unintentionally discriminate against protected groups.
Answer: A
Explanation:
The most important step for the HR department to take when implementing this new software is to provide notice to employees that their emails will be scanned by the software and creating automated profiles. This is because the software involves the collection and use of personal information from employees, which may implicate their privacy rights and expectations. By providing notice, the HR department can inform employees about the purpose, scope, and consequences of the software, as well as their choices and rights regarding their data. Notice is also a key element of transparency and accountability, which are essential principles of privacy management. Providing notice can also help the HR department comply with various privacy laws and regulations that may apply to the software, such as the Electronic Communications Privacy Act (ECPA), the Stored Communications Act (SCA), the Fair Credit Reporting Act (FCRA), and state privacy laws. Notice can also help the HR department avoid potential legal risks and liabilities that may arise from the software, such as claims of invasion of privacy, breach of contract, or violation of employee rights. References:
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 4,
* Section 4.2.1, pp. 97-98.
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 5, Section 5.2.1, pp. 125-126.
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 6, Section 6.2.1, pp. 153-154.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide by Mike Chapple and Joe Shelley, Chapter 4, Section 4.1, pp. 113-114.
NEW QUESTION # 35
SCENARIO
Please use the following to answer the next question:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Upon review, the data privacy leader discovers that the Company's documented data inventory is obsolete. What is the data privacy leader's next best source of information to aid the investigation?
- A. Interviews with key marketing personnel
- B. Database schemas held by the retailer
- C. Lists of all customers, sorted by country
- D. Reports on recent purchase histories
Answer: A
Explanation:
The data privacy leader needs to identify all the personal data that the Company has received from the retailer, as well as the purposes, retention periods, and sharing practices of such data.
Since the data inventory is obsolete, the data privacy leader cannot rely on it to provide accurate and complete information. Therefore, the next best source of information is to interview the key marketing personnel who are responsible for the partnership with the retailer and the use of the personal data. The marketing personnel can provide insights into the data flows, the data categories, the data processing activities, and the data protection measures that the Company has implemented. They can also help the data privacy leader to locate the relevant documents, contracts, and records that can support the investigation.
NEW QUESTION # 36
Which of the following federal agencies does NOT have regulatory authority related to privacy?
- A. Consumer Financial Protection Bureau.
- B. U.S. Department of Commerce.
- C. Federal Reserve
- D. U.S. Department of Transportation.
Answer: D
NEW QUESTION # 37
What practice does the USA FREEDOM Act NOT authorize?
- A. The bulk collection of telephone data and internet metadata
- B. Emergency exceptions that allows the government to target roamers
- C. An increase in the maximum penalty for material support to terrorism
- D. An extension of the expiration for roving wiretaps
Answer: B
NEW QUESTION # 38
Which of the following laws is NOT involved in the regulation of employee background checks?
- A. The U.S. Fair Credit Reporting Act (FCRA).
- B. The California Investigative Consumer Reporting Agencies Act (ICRAA).
- C. The Gramm-Leach-Bliley Act (GLBA).
- D. The Civil Rights Act.
Answer: C
Explanation:
The law that is not involved in the regulation of employee background checks is B. The Gramm-Leach-Bliley Act (GLBA). The GLBA is a federal law that regulates the privacy and security of financial information collected, used, or shared by financial institutions, such as banks, insurance companies, or securities firms. The GLBA does not apply to employee background checks, unless the employer is a financial institution that obtains financial information from a consumer reporting agency for employment purposes. In that case, the employer must comply with the GLBA's notice and opt-out requirements, as well as the FCRA's requirements for using consumer reports. References:
* [IAPP CIPP/US Study Guide], Chapter 4: Workplace Privacy, pp. 113-114.
* IAPP CIPP/US Body of Knowledge, Section IV: Workplace Privacy, Subsection A: Employee Privacy Expectations, Topic 3: Background Checks.
* IAPP CIPP/US Practice Questions, Question 150.
NEW QUESTION # 39
......
Conclusion
The CIPP-US exam is into verifying a candidate's knowledge of the US data privacy laws and regulations. It helps to determine how well someone is fit for this field. For the ultimate success, the candidate should use the applicable guides and study course to ensure they pass it in one go.
IAPP CIPP-US: Certified Information Privacy Professional/United States (CIPP/US) Certified Professional salary
The average salary of a IAPP CIPP-US: Certified Information Privacy Professional/United States (CIPP/US) Certified Expert in:
- Europe - 55,347 EURO
- England - 50,632 POUND
- India - 12,42,327 INR
- United State - 70,247 USD
Check the Free demo of our CIPP-US Exam Dumps with 228 Questions: https://www.itexamdownload.com/CIPP-US-valid-questions.html
Clear your concepts with CIPP-US Questions Before Attempting Real exam: https://drive.google.com/open?id=1Wn6oUpPHvY2j4FtRtvzQPZiik2Rm-B4G