
CIPP-US Certification - The Ultimate Guide [Updated 2024]
CIPP-US Practice Exam and Study Guides - Verified By 2Pass4sure
NEW QUESTION # 14
What privacy concept grants a consumer the right to view and correct errors on his or her credit report?
- A. Choice.
- B. Access.
- C. Action.
- D. Notice.
Answer: D
NEW QUESTION # 15
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?
- A. The ability to receive reports from multiple credit reporting agencies.
- B. The ability to appeal negative credit-based decisions.
- C. The ability to investigate incidents of identity theft.
- D. The ability to correct inaccurate credit information.
Answer: C
NEW QUESTION # 16
Which statute is considered part of U.S. federal privacy law?
- A. The Personal Information Protection and Electronic Documents Act.
- B. The e-Privacy Directive.
- C. SB 1386.
- D. The Fair Credit Reporting Act.
Answer: D
NEW QUESTION # 17
A company's employee wellness portal offers an app to track exercise activity via users' mobile devices. Which of the following design techniques would most effectively inform users of their data privacy rights and privileges when using the app?
- A. Provide a link to the wellness program privacy policy at the bottom of each screen.
- B. Present a privacy policy to users during the wellness program registration process.
- C. Offer information about data collection and uses at key data entry points.
- D. Publish a privacy policy written in clear, concise, and understandable language.
Answer: B
NEW QUESTION # 18
Mega Corp. is a U.S.-based business with employees in California, Virginia, and Colorado. Which of the following must Mega Corp. comply with in regard to its human resources data?
- A. California Privacy Rights Act and Colorado Privacy Act.
- B. California Privacy Rights Act and Virginia Consumer Data Protection Act.
- C. California Privacy Rights Act.
- D. California Privacy Rights Act, Virginia Consumer Data Protection Act, and Colorado Privacy Act.
Answer: C
NEW QUESTION # 19
The rules for "e-discovery" mainly prevent which of the following?
- A. A breach of an organization's data retention program
- B. The practice of employees using personal devices for work
- C. The loss of information due to poor data retention practices
- D. A conflict between business practice and technological safeguards
Answer: D
Explanation:
E-discovery is the process by which parties share, review, and collect electronically stored information (ESI) to use as evidence in a legal matter1. The rules for e-discovery mainly prevent a conflict between business practice and technological safeguards, because they establish the standards and procedures for preserving, collecting, reviewing, and producing ESI in a way that balances the needs of litigation with the realities of technology2. For example, the Federal Rules of Civil Procedure (FRCP) provide guidance on the scope, timing, format, and methods of e-discovery, as well as the sanctions for failing to comply withe-discovery obligations3. The rules also encourage cooperation and communication among parties and courts to resolve e-discovery issues efficiently and effectively4. By following the rules for e-discovery, parties can avoid disputes, delays, and costs that may arise from incompatible or inconsistent business and technological practices.
The other options are not the main purpose of the rules for e-discovery, although they may be related or affected by them. The rules for e-discovery do not directly prevent the loss of information due to poor data retention practices, although they do impose a duty to preserve relevant ESI when litigation is reasonably anticipated5. The rules for e-discovery do not directly prevent the practice of employees using personal devices for work, although they do require parties to identify and disclose the sources of ESI that may be subject to discovery, including personal devices6. The rules for e-discovery do not directly prevent a breach of an organization's data retention program, although they do require parties to produce ESI in a reasonably usable form and to protect privileged or confidential information7.
References: 1: Everything You Need to Know About E-Discovery, The National Law Review. 2: E-Discovery: The Basics of E-Discovery Guide - Exterro, Exterro.com. 3: Federal Court and Government Agency E-Discovery Rules and Guidelines, Crowell & Moring LLP. 4: FRCP Rule 1, Cornell Law School. 5: FRCP Rule 37, Cornell Law School. 6: FRCP Rule 26, Cornell Law School. 7: FRCP Rule 34, Cornell Law School.
NEW QUESTION # 20
Which venture would be subject to the requirements of Section 5 of the Federal Trade Commission Act?
- A. An online merchant's free shipping offer
- B. A local nonprofit charity's fundraiser
- C. A city bus system's frequent rider program
- D. A national bank's no-fee checking promotion
Answer: A
Explanation:
Section 5 of the Federal Trade Commission Act (FTC Act) prohibits "unfair or deceptive acts or practices in or affecting commerce."1 This prohibition applies to all persons engaged in commerce, including banks, but also exempts some entities, such as nonprofit organizations and common carriers, from FTC jurisdiction.2 Therefore, among the four options, only an online merchant's free shipping offer would be subject to the requirements of Section 5, as it involves a commercial activity thatcould potentially mislead or harm consumers. For example, if the online merchant fails to disclose the terms and conditions of the offer, or charges hidden fees, or delivers the products late or damaged, it could violate Section 5 by engaging in a deceptive practice.3 References: 1: Section 5 | Federal Trade Commission 2: Federal Trade Commission Act Section 5: Unfair or Deceptive Acts or Practices, page 13: IAPP CIPP/US Certified Information Privacy Professional Study Guide, page 23.
NEW QUESTION # 21
Which authority supervises and enforces laws regarding advertising to children via the Internet?
- A. The Office for Civil Rights
- B. The Department of Homeland Security
- C. The Federal Communications Commission
- D. The Federal Trade Commission
Answer: D
NEW QUESTION # 22
According to the FTC Report of 2012, what is the main goal of Privacy by Design?
- A. Establishing a system of self-regulatory codes for mobile-related services
- B. Implementing a system of standardization for privacy notices
- C. Obtaining consumer consent when collecting sensitive data for certain purposes
- D. Incorporating privacy protections throughout the development process
Answer: D
NEW QUESTION # 23
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?
- A. The ability to receive reports from multiple credit reporting agencies.
- B. The ability to investigate incidents of identity theft.
- C. The ability to correct inaccurate credit information.
- D. The ability to appeal negative credit-based decisions.
Answer: C
Explanation:
The Fair Credit Reporting Act (FCRA) was originally intended to provide consumers with the ability to correct inaccurate credit information that could affect their access to credit, employment, insurance, and other benefits. The FCRA gives consumers the right to access their credit reports from the three major credit reporting agencies (Equifax, Experian, and TransUnion) for free once every 12 months, and to dispute any errors or inaccuracies with the credit reporting agencies or the information furnishers (such as lenders, creditors, or debt collectors). The FCRA also requires the credit reporting agencies and the information furnishers to investigate and resolve the disputes within 30 days, and to delete or correct any information that is found to be inaccurate, incomplete, or outdated. The FCRA also provides consumers with the right to place fraud alerts or security freezes on their credit reports if they are victims or potential victims of identity theft, and to receive notifications from users of their credit reports (such as employers or insurers) if any adverse action is taken based on their credit information. References:
* Fair Credit Reporting Act - Wikipedia
* What is the Fair Credit Reporting Act (FCRA)? | Money
* The Fair Credit Reporting Act of 1970 - The Balance
* How the Fair Credit Reporting Act (FCRA) Protects Consumer Rights
NEW QUESTION # 24
Which is an exception to the general prohibitions on telephone monitoring that exist under the U.S. Wiretap Act?
- A. Internet calls exception
- B. Ordinary course of business exception
- C. Call center exception
- D. Inter-company communications exception
Answer: B
Explanation:
The U.S. Wiretap Act prohibits the interception and disclosure of wire, oral, or electronic communications, unless one of the statutory exceptions applies. One of these exceptions is the ordinary course of business exception, which allows an employer or service provider to intercept communications that are made in the ordinary course of its business, such as for quality control, training, or security purposes. This exception does not apply to communications that are not related to the business, such as personal calls or emails, or to communications that are intercepted for other reasons, such as harassment, discrimination, or retaliation. The scope and applicability of this exception may vary depending on the context, the consent of the parties, and the state law. The other options are not valid exceptions under the Wiretap Act. References: 1, 2, 3, 4
NEW QUESTION # 25
SCENARIO
Please use the following to answer the next QUESTION
Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in California. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask questions about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements.
Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision.
Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results.
Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. Celeste believes that even if the business grows a customer database of a few thousand, it's unlikely that a state agency would hassle an honest business if an accidental security incident were to occur.
In any case, Celeste feels that all they need is common sense - like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina.
Which law will be most relevant to Felicia's plan to ask applicants about drug addiction?
- A. The Americans with Disabilities Act (ADA).
- B. The Occupational Safety and Health Act (OSHA).
- C. The Health Insurance Portability and Accountability Act (HIPAA).
- D. The Genetic Information Nondiscrimination Act of 2008.
Answer: A
Explanation:
The ADA prohibits employers from discriminating against qualified individuals with disabilities in all aspects of employment, including hiring, firing, promotion, compensation, and training. The ADA also limits the types of medical inquiries and examinations that employers can make of applicants and employees. Under the ADA, a disability is defined as a physical or mental impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. The ADA covers current, past, and perceived drug addiction as a disability, unless the individual is currently engaging in the illegal use of drugs. Therefore, Felicia's plan to ask applicants about drug addiction may violate the ADA, unless she can show that the inquiry is job-related and consistent with business necessity. The other laws are not directly relevant to Felicia's plan, although they may have other implications for her business. References: ADA, IAPP CIPP/US Study Guide (p. 95-96)
NEW QUESTION # 26
All of the following are tasks in the "Discover" phase of building an information management program EXCEPT?
- A. Developing a process for review and update of privacy policies
- B. Facilitating participation across departments and levels
- C. Deciding how aggressive to be in the use of personal information
- D. Understanding the laws that regulate a company's collection of information
Answer: A
Explanation:
The "Discover" phase of building an information management program is the first step in the process of creating a privacy framework. It involves identifying the types, sources, and flows of personal information within an organization, as well as the legal, regulatory, and contractual obligations that apply to it. The tasks in this phase include:
* Conducting a data inventory and mapping exercise to document what personal information is collected, used, shared, and stored by the organization, and how it is protected.
* Assessing the current state of privacy compliance and risk by reviewing existing policies, procedures, and practices, and identifying any gaps or weaknesses.
* Understanding the laws that regulate a company's collection of information, such as the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), the Health Insurance Portability and Accountability Act (HIPAA), and the California Consumer Privacy Act (CCPA).
* Facilitating participation across departments and levels to ensure that all stakeholders are involved and informed of the privacy goals and objectives, and to foster a culture of privacy awareness and accountability.
Developing a process for review and update of privacy policies is not a task in the "Discover" phase, but rather in the "Implement" phase, which is the third step in the process of creating a privacy framework. It involves putting the privacy policies and procedures into action, and ensuring that they are effective and compliant. The tasks in this phase include:
* Developing a process for review and update of privacy policies to reflect changes in the business environment, legal requirements, and best practices, and to incorporate feedback from internal and external audits and assessments.
* Implementing privacy training and awareness programs to educate employees and other relevant parties on their roles and responsibilities regarding privacy, and to promote a privacy-by-design approach.
* Establishing privacy governance and oversight mechanisms to monitor and measure the performance and outcomes of the privacy program, and to ensure accountability and transparency.
* Developing a process for responding to privacy incidents and requests from data subjects, regulators, and other parties, and to mitigate and remediate any privacy risks or harms.
References:
* IAPP CIPP/US Body of Knowledge, Domain I: Information Management from a U.S. Perspective, Section A: Building a Privacy Program
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 1: Information Management from a U.S. Perspective, Section 1.1: Building a Privacy Program
* Practice Exam - International Association of Privacy Professionals
NEW QUESTION # 27
Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?
- A. Integrating privacy protections during product development.
- B. Announcing the tracking of online behavior for advertising purposes.
- C. Allowing consumers to opt in before collecting any data.
- D. Mitigating harm to consumers after a security breach.
Answer: A
Explanation:
According to the FTC report, the most important directive for businesses is to adopt a "privacy by design" approach, which means integrating privacy protections throughout the entire product lifecycle, from initial design to disposal. This includes implementing reasonable security measures, collecting only the data needed for a specific purpose, retaining data only as long as necessary, and safely disposing of data that is no longer needed. The FTC report also recommends that businesses provide clear and transparent privacy notices, offer consumers meaningful choices about how their data is used, and increase their accountability for data practices. References: FTC Report, IAPP CIPP/US Study Guide (p. 32-33)
NEW QUESTION # 28
U.S. federal laws protect individuals from employment discrimination based on all of the following EXCEPT?
- A. Age.
- B. Marital status.
- C. Genetic information.
- D. Pregnancy.
Answer: B
NEW QUESTION # 29
Which law provides employee benefits, but often mandates the collection of medical information?
- A. The Occupational Safety and Health Act.
- B. The Americans with Disabilities Act.
- C. The Family and Medical Leave Act.
- D. The Employee Medical Security Act.
Answer: C
Explanation:
The Family and Medical Leave Act (FMLA) is a federal law that provides eligible employees with up to 12 weeks of unpaid, job-protected leave per year for certain family and medical reasons, such as the birth or adoption of a child,the serious health condition of the employee or a family member, or a qualifying exigency arising from the employee's spouse, child, or parent being on covered active duty or call to covered active duty status in the Armed Forces. The FMLA also provides eligible employees with up to 26 weeks of unpaid, job-protected leave per year to care for a covered service member with a serious injury or illness if the employee is the spouse, child, parent, or next of kin of the service member. The FMLA applies to all public agencies, including state, local, and federal employers, and local education agencies (schools), and to private sector employers who employ 50 or more employees for at least 20 workweeks in the current or preceding calendar year.
The FMLA often requires employers to collect medical information from employees who request FMLA leave or from their health care providers to certify the need for leave, the duration of leave, and the employee's ability to return to work. The FMLA regulations specify the type and amount of information that employers may request and require for different types of FMLA leave, such as:
* Basic medical facts, such as the diagnosis, symptoms, hospitalization, doctor visits, whether medication has been prescribed, and any referrals for evaluation or treatment, for the employee's own serious health condition or that of a family member.
* Information on the medical necessity of intermittent leave or reduced schedule leave and the expected frequency and duration of such leave, for the employee's own serious health condition or that of a family member, or for planned medical treatment.
* A statement of the facts regarding the qualifying exigency, such as the type of military duty, the dates of the covered active duty, and the contact information of the military member, for leave due to a qualifying exigency arising from the employee's spouse, child, or parent being on covered active duty or call to covered active duty status in the Armed Forces.
* Information on the medical condition, treatment, and recovery of the covered service member, such as the date of injury or onset of illness, the current medical status, the prognosis, and the estimated time of treatment, for leave to care for a covered service member with a serious injury or illness.
The FMLA also imposes certain obligations on employers to protect the privacy and security of the medical information they collect from employees or their health care providers. For example, employers must:
* Maintain records and documents relating to medical certifications, recertifications, or medical histories of employees or employees' family members as confidential medical records in separate files/records from the usual personnel files, and if the Americans with Disabilities Act (ADA) applies, such records
* must be maintained in conformance with ADA confidentiality requirements.
* Ensure that any electronic systems used to maintain such records meet the confidentiality requirements of the FMLA and the ADA, and that only authorized persons have access to such records.
* Limit the disclosure of such records to supervisors and managers who need to know about an employee's FMLA leave, first aid and safety personnel when an employee's medical condition might require emergency treatment, and government officials investigating compliance with the FMLA.
* Comply with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule when requesting medical information from an employee's health care provider, such as obtaining a valid authorization from the employee or using a HIPAA-compliant certification form.
* Refrain from requesting more information than allowed by the FMLA regulations, such as asking for an employee's complete medical records or information unrelated to the FMLA leave request.
* Respect the employee's right to revoke a medical authorization or challenge a medical certification, and follow the procedures for resolving disputes over the validity or sufficiency of such documents.
References:
* The Family and Medical Leave Act (FMLA)
* FMLA Employee Guide
* FMLA Employer Guide
* FMLA Regulations
* FMLA Forms
NEW QUESTION # 30
SCENARIO
Please use the following to answer the next question:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many questions, he was pleased about his new position.
How can the radiology department address Declan's concern about paper waste and still comply with the Health Insurance Portability and Accountability Act (HIPAA)?
- A. Direct patients to the correct area of the hospital website
- B. Confirm that patients are given the privacy notice on their first visit
- C. State the privacy policy to the patient verbally
- D. Post the privacy notice in a prominent location instead
Answer: A
NEW QUESTION # 31
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to do what?
- A. Determine which bodies will be involved in adjudication
- B. Decide if any enforcement actions are justified
- C. Adhere to its industry's code of conduct
- D. Appeal decisions made against it
Answer: C
Explanation:
See IAPP book, Section 3.10, paragraph 2.
NEW QUESTION # 32
A law enforcement subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?
- A. ECPA
- B. SCA
- C. CALEA
- D. USA Freedom Act
Answer: C
Explanation:
To amend title 18, United States Code, to make clear a telecommunications carrier's duty to cooperate in the interception of communications for Law Enforcement purposes, and for other purposes.
NEW QUESTION # 33
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asi a. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
The Board has asked Otto whether the company will need to comply with the new California Consumer Privacy Law (CCPA). What should Otto tell the Board?
- A. That the company is governed by CCPA, but does not need to take any additional steps because it follows CPBR.
- B. That CCPA will apply to the company only after the California Attorney General determines that it will enforce the statute.
- C. That business contact information could be considered personal information governed by CCPA.
- D. That CCPA only applies to companies based in California, which exempts the company from compliance.
Answer: C
Explanation:
CCPA applies regardless of enforcement. Under the CPRA, which amended the CCPA, business contact information is PII.
NEW QUESTION # 34
Why was the Privacy Protection Act of 1980 drafted?
- A. To assist in the prosecution of white-collar crimes
- B. To respond to police searches of newspaper facilities
- C. To protect individuals from personal privacy invasion by the police
- D. To assist prosecutors in civil litigation against newspaper companies
Answer: B
Explanation:
The Privacy Protection Act of 1980 (PPA) is a federal law that protects journalists and newsrooms from search and seizure by government officials in connection with criminal investigations or prosecutions. The PPA prohibits the government from searching for or seizing any work product materials or documentary materials possessed by a person who intends to disseminate them to the public through a newspaper, book, broadcast, or other similar form of public communication, unless certain exceptions apply. The PPA was drafted in response to the Supreme Court's decision in Zurcher v. Stanford Daily, which upheld the constitutionality of a police search of a student newspaper's office without a subpoena, based on probable cause that the newspaper had evidence of a crime. The PPA was intended to protect the First Amendment rights of the press and the privacy interests of journalists and their sources from unreasonable government intrusion123. References:
* 1: IAPP, Privacy Protection Act of 1980, https://epic.org/the-privacy-protection-act-of-1980/
* 2: DOJ, Privacy Protection Act of 1980,
https://www.justice.gov/archives/jm/criminal-resource-manual-661-privacy-protection-act-1980
* 3: Wikipedia, Privacy Protection Act of 1980,
https://en.wikipedia.org/wiki/Privacy_Protection_Act_of_1980
NEW QUESTION # 35
......
Ultimate Guide to the CIPP-US - Latest Edition Available Now: https://certtree.2pass4sure.com/Certified-Information-Privacy-Professional/CIPP-US-actual-exam-braindumps.html