
[Mar-2026 Newly Released] Pass CIPP-US Exam - Real Questions and Answers
Pass CIPP-US Review Guide, Reliable CIPP-US Test Engine
NEW QUESTION # 25
Which was NOT one of the five priority areas listed by the Federal Trade Commission in its 2012 report, "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers"?
- A. Promoting enforceable self-regulatory codes
- B. Large platform providers
- C. International data transfers
- D. Do Not Track
Answer: D
Explanation:
The Federal Trade Commission (FTC) issued its 2012 report, "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers"1, which outlined a framework for privacy protection based on three main principles: privacy by design, simplified consumer choice, and greater transparency. The report also identified five priority areas for the FTC's privacy enforcement and policy efforts, which were:
Data brokers
Large platform providers
Mobile
Promoting enforceable self-regulatory codes
International data transfers
Do Not Track was not one of the five priority areas, but rather a specific mechanism for implementing the principle of simplified consumer choice. The report endorsed the development of a Do Not Track system that would allow consumers to opt out of online behavioral advertising across websites and platforms. The report also noted the progress made by various stakeholders, such as the World Wide Web Consortium (W3C), the Digital Advertising Alliance (DAA), and browser companies, in advancing the Do Not Track initiative.
NEW QUESTION # 26
The "Consumer Privacy Bill of Rights" presented in a 2012 Obama administration report is generally based on?
- A. Common law principles
- B. European Union Directive
- C. The 1974 Privacy Act
- D. Traditional fair information practices
Answer: D
Explanation:
"he 2012 White House Report contains a preface signed by President Obama and defines the "Consumer Privacy Bill of Rights" based on traditional fair information practices (FIPs)."
NEW QUESTION # 27
Which of the following would NOT fall under the jurisdiction of the GDPR?
- A. A US company who sells products and services in South America.
- B. A Spanish company that processes data of US citizens.
- C. A German company with assets in France and employees in both companies.
- D. An Italian company selling products and services worldwide.
Answer: A
Explanation:
The GPDR applies to companies with assets and employees in the EU, to companies that sell to people in the EU and to data processed in the EU.
NEW QUESTION # 28
Your company, an online store selling digital keys to video games, has received a data access request from an individual. Specifically, the individual wants access to her recent purchase history, as she has misplaced the emails containing the digital keys to multiple game purchases she made last month.
From a security standpoint, what would the user have to do under CCPA in order to acceptably verify her identity?
- A. Provide a notarized affidavit signed by two witnesses.
- B. Log in to her password-protected account with the company
- C. Phone the company and provide her contact details and credit card number
- D. Take a photo of herself with her driver license
Answer: B
Explanation:
Under the California Consumer Privacy Act (CCPA), businesses must verify the identity of individuals making data access requests to ensure the security of personal information. The most secure and straightforward way to verify a consumer's identity is by requiring the individual to log in to their password- protected account, as this demonstrates that the requester is the account owner.
Why Password-Protected Accounts Are Best for Verification:
* Account-Based Relationship:If the consumer has a password-protected account with the business, verification can typically be achieved by having the consumer log in to the account. This is considered a sufficient method of verifying identity under CCPA guidelines.
* Minimizing Risk:Verifying identity through account login reduces the risk of fraudulent access to personal information, as only the account owner has access to the login credentials.
Explanation of Options:
* A. Take a photo of herself with her driver license:While this might verify identity, it is more intrusive and poses unnecessary risks of identity theft. This is not a preferred or common method under the CCPA.
* B. Provide a notarized affidavit signed by two witnesses:This is excessive and impractical for verifying identity in most cases, particularly for an online store.
* C. Log in to her password-protected account with the company:This is correct. Logging into a password-protected account is a straightforward and secure way to verify the identity of a requester under the CCPA.
* D. Phone the company and provide her contact details and credit card number:This method is insecure, as it could lead to identity theft or fraudulent access if someone else provides this information.
References from CIPP/US Materials:
* CCPA Regulations (11 CCR ยง 999.323): Specifies identity verification requirements, including the use of password-protected accounts.
* IAPP CIPP/US Certification Textbook: Covers secure methods for verifying consumer identity under the CCPA.
NEW QUESTION # 29
When does the Telemarketing Sales Rule require an entity to share a do-not-call request across its organization?
- A. When a call is not the result of an error or other unforeseen cause
- B. When the goods and services sold by its divisions are very similar
- C. When the operational structures of its divisions are not transparent
- D. When the entity manages user preferences through multiple platforms
Answer: C
Explanation:
The Telemarketing Sales Rule (TSR) is a federal regulation that implements the Telemarketing and Consumer Fraud and Abuse Prevention Act of 199. The TSR aims to protect consumers from deceptive or abusive telemarketing practices, such as unwanted calls, false or misleading claims, unauthorized billing, and privacy violations.
The TSR requires telemarketers and sellers to comply with the National Do Not Call Registry, which is a list of phone numbers of consumers who have indicated that they do not want to receive telemarketing calls.
The TSR also requires telemarketers and sellers to honor the do-not-call requests of individual consumers, regardless of whether their numbers are on the National Do Not Call Registry or not.
A do-not-call request is a statement made by a consumer, either orally or in writing, that they do not wish to receive any more calls from a specific telemarketer or seller. The TSR requires an entity to share a do-not-call request across its organization when the operational structures of its divisions are not transparent to consumers. This means that the entity must treat the do-not-call request as if it applies to all of its affiliates and subsidiaries that engage in telemarketing, unless the consumer would reasonably expect them to be separate and distinct entities based on their names, products, or services. The TSR does not require an entity to share a do-not-call request across its organization in the following situations:
When the goods and services sold by its divisions are very similar. This is not a relevant factor for determining whether the entity must share a do-not-call request across its organization. The key factor is whether the consumers can distinguish between the different divisions based on their operational structures.
When a call is not the result of an error or other unforeseen cause. This is not an exception to the requirement to honor a do-not-call request. The TSR prohibits telemarketers and sellers from calling a consumer who has made a do-not-call request, unless the call falls under one of the specific exemptions, such as calls from or on behalf of tax-exempt nonprofit organizations, calls to consumers with whom the seller has an established business relationship, or calls to consumers who have given prior express written consent.
When the entity manages user preferences through multiple platforms. This is not an excuse for not sharing a do-not-call request across its organization. The TSR requires telemarketers and sellers to maintain an internal do-not-call list of consumers who have asked them not to call again, and to update the list at least once every 31 days. The entity must ensure that the do-not- call request is recorded and communicated across all of its platforms that are used for telemarketing purposes.
NEW QUESTION # 30
What was the primary reason for the creation of HIPAA?
- A. To introduce protected health information security measures.
- B. To create a common database within healthcare systems for patient diagnosis and prescription management.
- C. To increase the efficiency of electronic healthcare payments.
- D. To extend privacy laws to business associates within health care.
Answer: C
Explanation:
Although HIPAA contains extensive privacy protection, the law is mainly adopted to increase the efficiency of (electronic) healthcare payments.
NEW QUESTION # 31
What was unique about the action that the Federal Trade Commission took against B.J.'s Wholesale Club in 2005?
- A. It made user consent mandatory after any revisions of policy.
- B. It was the first substantial U.S.-EU Safe Harbor enforcement.
- C. It made third-party audits a penalty for policy violations.
- D. It was based on matters of fairness rather than deception.
Answer: D
Explanation:
The Federal Trade Commission (FTC) is the primary federal agency that enforces consumer privacy and data security laws in the United States. The FTC has the authority to bring enforcement actions against businesses that engage in unfair or deceptive acts or practices that affect commerce, under Section 5 of the FTC Act. Unfair acts or practices are those that cause or are likely to cause substantial injury to consumers that is not reasonably avoidable by consumers and is not outweighed by countervailing benefits to consumers or competition. Deceptive acts or practices are those that involve a material representation, omission, or practice that is likely to mislead consumers acting reasonably under the circumstances.
The FTC's action against B.J.'s Wholesale Club in 2005 was unique because it was based on matters of fairness rather than deception. The FTC alleged that B.J.'s Wholesale Club, a retailer that operates warehouse stores and gas stations, failed to provide reasonable security for the sensitive information of its customers, such as name, card number, and expiration date, that it collected from the magnetic stripes of credit and debit cards. The FTC claimed that this information was used by unauthorized persons to make millions of dollars of fraudulent purchases. The FTC did not allege that B.J.'s Wholesale Club made any false or misleading statements or omissions about its data security practices, but rather that its failure to take appropriate security measures was an unfair practice that violated Section 5 of the FTC Act. The FTC argued that B.J.'s Wholesale Club's lax security caused or was likely to cause substantial injury to consumers that was not reasonably avoidable by consumers and was not outweighed by any benefits to consumers or competition. The FTC's action against B.J.'s Wholesale Club was one of the first cases in which the FTC used its unfairness authority to address data security issues, and it set a precedent for future enforcement actions against businesses that fail to protect consumer data. The settlement required B.J.'s Wholesale Club to implement a comprehensive information security program and obtain audits by an independent third-party security professional every other year for 20 years.
NEW QUESTION # 32
U.S. federal laws protect individuals from employment discrimination based on all of the following EXCEPT?
- A. Pregnancy.
- B. Age.
- C. Marital status.
- D. Genetic information.
Answer: C
NEW QUESTION # 33
What was the original purpose of the Federal Trade Commission Act?
- A. To ensure privacy rights of U.S. citizens
- B. To negotiate consent decrees with companies violating personal privacy
- C. To protect consumers
- D. To enforce antitrust laws
Answer: D
Explanation:
The Federal Trade Commission Act (FTCA) was adopted in 1914 as part of the Progressive Era reforms that aimed to curb the power and influence of monopolies and trusts in the U.S. economy. The FTCA created the Federal Trade Commission (FTC) as an independent agency to investigate and prevent unfairmethods of competition and unfair or deceptive acts or practices in or affecting commerce. The FTCA also gave the FTC the authority to issue cease and desist orders, seek injunctions, and impose civil penalties for violations of the law. The FTCA was intended to complement and supplement the existing antitrust laws, such as the Sherman Act and the Clayton Act, that prohibited restraints of trade, price-fixing, mergers, and other anticompetitive conduct.
The other options are not correct, because:
* The FTCA did not explicitly address privacy rights of U.S. citizens, although the FTC later used its authority under the FTCA to enforce against unfair or deceptive privacy practices, such as making false or misleading claims, failing to disclose material information, or violating consumers' choices or expectations regarding their personal data.
* The FTCA did not specifically focus on consumer protection, although the FTC later expanded its scope to include consumer protection issues, such as advertising and marketing, credit and finance, privacy and security, and consumer education. The FTC also enforced other consumer protection laws, such as the Truth in Lending Act, the Fair Credit Reporting Act, the Children's Online Privacy Protection Act, and the CAN-SPAM Act.
* The FTCA did not authorize the FTC to negotiate consent decrees with companies violating personal privacy, although the FTC later used consent decrees as a common tool to settle privacy cases and impose remedial measures, such as audits, reports, and compliance programs. Consent decrees are agreements between the FTC and the parties involved in a case that resolve the FTC's charges without admitting liability or wrongdoing.
References:
* FTC website, Federal Trade Commission Act
* Britannica website, Federal Trade Commission Act (FTCA)
* IAPP CIPP/US Study Guide, Chapter 1: Introduction to the U.S. Privacy Environment, pp. 11-12
* IAPP website, Federal Trade Commission Act, Section 5 of
NEW QUESTION # 34
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- A. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
- B. A bill of rights for individuals seeking access to their personal information.
- C. A code of responsibilities for medical establishments to uphold privacy laws.
- D. An international court ruling on personal information held in the commercial sector.
Answer: B
NEW QUESTION # 35
Which statement is FALSE regarding the provisions of the Employee Polygraph Protection Act of
1988 (EPPA)?
- A. The EPPA requires that employers post essential information about the Act in a conspicuous location.
- B. The EPPA includes an exception that allows polygraph tests in professions in which employee honesty is necessary for public safety.
- C. Employers involved in the manufacture of controlled substances may terminate employees based on polygraph results if other evidence exists.
- D. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits.
Answer: D
Explanation:
The false statement regarding the provisions of the EPPA is C. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits. The EPPA does not regulate psychological testing, only polygraph testing. Psychological testing is a broad term that covers various types of assessments that measure cognitive abilities, personality traits, interests, values, and skills. Employers may use psychological testing for various purposes, such as hiring, promotion, training, or development, as long as they comply with other laws and regulations, such as the Americans with Disabilities Act (ADA), the Equal Employment Opportunity Commission (EEOC) guidelines, and the Uniform Guidelines on Employee Selection Procedures. However, employers should be careful to ensure that the psychological tests they use are valid, reliable, job-related, and nondiscriminatory, and that they respect the privacy and dignity of the test takers.
NEW QUESTION # 36
An organization self-certified under Privacy Shield must, upon request by an individual, do what?
- A. Provide the identities of third and fourth parties that may potentially receive personal information.
- B. Provide the identities of third parties with whom the organization shares personal information.
- C. Suspend the use of all personal information collected by the organization to fulfill its original purpose.
- D. Identify all personal information disclosed during a criminal investigation.
Answer: B
NEW QUESTION # 37
A large online bookseller decides to contract with a vendor to manage Personal Information (PI). What is the least important factor for the company to consider when selecting the vendor?
- A. The vendor's financial health
- B. The vendor's employee training program
- C. The vendor's reputation
- D. The vendor's employee retention rates
Answer: D
Explanation:
When selecting a vendor to manage personal information, the company should consider various criteria, such as the vendor's reputation, financial health, employee training program, privacy policies, security practices, compliance record, contractual terms, and service quality. However, the vendor's employee retention rates may not be as important as the other factors, as they do not directly affect the vendor's ability to protect and process the personal information entrusted to them. While high employee turnover may indicate some issues with the vendor's management or culture, it may not necessarily impact the vendor's performance or reliability, as long as the vendor has adequate measures to ensure continuity, accountability, and confidentiality of the personal information they handle. References:
* Vendor Selection Process: a Step-by-Step Guide, section "Step 2: Define the vendor selection criteria"
* [IAPP CIPP/US Study Guide], p. 81-82, section 3.4.1
* [IAPP CIPP/US Body of Knowledge], p. 18-19, section C.2.a
NEW QUESTION # 38
What role does the U.S. Constitution play in the area of workplace privacy?
- A. It provides legal precedent for physical information security, but not for electronic security
- B. It provides contractual protections to members of labor unions, but not to employees at will
- C. It provides enforcement resources to large employers, but not to small businesses
- D. It provides significant protections to federal and state governments, but not to private-sector employment
Answer: D
Explanation:
The U.S. Constitution plays a limited role in the area of workplace privacy, because it mainly applies to the actions of the government, not private employers. The Fourth Amendment protects the right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures. The Supreme Court has interpreted this right to include a reasonable expectation of privacy in certain situations, such as in one's home, car, or personal belongings. However, this right does not extend to private-sector employees, who are not protected by the Constitution from the actions of their employers, unless the employer is acting as an agent of the government. Private-sector employees may have some privacy rights under state laws, common law, or contractual agreements, but these vary depending on the jurisdiction and the circumstances.
Public-sector employees, on the other hand, are protected by the Constitution from unreasonable searches and seizures by their employers, who are considered part of the government. Public- sector employees have a reasonable expectation of privacy in their workplace, unless there is a legitimate work-related reason for the search or seizure, such as to ensure safety, security, or efficiency. Public- sector employers must also comply with the due process and equal protection clauses of the Fifth and Fourteenth Amendments, which prohibit the government from depriving any person of life, liberty, or property without due process of law, or from denying any person the equal protection of the laws. These clauses protect public-sector employees from arbitrary or discriminatory actions by their employers that affect their employment status or benefits.
Therefore, the U.S. Constitution plays a significant role in the area of workplace privacy for federal and state governments, but not for private-sector employment, because it only regulates the actions of the government, not private actors.
NEW QUESTION # 39
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?
- A. Refrain from selling their personal information to third parties.
- B. Correct their personal information.
- C. Delete their personal information.
- D. Disclose their personal information to them.
Answer: D
Explanation:
https://oag.ca.gov/privacy/ccpa
NEW QUESTION # 40
SCENARIO
Please use the following to answer the next QUESTION
Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in Californi a. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask Question:s about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements.
Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision.
Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. Celeste believes that even if the business grows a customer database of a few thousand, it's unlikely that a state agency would hassle an honest business if an accidental security incident were to occur.
In any case, Celeste feels that all they need is common sense - like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina.
Based on Felicia's Bring Your Own Device (BYOD) plan, the business consultant will most likely advise Felicia and Celeste to do what?
- A. Adopt the same kind of monitoring policies used for work-issued devices.
- B. Reconsider the plan in favor of a policy of dedicated work devices.
- C. Make employment decisions based on those willing to consent to the plan in writing.
- D. Weigh any productivity benefits of the plan against the risk of privacy issues.
Answer: C
NEW QUESTION # 41
SCENARIO
Please use the following to answer the next question:
Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. Miraculous normally treats patients in person, but has recently decided to start offering tliehealth appointments, where patients can have virtual appointments with on-site doctors via a phone app For this new initiative. Miraculous is considering a product built by MedApps, a company that makes quality teleheaith apps for healthcare practices and licenses them to be used with the practices" branding. MedApps provides technical support for the app. which it hosts in the cloud. MedApps also offers an optional benchmarking service for providers who wish to compare their practice to others using the service.
Riya is the Privacy Officer at Miraculous, responsible for the practice's compliance with HIPAA and other applicable laws, and she works with the Miraculous procurement team to get vendor agreements in place She occasionally assists procurement in vetting vendors and inquiring about their own compliance practices. as well as negotiating the terms of vendor agreements. Riya is currently reviewing the suitability of the MedApps app from a privacy perspective.
Riya has also been asked by the Miraculous Healthcare business operations team to review the MedApps' optional benchmarking service. Of particular concern is the requirement that Miraculous Healthcare upload information about the appointments to a portal hosted by MedAppsa.
If MedApps receives an access request under CCPAfrom a California-based app user, how should It handle the request?
- A. MedApps should promptly forward the request to Miraculous for instructions on handling.
- B. MedApps should provide the privacy notice in an easily readable format
- C. MedApps should immediately begin deleting the user's data.
- D. MedApps should decline the request because MedApps is not based In California.
Answer: A
Explanation:
Under the California Consumer Privacy Act (CCPA), businesses are required to respond to consumer requests for access, deletion, or information about how their data is processed.
However, the responsibilities differ depending on whether the entity is acting as a business or a service provider under the CCPA.
Key CCPA Definitions:
Business:
The entity that determines the purposes and means of processing personal information. In this scenario, Miraculous Healthcare is the business because it determines how the app and its associated data are used to deliver healthcare services.
Service Provider:
The entity that processes personal information on behalf of the business pursuant to a contractual agreement.
MedApps acts as a service provider because it is hosting and managing the app and the data on behalf of Miraculous Healthcare.
As a service provider, MedApps is restricted in how it can handle consumer data and must follow the instructions of the business (Miraculous Healthcare) for any data-related requests. Therefore, if MedApps receives an access or deletion request from a California-based user, it must forward the request to Miraculous Healthcare, which is responsible for determining how to respond in compliance with the CCPA.
NEW QUESTION # 42
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?
- A. It expanded the definition of "consumer reports" to include communications relating to employee investigations
- B. It increased the obligation of organizations to dispose of consumer data in ways that prevent unauthorized access
- C. It stipulated the purpose of obtaining a consumer report can only be for a review of the employee's credit worthiness
- D. It required employers to get an employee's consent in advance of requesting a consumer report for internal investigation purposes
Answer: B
Explanation:
Section: (none)
Explanation
NEW QUESTION # 43
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
How can the radiology department address Declan's concern about paper waste and still comply with the Health Insurance Portability and Accountability Act (HIPAA)?
- A. Confirm that patients are given the privacy notice on their first visit
- B. State the privacy policy to the patient verbally
- C. Post the privacy notice in a prominent location instead
- D. Direct patients to the correct area of the hospital website
Answer: D
Explanation:
Section: (none)
Explanation
NEW QUESTION # 44
Which federal agency plays a role in privacy policy, but does NOT have regulatory authority?
- A. The Office of the Comptroller of the Currency.
- B. The Department of Transportation.
- C. The Department of Commerce.
- D. The Federal Communications Commission.
Answer: C
Explanation:
The Department of Commerce (DOC) plays a role in privacy policy by promoting the development and adoption of voluntary codes of conduct, standards, and best practices for the private sector, as well as facilitating cross-border data transfers through mechanisms such as the EU-U.S. Privacy Shield and the APEC Cross-Border Privacy Rules. However, the DOC does not have regulatory authority to enforce privacy laws or impose sanctions for privacy violations. The other agencies listed have some degree of regulatory authority over privacy issues within their respective domains. For example, the Office of the Comptroller of the Currency (OCC) supervises national banks and federal savings associations and enforces the GLBA privacy and security rules for these institutions. The Federal Communications Commission (FCC) regulates interstate and international communications and enforces the privacy and security rules for telecommunications carriers, broadband providers, and voice over internet protocol (VoIP) services. The Department of Transportation (DOT) oversees the transportation sector and enforces the privacy and security rules for airlines, travel agents, and other covered entities under the Aviation and Transportation Security Act (ATSA). References:
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 1: Introduction to the
U.S. Privacy Environment, Section 1.3: Federal Agencies with a Role in Privacy, p. 18-19
* IAPP CIPP/US Body of Knowledge, Domain I: Introduction to the U.S. Privacy Environment, Objective
I.B: Identify the major federal agencies with a role in privacy, Subobjective I.B.4: Identify the role of the Department of Commerce, p. 7
* IAPP CIPP/US Exam Blueprint, Domain I: Introduction to the U.S. Privacy Environment, Objective I.B:
Identify the major federal agencies with a role in privacy, Subobjective I.B.4: Identify the role of the Department of Commerce, p. 3
NEW QUESTION # 45
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asi a. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
The Board has asked Otto whether the company will need to comply with the new California Consumer Privacy Law (CCPA). What should Otto tell the Board?
- A. That business contact information could be considered personal information governed by CCPA.
- B. That the company is governed by CCPA, but does not need to take any additional steps because it follows CPBR.
- C. That CCPA will apply to the company only after the California Attorney General determines that it will enforce the statute.
- D. That CCPA only applies to companies based in California, which exempts the company from compliance.
Answer: C
NEW QUESTION # 46
Which of the following would NOT constitute an exception to the authorization requirement under the HIPAA Privacy Rule?
- A. Disclosing health information to file a child abuse report.
- B. Disclosing health information needed to pay a third party billing administrator.
- C. Disclosing health information for public health activities.
- D. Disclosing health information needed to treat a medical emergency.
Answer: B
Explanation:
The HIPAA Privacy Rule requires covered entities to obtain an individual's written authorization for any use or disclosure of protected health information (PHI) that is not for treatment, payment, or health care operations or otherwise permitted or required by the Privacy Rule. However, there are some exceptions to the authorization requirement for certain public interest-related activities, such as disclosing health information for public health activities, reporting child abuse, or treating a medical emergency. These exceptions are intended to balance the privacy interests of individuals with the public interest in protecting health and safety, promoting quality health care, and ensuring compliance with the law. Disclosing health information needed to pay a third party billing administrator is not one of the exceptions to the authorization requirement, as it is considered a payment activity that falls under the general rule of requiring authorization.
Therefore, it is the correct answer to the question.
NEW QUESTION # 47
What was the original purpose of the Foreign Intelligence Surveillance Act?
- A. To further clarify when a warrant is not required for a wiretap performed internally by the telephone company outside the suspect's home, stemming from the Olmstead v. United States decision.
- B. To further define a framework for authorizing wiretaps by the executive branch for national security purposes under Article II of the Constitution.
- C. To further clarify a reasonable expectation of privacy stemming from the Katz v. United States decision.
- D. To further define what information can reasonably be under surveillance in public places under the USA PATRIOT Act, such as Internet access in public libraries.
Answer: B
NEW QUESTION # 48
SCENARIO
Please use the following to answer the next QUESTION:
Larry has become increasingly dissatisfied with his telemarketing position at SunriseLynx, and particularly with his supervisor, Evan. Just last week, he overheard Evan mocking the state's Do Not Call list, as well as the people on it. "If they were really serious about not being bothered," Evan said, "They'd be on the national DNC list. That's the only one we're required to follow. At SunriseLynx, we call until they ask us not to." Bizarrely, Evan requires telemarketers to keep records of recipients who ask them to call "another time." This, to Larry, is a clear indication that they don't want to be called at all. Evan doesn't see it that way.
Larry believes that Evan's arrogance also affects the way he treats employees. The U.S. Constitution protects American workers, and Larry believes that the rights of those at SunriseLynx are violated regularly. At first Evan seemed friendly, even connecting with employees on social medi a. However, following Evan's political posts, it became clear to Larry that employees with similar affiliations were the only ones offered promotions.
Further, Larry occasionally has packages containing personal-use items mailed to work. Several times, these have come to him already opened, even though this name was clearly marked. Larry thinks the opening of personal mail is common at SunriseLynx, and that Fourth Amendment rights are being trampled under Evan's leadership.
Larry has also been dismayed to overhear discussions about his coworker, Sadie. Telemarketing calls are regularly recorded for quality assurance, and although Sadie is always professional during business, her personal conversations sometimes contain sexual comments. This too is something Larry has heard Evan laughing about. When he mentioned this to a coworker, his concern was met with a shrug. It was the coworker's belief that employees agreed to be monitored when they signed on. Although personal devices are left alone, phone calls, emails and browsing histories are all subject to surveillance. In fact, Larry knows of one case in which an employee was fired after an undercover investigation by an outside firm turned up evidence of misconduct. Although the employee may have stolen from the company, Evan could have simply contacted the authorities when he first suspected something amiss.
Larry wants to take action, but is uncertain how to proceed.
In regard to telemarketing practices, Evan the supervisor has a misconception regarding?
- A. The relationship of state law to federal law
- B. The conditions under which recipients can opt out
- C. The wishes of recipients who request callbacks
- D. The right to monitor calls for quality assurance
Answer: C
NEW QUESTION # 49
The CFO of a pharmaceutical company is duped by a phishing email and discloses many of the company's employee personnel files to an online predator. The files include employee contact information, job applications, performance reviews, discipline records, and job descriptions.
Which of the following state laws would be an affected employee's best recourse against the employer?
- A. The state personnel record review statute.
- B. The state data destruction statute.
- C. The state UDAP statute.
- D. The state social security number confidentiality statute.
Answer: A
Explanation:
A state personnel record review statute typically governs the access, maintenance, and protection of employee personnel records. It may establish certain rights for employees to access their own personnel records, and it could also include provisions related to data security and breaches of employee information. Given that the disclosed information includes employee contact information, job applications, performance reviews, and other personnel-related data, the affected employee could potentially rely on this statute to seek remedies or protections related to the breach of their personal and confidential information.
NEW QUESTION # 50
......
100% Free CIPP-US Daily Practice Exam With 228 Questions: https://www.prep4away.com/IAPP-certification/braindumps.CIPP-US.ete.file.html
CIPP-US Test Engine Practice Test Questions, Exam Dumps: https://drive.google.com/open?id=1BjTOH2wtlfL2sOTJArM-9TUyL761PUHh