Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the IAPP Certified Information Privacy Professional CIPP-US Questions and answers with ValidTests

Exam CIPP-US All Questions
Exam CIPP-US Premium Access

View all detail and faqs for the CIPP-US exam

Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions
Questions # 1:

A company’s employee wellness portal offers an app to track exercise activity via users’ mobile devices. Which of the following design techniques would most effectively inform users of their data privacy rights and privileges when using the app?

Options:

A.

Offer information about data collection and uses at key data entry points.

B.

Publish a privacy policy written in clear, concise, and understandable language.

C.

Present a privacy policy to users during the wellness program registration process.

D.

Provide a link to the wellness program privacy policy at the bottom of each screen.

Expert Solution
Questions # 2:

What is the purpose of a cure provision in a stale data privacy law?

Options:

A.

To allow a business a limited timeframe to fix alleged violations before facing enforcement.

B.

To allow consumers a period of time to discover their data has been mishandled

C.

To allow a state to initiate formal enforcement actions for a fixed time period.

D.

To allow certain provisions of a law to expire after a defined time period

Expert Solution
Questions # 3:

In 2012, the White House and the FTC both issued reports advocating a new approach to privacy enforcement that can best be described as what?

Options:

A.

Harm-based.

B.

Self-regulatory.

C.

Comprehensive.

D.

Notice and choice.

Expert Solution
Questions # 4:

Within what time period must a commercial message sender remove a recipient’s address once they have asked to stop receiving future e-mail?

Options:

A.

7 days

B.

10 days

C.

15 days

D.

21 days

Expert Solution
Questions # 5:

SCENARIO

Please use the following to answer the next QUESTION:

A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer’s data handling practices.

The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: “Please act immediately by identifying all personal data received from our company.”

This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup’s rapid market penetration.

As the Company’s data privacy leader, you are sensitive to the criticality of the relationship with the retailer.

At this stage of the investigation, what should the data privacy leader review first?

Options:

A.

Available data flow diagrams

B.

The text of the original complaint

C.

The company’s data privacy policies

D.

Prevailing regulation on this subject

Expert Solution
Questions # 6:

Which of the following does Title VII of the Civil Rights Act prohibit an employer from asking a job applicant?

Options:

A.

Questions about age

B.

Questions about a disability

C.

Questions about a national origin

D.

Questions about intended pregnancy

Expert Solution
Questions # 7:

What is the most likely reason that states have adopted their own data breach notification laws?

Options:

A.

Many states have unique types of businesses that require specific legislation

B.

Many lawmakers believe that federal enforcement of current laws has not been effective

C.

Many types of organizations are not currently subject to federal laws regarding breaches

D.

Many large businesses have intentionally breached the personal information of their customers

Expert Solution
Questions # 8:

SCENARIO

Please use the following to answer the next QUESTION:

A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer’s data handling practices.

The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: “Please act immediately by identifying all personal data received from our company.”

This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup’s rapid market penetration.

As the Company’s data privacy leader, you are sensitive to the criticality of the relationship with the retailer.

Upon review, the data privacy leader discovers that the Company’s documented data inventory is obsolete. What is the data privacy leader’s next best source of information to aid the investigation?

Options:

A.

Reports on recent purchase histories

B.

Database schemas held by the retailer

C.

Lists of all customers, sorted by country

D.

Interviews with key marketing personnel

Expert Solution
Questions # 9:

Which federal agency plays a role in privacy policy, but does NOT have regulatory authority?

Options:

A.

The Office of the Comptroller of the Currency.

B.

The Federal Communications Commission.

C.

The Department of Transportation.

D.

The Department of Commerce.

Expert Solution
Questions # 10:

Which of the following is NOT one of three broad categories of products offered by data brokers, as identified by the U.S. Federal Trade Commission (FTC)?

Options:

A.

Research (such as information for understanding consumer trends).

B.

Risk mitigation (such as information that may reduce the risk of fraud).

C.

Location of individuals (such as identifying an individual from partial information).

D.

Marketing (such as appending data to customer information that a marketing company already has).

Expert Solution
Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions