New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CIPM Exam Dumps - IAPP Certified Information Privacy Manager Questions and Answers

Question # 24

Which of the following is TRUE about a PIA (Privacy Impact Analysis)?

Options:

A.

Any project that involves the use of personal data requires a PIA

B.

A Data Protection Impact Analysis (DPIA) process includes a PIA

C.

The PIA must be conducted at the early stages of the project lifecycle

D.

The results from a previous information audit can be leveraged in a PIA process

Buy Now
Question # 25

You would like your organization to be independently audited to demonstrate compliance with international privacy standards and to identify gaps for remediation.

Which type of audit would help you achieve this objective?

Options:

A.

First-party audit.

B.

Second-party audit.

C.

Third-party audit.

D.

Fourth-party audit.

Buy Now
Question # 26

SCENARIO

Please use the following lo answer the next question:

The board risk committee of your organization is particularly concerned not only by the number and frequency of data breaches reported to it over the past 12 months, but also the inconsistency in responses and poor incident response turnaround times.

Upon reviewing the current incident response plan (IRP), it was discovered that while the business continuity plan (BCP) had been updated on time, the IRP, linked to BCP. was last updated over three years ago.

The board risk committee has noted this as high risk especially since company policy is to review and update policies and plans annually. Consequently, the newly appointed data protection officer (DPO) was requested to provide a paper on how she would remediate the situation.

As a seasoned data privacy professional, you have been requested to assist the new DPO.

Which additional proactive step listed below would best mitigate these risks in the future?

Options:

A.

Make the IRP a live document that is evaluated for completeness during each incident.

B.

Make copies of the IRP in various place so it can be accessed remotely or when offline.

C.

Add comments about incidents to the IRP to record what action was taken.

D.

Make sure that everyone listed in the IRP has a copy of the IRP

Buy Now
Question # 27

SCENARIO

Please use the following to answer the next QUESTION:

Perhaps Jack Kelly should have stayed in the U.S. He enjoys a formidable reputation inside the company, Special Handling Shipping, for his work in reforming certain "rogue" offices. Last year, news broke that a police sting operation had revealed a drug ring operating in the Providence, Rhode Island office in the United States. Video from the office's video surveillance cameras leaked to news operations showed a drug exchange between Special Handling staff and undercover officers.

In the wake of this incident, Kelly had been sent to Providence to change the "hands off" culture that upper management believed had let the criminal elements conduct their illicit transactions. After a few weeks under Kelly's direction, the office became a model of efficiency and customer service. Kelly monitored his workers' activities using the same cameras that had recorded the illegal conduct of their former co-workers.

Now Kelly has been charged with turning around the office in Cork, Ireland, another trouble spot. The company has received numerous reports of the staff leaving the office unattended. When Kelly arrived, he found that even when present, the staff often spent their days socializing or conducting personal business on their mobile phones. Again, he observed their behaviors using surveillance cameras. He issued written reprimands to six staff members based on the first day of video alone.

Much to Kelly's surprise and chagrin, he and the company are now under investigation by the Data Protection Commissioner of Ireland for allegedly violating the privacy rights of employees. Kelly was told that the

company's license for the cameras listed facility security as their main use, but he does not know why this matters. He has pointed out to his superiors that the company's training programs on privacy protection and data collection mention nothing about surveillance video.

You are a privacy protection consultant, hired by the company to assess this incident, report on the legal and compliance issues, and recommend next steps.

What should you advise this company regarding the status of security cameras at their offices in the United States?

Options:

A.

Add security cameras at facilities that are now without them.

B.

Set policies about the purpose and use of the security cameras.

C.

Reduce the number of security cameras located inside the building.

D.

Restrict access to surveillance video taken by the security cameras and destroy the recordings after a designated period of time.

Buy Now
Question # 28

Which of the following best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?

Options:

A.

Employees must sign an ad hoc contractual agreement each time personal data is exported.

B.

All employees are subject to the rules in their entirety, regardless of where the work is taking place.

C.

All employees must follow the privacy regulations of the jurisdictions where the current scope of their work is established.

D.

Employees who control personal data must complete a rigorous certification procedure, as they are exempt from legal enforcement.

Buy Now
Question # 29

When supporting the business and data privacy program expanding into a new jurisdiction, it is important to do all of the following EXCEPT?

Options:

A.

Identify the stakeholders.

B.

Appoint a new Privacy Officer (PO) for that jurisdiction.

C.

Perform an assessment of the laws applicable in that new jurisdiction.

D.

Consider culture and whether the privacy framework will need to account for changes in culture.

Buy Now
Question # 30

SCENARIO

Please use the following to answer the next QUESTION:

Richard McAdams recently graduated law school and decided to return to the small town of Lexington, Virginia to help run his aging grandfather's law practice. The elder McAdams desired a limited, lighter role in the practice, with the hope that his grandson would eventually take over when he fully retires. In addition to hiring Richard, Mr. McAdams employs two paralegals, an administrative assistant, and a part-time IT specialist who handles all of their basic networking needs. He plans to hire more employees once Richard gets settled and assesses the office's strategies for growth.

Immediately upon arrival, Richard was amazed at the amount of work that needed to done in order to modernize the office, mostly in regard to the handling of clients' personal data. His first goal is to digitize all the records kept in file cabinets, as many of the documents contain personally identifiable financial and medical data. Also, Richard has noticed the massive amount of copying by the administrative assistant throughout the day, a practice that not only adds daily to the number of files in the file cabinets, but may create security issues unless a formal policy is firmly in place Richard is also concerned with the overuse of the communal copier/ printer located in plain view of clients who frequent the building. Yet another area of concern is the use of the same fax machine by all of the employees. Richard hopes to reduce its use dramatically in order to ensure that personal data receives the utmost security and protection, and eventually move toward a strict Internet faxing policy by the year's end.

Richard expressed his concerns to his grandfather, who agreed, that updating data storage, data security, and an overall approach to increasing the protection of personal data in all facets is necessary Mr. McAdams granted him the freedom and authority to do so. Now Richard is not only beginning a career as an attorney, but also functioning as the privacy officer of the small firm. Richard plans to meet with the IT employee the following day, to get insight into how the office computer system is currently set-up and managed.

As Richard begins to research more about Data Lifecycle Management (DLM), he discovers that the law office can lower the risk of a data breach by doing what?

Options:

A.

Prioritizing the data by order of importance.

B.

Minimizing the time it takes to retrieve the sensitive data.

C.

Reducing the volume and the type of data that is stored in its system.

D.

Increasing the number of experienced staff to code and categorize the incoming data.

Buy Now
Question # 31

Under the General Data Protection Regulation (GDPR), which situation would be LEAST likely to require a Data Protection Impact Assessment (DPIA)?

Options:

A.

A health clinic processing its patients’ genetic and health data

B.

The use of a camera system to monitor driving behavior on highways

C.

A Human Resources department using a tool to monitor its employees’ internet activity

D.

An online magazine using a mailing list to send a generic daily digest to marketing emails

Buy Now
Question # 32

Under the General Data Protection Regulation (GDPR), international data transfer is allowed using the mechanisms in all of the following scenarios EXCEPT between companies who?

Options:

A.

Are part of the same group of enterprise using approved Binding Corporate Rules (BCRs).

B.

Have signed up to the EU Standard Contractual Clauses.

C.

Have put in place a binding confidentiality agreement.

D.

Have put in place an approved code of conduct.

Buy Now
Question # 33

Which of the following is elective when responding to a cross-jurisdictional breach of personal information?

Options:

A.

Setting up a customer notification center.

B.

Capturing when the breach was discovered.

C.

Calculating how many individuals were affected.

D.

Determining the citizenship of the affected individuals.

Buy Now
Exam Code: CIPM
Exam Name: Certified Information Privacy Manager (CIPM)
Last Update: Jan 18, 2026
Questions: 262
CIPM pdf

CIPM PDF

$25.5  $84.99
CIPM Engine

CIPM Testing Engine

$28.5  $94.99
CIPM PDF + Engine

CIPM PDF + Testing Engine

$40.5  $134.99