Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

CIPM Exam Dumps - IAPP Certified Information Privacy Manager Questions and Answers

Question # 24

SCENARIO

Please use the following lo answer the next question:

You are the privacy manager within the privacy office of a National Forest Parks and Recreation Department. While having lunch with a colleague from the IT division, you learn that the IT director has put out a request for proposal (RFP) which calls for a system that collects the personal data of park attendees.

You consult with a few other colleagues in IT and learn that the RFP is worded such that it leaves it to the vendors to demonstrate what information they would collect from people who enter parks anywhere in the country, either in a vehicle or on foot. A partial list of the information collected includes:

• personal identifiers such as name, address, age, gender;

• vehicle registration information:

• facial images of park attendees;

• health information (e.g.. physical disabilities, use of mobility devices)

The stated purpose of the RFP is to:

"Improve the National Forest. Parks, and Recreation Department's ability to track and monitor service usage thereby Increasing the robustness of our customer data and to improve service offerings.''

Companies have already started submitting proposals for software solutions that address these information gathering practices. There is only one week left before the RFP closes.

The IT department has put together an RFP evaluation team but no one from the privacy office has been a Dart of the RFP ud to this point. This occurred deposite the fact….

Which of the following is the least important privacy consideration associated with assessing data when implementing a large-scale project like this?

Options:

A.

Standardization of privacy safeguards on a national scale.

B.

Classification of the types of personal information collected by the system

C.

Identifying operational risks associated with data storage, access and disposal.

D.

Third-party vendor assessment to determine how well privacy practices of vendors align with your organization's practices.

Buy Now
Question # 25

SCENARIO

Please use the following to answer the next QUESTION:

Richard McAdams recently graduated law school and decided to return to the small town of Lexington, Virginia to help run his aging grandfather's law practice. The elder McAdams desired a limited, lighter role in the practice, with the hope that his grandson would eventually take over when he fully retires. In addition to hiring Richard, Mr. McAdams employs two paralegals, an administrative assistant, and a part-time IT specialist who handles all of their basic networking needs. He plans to hire more employees once Richard gets settled and assesses the office's strategies for growth.

Immediately upon arrival, Richard was amazed at the amount of work that needed to done in order to modernize the office, mostly in regard to the handling of clients' personal data. His first goal is to digitize all the records kept in file cabinets, as many of the documents contain personally identifiable financial and medical data. Also, Richard has noticed the massive amount of copying by the administrative assistant throughout the day, a practice that not only adds daily to the number of files in the file cabinets, but may create security issues unless a formal policy is firmly in place Richard is also concerned with the overuse of the communal copier/ printer located in plain view of clients who frequent the building. Yet another area of concern is the use of the same fax machine by all of the employees. Richard hopes to reduce its use dramatically in order to ensure that personal data receives the utmost security and protection, and eventually move toward a strict Internet faxing policy by the year's end.

Richard expressed his concerns to his grandfather, who agreed, that updating data storage, data security, and an overall approach to increasing the protection of personal data in all facets is necessary Mr. McAdams granted him the freedom and authority to do so. Now Richard is not only beginning a career as an attorney, but also functioning as the privacy officer of the small firm. Richard plans to meet with the IT employee the following day, to get insight into how the office computer system is currently set-up and managed.

Which of the following policy statements needs additional instructions in order to further protect the personal data of their clients?

Options:

A.

All faxes sent from the office must be documented and the phone number used must be double checked to ensure a safe arrival.

B.

All unused copies, prints, and faxes must be discarded in a designated recycling bin located near the work station and emptied daily.

C.

Before any copiers, printers, or fax machines are replaced or resold, the hard drives of these devices must be deleted before leaving the office.

D.

When sending a print job containing personal data, the user must not leave the information visible on the computer screen following the print command and must retrieve the printed document immediately.

Buy Now
Question # 26

Under the General Data Protection Regulation (GDPR), what must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?

Options:

A.

An obligation on the processor to report any personal data breach to the controller within 72 hours,

B.

An obligation on both parties to report any serious personal data breach to the supervisory authority

C.

An obligation on both parties to agree to a termination of the agreement if the other party is responsible for a personal data breach.

D.

An obligation on the processor to assist the controller in complying with the controller's obligations to notify the supervisory authority about personal data breaches.

Buy Now
Question # 27

Under the General Data Protection Regulation (GDPR), what must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?

Options:

A.

An obligation on the processor to report any personal data breach to the controller within 72 hours.

B.

An obligation on both parties to report any serious personal data breach to the supervisory authority.

C.

An obligation on both parties to agree to a termination of the agreement if the other party is responsible for a personal data breach.

D.

An obligation on the processor to assist the controller in complying with the controller's obligations to notify the supervisory authority about personal data breaches.

Buy Now
Question # 28

A company's human resources (HR) group is working with their information security team lo tag data within their systems as ''special data" or "sensitive data" What is the most probable reason for the group to do so?

Options:

A.

To ensure the data is fully controlled and used for only authorized purposes.

B.

To apply the organization's data deletion standard.

C.

To create a robust record of processing activities.

D.

To prepare for an upcoming regulatory audit under GDPR.

Buy Now
Question # 29

What is the main reason for conducting a data inventory or data map of your organization?

Options:

A.

To test the security of your organization's main data systems.

B.

To assess different methods for collecting data by your organization.

C.

To know where your organization’s data is located and how it is used.

D.

To evaluate whether your vendors have the required policies and procedures in place.

Buy Now
Question # 30

A privacy maturity model provides all of the following EXCEPT?

Options:

A.

A standard reference to assess a privacy program's current level of development.

B.

A way to highlight what functions a company lacks for proper program management.

C.

A way to guarantee that a company is compliant with applicable laws and regulations.

D.

An example of the methods and practices necessary to evaluate a company’s level of risk.

Buy Now
Question # 31

SCENARIO

Please use the following to answer the next QUESTION:

For 15 years, Albert has worked at Treasure Box – a mail order company in the United States (U.S.) that used to sell decorative candles around the world, but has recently decided to limit its shipments to customers in the 48 contiguous states. Despite his years of experience, Albert is often overlooked for managerial positions. His frustration about not being promoted, coupled with his recent interest in issues of privacy protection, have motivated Albert to be an agent of positive change.

He will soon interview for a newly advertised position, and during the interview, Albert plans on making executives aware of lapses in the company’s privacy program. He feels certain he will be rewarded with a promotion for preventing negative consequences resulting from the company’s outdated policies and procedures.

For example, Albert has learned about the AICPA (American Institute of Certified Public Accountans)/CICA (Canadian Institute of Chartered Accountants) Privacy Maturity Model (PMM). Albert thinks the model is a useful way to measure Treasure Box’s ability to protect personal data. Albert has noticed that Treasure Box fails to meet the requirements of the highest level of maturity of this model; at his interview, Albert will pledge to assist the company with meeting this level in order to provide customers with the most rigorous security available.

Albert does want to show a positive outlook during his interview. He intends to praise the company’s commitment to the security of customer and employee personal data against external threats. However, Albert worries about the high turnover rate within the company, particularly in the area of direct phone marketing. He sees many unfamiliar faces every day who are hired to do the marketing, and he often hears complaints in the lunch room regarding long hours and low pay, as well as what seems to be flagrant disregard for company procedures.

In addition, Treasure Box has had two recent security incidents. The company has responded to the incidents with internal audits and updates to security safeguards. However, profits still seem to be affected and anecdotal evidence indicates that many people still harbor mistrust. Albert wants to help the company recover. He knows there is at least one incident the public in unaware of, although Albert does not know the details. He believes the company’s insistence on keeping the incident a secret could be a further detriment to its reputation. One further way that Albert wants to help Treasure Box regain its stature is by creating a toll-free number for customers, as well as a more efficient procedure for responding to customer concerns by postal mail.

In addition to his suggestions for improvement, Albert believes that his knowledge of the company’s recent business maneuvers will also impress the interviewers. For example, Albert is aware of the company’s intention to acquire a medical supply company in the coming weeks.

With his forward thinking, Albert hopes to convince the managers who will be interviewing him that he is right for the job.

In consideration of the company’s new initiatives, which of the following laws and regulations would be most

appropriate for Albert to mention at the interview as a priority concern for the privacy team?

Options:

A.

Gramm-Leach-Bliley Act (GLBA)

B.

The General Data Protection Regulation (GDPR)

C.

The Telephone Consumer Protection Act (TCPA)

D.

Health Insurance Portability and Accountability Act (HIPAA)

Buy Now
Question # 32

Under which circumstances would people who work in human resources be considered a secondary audience for privacy metrics?

Options:

A.

They do not receive training on privacy issues

B.

They do not interface with the financial office

C.

They do not have privacy policy as their main task

D.

They do not have frequent interactions with the public

Buy Now
Question # 33

K a privacy professional wants to show that an organization's privacy program is working as intended, the professional should?

Options:

A.

Collect feedback from customers about the privacy program.

B.

Carry out a personal data breach tabletop exercise.

C.

Collect and analyze privacy program metrics.

D.

Review privacy policies.

Buy Now
Exam Code: CIPM
Exam Name: Certified Information Privacy Manager (CIPM)
Last Update: Sep 3, 2025
Questions: 243
CIPM pdf

CIPM PDF

$29.75  $84.99
CIPM Engine

CIPM Testing Engine

$33.25  $94.99
CIPM PDF + Engine

CIPM PDF + Testing Engine

$47.25  $134.99