Summer Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dealsixty

CIPP-US Exam Dumps - IAPP Certified Information Privacy Professional Questions and Answers

Question # 4

Which of these organizations would be required to provide its customers with an annual privacy notice?

Options:

A.

The Four Winds Tribal College.

B.

The Golden Gavel Auction House.

C.

The King County Savings and Loan.

D.

The Breezy City Housing Commission.

Buy Now
Question # 5

Which of the following best describes what a “private right of action” is?

Options:

A.

The right of individuals to keep their information private.

B.

The right of individuals to submit a request to access their information.

C.

The right of individuals harmed by data processing to have their information deleted.

D.

The right of individuals harmed by a violation of a law to file a lawsuit against the violation.

Buy Now
Question # 6

Acme Student Loan Company has developed an artificial intelligence algorithm that determines whether an individual is likely to pay their bill or default. A person who is determined by the algorithm to be more likely to default will receive frequent payment reminder calls, while those who are less likely to default will not receive payment reminders.

Which of the following most accurately reflects the privacy concerns with Acme Student Loan Company using

artificial intelligence in this manner?

Options:

A.

If the algorithm uses risk factors that impact the automatic decision engine. Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.

B.

If the algorithm makes automated decisions based on risk factors and public information, Acme need not determine if the algorithm has a disparate impact on protected classes.

C.

If the algorithm’s methodology is disclosed to consumers, then it is acceptable for Acme to have a disparate impact on protected classes.

D.

If the algorithm uses information about protected classes to make automated decisions, Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.

Buy Now
Question # 7

What information did the Red Flag Program Clarification Act of 2010 add to the original Red Flags rule?

Options:

A.

The most common methods of identity theft.

B.

The definition of what constitutes a creditor.

C.

The process for proper disposal of sensitive data.

D.

The components of an identity theft detection program.

Buy Now
Question # 8

Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?

Options:

A.

A bill of rights for individuals seeking access to their personal information.

B.

A code of responsibilities for medical establishments to uphold privacy laws.

C.

An international court ruling on personal information held in the commercial sector.

D.

A baseline of marketers’ minimum responsibilities for providing opt-out mechanisms.

Buy Now
Question # 9

The CFO of a pharmaceutical company is duped by a phishing email and discloses many of the company’s employee personnel files to an online predator. The files include employee contact information, job applications, performance reviews, discipline records, and job descriptions.

Which of the following state laws would be an affected employee’s best recourse against the employer?

Options:

A.

The state social security number confidentiality statute.

B.

The state personnel record review statute.

C.

The state data destruction statute.

D.

The state UDAP statute.

Buy Now
Question # 10

What consumer protection did the Fair and Accurate Credit Transactions Act (FACTA) require?

Options:

A.

The ability for the consumer to correct inaccurate credit report information

B.

The truncation of account numbers on credit card receipts

C.

The right to request removal from e-mail lists

D.

Consumer notice when third-party data is used to make an adverse decision

Buy Now
Question # 11

Which of the following is an example of federal preemption?

Options:

A.

The Payment Card Industry’s (PCI) ability to self-regulate and enforce data security standards for payment card data.

B.

The U.S. Federal Trade Commission’s (FTC) ability to enforce against unfair and deceptive trade practices across sectors and industries.

C.

The California Consumer Privacy Act (CCPA) regulating businesses that have no physical brick-and-mortal presence in California, but which do business there.

D.

The U.S. Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act prohibiting states from passing laws that impose greater obligations on senders of email marketing.

Buy Now
Question # 12

What is the main reason some supporters of the European approach to privacy are skeptical about self- regulation of privacy practices?

Options:

A.

A large amount of money may have to be sent on improved technology and security

B.

Industries may not be strict enough in the creation and enforcement of rules

C.

A new business owner may not understand the regulations

D.

Human rights may be disregarded for the sake of privacy

Buy Now
Question # 13

What is the main purpose of the CAN-SPAM Act?

Options:

A.

To diminish the use of electronic messages to send sexually explicit materials

B.

To authorize the states to enforce federal privacy laws for electronic marketing

C.

To empower the FTC to create rules for messages containing sexually explicit content

D.

To ensure that organizations respect individual rights when using electronic advertising

Buy Now
Exam Code: CIPP-US
Exam Name: Certified Information Privacy Professional/United States (CIPP/US)
Last Update: Jun 1, 2025
Questions: 194
CIPP-US pdf

CIPP-US PDF

$34  $84.99
CIPP-US Engine

CIPP-US Testing Engine

$38  $94.99
CIPP-US PDF + Engine

CIPP-US PDF + Testing Engine

$54  $134.99