Browse all practice questions for the Certified Information Privacy Professional/United States (CIPP/US) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certified Information Privacy Professional/United States (CIPP/US) Practice Test 2026 - Free CIPP/US Exam Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • What happens after authentication in the access control process?
  • What role does the Federal Trade Commission (FTC) play in privacy enforcement?
  • Which legal theory refers to the failure to exercise ordinary care?
  • What is the first phase of privacy program development?
  • What does "pseudonymization" achieve in data protection?
  • What does the term "preemption" imply in relation to federal and state laws?
  • What can be a purpose for collecting personal data without consent?
  • What is included in the communication phase of a privacy program?
  • Which act is focused on protecting the privacy of electronic communications?
  • What defines a protective order in the court system?
  • What significant creation did the Dodd-Frank Wall Street Reform and Consumer Protection Act establish?
  • Why is 'data minimization' a critical principle in privacy practices?
  • Which of the following is NOT a characteristic of a Data Processor?
  • Which of the following best describes Electronically Stored Information (ESI)?
  • Which of the following reflects an intent of the Consumer Privacy Bill of Rights?
  • What does "opt-out" mean in privacy terms?
  • Which act must organizations comply with to protect consumer financial information?
  • Which regulation governs the processing of personal data in the European Union?
  • What authority does the Consumer Financial Protection Bureau (CFPB) have?
  • What is the main objective of the Fair Credit Reporting Act (FCRA)?
  • What is the definition of civil litigation?
  • Where in the U.S. Constitution is the concept of privacy explicitly mentioned?
  • Which of the following is not a category of security under multiple regulations?
  • What is the primary focus of data management practices in privacy?
  • What is the purpose of substitute notice in breach notification laws?
  • Why is consent particularly important for data disclosures?
  • In data protection terminology, what do "controllers" and "processors" refer to?
  • Which type of information is considered Sensitive Personal Information (SPI)?
  • What is a key requirement of the Fair and Accurate Credit Transactions Act of 2003 (FACTA)?
  • Under HIPAA, which of the following is considered a "covered entity"?
  • What is the purpose of the privilege rule in legal contexts?
  • What is the primary function of a Data Protection Authority (DPA)?
  • What is the aim of conducting a Privacy Impact Assessment (PIA)?
  • Which entities does the Fair Credit Reporting Act (FCRA) apply to?
  • What is one of the main priorities of the Consumer Privacy Bill of Rights?
  • What does the accountability principle require from organizations?
  • What does a National Security Letter (NSL) typically seek to obtain?
  • What is the primary purpose of a privacy policy within an organization?
  • What type of information does health information pertain to?
  • Which of the following best describes the concept of negligence?
  • What does civil and criminal penalties for FCRA non-compliance generally involve?
  • Who is responsible for initiating criminal litigation?
  • Which privacy regulation places specific restrictions on the sale of personal information of minors?
  • What is one requirement under the GLBA Safeguards Rule?
  • Which of the following is a requirement under the GDPR for processing personal data?
  • Which organization is responsible for the enforcement of consumer protection laws in the U.S.?
  • Which of the following best describes data minimization?
  • What does the Fair Credit Reporting Act (FCRA) require regarding consumer data?
  • Which of the following concepts is part of privacy governance?
  • Which branch of the U.S. Federal Government is responsible for creating laws?
  • Which of the following describes the Red Flags Rule's intention?
  • What does "judicial oversight" refer to in data access requests?
  • What does Article 5 of the FTC Act declare unlawful?
  • What is the expected outcome when individuals use the Opt In model?
  • Which agency is responsible for enforcing the Children’s Online Privacy Protection Act (COPPA)?
  • What is a Co-regulatory Model primarily used for?
  • What does preemption refer to in the legal context?
  • What is a consent decree?
  • In a privacy program, what does the 'Evolve' phase primarily focus on?
  • Which Act broadened the restrictions imposed by PPRA regarding surveys?
  • What does the term "data portability" refer to in privacy legislation?
  • What is the purpose of defamation in a legal context?
  • What does the enforcement of codes in a Co-regulatory Model rely on?
  • What does the EU Data Protection Directive primarily aim to protect?
  • Under the CCPA, in which situation can personal data be collected without consent?
  • What does "cross-border data transfer" involve?
  • What role does a Data Processor play in relation to data processing?
  • What is the primary focus of authentication in the context of data security?
  • What is one of the main aims of the CCPA?
  • What is the primary objective of privacy governance?
  • What does data classification help define?
  • What does "Opt In" signify in data sharing?
  • What is the intent behind the Americans with Disabilities Act (ADA)?
  • What does post-breach analysis involve?
  • Why is encryption significant in data protection?
  • What is a primary component of vendor management?
  • What does a protective order accomplish in a legal setting?
  • What is the importance of a Data Protection Officer (DPO) in an organization?
  • How does the FTC define a deceptive practice?
  • What is the Sectoral Model in data protection?
  • What do reasonable security measures entail under privacy laws?
  • What option do consumers have regarding marketing communications under FACTA?
  • Who is responsible for enforcing COPPA?
  • What is the definition of a data breach?
  • What overarching principle is upheld by the EU Data Protection Directive?
  • What are the two recourses available to a company found guilty of violating privacy regulations by the FTC?
  • Which element involves determining how data is classified within a privacy framework?
  • What does the private right of action allow an individual to do?
  • What is the purpose of a privacy notice?
  • What is a characteristic of "Simplified choice" in consumer privacy?
  • What is a primary responsibility of the Consumer Reporting Agency (CRA)?
  • Which agency enforces the CAN-SPAM Act?
  • What is a "data retention policy"?
  • What is the purpose of the practice known as redaction?
  • Which of the following is a key activity in the 'Build' phase of privacy program development?
  • What does a subject access request allow individuals to do?
  • Who typically initiates civil litigation?
  • What is a Personal Health Record (PHR)?
  • Who is classified as a Data Subject?
  • What type of data falls under "sensitive personal data" according to GDPR?
  • What actions should an organization take immediately after a data breach?
  • Which organization is responsible for administering the CIPP/US certification?
  • What is a core component of self-regulatory enforcement?
  • What is an essential part of the corrective actions phase in a privacy incident response program?
  • Which practice promotes effective cross-border cooperation in privacy enforcement?
  • Which term describes the movement of personal data across national borders?
  • What is data subject consent in the context of data processing?
  • What is a key step in post-breach analysis?
  • What term refers to the ability of consumers to view the information collected about them?
  • What does a Privacy Impact Assessment (PIA) help identify?
  • Which of the following is considered an unfair trade practice?
  • Which of the following is NOT a main component of the CIPP/US body of knowledge?
  • What does the term "data breach" refer to in terms of privacy regulation?
  • What is meant by Habeas Data?
  • What does the term "choice" signify in relation to personal information?
  • What rights does the Family Educational Rights and Privacy Act (FERPA) grant students?
  • In the context of personal information, what is the significance of Choice and Consent?
  • Which organization aims to create policies that enhance economic, environmental, and social well-being among its member countries?
  • Which of the following is an example of personal data?
  • What is the purpose of the Children's Online Privacy Protection Act of 1998 (COPPA)?
  • What does access refer to in the context of personal information held by an organization?
  • What principle is referred to as "data minimization"?
  • What does "Opt Out" refer to in the context of data sharing?
  • What does the GLBA Privacy Rule require from financial institutions?
  • What is meant by "publicity given to private life" in legal terms?
  • What are Trust Marks used to demonstrate?
  • What federal law governs the privacy of student education records?
  • Which organization is known for establishing standards for managing electronic discovery compliance?
  • What does the FTC consider an unfair practice?
  • When are telemarketing calls allowed to be made according to the regulations?
  • Which of the following rights is typically granted under U.S. laws regarding personal information?
  • What rights does the CCPA grant to California residents?
  • What obligations do businesses have under the CCPA regarding consumer requests?
  • What type of information can be included in electronically stored information (ESI)?
  • What is the primary purpose of privacy notices?
  • What does the tort claim of publicity given to private life indicate?
  • In HIPAA, what is required of patients regarding their health information?
  • What is the primary purpose of the Health Insurance Portability and Accountability Act (HIPAA)?
  • What key element is emphasized in the Consumer Privacy Bill of Rights?
  • What is the burden of proof required in civil litigation?
  • Which of the following best describes the responsibilities of a Data Controller?
  • In what context might choice regarding personal information be considered implied?
  • What characterizes a Consumer Reporting Agency (CRA)?
  • What is the outcome if an organization fails to provide adequate notice of a data breach?
  • How does a PIA contribute to data protection?
  • Under the GDPR, what is the term for the lawful basis that allows processing personal data?
  • Under HIPAA, what does a Qualified Protection Order (QPO) prohibit?
  • Which principle emphasizes the importance of informing individuals about data collection and use?
  • Which principle of data protection emphasizes organizational accountability?
  • What constitutes Personal Health Information (PHI)?
  • How does implicit consent differ from explicit consent?
  • What are the three core areas examined in the CIPP/US exam?
  • What type of agency is the National Labor Relations Board (NLRB)?
  • What is described by common law?
  • What is the principle of "privacy by design"?
  • What is a critical element of data subject preference?
  • Which of the following best describes the scope of Sensitive Personal Information?
  • What is one of the goals of the APEC Cross-border Privacy Enforcement Arrangement (CPEA)?
  • What does the term "Ajudication" in self-regulatory enforcement refer to?
  • Which of the following is NOT one of the six questions to ask when understanding a law?
  • What are the key principles underpinning the Fair Information Practice Principles (FIPPs)?
  • What does the Protection of Pupil Rights Amendment (PPRA) extend to?
  • Which of the following is a phase in the privacy incident response program?
  • What does the term "stored communications" refer to?
  • Which of the following is a key component of the GDPR?
  • Which agency is responsible for investigating and addressing unfair labor practices in the United States?
  • What does the Red Flags Rule require from certain financial entities?
  • What was the significance of the Privacy Shield framework?
  • Who is typically responsible for ensuring compliance with the GDPR within an organization?
  • What role does the Federal Trade Commission (FTC) play?
  • What is the obligation related to Confidentiality?
  • What is one implication of judicial oversight on data access?
  • Which of the following describes evidentiary privilege?
  • What is the role of the Sedona Conference in privacy and data management?
  • What does "Privacy by Design" aim to achieve?
  • Under the CCPA, for how long must organizations retain personal data?
  • Which rule prohibits automated calls to mobile phones without consent?
  • How is "personal data" defined under the GDPR?
  • Which act prohibits discrimination against individuals with disabilities in the employment context?
  • What is the concept of strict tort liability?
  • What is the primary responsibility of a Data Protection Officer (DPO)?
  • Which of the following theories encompasses false security regarding a product's safety?
  • What is the focus of electronic discovery (e-discovery) in civil litigation?
  • What is the process of removing or modifying personal information from a dataset called?
  • What role does a Data Controller play in privacy practices?
  • Which of the following laws is designed to prevent workplace discrimination?
  • What is the definition of negligence in a legal context?
  • What are deceptive trade practices?
  • What body enforces compliance with the FCRA?
  • What should be included in a privacy policy according to best practices?
  • What is the essence of a risk-based approach in privacy compliance?
  • Which entity typically regulates deceptive trade practices?
  • What type of punishment is typically associated with civil cases?
  • What does the FTC Telemarketing Sales Rule regulate?
  • What unlawful practice did the FTC find BJ's Wholesale Club guilty of?
  • What is one aim of the Global Privacy Enforcement Network (GPEN)?
  • Which legal theory involves false statements that could harm someone's reputation?
  • What is the primary goal of the Organisation for Economic Co-operation and Development (OECD)?
  • Which act is also known as the Financial Services Modernization Act of 1999?
  • What does the term “accountability” refer to in the context of data sharing and transfer?
  • What is the primary purpose of the CIPP/US certification?
  • What is the maximum penalty for non-compliance with the CCPA?
  • What does evidentiary privilege limit?
  • What recent changes have impacted the enforcement of privacy regulations?
  • What does a Privacy Impact Assessment (PIA) evaluate?
  • What does the acronym CCPA stand for?
  • What does breach of warranty refer to in legal terms?
  • What is meant by "implicit consent" in privacy practices?
  • What principle emphasizes organizations should consider privacy at every development stage?
  • Which law provides the framework for the privacy and security of health information in the United States?
  • Which of the following describes the concept of Personal Health Information?
  • What does the Equal Employment Opportunity Commission (EEOC) oversee?
  • When must organizations notify affected individuals of a data breach under the law?
  • Which federal agency is primarily involved in enforcing privacy rights?
  • What is the burden of proof required in criminal litigation?
  • What best describes a Comprehensive Model of data protection?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy