Question 1
Scenario: A company implements a new data collection system. What governance step is required to assess privacy impacts before deployment?
Show answer & explanation
Correct answer: A - Conduct a privacy impact assessment
10 free, exam-style Certified Information Privacy Professional/United States (CIPPUS) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CIPPUS practice test to study every exam domain.
These 10 free CIPPUS questions are organized by exam domain, so you can see how each part of the Certified Information Privacy Professional/United States blueprint is tested. Reveal the answer and explanation under each question.
Scenario: A company implements a new data collection system. What governance step is required to assess privacy impacts before deployment?
Correct answer: A - Conduct a privacy impact assessment
Scenario: U.S. company transfers EU customer data to U.S. servers using Data Privacy Framework. What is required for compliance?
Correct answer: A - Self-certification and adherence to DPF principles
Scenario: Organization discovers a large data breach affecting 5,000 customers. What is the notification timeline requirement?
Correct answer: A - Without unreasonable delay, maximum 60 days
Scenario: A company designs a new mobile app. What Privacy by Design principle requires implementing preventive privacy measures?
Correct answer: A - Proactive not reactive
Scenario: An app targeted at children collects geolocation data without verifiable parental consent. What law is violated? The app is for users aged 8-12 and shares data with advertisers.
Correct answer: A - COPPA
Scenario: A business associate discovers a breach of protected health information. What must they do regarding the covered entity?
Correct answer: A - Notify covered entity without unreasonable delay
Scenario: A bank shares customer account details with its marketing affiliate without providing opt-out notice. What law applies?
Correct answer: A - GLBA Privacy Rule violation
Scenario: A marketer uses web-scraped data from public profiles to send targeted text messages without consent. What requirement applies?
Correct answer: A - TCPA requirement for prior express written consent
Scenario: Employer uses AI-driven tool to screen job applicants' resumes in New York City. What is required under NYC AEDT Law?
Correct answer: A - Bias audit required annually
Scenario: Company monitors employee emails on company server for business purposes. What does ECPA allow?
Correct answer: A - Allowed under business purpose exception
The CIPPUS exam also covers these domains. Drill them in the full free practice test:
Practice hundreds more CIPPUS questions with instant scoring, weak-area drills, and full exam simulations.