Pass CIPP-US Exam Latest Practice Questions Updated on Sep 04, 2026 [Q104-Q119]

4.6/5 - (5 votes)

Pass CIPP-US Exam Latest Practice Questions Updated on Sep 04, 2026

IAPP CIPP-US Study Guide Archives 

IAPP CIPP-US Exam Overview:

Certification Vendor: IAPP
Exam Name: CIPP/US Certification Exam
Exam Number: CIPP-US
Exam Price: $550 USD (standard registration, subject to change and region/member pricing)
Certificate Validity Period: 2 years
Real Exam Qty: Approximately 90 multiple-choice questions
Exam Duration: 150 minutes
Exam Format: Multiple-choice, Computer-based exam (proctored)
Related Certifications: CIPP/E
CIPP/C
CIPP/A
CIPM
CIPT
Available Languages: English
Passing Score: 300 (scaled score, 100–500 scale)
Recommended Training: IAPP Body of Knowledge / Study Guide
IAPP Official CIPP/US Training
Exam Registration: Pearson VUE Exam Delivery
IAPP CIPP/US Registration
Sample Questions: IAPP CIPP-US Sample Questions
Exam Way: Computer-based proctored exam delivered via Pearson VUE test centers or online proctoring.
Pre Condition: No formal prerequisites required; prior privacy or legal knowledge is strongly recommended.
Official Syllabus URL: https://iapp.org/certify/cippus/

 

NO.104 When does the Telemarketing Sales Rule require an entity to share a do-not-call request across its organization?

 
 
 
 

NO.105 California’s SB 1386 was the first law of its type in the United States to do what?

 
 
 
 

NO.106 Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?

 
 
 
 

NO.107 Under the EU-US Data Privacy Framework, what must participating organizations provide to individuals in regard to complaints and disputes?

 
 
 
 

NO.108 Which of the following practices is NOT a key component of a data ethics framework?

 
 
 
 

NO.109 What practice do courts commonly require in order to protect certain personal information on documents, whether paper or electronic, that is involved in litigation?

 
 
 
 

NO.110 Which of the following most accurately describes the regulatory status ot pandemic contact-tracing apps in the United States?

 
 
 
 

NO.111 What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?

 
 
 
 

NO.112 What is the main purpose of the Global Privacy Enforcement Network?

 
 
 
 

NO.113 Mega Corp. is a U.S.-based business with employees in California, Virginia, and Colorado. Which of the following must Mega Corp. comply with in regard to its human resources data?

 
 
 
 

NO.114 SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer’s privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer’s personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl’s concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company’s day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the best reason for Cheryl to follow Janice’s suggestion about classifying customer data?

 
 
 
 

NO.115 A company’s employee wellness portal offers an app to track exercise activity via users’ mobile devices.
Which of the following design techniques would most effectively inform users of their data privacy rights and privileges when using the app?

 
 
 
 

NO.116 Which of the following conditions would NOT be sufficient to excuse an entity from providing breach notification under state law?

 
 
 
 

NO.117 Under the California Consumer Privacy Act (as amended by the California Pnvacy Rights Act), a consumer may Initiate a civil action against a business for?

 
 
 
 

NO.118 Which of the following would NOT be regulated by the Illinois Biometnc Information Pnvacy Act (BIPA)?

 
 
 
 

NO.119 SCENARIO
Please use the following to answer the next QUESTION
Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in Californi a. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants’ postings on social media, ask Question:s about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements.
Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle’s GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision.
Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia’s concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. Celeste believes that even if the business grows a customer database of a few thousand, it’s unlikely that a state agency would hassle an honest business if an accidental security incident were to occur.
In any case, Celeste feels that all they need is common sense – like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she’s right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina.
Regarding credit checks of potential employees, Celeste has a misconception regarding what?

 
 
 
 

The CIPP-US exam covers various topics related to privacy laws and regulations in the United States, including the Fair Credit Reporting Act (FCRA), the Children’s Online Privacy Protection Act (COPPA), the Health Insurance Portability and Accountability Act (HIPAA), and various state laws related to data privacy. CIPP-US exam also covers important frameworks and guidelines such as the General Data Protection Regulation (GDPR) and the Privacy Shield Framework. The CIPP-US certification is recognized as the gold standard for privacy professionals in the United States, and passing the exam demonstrates a high level of understanding and expertise in the field of privacy.

 

CIPP-US Questions Prepare with Learning Information: https://www.dumpleader.com/CIPP-US_exam.html

         

Related Links: myportal.utt.edu.tt zenwriting.net myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw www.stes.tyc.edu.tw

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below