Free IAPP CIPP-US Exam Questions

Become IAPP Certified with updated CIPP-US exam questions and correct answers

Page:    1 / 41      
Total 201 Questions | Updated On: Jan 10, 2025
Add To Cart
Question 1

A company based in United States receives information about its UK subsidiary’s employees in connection with
the centralized HR service it provides.
How can the UK company ensure an adequate level of data protection that would allow the restricted data
transfer to continue?


Answer: B
Question 2

SCENARIO
Please use the following to answer the next question:
Matt went into his son’s bedroom one evening and found him stretched out on his bed typing on his laptop.
“Doing your homework?” Matt asked hopefully.
“No,” the boy said. “I’m filling out a survey.”
Matt looked over his son’s shoulder at his computer screen. “What kind of survey?”
“It’s asking questions about my opinions.”
“Let me see,” Matt said, and began reading the list of questions that his son had already answered. “It’s asking
your opinions about the government and citizenship. That’s a little odd. You’re only ten.”
Matt wondered how the web link to the survey had ended up in his son’s email inbox. Thinking the message
might have been sent to his son by mistake he opened it and read it. It had come from an entity called the
Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read
further he learned that kids who took the survey were automatically registered in a contest to win the first book
in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if
he had been prompted to give information about himself in order to take the survey. His son told him he had
been asked to give his name, address, telephone number, and date of birth, and to answer questions about his
favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way
that it was. Then he noticed several other commercial emails from marketers advertising products for children
in his son’s inbox, and he decided it was time to report the incident to the proper authorities.
Based on the incident, the FTC’s enforcement actions against the marketer would most likely include what
violation?


Answer: D
Question 3

Mega Corp. is a U.S.-based business with employees in California, Virginia, and Colorado. Which of the following must Mega Corp. comply with in regard to its human resources data? 


Answer: D
Question 4

All of the following organizations are specified as covered entities under the Health Insurance Portability and Accountability Act (HIPAA) EXCEPT? 


Answer: B
Question 5

Edward Snowden’s revelations regarding government programs collecting massive amounts of information about U.S. citizens and noncitizens led to the passage of which law?


Answer: C
Page:    1 / 41      
Total 201 Questions | Updated On: Jan 10, 2025
Add To Cart

© Copyrights DumpsCertify 2025. All Rights Reserved

We use cookies to ensure your best experience. So we hope you are happy to receive all cookies on the DumpsCertify.