Skip to content

CIPP-US CIPP/US Practice Questions

Prepare for CIPP-US with more than an answer.

290 questions in the full set20 sample questionsUpdated Jan 29, 2026
Exam fee
$550 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. Introduction to the U.S. Privacy Environment18%
  2. Limits on Private-Sector Collection and Use of Data22%
  3. Government and Court Access to Private-Sector Information15%
  4. Workplace Privacy12%
  5. State Privacy Laws23%
  1. 1

    Which venture would be subject to the requirements of Section 5 of the Federal Trade Commission Act?

    Show answer details

    Correct answer: B

    B

  2. 2

    An organization self-certified under Privacy Shield must, upon request by an individual, do what?

    Show answer details
  3. 3

    Which of the following federal agencies does NOT enforce the Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA)?

    Show answer details
  4. 4

    SCENARIO

    Please use the following to answer the next question:

    A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer’s data handling practices.

    The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by

    the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: “Please act immediately by identifying all personal data received from our company.'

    This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup’s rapid market penetration.

    As the Company’s data privacy leader, you are sensitive to the criticality of the relationship with the retailer.

    At this stage of the investigation, what should the data privacy leader review first?

    Show answer details

    Correct answer: D

    D

  5. 5

    A company's legal department issues a litigation hold for an employee's email account. However, a pre-existing automated data retention policy, which the IT team overlooks, permanently deletes the emails 90 days after issuance of the hold. In the context of e-discovery, what is the most significant legal risk the company now faces?

    graph TD A[Legal Dept issues Litigation Hold] --> B{IT Team Notified}; B --> C[Employee Email Account]; D[Automated 90-Day Deletion Policy] --> C; C -- after 90 days --> E((Emails Permanently Deleted)); A --X D;

    Show answer details

    Correct answer: C

    The failure to preserve electronically stored information (ESI) after a duty to preserve has attached (such as a litigation hold) is known as spoliation of evidence. Courts have the authority to issue sanctions for spoliation, which can range from monetary fines to, in serious cases, an adverse inference instruction, where the judge tells the jury to assume the destroyed evidence was unfavorable to the party that destroyed it. This can be devastating to a case.

  6. 6

    Which jurisdiction must courts have in order to hear a particular case?

    Show answer details
  7. 7

    Which authority supervises and enforces laws regarding advertising to children via the Internet?

    Show answer details
  8. 8

    According to Section 5 of the FTC Act, self-regulation primarily involves a company’s right to do what?

    Show answer details
  9. 9

    Which was NOT one of the five priority areas listed by the Federal Trade Commission in its 2012 report, “Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers'?

    Show answer details
  10. 10

    The “Consumer Privacy Bill of Rights" presented in a 2012 Obama administration report is generally based on?

    Show answer details

Create an account to continue.