CIPP-CN Certified Information Privacy Professional - China Practice Questions
Prepare for CIPP-CN with more than an answer.
- Exam fee
- $550 USD
- Time limit
- 150 minutes
- Questions on the exam
- 90
- Passing score
- 300 (scale 0-500)
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 3
- Introduction to Personal Information Protection in China33%
- The Personal Information Protection Law (PIPL)34%
- Sectoral Regulations and Compliance33%
- 1
Case Study: AutoDrive CN
AutoDrive CN is an autonomous driving startup collecting road mapping data and vehicle telemetry. They collect video feeds that inadvertently capture pedestrian faces and license plates. They plan to share this data with a mapping partner.
Scenario: A pedestrian requests the deletion of their face data from the training set. However, the data has already been anonymized and aggregated into the mapping model, making it technically impossible to isolate the specific individual's data.
How should AutoDrive CN respond to the deletion request according to PIPL?
Show answer details
Correct answer: D
If data is truly anonymized (irreversibly de-identified), it falls outside the scope of 'Personal Information' under PIPL. Therefore, the rights of the individual (like deletion) no longer apply to that specific dataset. The company should explain this status to the requester.
- 2
When determining if a foreign entity is subject to the PIPL (Extraterritorial Scope), which of the following activities would trigger the application of Chinese law? (Select TWO)
Show answer details
Correct answer: A, B
PIPL Article 3 applies to overseas processing if the purpose is to analyze/assess behavior of persons in China.
PIPL Article 3 applies if the purpose is providing products/services to persons in China.
- 3
The 'Standard Contract' (China SCCs) for cross-border transfer is one of the three valid mechanisms for outbound data transfer. For which type of organization is this mechanism primarily intended?
Show answer details
Correct answer: A
The Standard Contract is designed for processors who fall BELOW the thresholds for mandatory CAC assessment (e.g., non-CIIO, <1M users, <100k PI transferred). It is a filing based mechanism.
- 4
Under the Data Security Law (DSL), who is responsible for formulating the catalog of 'Important Data' for a specific industry (e.g., Transportation or Finance)?
Show answer details
Correct answer: B
DSL Article 21 mandates that regions and departments (sectoral regulators) shall determine the specific catalog of important data for their respective regions and departments/industries.
- 5
A human resources manager wants to review the chat logs of an employee suspected of leaking trade secrets. The company uses an enterprise communication tool. What is the most compliant approach under PIPL regarding employee monitoring?
Show answer details
Correct answer: C
PIPL Article 13(2) allows processing without consent if necessary for HR management under lawfully established labor rules/collective contracts. Transparency (notice) in the employee handbook is critical.
- 6
A Shanghai-based e-commerce platform processes the personal information of 2 million users. The company plans to migrate its customer database to a cloud server located in Singapore to improve regional latency. According to the Personal Information Protection Law (PIPL) and CAC measures, which compliance mechanism MUST the company adopt for this cross-border transfer?
Show answer details
Correct answer: D
Under PIPL and the Measures for the Security Assessment of Outbound Data Transfers, a mandatory CAC Security Assessment is triggered if a data processor processes the personal information of more than 1 million individuals. Since the company has 2 million users, it exceeds this threshold, making the CAC Security Assessment the only valid mechanism, superseding SCCs or Certification.
- 7
A multinational pharmaceutical company operates a research center in Beijing. They intend to transfer clinical trial data involving genetic markers of 5,000 Chinese citizens to their headquarters in Switzerland. Which specific regulatory requirement governs the export of this specific category of data?
Show answer details
Correct answer: B
Genetic data falls under the Human Genetic Resources (HGR) regulations in addition to PIPL. The export of HGR requires specific approval or filing with the Human Genetic Resources Administration of China (HGRAC/MOST), regardless of the volume thresholds that might otherwise apply under PIPL alone. This is a dual-compliance scenario.
- 8
Under the Data Security Law (DSL), data is classified based on its potential impact on national security, public interest, and the legitimate rights of individuals or organizations. Which classification represents data that, if tampered with, destroyed, leaked, or illegally obtained, would directly harm national security, the economy, or major public interests?
Show answer details
Correct answer: A
The DSL establishes a category called 'National Core Data' (State Core Data), which refers to data related to national security, the lifelines of the national economy, important aspects of people's livelihood, and major public interests. This is the highest classification level, requiring the strictest protection measures.
- 9
A Beijing-based tech startup is developing a mobile application for children aged 10-13. The app collects geolocation data to enable a 'find my friends' feature. Which specific compliance steps are MANDATORY under the Provisions on the Cyber Protection of Children's Personal Information? (Select TWO)
Show answer details
Correct answer: A, C
Network operators processing children's data must establish and publish a specialized personal information protection rule specifically for children, separate or distinct from the general privacy policy.
For children under 14, the law mandates obtaining consent specifically from the guardian/parent. Consent from the child alone is insufficient.
- 10
An organization is conducting a Personal Information Protection Impact Assessment (PIA) as required by PIPL. Which of the following elements is NOT strictly required to be included in the PIA report according to PIPL Article 55?
Show answer details
Correct answer: C
PIPL Article 55 requires a PIA to cover: (1) lawfulness/necessity of purpose/method, (2) impact on rights/interests, and (3) effectiveness of protection measures. Financial budgets for monetization are not a required element of a compliance-focused PIA.
