[Sep-2026] Get 100% Real CIPP-US Exam Questions, Accurate & Verified Prep4away Dumps in the Real Exam! [Q32-Q53]

Share

[Sep-2026] Get 100% Real CIPP-US Exam Questions, Accurate & Verified Prep4away Dumps in the Real Exam!

Pass Your Certified Information Privacy Professional Exams Fast. All Top CIPP-US Exam Questions Are Covered.

NEW QUESTION # 32
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?

  • A. A bill of rights for individuals seeking access to their personal information.
  • B. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
  • C. A code of responsibilities for medical establishments to uphold privacy laws.
  • D. An international court ruling on personal information held in the commercial sector.

Answer: A

Explanation:
Explanation/Reference: http://documents1.worldbank.org/curated/en/751621525705087132/text/WPS8431.txt


NEW QUESTION # 33
Under the EU-US Data Privacy Framework, what must participating organizations provide to individuals in regard to complaints and disputes?

  • A. A means of communicating with the organization's privacy team.
  • B. A description of the organization's data processing policies
  • C. A copy 01 the individual's personal data
  • D. An independent recourse mechanism.

Answer: D

Explanation:
Under the EU-US Data Privacy Framework (DPF), organizations that participate in the framework must provide individuals with a way to resolve complaints and disputes about how their personal data is handled.
Specifically, organizations are required to offer an independent recourse mechanism to ensure compliance with the principles of the framework. This mechanism enables individuals to bring their complaints forward and have them addressed through an impartial and accessible process.
The independent recourse mechanism is critical to the DPF as it reinforces accountability and builds trust in cross-border data transfers. Organizations must select a third-party dispute resolution provider (such as an alternative dispute resolution body or a regulatory body) and disclose this mechanism in their privacy policies.
The mechanism must be provided free of charge to the individual.
Explanation of Options:
* A. An independent recourse mechanism: This is the correct answer, as it is explicitly required under the EU-US Data Privacy Framework for resolving disputes and complaints related to data privacy.
* B. A copy of the individual's personal data: While data access rights are part of broader privacy regulations (e.g., GDPR), this is not specific to the EU-US DPF's requirements regarding complaint handling.
* C. A description of the organization's data processing policies: While transparency about data processing is an important requirement under the DPF, it does not address the need for a formal dispute resolution mechanism.
* D. A means of communicating with the organization's privacy team: While communication channels are essential, they do not meet the requirement for an independent recourse mechanism as stipulated by the DPF.
References from CIPP/US Materials:
* EU-US Data Privacy Framework Principles: Specifically, the "Recourse, Enforcement, and Liability" principle requires participating organizations to provide an independent recourse mechanism for complaints.
* IAPP CIPP/US Certification Textbook: Discusses dispute resolution and redress mechanisms as a cornerstone of international data transfer agreements.
* US Department of Commerce Privacy Shield Program Website: Similar requirements under the now-replaced Privacy Shield have been carried over to the DPF, ensuring individuals have access to independent redress mechanisms.


NEW QUESTION # 34
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asi a. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
The Board has asked Otto whether the company will need to comply with the new California Consumer Privacy Law (CCPA). What should Otto tell the Board?

  • A. That business contact information could be considered personal information governed by CCPA.
  • B. That CCPA only applies to companies based in California, which exempts the company from compliance.
  • C. That the company is governed by CCPA, but does not need to take any additional steps because it follows CPBR.
  • D. That CCPA will apply to the company only after the California Attorney General determines that it will enforce the statute.

Answer: D


NEW QUESTION # 35
What was the original purpose of the Federal Trade Commission Act?

  • A. To ensure privacy rights of U.S. citizens
  • B. To protect consumers
  • C. To enforce antitrust laws
  • D. To negotiate consent decrees with companies violating personal privacy

Answer: C

Explanation:
IAPP book, Section 3.3, first sentence. "The FTC was founded in 1914 to enforce antitrust laws, and its general consumer protection mission was established by a statutory change in 1938." In particular in considering this answer, note that the FTC Act was initially passed in 1914.


NEW QUESTION # 36
According to the FTC Report of 2012, what is the main goal of Privacy by Design?

  • A. Implementing a system of standardization for privacy notices
  • B. Establishing a system of self-regulatory codes for mobile-related services
  • C. Incorporating privacy protections throughout the development process
  • D. Obtaining consumer consent when collecting sensitive data for certain purposes

Answer: C


NEW QUESTION # 37
Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?

  • A. Allowing consumers to opt in before collecting any data.
  • B. Integrating privacy protections during product development.
  • C. Mitigating harm to consumers after a security breach.
  • D. Announcing the tracking of online behavior for advertising purposes.

Answer: B

Explanation:
https://www.ftc.gov/sites/default/files/documents/reports/federal-trade-commission-report-protecting-consumer-privacy-era-rapid-change-recommendations/120326privacyreport.pdf


NEW QUESTION # 38
A software company wants to use web scraping to collect personal data from professional networking websites in order to train an artificial intelligence program to evaluate Job applications. The company has identified several actions for limiting their potential legal liability regarding affected data subjects and professional networking websites. Which of the following would be the least effective action for helping them do this?

  • A. Limiting the amount of the personally identifiable information they collect
  • B. Adding a notice to the company website's terms of use disclosing the use of web scraping
  • C. Following the terms of use posted on professional networking websites that are scraped.
  • D. Decertifying the scraped data before selling it to any third parties.

Answer: B

Explanation:
Web scraping to collect personal data can pose significant legal and ethical risks, particularly when it involves professional networking sites or other platforms where terms of service (ToS) explicitly prohibit such activity.
To limit liability, the software company must take proactive measures to comply with applicable laws (such as privacy laws) and contractual obligations (e.g., terms of use on the scraped websites).
Adding a notice to the company website's terms of use would be the least effective action, as it does not address the legal and ethical issues associated with scraping data from third-party websites. Simply adding a notice about the company's use of scraping does not mitigate liability for violating the ToS of professional networking websites or violating privacy rights under laws like the GDPR or CCPA.
Explanation of Options:
* A. Following the terms of use posted on professional networking websites that are scraped:This is one of the most effective ways to limit legal liability. Violating ToS can result in lawsuits or legal penalties, so adhering to them is critical.
* B. Adding a notice to the company website's terms of use disclosing the use of web scraping:This is the least effective action. Including this notice on the company's own website does not address potential violations of third-party website ToS or the privacy rights of affected individuals.
* C. Limiting the amount of the personally identifiable information they collect:Minimizing the amount of data collected aligns with data protection principles, such as data minimization under the GDPR, and can reduce privacy risks.
* D. Deidentifying the scraped data before selling it to any third parties:Deidentifying or anonymizing data is a critical step for reducing legal liability and complying with privacy laws.
However, the company should also ensure that the deidentification is robust and irreversible.
References from CIPP/US Materials:
* GDPR Article 5: Establishes principles such as data minimization and accountability for data processing.
* IAPP CIPP/US Certification Textbook: Highlights the risks of web scraping and the importance of adhering to contractual obligations and privacy laws.


NEW QUESTION # 39
Which of the following scenarios would NOT be covered under HIPAA?

  • A. Chemotherapy related to cancer treatment in a medical facility
  • B. Doctor visit for annual physical
  • C. Billing codes, patient name, and insurance identification sent to an insurance company for payment
  • D. Medical books purchased through Amazon

Answer: D

Explanation:
It is important to understand that HIPAA applies to these covered entities, but not to other healthcare providers and services. Individuals surfing the web or purchasing books about healthcare are not covered by HIPAA.


NEW QUESTION # 40
Read this notice:
Our website uses cookies. Cookies allow us to identify the computer or device you're using to access the site, but they don't identify you personally. For instructions on setting your Web browser to refuse cookies, click here.
What type of legal choice does not notice provide?

  • A. Opt-out
  • B. Implied consent
  • C. Mandatory
  • D. Opt-in

Answer: B

Explanation:
* A cookie is a small piece of data that a website sends to a user's browser and stores on the user's device, usually for the purpose of remembering the user's preferences, settings, or actions1.
* A cookie notice is a message that informs the user about the website's use of cookies and the user's choices regarding the acceptance or rejection of cookies2.
* A legal choice is the mechanism that the website provides to the user to express their consent or dissent to the use of cookies2.
* There are different types of legal choices for cookie notices, depending on the applicable laws and regulations, such as the General Data Protection Regulation (GDPR) in the European Union or the California Consumer Privacy Act (CCPA) in the United States34.
* The four types of legal choices mentioned in the question are:
* Mandatory: The website does not allow the user to access the site unless they accept the use of cookies. This type of choice is generally considered unlawful and non-compliant with the GDPR and the CCPA34.
* Implied consent: The website assumes that the user consents to the use of cookies by continuing to browse the site or by dismissing the cookie notice. This type of choice is often used by websites that operate in the U.S. or other jurisdictions that do not have strict cookie laws, but it may not be sufficient for the GDPR or the CCPA34.
* Opt-in: The website requires the user to explicitly agree to the use of cookies by clicking a button or checking a box. This type of choice is usually compliant with the GDPR and the CCPA, as it ensures that the user gives informed and affirmative consent34.
* Opt-out: The website allows the user to reject the use of cookies by clicking a link or changing their browser settings. This type of choice is also compliant with the GDPR and the CCPA, as it gives the user the right to withdraw their consent at any time34.
* Based on the description of the cookie notice in the question, the type of legal choice that the notice provides is implied consent, as the website does not explicitly ask for the user's agreement, but rather assumes that the user accepts the use of cookies by using the site. The notice also provides a link for the user to opt out of cookies by setting their browser to refuse them.
References: 1: Cookie 2: Cookie Notice 3: INSIGHT: Website Cookies and Privacy-GDPR, CCPA, and Evolving Standards for Online Consent 4: Do You Need A Cookie Notice


NEW QUESTION # 41
The U.S. Supreme Court has recognized an individual's right to privacy over personal issues, such as contraception, by acknowledging which of the following?

  • A. Federal preemption of state constitutions that expressly recognize an individual right to privacy.
  • B. An interpretation of the U.S. Constitution's explicit definition of privacy that extends to personal issues.
  • C. A "penumbra" of unenumerated constitutional rights as well as more general protections of due process of law.
  • D. The doctrine of stare decisis, which allows the U.S. Supreme Court to follow the precedent of previously decided case law.

Answer: C

Explanation:
The U.S. Supreme Court has recognized an individual's right to privacy over personal issues, such as contraception, by acknowledging a "penumbra" of unenumerated constitutional rights as well as more general protections of due process of law. This means that the right to privacy is not explicitly stated in the Constitution, but it is implied from other rights that are explicitly stated, such as the First Amendment rights of speech and assembly, the Third Amendment right to be free from quartering of soldiers, the Fourth Amendment right to be secure from unreasonable searches and seizures, the Fifth Amendment right to be free from self-incrimination, and the Ninth Amendment right to retain other rights not enumerated in the Constitution. These rights create a "zone of privacy" that protects individuals from undue government interference in their personal affairs. The Supreme Court first articulated this concept of privacy in Griswold v. Connecticut (1965), where it struck down a state law that prohibited the use of contraceptives by married couples. The Court also relied on the due process clause of the Fourteenth Amendment, which prohibits states from depriving any person of life, liberty, or property without due process of law. The Court interpreted this clause to include a substantive component that protects certain fundamental rights from state regulation, unless there is a compelling state interest and the regulation is narrowly tailored to achieve that interest. The Court has applied this due process analysis to other privacy issues, such as abortion, marriage, and sexual orientation. References:
* Privacy | Wex | US Law | LII / Legal Information Institute
* Privacy isn't in the Constitution - but it's everywhere in constitutional law
* Privacy Rights and Personal Autonomy Legally Protected by the ... - Justia
* Right to privacy | Wex | US Law | LII / Legal Information Institute


NEW QUESTION # 42
What is the purpose of a cure provision in a stale data privacy law?

  • A. To allow certain provisions of a law to expire after a defined time period
  • B. To allow consumers a period of time to discover their data has been mishandled
  • C. To allow a business a limited timeframe to fix alleged violations before facing enforcement.
  • D. To allow a state to initiate formal enforcement actions for a fixed time period.

Answer: C

Explanation:
A cure provision in state data privacy laws gives businesses an opportunity to remediate violations of the law within a specified timeframe after receiving notice of the alleged violation.
This provision is intended to promote compliance rather than immediately imposing penalties or enforcement actions.
Key Aspects of Cure Provisions:
Notice and Cure Period:
Businesses are given a timeframe (e.g., 30 days) to address the alleged violation before formal enforcement actions are taken by state authorities.
Encouraging Compliance:
Cure provisions incentivize businesses to implement corrective actions and ensure compliance without incurring fines or penalties for minor or first-time violations.
State-Specific Examples:
The California Consumer Privacy Act (CCPA) initially included a 30-day cure provision, though it was later limited under the California Privacy Rights Act (CPRA). Other state laws, such as Virginia's Consumer Data Protection Act (VCDPA), also include cure provisions.


NEW QUESTION # 43
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the best reason for Cheryl to follow Janice's suggestion about classifying customer data?

  • A. It will help employees stay better organized
  • B. It will help the company meet a federal mandate
  • C. It will prevent the company from collecting too much personal information (PI)
  • D. It will increase the security of customers' personal information (PI)

Answer: D


NEW QUESTION # 44
Under the Driver's Privacy Protection Act (DPPA), which of the following parties would require consent of an individual in order to obtain his or her Department of Motor Vehicle information?

  • A. Attorneys gathering information related to lawsuits.
  • B. Insurance companies needing to investigate claims.
  • C. Law enforcement agencies performing investigations.
  • D. Marketers wishing to distribute bulk materials.

Answer: D

Explanation:
https://dmv.ny.gov/forms/mv15dppa.pdf


NEW QUESTION # 45
What type of material is exempt from an individual's right to disclosure under the Privacy Act?

  • A. Material reporting investigative efforts pertaining to the enforcement of criminal law.
  • B. Material requires by statute to be maintained and used solely for research purposes.
  • C. Material used to determine potential collaboration with foreign governments in negotiation of trade deals.
  • D. Material reporting investigative efforts to prevent unlawful persecution of an individual.

Answer: C


NEW QUESTION # 46
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?

  • A. Correct their personal information.
  • B. Disclose their personal information to them.
  • C. Delete their personal information.
  • D. Refrain from selling their personal information to third parties.

Answer: A

Explanation:
The CCPA grants California residents the right to request that a business delete, disclose, or stop selling their personal information, but it does not grant them the right to request that a business correct their personal information. However, the CPRA, which will amend and expand the CCPA in 2023, will grant California residents the right to request that a business correct inaccurate personal information.


NEW QUESTION # 47
What privacy concept grants a consumer the right to view and correct errors on his or her credit report?

  • A. Choice.
  • B. Action.
  • C. Access.
  • D. Notice.

Answer: C

Explanation:
Access is the privacy concept that grants a consumer the right to view and correct errors on his or her credit report. The Fair Credit Reporting Act (FCRA) gives consumers the right to access their credit reports from the three nationwide credit reporting agencies (Equifax, Experian, and TransUnion) once every 12 months for free. Consumers also have the right to dispute any inaccurate or incomplete information in their credit reports and request that the credit reporting agencies investigate and correct the errors. The FCRA also requires the credit reporting agencies to provide consumers with a notice of their rights and a summary of the dispute process.


NEW QUESTION # 48
In what way does the "Red Flags Rule" under the Fair and Accurate Credit Transactions Act (FACTA) relate to the owner of a grocery store who uses a money wire service?

  • A. It requires the owner to implement an identity theft warning system
  • B. It is not usually enforced in the case of a small financial institution
  • C. It mandates the use of updated technology for securing credit records
  • D. It does not apply because the owner is not a creditor

Answer: D

Explanation:
https://www.ftc.gov/business-guidance/resources/fighting-identity-theft-red-flags-rule-how-guide-business#who


NEW QUESTION # 49
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?

  • A. A bill of rights for individuals seeking access to their personal information.
  • B. An international court ruling on personal information held in the commercial sector.
  • C. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
  • D. A code of responsibilities for medical establishments to uphold privacy laws.

Answer: B

Explanation:
The APEC principles are part of the APEC Privacy Framework, which is an inter-governmental agreement among the 21 member economies of the Asia-Pacific Economic Cooperation (APEC) to promote information privacy protection and the free flow of information in the region. The APEC Privacy Framework consists of four parts: a preamble, a scope, a set of nine information privacy principles, and an implementation section.
The APEC information privacy principles are:
* Preventing harm: Personal information controllers should take reasonable steps to protect personal information from loss, misuse, unauthorized access, disclosure, alteration, and destruction, and to address the risks and challenges posed by specific technologies and business practices.
* Notice: Personal information controllers should provide clear and easily accessible statements about their personal information handling practices, including the types of personal information they collect, the purposes for which they collect it, the types of third parties to which they disclose it, the choices and means they offer individuals for limiting the use and disclosure of their personal information, and how they can contact the personal information controller with inquiries or complaints.
* Collection limitation: Personal information controllers should limit the collection of personal information to what is relevant for the purposes of collection and should collect personal information by lawful and fair means and, where appropriate, with notice to, or consent of, the individual concerned.
* Use limitation: Personal information controllers should use personal information only for the purposes for which it was collected or for purposes that a reasonable person would consider appropriate in the circumstances, and should retain personal information only as long as necessary to fulfill the stated purposes or as required by law or regulation.
* Choice: Personal information controllers should offer individuals choices and means to limit the use and disclosure of their personal information, where appropriate, and should respect the choices made by individuals.
* Integrity of personal information: Personal information controllers should take reasonable steps to ensure that personal information is accurate, complete, and up-to-date for the purposes for which it is used.
* Security safeguards: Personal information controllers should protect personal information with reasonable security safeguards against risks such as loss, unauthorized access, destruction, misuse, modification, and disclosure.
* Access and correction: Personal information controllers should give individuals the ability to access and, where appropriate, correct their personal information that is under their control, subject to reasonable limitations, such as where the burden or expense of providing access would be disproportionate to the risks to the individual's privacy, or where the legitimate rights of persons other than the individual would be violated.
* Accountability: Personal information controllers should be accountable for complying with the privacy principles and should have in place mechanisms to ensure their implementation and compliance.
The APEC Privacy Framework is not a binding legal instrument, but rather a voluntary and flexible arrangement that allows each member economy to implement the principles according to its own domestic laws and regulations, applicable international frameworks, and cultural and social values. The APEC Privacy Framework also provides for cross-border cooperation and information sharing among member economies, as well as the development of mechanisms to facilitate the cross-border transfer of personal information,such as the APEC Cross-Border Privacy Rules (CBPR) System and the APEC Privacy Recognition for Processors (PRP) System. These mechanisms are based on a common set of rules and standards derived from the APEC Privacy Framework, and are intended to enhance the protection of personal information that flows across borders and to increase the interoperability among different privacy regimes in the region and beyond. References:
* APEC Privacy Framework (2015)
* APEC Cross-Border Privacy Rules (CBPR) System
* APEC Privacy Recognition for Processors (PRP) System
* APEC Privacy Framework: A New Model for Transborder Data Flows


NEW QUESTION # 50
When may a financial institution share consumer information with non-affiliated third parties for marketing purposes?

  • A. After disclosing information-sharing practices to customers and after giving them an opportunity to opt out.
  • B. After disclosing marketing practices to customers and after giving them an opportunity to opt in.
  • C. After disclosing information-sharing practices to customers and after giving them an opportunity to opt in.
  • D. After disclosing marketing practices to customers and after giving them an opportunity to opt out.

Answer: A

Explanation:
According to the Gramm-Leach-Bliley Act (GLBA) and its implementing Regulation P, a financial institution may share consumer information with non-affiliated third parties for marketing purposes only after disclosing its information-sharing practices to customers and after giving them an opportunity to opt out of such sharing. The GLBA defines a customer as a consumer who has a continuing relationship with a financial institution that provides one or more financial products or services to be used primarily for personal, family, or household purposes. A consumer is an individual who obtains or has obtained a financial product or service from a financial institution that is to be used primarily for personal, family, or household purposes, or that individual's legal representative. A non-affiliated third party is any person except a financial institution's affiliate or a person employed jointly by a financial institution and a company that is not the financial institution's affiliate. An affiliate is any company that controls, is controlled by, or is under common control with another company.
The GLBA requires that a financial institution provide a privacy notice to customers: (i) at the time of establishing the customer relationship; (ii) annually during the continuation of the customer relationship; and (iii) before disclosing any nonpublic personal information (NPI) about the customer to any non-affiliated third party, unless an exception applies. The privacy notice must describe the categories of NPI that the financial institution collects and discloses; the categories of affiliates and non-affiliated third parties to whom the financial institution discloses NPI; the categories of NPI disclosed to service providers and joint marketers; the policies and practices with respect to protecting the confidentiality and security of NPI; and the disclosures of NPI to which the customer has a right to opt out. The financial institution must also provide a reasonable means for the customer to opt out of the disclosure of NPI to non-affiliated third parties, such as a check-off box, a reply form, or a toll-free telephone number. The opt-out notice must be clear and conspicuous, and must state that the customer can opt out at any time. The opt-out notice must also explain how the customer can opt out, and the effect of opting out. The financial institution must honor the customer's opt-out direction as soon as reasonably practicable after receiving it, and must not disclose any NPI to which the opt-out applies, unless an exception applies. The GLBA provides several exceptions to the opt-out requirement, such as when the disclosure of NPI is necessary to effect, administer, or enforce a transaction requested or authorized by the customer; when the disclosure of NPI is required or permitted by law; when the disclosure of NPI is to a consumer reporting agency in accordance with the Fair Credit Reporting Act; or when the disclosure of NPI is to a person that performs marketing services on behalf of the financial institution or on behalf of the financial institution and another financial institution under a joint marketing agreement. A joint marketing agreement is a formal written contract between a financial institution and any other person under which the parties agree to offer, endorse, or sponsor a financial product or service. The joint marketing agreement must prohibit the other person from using or disclosing the NPI for any purpose other than offering, endorsing, or sponsoring the financial product or service covered by the agreement.
The GLBA also requires that a financial institution provide a privacy notice to consumers who are not customers before disclosing any NPI about the consumer to any non-affiliated third party, unless an exception applies. The financial institution does not need to provide an opt-out notice to consumers who are not customers, unless it has a customer relationship with them. However, if the financial institution establishes a customer relationship with a consumer who was previously not a customer, it must provide a privacy notice and an opt-out notice to the customer as described above.


NEW QUESTION # 51
Which of the following practices is NOT a key component of a data ethics framework?

  • A. Preferability testing.
  • B. Data governance.
  • C. Auditing.
  • D. Automated decision-making.

Answer: A


NEW QUESTION # 52
In March 2012, the FTC released a privacy report that outlined three core principles for companies handling consumer data. Which was NOT one of these principles?

  • A. Simplifying consumer choice.
  • B. Enhancing security measures.
  • C. Practicing Privacy by Design.
  • D. Providing greater transparency.

Answer: B

Explanation:
The FTC's privacy report, titled "Protecting Consumer Privacy in an Era of Rapid Change", proposed a framework for companies that collect and use consumer data. The framework consisted of three core principles: privacy by design, simplified consumer choice, and greater transparency. Privacy by design means that companies should incorporate privacy protections into their everyday business practices, such as data security, reasonable collection limits, sound retention practices, and data accuracy. Simplified consumer choice means that companies should provide consumers with clear and easy-to-understand choices about the collection and use of their data, and respect their preferences. Greater transparency means that companies should increase the visibility and accessibility of their data practices, such as providing clear and concise privacy notices, educating consumers about the commercial datapractices, and providing consumers with access to their data. Enhancing security measures is not one of the core principles of the FTC's privacy framework, although it is a component of the privacy by design principle. References:
* IAPP CIPP/US Body of Knowledge, Section I.A.1.a
* IAPP CIPP/US Textbook, Chapter 1, pp. 13-15
* FTC Privacy Report, Executive Summary, pp. i-vii


NEW QUESTION # 53
......

Penetration testers simulate CIPP-US exam: https://pass4sure.troytecdumps.com/CIPP-US-troytec-exam-dumps.html