New Year Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CIPP-US Exam Dumps - Certified Information Privacy Professional/United States (CIPP/US)

Go to page:
Question # 25

Which statute is considered part of U.S. federal privacy law?

A.

The Fair Credit Reporting Act.

B.

SB 1386.

C.

The Personal Information Protection and Electronic Documents Act.

D.

The e-Privacy Directive.

Full Access
Question # 26

SCENARIO

Please use the following to answer the next QUESTION:

A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer’s data handling practices.

The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: “Please act immediately by identifying all personal data received from our company.”

This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup’s rapid market penetration.

As the Company’s data privacy leader, you are sensitive to the criticality of the relationship with the retailer.

Under the GDPR, the complainant’s request regarding her personal information is known as what?

A.

Right of Access

B.

Right of Removal

C.

Right of Rectification

D.

Right to Be Forgotten

Full Access
Question # 27

Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusing on placing privacy professionals in roles at major companies. Job candidates create online profiles

outlining their experience and credentials, and can pay $19.99/month via credit card to have their profiles promoted to potential employers. Privacy Is Hiring Inc. keeps all customer data at rest encrypted on its servers.

Under what circumstances would Privacy Is Hiring Inc., need to notify affected individuals in the event of a data breach?

A.

If law enforcement has completed its investigation and has authorized Privacy Is Hiring Inc. to provide the notification to clients and applicable regulators.

B.

If the job candidates’ credit card information and the encryption keys were among the information taken.

C.

If Privacy Is Hiring Inc., reasonably believes that job candidates will be harmed by the data breach.

D.

If the personal information stolen included the individuals’ names and credit card pin numbers.

Full Access
Question # 28

The Cable Communications Policy Act of 1984 requires which activity?

A.

Delivery of an annual notice detailing how subscriber information is to be used

B.

Destruction of personal information a maximum of six months after it is no longer needed

C.

Notice to subscribers of any investigation involving unauthorized reception of cable services

D.

Obtaining subscriber consent for disseminating any personal information necessary to render cable services

Full Access
Question # 29

Which of the following would NOT constitute an exception to the authorization requirement under the HIPAA Privacy Rule?

A.

Disclosing health information for public health activities.

B.

Disclosing health information to file a child abuse report.

C.

Disclosing health information needed to treat a medical emergency.

D.

Disclosing health information needed to pay a third party billing administrator.

Full Access
Question # 30

A student has left high school and is attending a public postsecondary institution. Under what condition may a school legally disclose educational records to the parents of the student without consent?

A.

If the student has not yet turned 18 years of age

B.

If the student is in danger of academic suspension

C.

If the student is still a dependent for tax purposes

D.

If the student has applied to transfer to another institution

Full Access
Question # 31

What important action should a health care provider take if the she wants to qualify for funds under the Health Information Technology for Economic and Clinical Health Act (HITECH)?

A.

Make electronic health records (EHRs) part of regular care

B.

Bill the majority of patients electronically for their health care

C.

Send health information and appointment reminders to patients electronically

D.

Keep electronic updates about the Health Insurance Portability and Accountability Act

Full Access
Question # 32

Which of the following privacy rights is NOT available under the Colorado Privacy Act?

A.

The right to access sensitive data.

B.

The right to correct sensitive data.

C.

The right to delete sensitive data.

D.

The right to limit the use of sensitive data.

Full Access
Go to page: