10 free IAPP CIPP/US practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 272 questions. Work through them, then open each answer to check your reasoning.
Get all 272 questions (US$39) · Download these 10 as a PDF
Question 1
Which jurisdiction must courts have in order to hear a particular case?
Show answer and explanation
Correct answer: C. Personal jurisdiction and subject matter jurisdiction
Courts must have both personal jurisdiction (authority over the defendant or property) and subject matter jurisdiction (authority over the type of case) to hear a case. Personal jurisdiction ensures the court can exercise power over the parties involved, while subject matter jurisdiction ensures the court has the legal authority to decide cases of that particular type.
Why the other options are wrong
- A. Regulatory jurisdiction is not a foundational requirement for courts to hear cases; only personal and subject matter jurisdiction are required.
- B. Professional jurisdiction is not a recognized legal requirement for courts to hear cases.
- D. Professional jurisdiction is not a standard legal requirement for court authority.
Question 2
Which authority supervises and enforces laws regarding advertising to children via the Internet?
Show answer and explanation
Correct answer: B. The Federal Trade Commission
The Federal Trade Commission (FTC) is the primary federal authority responsible for supervising and enforcing laws regarding advertising to children, including Internet advertising. This authority is exercised through enforcement of the Children's Online Privacy Protection Act (COPPA) and the FTC Act.
Why the other options are wrong
- A. The Office for Civil Rights focuses on civil rights enforcement, not advertising regulation.
- C. The Federal Communications Commission regulates broadcast and telecommunications, not primarily Internet advertising practices.
- D. The Department of Homeland Security focuses on national security and border protection, not consumer advertising enforcement.
Question 3
According to Section 5 of the FTC Act, self-regulation primarily involves a company’s right to do what?
Show answer and explanation
Correct answer: C. Adhere to its industry’s code of conduct
Section 5 of the FTC Act recognizes self-regulation as a company's ability and responsibility to adhere to its industry's code of conduct. Self-regulation allows companies to establish and follow standards developed by their industry rather than relying solely on government enforcement, provided these standards are enforceable and protect consumers.
Why the other options are wrong
- A. Determining which bodies conduct adjudication is not the primary focus of sel-egulation under Section 5.
- B. Companies do not have the right to decide unilaterally whether enforcement actions are justified; this remains an FTC responsibility.
- D. The ability to appeal decisions is a procedural right, not the primary purpose of sel-egulation under Section 5.
Question 4
Which was NOT one of the five priority areas listed by the Federal Trade Commission in its 2012 report, “Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers”?
Show answer and explanation
Correct answer: A. International data transfers
The FTC's 2012 report "Protecting Consumer Privacy in an Era of Rapid Change" identified four main priority areas: promoting enforceable self-regulatory codes, large platform providers, Do Not Track, and data security. International data transfers was not listed as one of the five priority areas in this specific report.
Why the other options are wrong
- B. Large platform providers was one of the priority areas identified in the 2012 FTC report.
- C. Promoting enforceable self-regulatory codes was one of the priority areas identified in the 2012 FTC report.
- D. Do Not Track was one of the priority areas identified in the 2012 FTC report.
Question 5
The “Consumer Privacy Bill of Rights” presented in a 2012 Obama administration report is generally based on?
Show answer and explanation
Correct answer: D. Traditional fair information practices
The 2012 Consumer Privacy Bill of Rights presented by the Obama administration was based on traditional fair information practices, which include principles such as transparency, choice, access, security, and accountability. These foundational principles have guided privacy policy development for decades and form the basis of modern consumer privacy frameworks.
Why the other options are wrong
- A. While the 1974 Privacy Act is important privacy legislation, it is not the primary basis for the 2012 Consumer Privacy Bill of Rights.
- B. Common law principles alone do not provide the comprehensive framework underlying the Consumer Privacy Bill of Rights.
- C. Although EU directives influence privacy thinking, the Consumer Privacy Bill of Rights was specifically grounded in traditional fair information practices rather than EU models.
Question 6
What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?
Show answer and explanation
Correct answer: A. A consent decree
A consent decree is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party, typically to resolve legal disputes without requiring the adverse party to admit wrongdoing. It is enforceable as a court order.
Why the other options are wrong
- B. Stare decisis decree is not a recognized legal term; stare decisis refers to following precedent, not a type of decree.
- C. A judgment rider is not a standard legal term for formalizing agreements between agencies and adverse parties.
- D. Common law judgment refers to decisions based on precedent and case law, not agreements between agencies and adverse parties.
Question 7
Read this notice:
Our website uses cookies. Cookies allow us to identify the computer or device you’re using to access the site, but they don’t identify you personally. For instructions on setting your Web browser to refuse cookies, click here.
What type of legal choice does not notice provide?
Show answer and explanation
Correct answer: D. Opt-out
The notice describes an opt-out choice because it informs users that cookies will be used by default and provides instructions on how to refuse them. Users can choose to decline cookies after being notified, which is the defining characteristic of an opt-out mechanism, as opposed to requiring affirmative consent before cookies are deployed.
Why the other options are wrong
- A. The notice provides a choice, not a mandatory requirement.
- B. Implied consent typically means consent inferred from action or silence without explicit notification of the choice mechanism.
- C. Opt-in would require users to affirmatively choose to accept cookies before they are used; this notice deploys cookies first and allows refusal.
Question 8
Show the case study this question is based on
SCENARIO
Please use the following to answer the next question:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customers’ privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer’s personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worries Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl’s concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company’s day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the best reason for Cheryl to follow Janice’s suggestion about classifying customer data?
Show answer and explanation
Correct answer: C. It will increase the security of customers’ personal information (PI)
Classifying customer data according to sensitivity levels allows the company to apply appropriate security measures to each category of information. Highly sensitive data (such as financial information) can receive stronger protections, while less sensitive data can receive proportional protections, resulting in an overall increase in the security of customers' personal information.
Why the other options are wrong
- A. While data classification may assist with organization, this is a secondary benefit, not the best reason to implement the practice.
- B. The scenario does not indicate that federal mandates require data classification; Cheryl is implementing privacy practices voluntarily.
- D. Data classification does not prevent excessive collection; it addresses how data is protected and managed once collected.
Question 9
Show the case study this question is based on
SCENARIO
Please use the following to answer the next question:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customers’ privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer’s personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worries Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl’s concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company’s day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the most likely risk of Fitness Coach, Inc. adopting Janice’s first draft of the privacy policy?
Show answer and explanation
Correct answer: A. Leaving the company susceptible to violations by setting unrealistic goals
Janice's first draft sets unrealistic goals that would be difficult for Fitness Coach to implement operationally. The one-year data retention limit and absolute prohibition on third-party sharing without written consent contradict the company's legitimate business needs, such as maintaining customer relationships during gaps in service and enabling contract instructors to access fitness level information. These stringent requirements are impractical for a fitness business and represent goals that cannot realistically be maintained, thereby creating vulnerability to policy violations when the company finds it necessary to deviate from them.
Why the other options are wrong
- B. The draft policy actually does address customer privacy concerns through data retention limits and third-party consent requirements; Cheryl's issue is operational feasibility, not unmet privacy needs.
- C. The scenario does not suggest the policy would demonstrate lack of trust in the organization; rather, it demonstrates an attempt to establish formal privacy protections.
- D. The question asks about the most likely risk of adopting the draft, not whether it complies with laws; compliance issues may exist but unrealistic implementation is the primary operational risk identified.
Question 10
Show the case study this question is based on
SCENARIO
Please use the following to answer the next question:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customers’ privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer’s personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worries Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl’s concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company’s day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the main problem with Cheryl’s suggested method of communicating the new privacy policy?
Show answer and explanation
Correct answer: B. The policy might not be implemented consistency across departments.
Implementing the policy gradually, one department at a time with layered documents for each department, creates significant risk of inconsistent implementation across the organization. Different departments may interpret and apply the policy differently, or may implement it at different standards, leading to inconsistency in how customer data is handled throughout Fitness Coach. This fragmented approach undermines the unified privacy framework that a formal policy is designed to establish.
Why the other options are wrong
- A. Policies can be valid even when communicated in phases; validity is not determined by simultaneous full communication.
- C. The scenario suggests employees may actually prefer gradual implementation; this is not presented as a concern about comfort levels.
- D. While understanding relationships between documents and overall policy could be a challenge, the main problem with Cheryl's approach is the risk of inconsistent enforcement and application across departments rather than employee comprehension.
That was 10 of 272.
The full IAPP CIPP/US pack has all 272 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
