Try 12 Certified Information Privacy Professional/China (CIPP/CN) sample questions on China privacy concepts, personal information processing, sensitive data, transfers, consent, and governance.
Certified Information Privacy Professional/China (CIPP/CN) preparation focuses on China privacy and data-protection concepts, including personal information processing, consent, sensitive personal information, cross-border transfers, governance, and accountability.
Use these 12 original sample questions for initial self-assessment. They are not official IAPP questions and do not reproduce a live exam.
Verify current certification names, exam policies, and requirements with the IAPP certification page .
Topic: personal information processing
What should an organization clarify before processing personal information?
Best answer: D
Explanation: China privacy preparation emphasizes purpose, scope, notice, consent or legal basis, retention, security, and rights.
Topic: sensitive personal information
Why does sensitive personal information require special care?
Best answer: A
Explanation: Sensitive personal information typically requires stronger safeguards and careful processing justification.
Topic: consent
When consent is needed, what makes it more defensible?
Best answer: C
Explanation: Consent should be informed, specific, and supportable through records.
Topic: cross-border transfer
What should be reviewed before transferring personal information outside China?
Best answer: B
Explanation: Cross-border transfer review is a key China privacy topic and may involve multiple safeguards.
Topic: data minimization
Which approach best supports minimization?
Best answer: B
Explanation: Minimization limits collection and reduces risk.
Topic: automated decision-making
Why should automated decision-making be governed?
Best answer: C
Explanation: Automated decisions can create individual impact and need governance, transparency, and control.
Topic: rights handling
What should a rights-handling workflow include?
Best answer: A
Explanation: Individual rights require repeatable operating procedures.
Topic: processor oversight
What is a strong control when entrusting processing to a third party?
Best answer: D
Explanation: Entrusted processing should be controlled through defined scope and safeguards.
Topic: security measures
Which control best supports personal-information security?
Best answer: A
Explanation: Security is a practical privacy obligation and supports safe processing.
Topic: privacy notice
What should a privacy notice help individuals understand?
Best answer: C
Explanation: Transparency helps individuals understand processing and exercise rights.
Topic: breach response
A suspected personal-information breach occurs. What is the best first response?
Best answer: D
Explanation: Breach response requires fact gathering, containment, risk assessment, and documented action.
Topic: governance
Which evidence best supports privacy governance maturity?
Best answer: B
Explanation: Governance maturity is shown through repeatable controls and evidence.