Try 12 Certified Information Privacy Professional/United States (CIPP/US) sample questions on U.S. privacy law, notices, rights, enforcement, sectors, and compliance judgment.
Certified Information Privacy Professional/United States (CIPP/US) preparation focuses on U.S. privacy frameworks, sector rules, enforcement, rights, notice, consent, governance, and practical compliance judgment.
Use these 12 original sample questions for initial self-assessment. They are not official IAPP questions and do not reproduce a live exam.
Verify current certification names, exam policies, and requirements with the IAPP certification page .
Topic: sectoral privacy
What is a key feature of U.S. privacy regulation compared with one comprehensive national private-sector privacy law?
Best answer: D
Explanation: U.S. privacy commonly combines sector-specific federal laws, state privacy statutes, enforcement actions, and consumer-protection principles.
Topic: notice
What makes a privacy notice misleading?
Best answer: C
Explanation: A notice must align with actual processing. Inaccurate privacy representations can create enforcement and trust risk.
Topic: consumer rights
A consumer submits a deletion request. What should an organization evaluate first?
Best answer: A
Explanation: Rights requests require process discipline: identity, scope, exceptions, deadline, downstream systems, and documentation.
Topic: service providers
Why are vendor contracts important in U.S. privacy compliance?
Best answer: B
Explanation: Service-provider and processor relationships need contractual controls that match privacy obligations and business purpose.
Topic: enforcement
Which practice creates enforcement risk?
Best answer: B
Explanation: Broken privacy promises and deceptive practices can trigger consumer-protection and privacy enforcement.
Topic: health privacy
Why does regulated health information require special handling?
Best answer: D
Explanation: U.S. health privacy includes sector-specific obligations and safeguards depending on the entity and data context.
Topic: children’s privacy
A service directed to children collects personal information. What should the privacy team assess?
Best answer: A
Explanation: Children’s privacy raises special notice, consent, use, and retention concerns.
Topic: breach response
What is usually needed before deciding whether notification is required after a data incident?
Best answer: C
Explanation: Breach notification analysis depends on facts, applicable law, affected data, risk, and timelines.
Topic: data minimization
Why does collecting unnecessary personal information increase privacy risk?
Best answer: B
Explanation: Minimization reduces risk by limiting what is collected, retained, accessed, and protected.
Topic: sensitive data
What is a common compliance concern with sensitive personal information?
Best answer: A
Explanation: Sensitive data often receives stronger protections because misuse can create greater harm.
Topic: privacy governance
Which evidence best supports a defensible privacy program?
Best answer: C
Explanation: Documentation and repeatable controls demonstrate that privacy obligations are managed, not improvised.
Topic: cross-border transfers
Why should cross-border data transfers be reviewed?
Best answer: D
Explanation: Transfer rules and contractual safeguards can vary by jurisdiction and processing context.