IAPP CIPP-US Practice Test - Questions Answers, Page 10
List of questions
Related questions
California's SB 1386 was the first law of its type in the United States to do what?
Require commercial entities to disclose a security data breach concerning personal information about the state's residents
Require notification of non-California residents of a breach that occurred in California
Require encryption of sensitive information stored on servers that are Internet connected
Require state attorney general enforcement of federal regulations against unfair and deceptive trade practices
Most states with data breach notification laws indicate that notice to affected individuals must be sent in the ''most expeditious time possible without unreasonable delay.'' By contrast, which of the following states currently imposes a definite limit for notification to affected individuals?
Maine
Florida
New York
California
Under state breach notification laws, which is NOT typically included in the definition of personal information?
State identification number
First and last name
Social Security number
Medical Information
Which of the following best describes what a ''private right of action'' is?
The right of individuals to keep their information private.
The right of individuals to submit a request to access their information.
The right of individuals harmed by data processing to have their information deleted.
The right of individuals harmed by a violation of a law to file a lawsuit against the violation.
Which of the following is NOT a principle found in the APEC Privacy Framework?
Integrity of Personal Information.
Access and Correction.
Preventing Harm.
Privacy by Design.
What is the most important action an organization can take to comply with the FTC position on retroactive changes to a privacy policy?
Describing the policy changes on its website.
Obtaining affirmative consent from its customers.
Publicizing the policy changes through social media.
Reassuring customers of the security of their information.
Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?
Implied consent from a minor's parent or guardian, or affirmative consent from the minor.
Affirmative consent from a minor's parent or guardian before collecting the minor's personal information online.
Implied consent from a minor's parent or guardian before collecting a minor's personal information online, such as when they permit the minor to use the internet.
Affirmative consent of a parent or guardian before collecting personal information of a minor offline (e.g., in person), which also satisfies any requirements for online consent.
If an organization maintains data classified as high sensitivity in the same system as data classified as low sensitivity, which of the following is the most likely outcome?
The organization will still be in compliance with most sector-specific privacy and security laws.
The impact of an organizational data breach will be more severe than if the data had been segregated.
Temporary employees will be able to find the data necessary to fulfill their responsibilities.
The organization will be able to address legal discovery requests efficiently without producing more information than necessary.
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
A bill of rights for individuals seeking access to their personal information.
A code of responsibilities for medical establishments to uphold privacy laws.
An international court ruling on personal information held in the commercial sector.
A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
Washington.
California.
New York.
Vermont.
Question