
CIPP-US Dumps By Pros - 1st Attempt Guaranteed Success
100% Guarantee Download CIPP-US Exam Dumps PDF Q&A
NEW QUESTION # 54
Acme Student Loan Company has developed an artificial intelligence algorithm that determines whether an individual is likely to pay their bill or default. A person who is determined by the algorithm to be more likely to default will receive frequent payment reminder calls, while those who are less likely to default will not receive payment reminders.
Which of the following most accurately reflects the privacy concerns with Acme Student Loan Company using artificial intelligence in this manner?
- A. If the algorithm uses risk factors that impact the automatic decision engine. Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.
- B. If the algorithm makes automated decisions based on risk factors and public information, Acme need not determine if the algorithm has a disparate impact on protected classes.
- C. If the algorithm uses information about protected classes to make automated decisions, Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.
- D. If the algorithm's methodology is disclosed to consumers, then it is acceptable for Acme to have a disparate impact on protected classes.
Answer: A
Explanation:
https://www.ftc.gov/business-guidance/blog/2020/04/using-artificial-intelligence-and-algorithms See above. Even the examples provided therein use public information, but result in disparate impacts, and therefore are subject to challenge by the FTC.
NEW QUESTION # 55
All of the following common law torts are relevant to employee privacy under US law EXCEPT?
- A. Infliction of emotional distress.
- B. Conversion.
- C. Defamation
- D. Intrusion upon seclusion.
Answer: D
Explanation:
Explanation/Reference: https://en.wikipedia.org/wiki/Privacy_law
NEW QUESTION # 56
California's SB 1386 was the first law of its type in the United States to do what?
- A. Require state attorney general enforcement of federal regulations against unfair and deceptive trade practices
- B. Require commercial entities to disclose a security data breach concerning personal information about the state's residents
- C. Require notification of non-California residents of a breach that occurred in California
- D. Require encryption of sensitive information stored on servers that are Internet connected
Answer: B
Explanation:
California's SB 1386, also known as the California Security Breach Information Act, was enacted in 2002 and became effective in 2003. It was the first law of its kind in the United States to require commercial entities that own or license personal information of California residents to notify them in the event of a security breach that compromises their unencrypted data. The law aims to protect the privacy and security of personal information and to enable individuals to take preventive measures against identity theft and fraud. The law applies to any business or person that conducts business in California and that owns or licenses computerized data that includes personal information, as defined by the law. Personal information includes an individual's first name or first initial and last name in combination with any one or more of the following data elements: Social Security number, driver's license number or California identification card number, account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account, or medical information or health insurance information. The law does not apply to encrypted information, publicly available information, or information that is lawfully obtained from federal, state, or local government records. The law requires the disclosure of a breach of the security of the system to any resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. The disclosure may be made by written notice, electronic notice, or substitute notice, as specified by the law. The law also requires any person or business that maintains computerized data that includes personal information that the person or business does not own to notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The law also authorizes a civil action for damages by a customer injured by a violation of the law and provides that the rights and remedies available under the law are cumulative to each other and to any other rights and remedies available under law. References:
* California Senate Bill 1386 (2002)
* California SB 1386: For the Love of Privacy
* What Is the California Security Breach Information Act?
* California Raises the Bar on Data Security and Privacy
NEW QUESTION # 57
More than half of U.S. states require telemarketers to?
- A. Register with the state before conducting business
- B. Provide written contracts for customer transactions
- C. Obtain written consent from potential customers
- D. Identify themselves at the beginning of a call
Answer: A
Explanation:
According to the IAPP CIPP/US Study Guide, more than half of U.S. states require telemarketers to register with the state before conducting business within the state. This registration requirement may involve paying a fee, posting a bond, or providing information about the telemarketer's identity, location, and business practices. The purpose of this requirement is to protect consumers from fraudulent or deceptive telemarketing calls and to facilitate the enforcement of state laws and regulations. The other options are not required by most states, although some states may have additional rules or guidelines for telemarketers regarding identification, consent, or contracts. References:
* IAPP CIPP/US Study Guide, Chapter 7: Marketing and Advertising
* State Telemarketing Registration Requirements
NEW QUESTION # 58
SCENARIO -
Please use the following to answer the next question:
Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada.
Miraculous normally treats patients in person, but has recently decided to start offering telehealth appointments, where patients can have virtual appointments with on-site doctors via a phone app.
For this new initiative, Miraculous is considering a product built by MedApps, a company that makes quality telehealth apps for healthcare practices and licenses them to be usedwith the practices' branding. MedApps provides technical support for the app, which it hosts in the cloud. MedApps also offers an optional benchmarking service for providers who wish to compare their practice to others using the service.
Riya is the Privacy Officer at Miraculous, responsible for the practice's compliance with HIPAA and other applicable laws, and she works with the Miraculous procurement team to get vendor agreements in place. She occasionally assists procurement in vetting vendors and inquiring about their own compliance practices, as well as negotiating the terms of vendor agreements. Riya is currently reviewing the suitability of the MedApps app from a privacy perspective.
Riya has also been asked by the Miraculous Healthcare business operations team to review the MedApps' optional benchmarking service. Of particular concern is the requirement that Miraculous Healthcare upload information about the appointments to a portal hosted by MedApps.
What HIPAA compliance issue would Miraculous have to consider before using the telehealth app?
- A. HIPAA does not permit in-person appointment data to be hosted in the cloud.
- B. HIPAA would require Miraculous and MedApps to enter into a Business Associate Agreement.
- C. HIPAA does not permit healthcare providers to use cloud hosting services.
- D. HIPAA would require Miraculous to obtain patient consent before in-person appointment data can be shared with third parties.
Answer: B
Explanation:
According to HIPAA, a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) on behalf of, or provides services to, a covered entity. A business associate agreement (BAA) is a written contract between a covered entity and a business associate that establishes the permitted and required uses and disclosures of PHI by the business associate, as well as the safeguards that the business associate must implement to protect the PHI. In this scenario, MedApps is a business associate of Miraculous, since it provides a telehealth app that involves the use or disclosure of PHI on behalf of Miraculous. Therefore, HIPAA would require Miraculous and MedApps to enter into a BAA before using the telehealth app. The other options are incorrect because HIPAA does not prohibit the use of cloud hosting services or the hosting of in-person appointment data in the cloud, as long as the appropriate safeguards and agreements are in place. HIPAA also does not require patient consent for the sharing of PHI with third parties for treatment, payment, or health care operations purposes, which would include the use of the telehealth app. References:
* HIPAA and Telehealth - Office for Civil Rights
* HIPAA Rules for telehealth technology - Telehealth.HHS.gov
* Notification of Enforcement Discretion for Telehealth - Office for Civil Rights
* Guidance: How the HIPAA Rules Permit Covered Health Care Providers and Health Plans to Provide Audio-Only Telehealth - Office for Civil Rights
* HIPAA Compliant App - Telehealth.org
* IAPP CIPP/US Certified Information Privacy Professional Study Guide - Chapter 3: HIPAA and HITECH, pages 75-76, 81-82, 86-87.
NEW QUESTION # 59
A company based in United States receives information about its UK subsidiary's employees in connection with the centralized HR service it provides.
How can the UK company ensure an adequate level of data protection that would allow the restricted data transfer to continue?
- A. By submitting to the ICO a new application for the UK BCRs using the UK BCR application forms, as their existing authorized EU BCRs are not recognized.
- B. By signing up to an approved code of conduct under UK GDPR to demonstrate compliance with its requirements, both for the parent and the subsidiary companies.
- C. By allowing each employee the option to opt-out to the restricted transfer, as it is necessary to send their names in order to book the sales bonuses.
- D. By revising the contract with the United States parent company incorporating EU SCCs, as it continues to be valid for restricted transfers under the UK regime.
Answer: A
Explanation:
SCCs are for transfers between third parties. BCRs are for intragroup transfers. Post Brexit, company's need to separately obtain approval with the UK ICO for their UK BCRs. "Holders of EU Binding Corporate Rules (EU BCRs) are now required to take action to continue relying on them as an appropriate safeguard for international data."
NEW QUESTION # 60
Which of these organizations would be required to provide its customers with an annual privacy notice?
- A. The Breezy City Housing Commission.
- B. The Golden Gavel Auction House.
- C. The Four Winds Tribal College.
- D. The King County Savings and Loan.
Answer: D
Explanation:
The annual privacy notice requirement under the Gramm-Leach-Bliley Act (GLBA) applies to financial institutions that collect nonpublic personal information from customers and disclose it to nonaffiliated third parties, unless they qualify for an exception. A financial institution is any entity that engages in activities that are financial in nature or incidental to such activities, as defined by section 4(k) of the Bank Holding Company Act of 1956. The King County Savings and Loan is a financial institution under this definition, as it engages in lending money and accepting deposits. Therefore, it is required to provide its customers with an annual privacy notice, unless it meets the conditions for an exception. The Four Winds Tribal College, the Golden Gavel Auction House, and the Breezy City Housing Commission are not financial institutions under the GLBA, as they do not engage in activities that are financial in nature or incidental to such activities. Therefore, they are not required to provide their customers with an annual privacy notice under the GLBA. References:
* Amendment to the Annual Privacy Notice Requirement Under the Gramm-Leach-Bliley Act, section I.
Background, paragraph 2.
* 17 CFR § 248.5 - Annual privacy notice to customers required., paragraph (a) (1).
* IAPP CIPP/US Study Guide, page 65.
NEW QUESTION # 61
John, a California resident, receives notification that a major corporation with $500 million in annual revenue has experienced a data breach. John's personal information in their possession has been stolen, including his full name and social security numb. John also learns that the corporation did not have reasonable cybersecurity measures in place to safeguard his personal information.
Which of the following answers most accurately reflects John's ability to pursue a legal claim against the corporation under the California Consumer Privacy Act (CCPA)?
- A. John can sue the corporation for the data breach to recover monetary damages suffered as a result of the data breach, and in some circumstances seek statutory damages irrespective of whether he suffered any financial harm.
- B. John cannot sue the corporation for the data breach because only the state's Attoney General has authority to file suit under the CCPA.
- C. John can sue the corporation for the data breach but only to recover monetary damages he actually suffered as a result of the data breach.
- D. John has no right to sue the corporation because the CCPA does not address any data breach rights.
Answer: A
Explanation:
California Code, Civil Code Section 1798.150(a)(1))
NEW QUESTION # 62
Which entities must comply with the Telemarketing Sales Rule?
- A. Nonprofit organizations calling on their own behalf
- B. For-profit organizations and for-profit telefunders regarding charitable solicitations
- C. For-profit organizations calling businesses when a binding contract exists between them
- D. For-profit and not-for-profit organizations when selling additional services to establish customers
Answer: B
Explanation:
The Telemarketing Sales Rule (TSR) is a federal regulation that applies to telemarketing calls, which are defined as "a plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call."1 The TSR requires telemarketers to make specific disclosures, prohibit misrepresentations, limit the times and number of calls, and set payment restrictions for the sale of certain goods and services. The TSR also gives consumers the right to opt out of receiving telemarketing calls by registering their phone numbers on the National Do Not Call Registry.2 The TSR applies to both for-profit and not-for-profit organizations, but there are some exemptions and partial exemptions for certain types of entities, calls, and transactions. For example, the TSR does not apply to nonprofit organizations calling on their own behalf, as they are not considered to be engaged intelemarketing.
However, if a nonprofit organization hires a for-profit telemarketer or telefunder to solicit charitable contributions on its behalf, the for-profit entity must comply with the TSR, as it is engaged in telemarketing.
Similarly, the TSR does not apply to for-profit organizations calling businesses when a binding contract exists between them, as they are not considered to be inducing the purchase of goods or services. However, if a for-profit organization calls businesses to sell additional services to established customers, the TSR applies, as it is considered to be inducing the purchase of goods or services.3 Therefore, among the four options, only for-profit organizations and for-profit telefunders regarding charitable solicitations must comply with the TSR, as they are engaged in telemarketing and do not fall under any of the exemptions or partial exemptions. References: 1: eCFR :: 16 CFR Part 310 - Telemarketing Sales Rule3, Section 310.22: Telemarketing Sales Rule | Federal Trade Commission1, Rule Summary3: Complying with the Telemarketing Sales Rule - Federal Trade Commission2, Exemptions to the TSR.
NEW QUESTION # 63
Which of the following best describes what a "private right of action" is?
- A. The right of individuals to keep their information private.
- B. The right of individuals harmed by data processing to have their information deleted.
- C. The right of individuals to submit a request to access their information.
- D. The right of individuals harmed by a violation of a law to file a lawsuit against the violation.
Answer: D
NEW QUESTION # 64
Which of the following would NOT constitute an exception to the authorization requirement under the HIPAA Privacy Rule?
- A. Disclosing health information to file a child abuse report.
- B. Disclosing health information for public health activities.
- C. Disclosing health information needed to treat a medical emergency.
- D. Disclosing health information needed to pay a third party billing administrator.
Answer: C
Explanation:
Section: (none)
Explanation
NEW QUESTION # 65
The Video Privacy Protection Act of 1988 restricted which of the following?
- A. When a user's viewing of online video content can be monitored
- B. Who advertisements for videos and video games may target
- C. Which purchase records of audio visual materials may be disclosed
- D. When downloading of copyrighted audio visual materials is allowed
Answer: C
Explanation:
The VPPA was enacted to prevent the wrongful disclosure of personally identifiable information (PII) concerning any consumer of a video tape service provider. PII includes information that identifies a person as having requested or obtained specific video materials or services from a video tape service provider. The VPPA prohibits such disclosure, except in certain limited circumstances, such as with the consumer's informed, written consent, or pursuant to a law enforcement warrant, subpoena, or court order. The VPPA also allows the disclosure of the names and addresses of consumers, but not the title, description, or subject matter of any video tapes or other audio visual material, for the exclusive use of marketing goods and services directly to the consumer, unless the consumer has opted out of such disclosure. The other options (B, C, and D) are not restricted by the VPPA. References:
* Video Privacy Protection Act - Wikipedia
* 18 U.S. Code § 2710 - Wrongful disclosure of video tape rental or sale records | U.S. Code | US Law | LII / Legal Information Institute
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 3: Federal Privacy Laws and Regulations, Section 3.5: Video Privacy Protection Act (VPPA)
NEW QUESTION # 66
Within what time period must a commercial message sender remove a recipient's address once they have asked to stop receiving future e-mail?
- A. 7 days
- B. 21 days
- C. 15 days
- D. 10 days
Answer: D
Explanation:
According to the CAN-SPAM Act of 2003, a federal law that regulates commercial email messages, a commercial message sender must honor a recipient's opt-out request within 10 business days. The sender must provide a clear and conspicuous way for the recipient to opt out of receiving future emails, such as a link or an email address. The sender must not charge a fee, require the recipient to provide any personal information, or make the recipient take any steps other than sending a reply email or visiting a single web page to opt out. The sender must also not sell, exchange, or transfer the email address of the recipient who has opted out, unless it is necessary to comply with the law or prevent fraud.
References:
* IAPP CIPP/US Body of Knowledge, Domain II: Limits on Private-sector Collection and Use of Data, Section B: Communications and Marketing
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 2: Limits on Private-sector Collection and Use of Data, Section 2.2: Communications and Marketing
* Practice Exam - International Association of Privacy Professionals
NEW QUESTION # 67
Which federal law or regulation preempts state law?
- A. Health Insurance Portability and Accountability Act
- B. Electronic Communications Privacy Act of 1986
- C. Controlling the Assault of Non-Solicited Pornography and Marketing Act
- D. Telemarketing Sales Rule
Answer: C
NEW QUESTION # 68
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
How can the radiology department address Declan's concern about paper waste and still comply with the Health Insurance Portability and Accountability Act (HIPAA)?
- A. State the privacy policy to the patient verbally
- B. Direct patients to the correct area of the hospital website
- C. Confirm that patients are given the privacy notice on their first visit
- D. Post the privacy notice in a prominent location instead
Answer: C
Explanation:
HIPAA requires covered entities to provide a notice of privacy practices (NPP) to individuals who receive health care services from the covered entity. The NPP must describe how the covered entity may use and disclose protected health information (PHI), the individual's rights with respect to their PHI, and the covered entity's obligations to protect the privacy of PHI. The NPP must be provided to the individual no later than the date of the first service delivery, either in person or electronically. The covered entity must also make the NPP available on request and post it on its website if it has one. The covered entity must also make a good faith effort to obtain a written acknowledgment from the individual that they received the NPP. If the individual refuses to sign the acknowledgment, the covered entity must document the attempt and the reason for the refusal.
The other options are not sufficient to comply with HIPAA. Stating the privacy policy verbally (option A) does not provide the individual with a written or electronic copy of the NPP that they can keep for future reference. Posting the privacy notice in a prominent location (option B) does not ensure that the individual receives the NPP or has an opportunity to review it before receiving services. Directing patients to the correct area of the hospital website (option C) does not provide the individual with the NPP at the time of service delivery, unless the individual agrees to receive the NPP electronically and has access to the website at that time. References:
* Notice of Privacy Practices for Protected Health Information
* Model Notices of Privacy Practices
* Sample Notice: Availability of Notice of Privacy Practices
* Notice of Privacy Practices
* Notice of Privacy Practices (NPP) Distribution and Acknowledgement
NEW QUESTION # 69
Once a breach has been definitively established, which task should be prioritized next?
- A. Providing notice to the affected parties so they can take precautionary measures.
- B. Involving law enforcement and state Attorneys General.
- C. Implementing remedial measures and evaluating how to prevent future breaches.
- D. Determining what was responsible for the breach and neutralizing the threat.
Answer: A
Explanation:
According to the IAPP CIPP/US study guide, the first priority after a breach has been confirmed is to notify the affected individuals, regulators, and other stakeholders as required by law or contract. This is to allow them to take steps to protect themselves from potential harm, such as identity theft, fraud, or reputational damage. Providing timely and accurate notice also helps to mitigate legal liability, preserve customer trust, and comply with applicable laws and regulations. The other tasks are also important, but they are not the immediate priority after a breach has been established. References: IAPP CIPP/US study guide, Chapter 6, Section 6.4.2, page 211.
NEW QUESTION # 70
What type of material is exempt from an individual's right to disclosure under the Privacy Act?
- A. Material used to determine potential collaboration with foreign governments in negotiation of trade deals.
- B. Material requires by statute to be maintained and used solely for research purposes.
- C. Material reporting investigative efforts to prevent unlawful persecution of an individual.
- D. Material reporting investigative efforts pertaining to the enforcement of criminal law.
Answer: A
NEW QUESTION # 71
The Family Educational Rights and Privacy Act (FERPA) requires schools to do all of the following EXCEPT?
- A. Respond to all reasonable student requests regarding explanation of their records.
- B. Verify the identity of students who make requests for access to their records.
- C. Obtain student authorization before releasing directory information in their records.
- D. Provide students with access to their records within a specified amount of time.
Answer: C
Explanation:
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records and gives parents or eligible students the right to access, amend, and control the disclosure of their records. FERPA applies to all educational agencies and institutions that receive funds under any program administered by the U.S. Department of Education12 FERPA requires schools to do all of the following:
* Verify the identity of students who make requests for access to their records. Schools must use reasonable methods to identify and authenticate the identity of parents, students, school officials, and any other parties to whom they disclose education records12
* Provide students with access to their records within a specified amount of time. Schools must provide parents or eligible students with an opportunity to inspect and review the student's education records within 45 days of receiving a request. Schoolsare not required to provide copies of records unless it is impossible for parents or eligible students to review the records at the school12
* Respond to all reasonable student requests regarding explanation of their records. Schools must provide parents or eligible students with an opportunity to request the amendment of the student's education records that they believe are inaccurate, misleading, or otherwise in violation of the student's privacy rights. Schools must consider the request and decide whether to amend the records within a reasonable time. If the school decides not to amend the records, it must inform the parent or eligible student of their right to a hearing on the matter12 FERPA does not require schools to do the following:
* Obtain student authorization before releasing directory information in their records. Directory information is information contained in a student's education record that would not generally be considered harmful or an invasion of privacy if disclosed. Examples of directory information include the student's name, address, phone number, e-mail address, date and place of birth, major field of study, participation in sports and activities, dates of attendance, degrees and awards received, and most recent school attended. Schools may disclose directory information without consent unless the parent or eligible student has opted out of such disclosure. Schools must notify parents and eligible students of the types of information they designate as directory information and of their right to opt out of directory information disclosure12 Therefore, the correct answer is D. Obtain student authorization before releasing directory information in their records.
References:
* Family Educational Rights and Privacy Act (FERPA)
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 4: Federal Privacy Laws, Section 4.3: The Family Educational Rights and Privacy Act (FERPA)
NEW QUESTION # 72
When developing a company privacy program, which of the following relationships will most help a privacy professional develop useful guidance for the organization?
- A. Relationships with company leaders responsible for approving, implementing, and periodically reviewing the corporate privacy program.
- B. Relationships with individuals within the privacy professional community who are able to share expertise and leading practices for different industries.
- C. Relationships with individuals across company departments and at different levels in the organization's hierarchy.
- D. Relationships with clients, vendors, and customers whose data will be primarily collected and used throughout the organizational program.
Answer: C
Explanation:
When developing a company privacy program, a privacy professional needs to understand the business objectives, processes, and risks of the organization, as well as the legal and regulatory requirements and best practices for privacy. To achieve this, a privacy professional should establish and maintain relationships with individuals across company departments and at different levels in the organization's hierarchy, such as IT, marketing, human resources, legal, compliance, security, and senior management. These relationships will help the privacy professional to gather relevant information, identify privacy issues and gaps, communicate privacy policies and procedures, provide training and awareness, monitor compliance, and resolve conflicts.
The other relationshipslisted are also important, but not as essential as the internal relationships for developing a company privacy program. References:
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 5: Developing a Privacy Program, Section 5.1: Privacy Program Framework, p. 145-146
* IAPP CIPP/US Body of Knowledge, Domain V: Developing a Privacy Program, Objective V.A:
Identify the components of a privacy program framework, Subobjective V.A.1: Identify the roles and responsibilities of individuals within the organization, p. 23
* IAPP CIPP/US Exam Blueprint, Domain V: Developing a Privacy Program, Objective V.A: Identify the components of a privacy program framework, Subobjective V.A.1: Identify the roles and responsibilities of individuals within the organization, p. 7
NEW QUESTION # 73
Which of the following is most likely to provide privacy protection to private-sector employees in the United States?
- A. The Federal Trade Commission Act (FTC Act)
- B. State law, contract law, and tort law
- C. Amendments one, four, and five of the U.S. Constitution
- D. The U.S. Department of Health and Human Services (HHS)
Answer: B
Explanation:
Unlike many other countries, the United States does not have a comprehensive federal law that regulates the privacy of private-sector employees. Instead, the privacy protection of employees depends largely on state law, contract law, and tort law. State law may provide specific rights and remedies for employees regarding issues such as drug testing, background checks, electronic monitoring, social media access, and genetic information.
Contract law may create obligations and expectations for employers and employees based on written or implied agreements, such as employment contracts, employee handbooks, or collective bargaining agreements.
Tort law may allow employees to sue their employers for invasion of privacy, such as intrusion upon seclusion, public disclosure of private facts, false light, or appropriation of name or likeness. The other options are less likely to provide privacy protection to private-sector employees in the United States. The FTC Act primarily regulates the privacy practices of businesses that collect and use consumer data, not employee data.
The U.S. Constitution only protects individuals from unreasonable searches and seizures by the government, not by private employers. The HHS only enforces the HIPAA Privacy Rule, which applies to covered entities and business associates that handle protected health information, not to all private-sector employers. References:
* IAPP CIPP/US Study Guide, Chapter 6: Workplace Privacy
* Privacy Rights of Employees Using Workplace Computers in the United States
* Employee Privacy Laws
NEW QUESTION # 74
A large online bookseller decides to contract with a vendor to manage Personal Information (PI). What is the least important factor for the company to consider when selecting the vendor?
- A. The vendor's employee training program
- B. The vendor's employee retention rates
- C. The vendor's financial health
- D. The vendor's reputation
Answer: C
NEW QUESTION # 75
Which of the following best describes an employer's privacy-related responsibilities to an employee who has left the workplace?
- A. An employer has a responsibility to permanently delete or expunge all sensitive employment records to minimize privacy risks to both the employer and former employee.
- B. An employer has a responsibility to maintain a former employee's access to computer systems and company data needed to support claims against the company such as discrimination.
- C. An employer may consider any privacy-related responsibilities terminated, as the relationship between employer and employee is considered primarily contractual.
- D. An employer has a responsibility to maintain the security and privacy of any sensitive employment records retained for a legitimate business purpose.
Answer: D
NEW QUESTION # 76
Which authority supervises and enforces laws regarding advertising to children via the Internet?
- A. The Office for Civil Rights
- B. The Department of Homeland Security
- C. The Federal Communications Commission
- D. The Federal Trade Commission
Answer: D
Explanation:
The Federal Trade Commission (FTC) is the primary federal agency that regulates advertising and marketing practices in the United States, including those targeting children via the Internet. The FTC enforces the Children's Online Privacy Protection Act (COPPA), which requires operators of websites and online services directed to children under 13 to obtain verifiable parental consent before collecting, using, or disclosing personal information from children. The FTC also enforces the FTC Act, which prohibits unfair or deceptive acts or practices in commerce, such as making false or misleading claims in advertising. The FTC has issued guidelines and reports on various aspects of digital advertising to children, such as sponsored content, influencers, data collection, persuasive design, and behavioral marketing. The FTC also hosts workshops and events to examine the impact of digital advertising on children and their ability to distinguish ads from entertainment. References:
* FTC website
* Digital Advertising to Children
* IAPP CIPP/US Study Guide, Chapter 5: Marketing and Privacy, pp. 169-170
NEW QUESTION # 77
SCENARIO
Please use the following to answer the next question :
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most effective kind of training CloudHealth could have given its employees to help prevent this type of data breach?
- A. Training on techniques for identifying phishing attempts
- B. Training on the difference between confidential and non-public information
- C. Training on CloudHealth's HR policy regarding the role of employees involved data breaches
- D. Training on the terms of the contractual agreement with HealthCo
Answer: A
NEW QUESTION # 78
What is the most likely reason that states have adopted their own data breach notification laws?
- A. Many types of organizations are not currently subject to federal laws regarding breaches
- B. Many lawmakers believe that federal enforcement of current laws has not been effective
- C. Many large businesses have intentionally breached the personal information of their customers
- D. Many states have unique types of businesses that require specific legislation
Answer: A
NEW QUESTION # 79
......
Earn Quick And Easy Success With CIPP-US Dumps: https://www.testkingpdf.com/CIPP-US-testking-pdf-torrent.html
Kickstart your Career with Real Updated Questions: https://drive.google.com/open?id=1quKzJjuHnUfAIRxcrLLJTgjy9uddx-R8

