Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

CIPP-US Exam Questions & Answers

Certified Information Privacy Professional/United States  •  IAPP

195 Questions 150 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample CIPP-US Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

What type of material is exempt from an individual's right to disclosure under the Privacy Act?

Correct Answer: D
Explanation:

The Privacy Act allows agencies to exempt certain records from some of its provisions, including the right to disclosure, if the records fall within one of the categories specified in subsections (j) or (k) of the Act. One of these categories is records maintained by an agency or component thereof which performs as its principal function any activity pertaining to the enforcement of criminal laws, including police efforts to prevent, control, or reduce crime or to apprehend criminals, and the activities of prosecutors, courts, correctional, probation, pardon, or parole authorities, and which consists of (A) information compiled for the purpose of identifying individual criminal offenders and alleged offenders and consisting only of identifying data and notations of arrests, the nature and disposition of criminal charges, sentencing, confinement, release, and parole and probation status; (B) information compiled for the purpose of a criminal investigation, including reports of informants and investigators, and associated with an identifiable individual; or reports identifiable to an individual compiled at any stage of the process of enforcement of the criminal laws from arrest or indictment through release from supervision. 5 U.S.C. 552a (j) (2). Therefore, material reporting investigative efforts pertaining to the enforcement of criminal law falls within this category and can be exempted from the right to disclosure under the Privacy Act.Reference:

Overview of the Privacy Act: 2020 Edition, Ten Exemptions, subsection (j) (2).

Privacy Act Exemptions, subsection (j) (2).

IAPP CIPP/US Study Guide, page 66.

Q2 MultipleChoice

Global Manufacturing Co's Human Resources department recently purchased a new software tool. This tool helps evaluate future candidates for executive roles by scanning emails to see what those candidates say and what is said about them. This provides the HR department with an automated ''360 review'' that lets them know how the candidate thinks and operates, what their peers and direct reports say about them, and how well they interact with each other.

What is the most important step for the Human Resources Department to take when implementing this new software?

Correct Answer: D
Explanation:

The most important step for the HR department to take when implementing this new software is to provide notice to employees that their emails will be scanned by the software and creating automated profiles. This is because the software involves the collection and use of personal information from employees, which may implicate their privacy rights and expectations. By providing notice, the HR department can inform employees about the purpose, scope, and consequences of the software, as well as their choices and rights regarding their data. Notice is also a key element of transparency and accountability, which are essential principles of privacy management. Providing notice can also help the HR department comply with various privacy laws and regulations that may apply to the software, such as the Electronic Communications Privacy Act (ECPA), the Stored Communications Act (SCA), the Fair Credit Reporting Act (FCRA), and state privacy laws. Notice can also help the HR department avoid potential legal risks and liabilities that may arise from the software, such as claims of invasion of privacy, breach of contract, or violation of employee rights.Reference:

Q4 MultipleChoice

What is the most important action an organization can take to comply with the FTC position on retroactive changes to a privacy policy?

Correct Answer: B
Explanation:

The FTC has stated that it is a deceptive practice to make retroactive changes to a privacy policy that affect how a company uses or shares previously collected personal information, unless the company obtains affirmative consent from the affected consumers. This means that the company must clearly and conspicuously disclose the changes and obtain the consumers' express agreement to them. Simply describing the policy changes on the website, publicizing them through social media, or reassuring customers of the security of their information are not sufficient to comply with the FTC's position.Reference:

FTC Staff Revises Online Behavioral Advertising Principles, paragraph 3.

Do I really have to obtain consent from all my customers to make a change to my privacy policy?, paragraph 2.

IAPP CIPP/US Study Guide, page 64.

Q5 MultipleChoice

An organization self-certified under Privacy Shield must, upon request by an individual, do what?

Correct Answer: B
Explanation:

According to the Privacy Shield Principles, an organization that self-certifies under the Privacy Shield Framework must provide individuals with the choice to opt out of the disclosure of their personal information to a third party or the use of their personal information for a purpose that is materially different from the purpose for which it was originally collected or subsequently authorized by the individual. To facilitate this choice, the organization must inform the individual of the type or identity of the third parties to which it discloses personal information and the purposes for which it does so. The organization must also provide a readily available and affordable independent recourse mechanism to investigate and resolve complaints and disputes regarding its compliance with the Privacy Shield Principles. If the organization transfers personal information to a third party acting as an agent, it must ensure that the agent provides at least the same level of privacy protection as is required by the Privacy Shield Principles and that it takes reasonable and appropriate steps to ensure that the agent effectively processes the personal information transferred in a manner consistent with the organization's obligations under the Privacy Shield Principles.Reference:

Privacy Shield Principles, section II. Choice Principle and section III. Accountability for Onward Transfer Principle

[IAPP CIPP/US Study Guide], p. 67-68, section 3.2.1 and p. 69-70, section 3.2.2

[IAPP CIPP/US Body of Knowledge], p. 15-16, section C.1.b and p. 16-17, section C.1.c

Get access to all 195 verified questions with detailed answers.

Unlock All CIPP-US Questions

Frequently Asked Questions

There are no formal prerequisites to sit for the CIPP-US exam, though IAPP recommends having some work experience in privacy or a related field. Most candidates have at least 1-2 years of professional experience in privacy, legal, compliance, or information security roles before attempting the certification.

The CIPP-US exam consists of 90 multiple-choice questions that must be completed within 2 hours. A passing score is 70% or higher, meaning you need to answer at least 63 questions correctly to pass.

The CIPP-US exam covers U.S. privacy laws and regulations including CCPA, GDPR applicability in the U.S., HIPAA, GLBA, FTC enforcement, state privacy laws, and constitutional privacy rights. It also includes practical application of privacy principles in business contexts and understanding privacy by design concepts.

The exam registration fee is typically around $395 for IAPP members and $495 for non-members, though prices may vary. The CIPP-US certification is valid for three years, after which you must renew through continuing education credits or retake the exam.

IAPP offers an official study guide called the 'CIPP-US Study Guide' and provides access to a course curriculum through their learning platform. Many candidates also supplement with privacy law textbooks, practice exams, webinars, and review courses offered by third-party providers to prepare thoroughly for the certification exam.
Exam Details
  • Exam CodeCIPP-US
  • VendorIAPP
  • Total Questions195
  • Duration150 min
  • LanguageEnglish
  • Last UpdatedSep 4, 2026
4.9/5

Pass CIPP-US First Time

Get all 195 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals