US Privacy Law (CIPP/US-aligned) Practice Exams

Three 50-question practice papers on the US privacy law landscape: the regulatory environment, sector-specific limits on private-sector data use, government access, workplace privacy and state privacy statutes. Educational practice material only — nothing here is legal advice.

3 practice papers · 150 questions · 90 minutes each · pass mark 70% · ₹196 for all papers

What the CIPP/US practice exams cover

Written from the published IAPP CIPP/US certification body of knowledge / exam blueprint.

Practice papers

Free CIPP/US sample questions

Sample question 1 (The US privacy environment)

A US-based e-commerce company collects customer marketing data, processes credit card payments, and sells wellness products that include health-related information. Which statement best characterizes how privacy obligations apply to this company under the US sectoral model?

  1. A single federal statute imposes uniform privacy standards across all data categories the company handles.
  2. Privacy obligations arise from different laws that apply to specific data categories and industry contexts.
  3. The company must follow state omnibus laws but is exempt from all sector-specific federal statutes.
  4. Common law torts fully replace sector-specific statutes for consumer data.

Answer: B. Privacy obligations arise from different laws that apply to specific data categories and industry contexts.

The US sectoral model means privacy obligations arise from different laws that target specific data categories, industries, or activities rather than from one overarching statute. Option B is correct because the company's obligations would come from a patchwork of sector-specific laws and state statutes. Option A is incorrect because the US does not have a single federal omnibus privacy statute governing all personal data. Option C is incorrect because state laws do not exempt companies from applicable federal sector-specific statutes; both layers can apply simultaneously. Option D is incorrect because common law torts supplement but do not replace the statutory and regulatory framework.

Sample question 2 (Limits on private-sector data use)

A regional health insurance plan contracts with a cloud storage provider to archive member claim records that contain diagnoses, treatment codes, and member names. Under HIPAA, which statement correctly describes the cloud provider's regulatory status?

  1. The cloud provider is a covered entity because it stores health plan records.
  2. The cloud provider is a business associate because it performs a service for the covered entity that involves access to protected health information.
  3. The cloud provider is outside HIPAA's reach because it is a technology company, not a medical provider.
  4. The cloud provider becomes a hybrid entity upon signing the contract.

Answer: B. The cloud provider is a business associate because it performs a service for the covered entity that involves access to protected health information.

Option B is correct because a business associate is a person or entity that performs functions or activities on behalf of a covered entity that involve access to protected health information; storing health plan records qualifies. Option A is wrong because merely storing records does not make the provider a health plan, health care clearinghouse, or health care provider, which are the three covered entity categories. Option C is wrong because HIPAA extends to vendors that handle PHI for covered entities through business associate agreements, regardless of their primary industry. Option D is wrong because a hybrid entity is a single legal entity with both covered and noncovered components under common ownership, not a vendor providing storage services.

Sample question 3 (Government and court access)

A federal law enforcement agent investigating a fraud case needs the contents of emails that a suspect has already sent and that are now stored on a cloud email service provider's servers. Under the Electronic Communications Privacy Act framework, which legal mechanism is generally required for the provider to disclose those stored email contents to the government?

  1. A wiretap order issued under Title III, because email content in transit and at rest are treated identically
  2. A search warrant supported by probable cause, because stored electronic communications content is protected by the Stored Communications Act
  3. A grand jury subpoena alone, because email stored with a third-party provider falls under the third-party doctrine and has no reasonable expectation of privacy
  4. A national security letter, because all disclosures of electronic communications to the federal government require NSL authority

Answer: B. A search warrant supported by probable cause, because stored electronic communications content is protected by the Stored Communications Act

Option B is correct because the Stored Communications Act, part of ECPA, protects the contents of stored electronic communications held by a provider and generally requires a warrant supported by probable cause for the government to obtain that content. Option A is wrong because a Title III wiretap order addresses real-time interception, not access to communications already in electronic storage. Option C is wrong because the third-party doctrine does not eliminate Fourth Amendment or statutory protection for stored email content, and a subpoena alone is not sufficient for content. Option D is wrong because national security letters are tied to national security investigations and do not authorize disclosure of stored email content in an ordinary fraud case.

Sample question 4 (Workplace privacy)

A regional logistics company plans to install GPS tracking devices on its delivery trucks to monitor driver routes, speeds, and break times. To comply with workplace privacy best practices and state laws regarding employee monitoring, what is the most appropriate action the company should take before implementing this system?

  1. Rely on implied consent because the drivers know the trucks are company property.
  2. Implement a clear written policy, notify employees in advance, and explain the scope of the monitoring.
  3. Only notify drivers if they are involved in an accident or traffic violation.
  4. Keep the tracking system hidden to ensure drivers behave as they naturally would.

Answer: B. Implement a clear written policy, notify employees in advance, and explain the scope of the monitoring.

Option B is correct because clear notice and a written policy are fundamental requirements for employee monitoring, especially location tracking, ensuring transparency and complying with various state laws. Option A is incorrect because implied consent is generally insufficient for location tracking. Option C is incorrect because notice must be given before implementation, not just after a violation occurs. Option D is incorrect because hidden tracking violates transparency principles and may violate state privacy laws.

Sample question 5 (State privacy laws)

A digital advertising platform tracks users across unrelated websites and builds behavioral profiles to serve targeted ads. The platform does not sell data for monetary consideration but does disclose data to third-party ad networks for cross-context behavioral advertising. Under comprehensive state consumer privacy laws modeled on the Virginia Consumer Data Protection Act, what consumer right is most directly implicated by this practice?

  1. The right to access the specific pieces of personal data collected
  2. The right to opt out of targeted advertising
  3. The right to delete personal data held by the controller
  4. The right to correct inaccurate personal information

Answer: B. The right to opt out of targeted advertising

Comprehensive state privacy laws such as the VCDPA give consumers the right to opt out of the processing of their personal data for purposes of targeted advertising, defined as displaying ads based on personal data obtained from the consumer's activities across nonaffiliated websites. Option A describes the access right, which is not the right most directly triggered by cross-context behavioral advertising. Option C is the deletion right, which a consumer could exercise generally but is not the right specifically tied to advertising profiling. Option D is the correction right, which relates to data accuracy rather than advertising practices.

About these papers

Unofficial practice material. Every question is original, written from the vendor's publicly published exam objectives, and no real exam item is reproduced or paraphrased. This paper is not affiliated with, endorsed by, sponsored by or certified by the certification owner, and passing it does not confer any certification.

More certification practice exams