無料Certified Information Privacy Professional CIPP-US究極の学習ガイド(更新された170問あります) [Q60-Q81]

Share

無料Certified Information Privacy Professional CIPP-US究極の学習ガイド(更新された170問あります)

トップクラスのCIPP-US練習試験問題


CIPP-US認定は、国際プライバシー専門家協会(IAPP)によって授与されます。これは、100か国以上で50,000人以上のメンバーを持つプライバシー専門家の世界最大の協会です。 IAPPは、個人データの保護を担当する専門家に教育および認証プログラムを提供することに取り組んでいます。

 

質問 # 60
What was unique about the action that the Federal Trade Commission took against B.J.'s Wholesale Club in
2005?

  • A. It made third-party audits a penalty for policy violations.
  • B. It was based on matters of fairness rather than deception.
  • C. It was the first substantial U.S.-EU Safe Harbor enforcement.
  • D. It made user consent mandatory after any revisions of policy.

正解:B

解説:
The Federal Trade Commission (FTC) is the primary federal agency that enforces consumer privacy and data security laws in the United States. The FTC has the authority to bring enforcement actions against businesses that engage in unfair or deceptive acts or practices that affect commerce, under Section 5 of the FTC Act.
Unfair acts or practices are those that cause or are likely to cause substantial injury to consumers that is not reasonably avoidable by consumers and is not outweighed by countervailing benefits to consumers or competition. Deceptive acts or practices are those that involve a material representation, omission, or practice that is likely to mislead consumers acting reasonably under the circumstances.
The FTC's action against B.J.'s Wholesale Club in 2005 was unique because it was based on matters of fairness rather than deception. The FTC alleged that B.J.'s Wholesale Club, a retailer that operates warehouse stores and gas stations, failed to provide reasonable security for the sensitive information of its customers, such as name, card number, and expiration date, that it collected from the magnetic stripes of credit and debit cards. The FTC claimed that this information was used by unauthorized persons to make millions of dollars of fraudulent purchases. The FTC did not allege that B.J.'s Wholesale Club made any false or misleading statements or omissions about its data security practices, but rather that its failure to take appropriate security measures was an unfair practice that violated Section 5 of the FTC Act. The FTC argued that B.J.'s Wholesale Club's lax security caused or was likely to cause substantial injury to consumers that was not reasonably avoidable by consumers and was not outweighed by any benefits to consumers or competition.
The FTC's action against B.J.'s Wholesale Club was one of the first cases in which the FTC used its unfairness authority to address data security issues,and it set a precedent for future enforcement actions against businesses that fail to protect consumer data. The settlement required B.J.'s Wholesale Club to implement a comprehensive information security program and obtain audits by an independent third-party security professional every other year for 20 years. References:
* FTC Complaint, Paragraphs 1-23
* FTC Agreement Containing Consent Order, Paragraphs 1-9
* FTC Analysis of Proposed Consent Order to Aid Public Comment, Pages 1-3
* [IAPP CIPP/US Study Guide], Pages 69-70


質問 # 61
What information did the Red Flag Program Clarification Act of 2010 add to the original Red Flags rule?

  • A. The most common methods of identity theft.
  • B. The components of an identity theft detection program.
  • C. The definition of what constitutes a creditor.
  • D. The process for proper disposal of sensitive data.

正解:C


質問 # 62
What is the most important action an organization can take to comply with the FTC position on retroactive changes to a privacy policy?

  • A. Obtaining affirmative consent from its customers.
  • B. Describing the policy changes on its website.
  • C. Publicizing the policy changes through social media.
  • D. Reassuring customers of the security of their information.

正解:A

解説:
The FTC has stated that it is a deceptive practice to make retroactive changes to a privacy policy that affect how a company uses or shares previously collected personal information, unless the company obtains affirmative consent from the affected consumers. This means that the company must clearly and conspicuously disclose the changes and obtain the consumers' express agreement to them. Simply describing the policy changes on the website, publicizing them through social media, or reassuring customers of the security of their information are not sufficient to comply with the FTC's position. References:
* FTC Staff Revises Online Behavioral Advertising Principles, paragraph 3.
* Do I really have to obtain consent from all my customers to make a change to my privacy policy?, paragraph 2.
* IAPP CIPP/US Study Guide, page 64.


質問 # 63
Most states with data breach notification laws indicate that notice to affected individuals must be sent in the
"most expeditious time possible without unreasonable delay." By contrast, which of the following states currently imposes a definite limit for notification to affected individuals?

  • A. New York
  • B. California
  • C. Maine
  • D. Florida

正解:D

解説:
Explanation/Reference: https://www.itgovernanceusa.com/data-breach-notification-laws


質問 # 64
The Video Privacy Protection Act of 1988 restricted which of the following?

  • A. Which purchase records of audio visual materials may be disclosed
  • B. When a user's viewing of online video content can be monitored
  • C. Who advertisements for videos and video games may target
  • D. When downloading of copyrighted audio visual materials is allowed

正解:A


質問 # 65
What type of material is exempt from an individual's right to disclosure under the Privacy Act?

  • A. Material reporting investigative efforts pertaining to the enforcement of criminal law.
  • B. Material used to determine potential collaboration with foreign governments in negotiation of trade deals.
  • C. Material requires by statute to be maintained and used solely for research purposes.
  • D. Material reporting investigative efforts to prevent unlawful persecution of an individual.

正解:D

解説:
https://www.dea.gov/foia/privacy-act-exemptions


質問 # 66
SCENARIO
Please use the following to answer the next QUESTION:
Larry has become increasingly dissatisfied with his telemarketing position at SunriseLynx, and particularly with his supervisor, Evan. Just last week, he overheard Evan mocking the state's Do Not Call list, as well as the people on it. "If they were really serious about not being bothered," Evan said, "They'd be on the national DNC list. That's the only one we're required to follow. At SunriseLynx, we call until they ask us not to." Bizarrely, Evan requires telemarketers to keep records of recipients who ask them to call "another time." This, to Larry, is a clear indication that they don't want to be called at all. Evan doesn't see it that way.
Larry believes that Evan's arrogance also affects the way he treats employees. The U.S. Constitution protects American workers, and Larry believes that the rights of those at SunriseLynx are violated regularly. At first Evan seemed friendly, even connecting with employees on social media. However, following Evan's political posts, it became clear to Larry that employees with similar affiliations were the only ones offered promotions.
Further, Larry occasionally has packages containing personal-use items mailed to work. Several times, these have come to him already opened, even though this name was clearly marked. Larry thinks the opening of personal mail is common at SunriseLynx, and that Fourth Amendment rights are being trampled under Evan's leadership.
Larry has also been dismayed to overhear discussions about his coworker, Sadie. Telemarketing calls are regularly recorded for quality assurance, and although Sadie is always professional during business, her personal conversations sometimes contain sexual comments. This too is something Larry has heard Evan laughing about. When he mentioned this to a coworker, his concern was met with a shrug. It was the coworker's belief that employees agreed to be monitored when they signed on. Although personal devices are left alone, phone calls, emails and browsing histories are all subject to surveillance. In fact, Larry knows of one case in which an employee was fired after an undercover investigation by an outside firm turned up evidence of misconduct. Although the employee may have stolen from the company, Evan could have simply contacted the authorities when he first suspected something amiss.
Larry wants to take action, but is uncertain how to proceed.
Based on the way he uses social media, Evan is susceptible to a lawsuit based on?

  • A. Defamation
  • B. Discrimination
  • C. Intrusion upon seclusion
  • D. Publicity given to private life

正解:B

解説:
Discrimination is the unfair or prejudicial treatment of people based on certain characteristics, such as race, gender, age, religion, or political affiliation. Discrimination can occur in various contexts, such as employment, education, housing, or public accommodations. Discrimination can violate federal, state, or local laws that prohibit discrimination on the basis of protected categories. In the scenario, Evan is susceptible to a lawsuit based on discrimination because he uses social media to favor employees who share his political views and deny promotions to those who do not. This could constitute political discrimination, which is prohibited by some state and local laws, such as the District of Columbia Human Rights Act and the New York City Human Rights Law. Additionally, Evan's use of social media could reveal other protected characteristics of his employees, such as their race, gender, age, religion, or sexual orientation, and expose him to claims of discrimination based on those grounds as well. For example, if Evan posts derogatory comments about a certain race or religion, and then denies a promotion to an employee of that race or religion, that employee could sue Evan for discrimination under federal laws, such as Title VII of the Civil Rights Act of 1964 or the Civil Rights Act of 1991. References:
* Political Discrimination in the Workplace | Nolo
* Social Media and Employment Law Summary of Key Cases and Legal Issues
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 4: State Privacy Laws and Regulations, Section 4.1: State Anti-Discrimination Laws.


質問 # 67
John, a California resident, receives notification that a major corporation with $500 million in annual revenue has experienced a data breach. John's personal information in their possession has been stolen, including his full name and social security numb. John also learns that the corporation did not have reasonable cybersecurity measures in place to safeguard his personal information.
Which of the following answers most accurately reflects John's ability to pursue a legal claim against the corporation under the California Consumer Privacy Act (CCPA)?

  • A. John cannot sue the corporation for the data breach because only the state's Attoney General has authority to file suit under the CCPA.
  • B. John can sue the corporation for the data breach but only to recover monetary damages he actually suffered as a result of the data breach.
  • C. John has no right to sue the corporation because the CCPA does not address any data breach rights.
  • D. John can sue the corporation for the data breach to recover monetary damages suffered as a result of the data breach, and in some circumstances seek statutory damages irrespective of whether he suffered any financial harm.

正解:D

解説:
The CCPA provides consumers with a private right of action to pursue statutory damages following data security breaches that impact certain sensitive categories of personal information and are caused by a business's failure to institute reasonable and appropriate security. The CCPA defines personal information for this purpose as an individual's name in combination with any of the following: social security number, driver's license number, account number, credit or debit card number, medical information, or health insurance information. The CCPA allows consumers to seek damages between $100 and $750 per consumer per incident, or actual damages, whichever is greater. The CCPA also requires consumers to provide the business with 30 days' written notice and an opportunity to cure the violation before initiating an action. Additionally, the CCPA requires consumers to notify the Attorney General within 30 days of filing the action and obtain the Attorney General's approval or nonobjection before proceeding with the action. Therefore, John can sue the corporation for the data breach to recover monetary damages suffered as a result of the data breach, and in some circumstances seek statutory damages irrespective of whether he suffered any financial harm, as long as he meets the requirements of the CCPA. References:
* CCPA Provides Private Right of Action for Data Security Breaches
* CCPA Private Right of Action - Data Breach Security Requirement
* CCPA Fines & Penalties for Data Protection Violations | MatrixPoint


質問 # 68
A company's employee wellness portal offers an app to track exercise activity via users' mobile devices. Which of the following design techniques would most effectively inform users of their data privacy rights and privileges when using the app?

  • A. Provide a link to the wellness program privacy policy at the bottom of each screen.
  • B. Publish a privacy policy written in clear, concise, and understandable language.
  • C. Present a privacy policy to users during the wellness program registration process.
  • D. Offer information about data collection and uses at key data entry points.

正解:C


質問 # 69
Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?

  • A. Allowing consumers to opt in before collecting any data.
  • B. Mitigating harm to consumers after a security breach.
  • C. Announcing the tracking of online behavior for advertising purposes.
  • D. Integrating privacy protections during product development.

正解:D

解説:
According to the FTC report, the most important directive for businesses is to adopt a "privacy by design" approach, which means integrating privacy protections throughout the entire product lifecycle, from initial design to disposal. This includes implementing reasonable security measures, collecting only the data needed for a specific purpose, retaining data only as long as necessary, and safely disposing of data that is no longer needed. The FTC report also recommends that businesses provide clear and transparent privacy notices, offer consumers meaningful choices about how their data is used, and increase their accountability for data practices. References: FTC Report, IAPP CIPP/US Study Guide (p. 32-33)


質問 # 70
SCENARIO
Please use the following to answer the next QUESTION
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated dat a. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
What could the company have done differently prior to the breach to reduce their risk?

  • A. Implemented a comprehensive policy for accessing customer information.
  • B. Honored the promise of its privacy policy to acquire information by using an opt-in method.
  • C. Communicated requests for changes to users' preferences across the organization and with third parties.
  • D. Looked for any persistent threats to security that could compromise the company's network.

正解:D


質問 # 71
SCENARIO
Please use the following to answer the next QUESTION :
Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your network?" Matt asked hopefully.
"No," the boy said. "I'm filling out a survey."
Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking QUESTIONS about my opinions."
"Let me see," Matt said, and began reading the list of QUESTIONS that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read further he learned that kids who took the survey were automatically registered in a contest to win the first book in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer QUESTIONS about his favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities.
How could the marketer have best changed its privacy management program to meet COPPA "Safe Harbor" requirements?

  • A. By receiving FTC approval for the content of its emails
  • B. By making a COPPA privacy notice available on website
  • C. By participating in an approved self-regulatory program
  • D. By regularly assessing the security risks to consumer privacy

正解:C

解説:
COPPA safe harbor programs comprise industry groups that self-regulate their member-operators and establish their own guidelines and requirements that must guarantee the same or greater protection for children as the standards set forth in the COPPA rule.


質問 # 72
SCENARIO
Please use the following to answer the next QUESTION
Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in Californi a. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask Question:s about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements.
Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision.
Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. Celeste believes that even if the business grows a customer database of a few thousand, it's unlikely that a state agency would hassle an honest business if an accidental security incident were to occur.
In any case, Celeste feels that all they need is common sense - like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina.
Based on Felicia's Bring Your Own Device (BYOD) plan, the business consultant will most likely advise Felicia and Celeste to do what?

  • A. Weigh any productivity benefits of the plan against the risk of privacy issues.
  • B. Adopt the same kind of monitoring policies used for work-issued devices.
  • C. Make employment decisions based on those willing to consent to the plan in writing.
  • D. Reconsider the plan in favor of a policy of dedicated work devices.

正解:C


質問 # 73
Which of the following federal agencies does NOT enforce the Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA)?

  • A. The Federal Trade Commission
  • B. The Department of Health and Human Services
  • C. The Office of the Comptroller of the Currency
  • D. The Consumer Financial Protection Bureau

正解:B


質問 # 74
All of the following are tasks in the "Discover" phase of building an information management program EXCEPT?

  • A. Facilitating participation across departments and levels
  • B. Developing a process for review and update of privacy policies
  • C. Understanding the laws that regulate a company's collection of information
  • D. Deciding how aggressive to be in the use of personal information

正解:B

解説:
The "Discover" phase of building an information management program is the first step in the process of creating a privacy framework. It involves identifying the types, sources, and flows of personal information within an organization, as well as the legal, regulatory, and contractual obligations that apply to it. The tasks in this phase include:
* Conducting a data inventory and mapping exercise to document what personal information is collected, used, shared, and stored by the organization, and how it is protected.
* Assessing the current state of privacy compliance and risk by reviewing existing policies, procedures, and practices, and identifying any gaps or weaknesses.
* Understanding the laws that regulate a company's collection of information, such as the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), the Health Insurance Portability and Accountability Act (HIPAA), and the California Consumer Privacy Act (CCPA).
* Facilitating participation across departments and levels to ensure that all stakeholders are involved and informed of the privacy goals and objectives, and to foster a culture of privacy awareness and accountability.
Developing a process for review and update of privacy policies is not a task in the "Discover" phase, but rather in the "Implement" phase, which is the third step in the process of creating a privacy framework. It involves putting the privacy policies and procedures into action, and ensuring that they are effective and compliant. The tasks in this phase include:
* Developing a process for review and update of privacy policies to reflect changes in the business environment, legal requirements, and best practices, and to incorporate feedback from internal and external audits and assessments.
* Implementing privacy training and awareness programs to educate employees and other relevant parties on their roles and responsibilities regarding privacy, and to promote a privacy-by-design approach.
* Establishing privacy governance and oversight mechanisms to monitor and measure the performance and outcomes of the privacy program, and to ensure accountability and transparency.
* Developing a process for responding to privacy incidents and requests from data subjects, regulators, and other parties, and to mitigate and remediate any privacy risks or harms.
References:
* IAPP CIPP/US Body of Knowledge, Domain I: Information Management from a U.S. Perspective, Section A: Building a Privacy Program
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 1: Information Management from a U.S. Perspective, Section 1.1: Building a Privacy Program
* Practice Exam - International Association of Privacy Professionals


質問 # 75
Which of the following practices is NOT a key component of a data ethics framework?

  • A. Auditing.
  • B. Data governance.
  • C. Preferability testing.
  • D. Automated decision-making.

正解:D

解説:
A data ethics framework is a set of principles and guidelines that help organizations ensure that their data practices are ethical, responsible, and trustworthy. According to the IAPP CIPP/US Study Guide, some of the key components of a data ethics framework are1:
* Data governance: the policies, processes, and standards that govern how data is collected, used, stored, and shared within an organization.
* Preferability testing: the process of assessing the potential impacts and risks of data-driven solutions on stakeholders, such as customers, employees, and society.
* Auditing: the process of monitoring, reviewing, and verifying the compliance and performance of data practices against the established ethical standards and legal requirements. Automated decision-making, on the other hand, is not a key component of a data ethics framework, but rather a data practice that may raise ethical issues and challenges. Automated decision-making refers to the use of algorithms, artificial intelligence, or machine learning to make decisions or recommendations without human intervention2. While automated decision-making can offer benefits such as efficiency, accuracy, and consistency, it can also pose risks such as bias, discrimination, lack of transparency, and accountability3.
Therefore, automated decision-making should be subject to ethical evaluation and oversight, but it is not itself a part of a data ethics framework. References:
* [IAPP CIPP/US Study Guide], Chapter 10, Section 10.4, page 287
* [IAPP Glossary], Automated Decision-Making
* IAPP Resources, Ethical Data Use and Automated Decision-Making: A Practical Guide


質問 # 76
Which of the following federal agencies does NOT enforce the Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA)?

  • A. The Federal Trade Commission
  • B. The Department of Health and Human Services
  • C. The Office of the Comptroller of the Currency
  • D. The Consumer Financial Protection Bureau

正解:B

解説:
* The Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA) is a federal regulation that requires any person or entity that maintains or possesses consumer information derived from consumer reports to dispose of such information in a secure and proper manner1.
* The Disposal Rule aims to protect consumers from identity theft and fraud by preventing unauthorized access to or use of their personal information1.
* The Disposal Rule is enforced by several federal agencies, depending on the type and sector of the entity that is subject to the rule1. These agencies include:
* The Federal Trade Commission (FTC), which has general authority over most entities that are not specifically regulated by other agencies2.
* The Consumer Financial Protection Bureau (CFPB), which has authority over consumer financial products and services, such as banks, credit unions, lenders, debt collectors, and credit reporting agencies3.
* The Office of the Comptroller of the Currency (OCC), which has authority over national banks and federal savings associations4.
* The Federal Deposit Insurance Corporation (FDIC), which has authority over state-chartered banks that are not members of the Federal Reserve System and state-chartered savings associations5.
* The Board of Governors of the Federal Reserve System (FRB), which has authority over state-chartered banks that are members of the Federal Reserve System, bank holding companies, and certain nonbank subsidiaries of bank holding companies.
* The National Credit Union Administration (NCUA), which has authority over federally insured credit unions.
* The Securities and Exchange Commission (SEC), which has authority over brokers, dealers, investment companies, and investment advisers.
* The Commodity Futures Trading Commission (CFTC), which has authority over commodity futures and options markets and intermediaries.
* The Department of Health and Human Services (HHS) is NOT one of the federal agencies that enforces the Disposal Rule under FACTA. HHS has authority over health information privacy and security under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH), but not under FACTA.
References: 1: Disposing of Consumer Report Information? Rule Tells How 2: FTC Enforcement 3: CFPB Enforcement 4: OCC Enforcement 5: FDIC Enforcement : [FRB Enforcement] : [NCUA Enforcement] : [SEC Enforcement] : [CFTC Enforcement] : [HHS Enforcement]


質問 # 77
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
At this stage of the investigation, what should the data privacy leader review first?

  • A. Prevailing regulation on this subject
  • B. The text of the original complaint
  • C. Available data flow diagrams
  • D. The company's data privacy policies

正解:C

解説:
Data flow diagrams are graphical representations of how data moves within an organization or between different entities. They can help identify the sources, destinations, and processing of personal data, as well as the legal basis, retention periods, and security measures for each data flow. Reviewing the available data flow diagrams can help the data privacy leader to quickly and accurately respond to the urgent request from the EU-based retail partner, as well as to assess the potential risks and compliance gaps in the data transfer process. Data flow diagrams are also a key component of data protection impact assessments (DPIAs), which are required by the GDPR for high-risk processing activities. References:
* IAPP CIPP/US Body of Knowledge, Section II, A, 2
* [IAPP CIPP/US Study Guide, Chapter 2, Section 2.3]
* [GDPR, Article 35]


質問 # 78
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Under the GDPR, the complainant's request regarding her personal information is known as what?

  • A. Right of Rectification
  • B. Right of Access
  • C. Right of Removal
  • D. Right to Be Forgotten

正解:D

解説:
Under the GDPR, the complainant's request regarding her personal information is known as the right to be forgotten, also known as the right to erasure. This right allows individuals to ask organizations to delete their personal data in certain circumstances, such as when the data is no longer necessary, the consent is withdrawn, or the processing is unlawful. The right to be forgotten is not absolute and may not apply if the processing is necessary for legal, public interest, or legitimate purposes. The right to be forgotten also requires organizations to inform any recipients of the data about the erasure request, unless it is impossible or involves disproportionate effort. References:
* Everything you need to know about the "Right to be forgotten"
* Right to erasure | ICO
* Art. 17 GDPR - Right to erasure ('right to be forgotten') - General ...
* [IAPP CIPP/US Certified Information Privacy Professional Study Guide], Chapter 6, page 213.


質問 # 79
According to FERPA, when can a school disclose records without a student's consent?

  • A. If the disclosure would not reveal a student's student identification number
  • B. If the disclosure is to practitioners who are involved in a student's health care
  • C. If the disclosure is to provide transcripts to a school where a student intends to enroll
  • D. If the disclosure is not to be conducted through email to the third party

正解:C

解説:
Explanation/Reference: https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html


質問 # 80
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?

  • A. It required employers to get an employee's consent in advance of requesting a consumer report for internal investigation purposes Section: (none) Explanation
  • B. It expanded the definition of "consumer reports" to include communications relating to employee investigations
  • C. It stipulated the purpose of obtaining a consumer report can only be for a review of the employee's credit worthiness
  • D. It increased the obligation of organizations to dispose of consumer data in ways that prevent unauthorized access

正解:D


質問 # 81
......


IAPP CIPP-US(認定情報プライバシープロフェッショナル/米国)認定試験は、米国のプライバシー専門家の知識と専門知識を検証するグローバルに認められた認定プログラムです。認定プログラムは、プライバシーの専門家が、米国で適用されるプライバシー法と規制の複雑で絶えず変化する世界を理解し、ナビゲートするのを支援するように設計されています。 CIPP-US認定試験は、米国のプライバシー法と規制に関連するさまざまなトピックに関するプライバシーの専門家の知識と専門知識をテストする包括的で挑戦的な試験です。

 

合格させるIAPP CIPP-US試験問題でテスト復刻エンジンとPDF:https://www.passtest.jp/IAPP/CIPP-US-shiken.html

実際問題を使ってCIPP-US問題集無料サンプル問題と練習テストエンジン:https://drive.google.com/open?id=11koQDMEHtH5qjORfc0h2N6KHsL0aLjiQ