
Free CIPP-US pdf Files With Updated and Accurate Dumps Training
Top-Class CIPP-US Question Answers Study Guide
IAPP CIPP-US (Certified Information Privacy Professional/United States) certification exam is a comprehensive test designed to evaluate an individual’s knowledge of privacy laws, regulations, and best practices in the United States. The CIPP-US certification is a globally recognized credential that demonstrates an individual’s expertise in the field of privacy and data protection. Certified Information Privacy Professional/United States (CIPP/US) certification exam is ideal for professionals who wish to enhance their knowledge and skills in the field of privacy and data protection.
NEW QUESTION # 77
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Under the GDPR, the complainant's request regarding her personal information is known as what?
- A. Right of Access
- B. Right to Be Forgotten
- C. Right of Rectification
- D. Right of Removal
Answer: B
Explanation:
Under the GDPR, the complainant's request regarding her personal information is known as the right to be forgotten, also known as the right to erasure. This right allows individuals to ask organizations to delete their personal data in certain circumstances, such as when the data is no longer necessary, the consent is withdrawn, or the processing is unlawful. The right to be forgotten is not absolute and may not apply if the processing is necessary for legal, public interest, or legitimate purposes. The right to be forgotten also requires organizations to inform any recipients of the data about the erasure request, unless it is impossible or involves disproportionate effort. References:
* Everything you need to know about the "Right to be forgotten"
* Right to erasure | ICO
* Art. 17 GDPR - Right to erasure ('right to be forgotten') - General ...
* [IAPP CIPP/US Certified Information Privacy Professional Study Guide], Chapter 6, page 213.
NEW QUESTION # 78
Which of the following describes the most likely risk for a company developing a privacy policy with standards that are much higher than its competitors?
- A. Getting accused of discriminatory practices
- B. Attracting skepticism from auditors
- C. Being more closely scrutinized for any breaches of policy
- D. Having a security system failure
Answer: C
Explanation:
A company that develops a privacy policy with standards that are much higher than its competitors may face the risk of being more closely scrutinized for any breaches of policy by regulators, customers, media, or other stakeholders. This is because the company sets a higher expectation for its privacy practices and may be held to a higher standard of accountability and transparency. If the company fails to comply with its own policy or experiences a data breach, it may face more severe consequences, such as reputational damage, loss of trust, legal liability, or regulatory sanctions. References:
* IAPP CIPP/US Body of Knowledge, Section I, B, 2
* [IAPP CIPP/US Study Guide, Chapter 1, Section 1.4]
NEW QUESTION # 79
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?
- A. It required employers to get an employee's consent in advance of requesting a consumer report for internal investigation purposes
- B. It expanded the definition of "consumer reports" to include communications relating to employee investigations
- C. It stipulated the purpose of obtaining a consumer report can only be for a review of the employee's credit worthiness
- D. It increased the obligation of organizations to dispose of consumer data in ways that prevent unauthorized access
Answer: D
Explanation:
Section: (none)
Explanation
NEW QUESTION # 80
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to do what?
- A. Determine which bodies will be involved in adjudication
- B. Decide if any enforcement actions are justified
- C. Appeal decisions made against it
- D. Adhere to its industry's code of conduct
Answer: D
Explanation:
See IAPP book, Section 3.10, paragraph 2.
NEW QUESTION # 81
In 2014, Google was alleged to have violated the Family Educational Rights and Privacy Act (FERPA) through its Apps for Education suite of tools. For what specific practice did students sue the company?
- A. Relying on verbal consent for a disclosure of education records
- B. Scanning emails sent to and received by students
- C. Making student education records publicly available
- D. Disclosing education records without obtaining required consent
Answer: B
Explanation:
The lawsuit, filed in 2014, claimed that Google violated the federal and state wiretap and privacy laws by scanning and indexing the emails of millions of students who used its Apps for Education suite, which included Gmail as a key feature12. The plaintiffs alleged that Google used the information from the scans to build profiles of students that could be used for targeted advertising or other commercial purposes, without their consent or knowledge12. The lawsuit also challenged Google's argument that the students consented to the scans when they first logged in to their accounts, saying that such consent was not valid under FERPA, which requires written consent for any disclosure of education records12. Google denied the allegations and argued that the scans were necessary for providing security, spam protection, and other functionality to the users12. The case was settled in 2016, with Google agreeing to change some of its practices and policies regarding the scanning of student emails3. References: 1: Lawsuit Alleges That Google Has Crossed A
'Creepy Line' With Student Data, Huffington Post, 1. 2: Google faces lawsuit over email scanning and student data, The Guardian, 2. 3: Google data case to be heard in Supreme Court, BBC, 3.
NEW QUESTION # 82
When designing contact tracing apps in relation to COVID-19 or any other diagnosed virus, all of the following privacy measures should be considered EXCEPT?
- A. Opt-out choice.
- B. Data retention.
- C. User confidentiality.
- D. Use limitations.
Answer: A
Explanation:
Contact tracing apps are designed to help public health authorities track and contain the spread of COVID-19 or any other diagnosed virus by notifying users who have been in close contact with an infected person.
However, these apps also raise privacy concerns, as they collect and process sensitive personal data, such as health status and location information. Therefore, contact tracing apps should follow the principles of privacy by design and default, which means that they should incorporate privacy measures into their development and operation, and offer the highest level of privacy protection to users.
Some of the privacy measures that should be considered when designing contact tracing apps are:
* Data retention: Contact tracing apps should only retain the personal data they collect for as long as necessary to achieve their public health purpose, and delete or anonymize the data afterwards. Data retention periods should be clearly communicated to users and based on scientific evidence and legal requirements.
* Use limitations: Contact tracing apps should only use the personal data they collect for the specific and legitimate purpose of contact tracing, and not for any other purposes, such as commercial, law enforcement, or surveillance. Use limitations should be enforced by technical and organizational measures, such as encryption, access controls, and audits.
* User confidentiality: Contact tracing apps should protect the confidentiality of users' personal data and identity, and not disclose them to third parties without their consent or legal authorization. User confidentiality should be ensured by technical and organizational measures, such as pseudonymization, aggregation, and data minimization.
Opt-out choice, on the other hand, is not a privacy measure that should be considered when designing contact tracing apps, as it would undermine their effectiveness and public health objective. Contact tracing apps rely on voluntary participation and widespread adoption by users to function properly and achieve their purpose.
Therefore, offering users the option to opt out of the app or certain features, such as data sharing or notifications, would reduce the app's coverage and accuracy, and potentially expose users and others to greater health risks. Instead of opt-out choice, contact tracing apps should provide users with clear and transparent information about how the app works, what data it collects and how it uses it, what benefits and risks it entails, and what rights and controls users have over their data. This way, users can make an informed and voluntary decision to use the app or not, based on their own preferences and values.
References:
* [IAPP CIPP/US Study Guide], Chapter 2: Privacy by Design and Default, pp. 35-36.
* [IAPP CIPP/US Body of Knowledge], Section II: Limits on Private-sector Collection and Use of Data,
* Subsection B: Privacy by Design, pp. 9-10.
* [IAPP Glossary], Terms: Contact Tracing, Privacy by Design, Privacy by Default.
NEW QUESTION # 83
Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operating in 7 other states. SMH uses an electronic medical record to enter and track information about its patients. Recently, SMH suffered a data breach where a third-party hacker was able to gain access to the SMH internal network.
Because it is a HIPPA-covered entity, SMH made a notification to the Office of Civil Rights at the U.S. Department of Health and Human Services about the breach.
Which statement accurately describes SMH's notification responsibilities?
- A. If SMH must make a notification in any other state in which it operates, it must also make a notification to individuals in New York.
- B. If SMH makes credit monitoring available to individuals who inquire, it will not have to make a separate notification to individuals in the state of New York.
- C. If SMH is compliant with HIPAA, it will not have to make a separate notification to individuals in the state of New York.
- D. If SMH has more than 500 patients in the state of New York, it will need to make separate notifications to these patients.
Answer: A
NEW QUESTION # 84
When may a financial institution share consumer information with non-affiliated third parties for marketing purposes?
- A. After disclosing information-sharing practices to customers and after giving them an opportunity to opt out.
- B. After disclosing information-sharing practices to customers and after giving them an opportunity to opt in.
- C. After disclosing marketing practices to customers and after giving them an opportunity to opt out.
- D. After disclosing marketing practices to customers and after giving them an opportunity to opt in.
Answer: A
NEW QUESTION # 85
Global Manufacturing Co's Human Resources department recently purchased a new software tool. This tool helps evaluate future candidates for executive roles by scanning emails to see what those candidates say and what is said about them. This provides the HR department with an automated "360 review" that lets them know how the candidate thinks and operates, what their peers and direct reports say about them, and how well they interact with each other.
What is the most important step for the Human Resources Department to take when implementing this new software?
- A. Confirming that employees have read and signed the employee handbook where they have been advised that they have no right to privacy as long as they are using the organization's systems, regardless of the protected group or laws enforced by EEOC.
- B. Providing notice to employees that their emails will be scanned by the software and creating automated profiles.
- C. Ensuring that the software contains a privacy notice explaining that employees have no right to privacy as long as they are running this software on organization systems to scan email systems.
- D. Making sure that the software does not unintentionally discriminate against protected groups.
Answer: D
NEW QUESTION # 86
Under the Fair Credit Reporting Act (FCRA), what must a person who is denied employment based upon his credit history receive?
- A. An opportunity to reapply with the employer.
- B. A list of rights from the Consumer Financial Protection Bureau (CFPB).
- C. Information from several consumer reporting agencies (CRAs).
- D. A prompt notification from the employer.
Answer: D
Explanation:
The FCRA requires that an employer who takes an adverse action against an applicant or employee based on information in a consumer report must provide a notice of the adverse action to the individual. The notice must include the name, address, and phone number of the CRA that supplied the report; astatement that the CRA did not make the decision and cannot explain why the adverse action was taken; a notice of the individual's right to dispute the accuracy or completeness of the information in the report; and a notice of the individual's right to obtain a free copy of the report from the CRA within 60 days12. References:
* CIPP/US Practice Questions (Sample Questions), Question 141, Answer A, Explanation A.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 4, Section 4.2, p.
101-102.
* Fair Credit Reporting Act (FCRA), Section 615, Subsection (a).
NEW QUESTION # 87
Which of the following state laws has an entity exemption for organizations subject to the Gramm-Leach-Bliley Act (GLBA)?
- A. California Consumer Privacy Act.
- B. California Privacy Rights Act.
- C. Virginia Consumer Data Protection Act
- D. Nevada Privacy Law.
Answer: B
Explanation:
The Virginia Consumer Data Protection Act (VCDPA) is a state law that provides comprehensive privacy rights and obligations for consumers and businesses in Virginia. The VCDPA applies to any entity that conducts business in Virginia or produces products or services that are targeted to residents of Virginia and that either: (a) controls or processes personal data of at least 100,000 consumers; or (b) controls or processes personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data. However, the VCDPA also provides several exemptions for certain types of entities and data, including an entity exemption for financial institutions or data subject to the Gramm-Leach-Bliley Act (GLBA). This means that organizations that are regulated by the GLBA are not subject to the VCDPA, regardless of the type or source of data they collect or process. The GLBA is a federal law that regulates the collection, use, and disclosure of personal financial information by financial institutions and their affiliates. The GLBA applies to any business that is significantly engaged in financial activities, such as banks, credit unions, securities firms, insurance companies, and certain fintech companies. The GLBA requires financial institutions to provide notice and choice to consumers about their privacy practices, to safeguard the security and confidentiality of consumer information, and to limit the sharing of consumer information with third parties. The GLBA also preempts state laws only to the extent that they are inconsistent with the GLBA, unless the state law provides greater protection to consumers.
The other state laws listed in the question do not have an entity exemption for organizations subject to the GLBA, but they may have partial or data exemptions for certain types of information that are regulated by the GLBA. For example, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) are state laws that provide comprehensive privacy rights and obligations for consumers and businesses in California. The CCPA and the CPRA apply to any business that collects or sells the personal information of California residents and that meets one or more of the following thresholds: (a) has annual gross revenues in excess of $25 million; (b) alone or in combination, annually buys, receives for the business's commercial purposes, sells, or shares for commercial purposes, the personal information of 50,000 or more consumers, households, or devices; or derives 50% or more of its annual revenues from selling consumers' personal information. However, the CCPA and the CPRA also provide several exemptions for certain types of entities and data, including a data exemption for personal information collected, processed, sold, or disclosed pursuant to the GLBA, if it is in conflict with the GLBA. This means that information that is subject to the GLBA is exempt from the privacy requirements of the CCPA and the CPRA, but not from the data breach liability provisions. The CCPA and the CPRA do not exempt financial institutions or other entities that are regulated by the GLBA from their scope, unless they only collect or process information that is subject to the GLBA.
The Nevada Privacy Law is a state law that provides privacy rights and obligations for consumers and operators of websites or online services in Nevada. The Nevada Privacy Law applies to any person who owns or operates an Internet website or online service for commercial purposes that collects and maintains covered information from consumers who reside in Nevada and use or visit the Internet website or online service.
Covered information includes any one or more of the following items of personally identifiable information about a consumer collected by an operator through an Internet website or online service and maintained by the operator in an accessible form: (a) a first and last name; (b) a home or other physical address which includes the name of a street and the name of a city or town; an electronic mail address; (d) a telephone number; (e) a social security number; (f) an identifier that allows a specific person to be contacted either physically or online; or (g) any other information concerning a person collected from the person through the Internet website or online service of the operator and maintained by the operator in combination with an identifier in a form that makes the information personally identifiable. However, the Nevada Privacy Law also provides several exemptions for certain types of entities and data, including a data exemption for any data that is subject to the GLBA. This means that information that is regulated by the GLBA is exempt from the Nevada Privacy Law, regardless of the type or source of data. The Nevada Privacy Law does not exempt financial institutions or other entities that are subject to the GLBA from its scope, unless they only collect or process information that is subject to the GLBA. References:
* VCDPA, Section 59.1-572 (A) (1)
* GLBA, 15 U.S.C. § 6801 et seq.
* CCPA, Section 1798.145 (e)
* CPRA, Section 1798.121
* Nevada Privacy Law, Section 603A.340 (1) (a)
NEW QUESTION # 88
Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusing on placing privacy professionals in roles at major companies. Job candidates create online profiles outlining their experience and credentials, and can pay $19.99/month via credit card to have their profiles promoted to potential employers. Privacy Is Hiring Inc. keeps all customer data at rest encrypted on its servers.
Under what circumstances would Privacy Is Hiring Inc., need to notify affected individuals in the event of a data breach?
- A. If Privacy Is Hiring Inc., reasonably believes that job candidates will be harmed by the data breach.
- B. If law enforcement has completed its investigation and has authorized Privacy Is Hiring Inc. to provide the notification to clients and applicable regulators.
- C. If the job candidates' credit card information and the encryption keys were among the information taken.
- D. If the personal information stolen included the individuals' names and credit card pin numbers.
Answer: C
Explanation:
California law requires a business or state agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person. (California Civil Code s. 1798.29(a) [agency] and California Civ. Code s. 1798.82(a) [person or business].) https://oag.ca.gov/privacy/databreach/reporting
NEW QUESTION # 89
What privacy concept grants a consumer the right to view and correct errors on his or her credit report?
- A. Choice.
- B. Access.
- C. Action.
- D. Notice.
Answer: D
NEW QUESTION # 90
Under the Fair and Accurate Credit Transactions Act (FACTA), what is the most appropriate action for a car dealer holding a paper folder of customer credit reports?
- A. To follow the Privacy Rule by notifying customers that the reports are being stored
- B. To follow the Safeguards Rule by transferring the reports to a secure electronic file
- C. To follow the Red Flags Rule by mailing the reports to customers
- D. To follow the Disposal Rule by having the reports shredded
Answer: D
Explanation:
"The Disposal Rule requires any individual or entity that uses a consumer report, or information derived from a consumer report, for a business purpose to dispose of that consumer information in a way that prevents unauthorized access and misuse of the data. Consumer reports can be electronic or written. The rule applies to both small and large organizations, including consumer reporting agencies, lenders, employers, insurers, landlords, car dealers, attorneys, debt collectors, and government agencies." and "Examples of acceptable, reasonable measures include developing and complying with policies to: Burn, pulverize or shred papers containing consumer report information so that the information cannot be read or reconstructed Destroy or erase electronic files or media containing consumer report information so that the information cannot be read or reconstructed Conduct due diligence and hire a document destruction contractor to dispose of material specifically identified as consumer report information consistent with the rule"
NEW QUESTION # 91
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
How can the radiology department address Declan's concern about paper waste and still comply with the Health Insurance Portability and Accountability Act (HIPAA)?
- A. Post the privacy notice in a prominent location instead
- B. Direct patients to the correct area of the hospital website
- C. Confirm that patients are given the privacy notice on their first visit
- D. State the privacy policy to the patient verbally
Answer: C
Explanation:
HIPAA requires covered entities to provide a notice of privacy practices (NPP) to individuals who receive health care services from the covered entity. The NPP must describe how the covered entity may use and disclose protected health information (PHI), the individual's rights with respect to their PHI, and the covered entity's obligations to protect the privacy of PHI. The NPP must be provided to the individual no later than the date of the first service delivery, either in person or electronically. The covered entity must also make the NPP available on request and post it on its website if it has one. The covered entity must also make a good faith effort to obtain a written acknowledgment from the individual that they received the NPP. If the individual refuses to sign the acknowledgment, the covered entity must document the attempt and the reason for the refusal.
The other options are not sufficient to comply with HIPAA. Stating the privacy policy verbally (option A) does not provide the individual with a written or electronic copy of the NPP that they can keep for future reference. Posting the privacy notice in a prominent location (option B) does not ensure that the individual receives the NPP or has an opportunity to review it before receiving services. Directing patients to the correct area of the hospital website (option C) does not provide the individual with the NPP at the time of service delivery, unless the individual agrees to receive the NPP electronically and has access to the website at that time. References:
* Notice of Privacy Practices for Protected Health Information
* Model Notices of Privacy Practices
* Sample Notice: Availability of Notice of Privacy Practices
* Notice of Privacy Practices
* Notice of Privacy Practices (NPP) Distribution and Acknowledgement
NEW QUESTION # 92
Which entities must comply with the Telemarketing Sales Rule?
- A. Nonprofit organizations calling on their own behalf
- B. For-profit organizations and for-profit telefunders regarding charitable solicitations
- C. For-profit and not-for-profit organizations when selling additional services to establish customers
- D. For-profit organizations calling businesses when a binding contract exists between them
Answer: B
Explanation:
Some types of businesses are not covered by the TSR even though they conduct telemarketing campaigns that may involve some interstate telephone calls to sell goods or services. These three types of entities are not subject to the FTC's jurisdiction, and are not covered by the TSR:
1. banks, federal credit unions, and federal savings and loans.
2. common carriers - such as long-distance telephone companies and airlines - when they are engaging in common carrier activity.
3. NON-PROFIT ORGANIZATIONS - those entities that are not organized to carry on business for their own, or their members', profit.
https://www.ftc.gov/business-guidance/resources/complying-telemarketing-sales-rule#comply
NEW QUESTION # 93
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
- A. New York.
- B. California.
- C. Washington.
- D. Vermont.
Answer: D
Explanation:
According to the web search results from my predefined tool, Vermont became the first state to pass a law specifically regulating the practices of data brokers in 2018. The law defines a data broker as "a business, or unit or units of a business, separately or together, that knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom the business does not have a direct relationship." The law requires data brokers to register with the Secretary of State, pay a registration fee, provide information about their data collection and opt-out practices, and implement security measures to protect the personal information they collect and sell. The law also imposes additional obligations on data brokers that possess the personal information of minors. The law aims to increase the transparency and accountability of the data broker industry and to protect the privacy rights of consumers12. References:
* Registered Data Brokers in the United States: 2021 | Privacy Rights ...
* Am I A Data Broker?: A Quick Primer on State Laws Regulating a ... - Taft
NEW QUESTION # 94
What role does the U.S. Constitution play in the area of workplace privacy?
- A. It provides enforcement resources to large employers, but not to small businesses
- B. It provides significant protections to federal and state governments, but not to private-sector employment
- C. It provides legal precedent for physical information security, but not for electronic security
- D. It provides contractual protections to members of labor unions, but not to employees at will
Answer: B
Explanation:
The U.S. Constitution plays a limited role in the area of workplace privacy, because it mainly applies to the actions of the government, not private employers. The Fourth Amendment protects the right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures1. The Supreme Court has interpreted this right to include a reasonable expectation of privacy in certain situations, such as in one's home, car, or personal belongings2. However, this right does not extend to private-sector employees, who are not protected by the Constitution from the actions of their employers, unless the employer is acting as an agent of the government3. Private-sector employees may have some privacy rights under state laws, common law, or contractual agreements, but these vary depending on the jurisdiction and the circumstances4.
Public-sector employees, on the other hand, are protected by the Constitution from unreasonable searches and seizures by their employers, who are considered part of the government. Public-sector employees have a reasonable expectation of privacy in their workplace, unless there is a legitimate work-related reason for the search or seizure, such as to ensure safety, security, or efficiency. Public-sector employers must also comply with the due process and equal protection clauses of the Fifth and Fourteenth Amendments, which prohibit the government from depriving any person of life, liberty, or property without due process of law, or from denying any person the equal protection of the laws. These clauses protect public-sector employees from arbitrary or discriminatory actions by their employers that affect their employment status or benefits.
Therefore, the U.S. Constitution plays a significant role in the area of workplace privacy for federal and state governments, but not for private-sector employment, because it only regulates the actions of the government, not private actors. References:
* 1: Cornell Law School, Fourth Amendment,
https://www.law.cornell.edu/constitution/fourth_amendment
* 2: FindLaw, What Is a Reasonable Expectation of Privacy?,
https://www.findlaw.com/criminal/criminal-rights/what-is-a-reasonable-expectation-of-privacy.html
* 3: FindLaw, Workplace Privacy,
https://www.findlaw.com/smallbusiness/employment-law-and-human-resources/workplace-privacy.html
* 4: Nolo, Privacy Rights of Employees,
https://www.nolo.com/legal-encyclopedia/privacy-rights-employees-29849.html
* : OPM, Employee Relations,
https://www.opm.gov/policy-data-oversight/employee-relations/reference-materials/employee-privacy/
* : Cornell Law School, Fifth Amendment, https://www.law.cornell.edu/constitution/fifth_amendment
* : FindLaw, Public Employees and the Constitution,
https://www.findlaw.com/employment/employment-rights/public-employees-and-the-constitution.html
NEW QUESTION # 95
Which action is prohibited under the Electronic Communications Privacy Act of 1986?
- A. Intercepting electronic communications and unauthorized access to stored communications
- B. Accessing stored communications with the consent of the sender or recipient of the message
- C. Monitoring employee telephone calls of a personal nature
- D. Monitoring all employee telephone calls
Answer: A
Explanation:
The Electronic Communications Privacy Act of 1986 (ECPA) is a federal law that protects the privacy of wire, oral, and electronic communications while they are being made, in transit, or stored on computers1. The ECPA has three titles: Title I prohibits the intentional interception, use, or disclosure of wire, oral, or electronic communications, except for certain exceptions, such as consent, provider protection, or law enforcement purposes2. Title II, also known as the Stored Communications Act (SCA), prohibits the unauthorized access to or disclosure of stored wire or electronic communications, such as email, voicemail, or online messages, except for certain exceptions, such as consent, provider protection, or law enforcement purposes3. Title III regulates the installation and use of pen register and trap and trace devices, which record thenumbers dialed to or from a telephone line, but not the content of the communications4.
Therefore, the action that is prohibited under the ECPA is intercepting electronic communications and unauthorized access to stored communications, which are covered by Title I and Title II of the Act, respectively. The other actions are not prohibited by the ECPA, as long as they comply with the exceptions and requirements of the Act. For example, monitoring all employee telephone calls or monitoring employee telephone calls of a personal nature may be allowed if the employer has a legitimate business purpose, has obtained the consent of the employees, or has a court order5. Accessing stored communications with the consent of the sender or recipient of the message is also allowed under the ECPA, as consent is one of the exceptions to the prohibition of unauthorized access3.
References: 1: Electronic Communications Privacy Act of 1986 (ECPA), Bureau of Justice Assistance. 2: 18
U.S. Code Chapter 119 - WIRE AND ELECTRONIC COMMUNICATIONS INTERCEPTION AND INTERCEPTION OF ORAL COMMUNICATIONS, Legal Information Institute. 3: 18 U.S. Code Chapter
121 - STORED WIRE AND ELECTRONIC COMMUNICATIONS AND TRANSACTIONAL RECORDS ACCESS, Legal Information Institute. 4: 18 U.S. Code Chapter 206 - PEN REGISTERS AND TRAP AND TRACE DEVICES, Legal Information Institute. 5: Monitoring Employees' Phone Calls and E-Mail, FindLaw.
NEW QUESTION # 96
SCENARIO
Please use the following to answer the next QUESTION:
Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your network?" Matt asked hopefully.
"No," the boy said. "I'm filling out a survey."
Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking Questions about my opinions."
"Let me see," Matt said, and began reading the list of Questions that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read further he learned that kids who took the survey were automatically registered in a contest to win the first book in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer Questions about his favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities.
How does Matt come to the decision to report the marketer's activities?
- A. The marketer failed to make an adequate attempt to provide Matt with information
- B. The marketer seems to have distributed his son's information without Matt's permission
- C. The marketer failed to identify himself and indicate the purpose of the messages
- D. The marketer did not provide evidence that the prize books were appropriate for children
Answer: A
NEW QUESTION # 97
Which law provides employee benefits, but often mandates the collection of medical information?
- A. The Occupational Safety and Health Act.
- B. The Family and Medical Leave Act.
- C. The Americans with Disabilities Act.
- D. The Employee Medical Security Act.
Answer: C
NEW QUESTION # 98
What practice does the USA FREEDOM Act NOT authorize?
- A. Emergency exceptions that allows the government to target roamers
- B. An extension of the expiration for roving wiretaps
- C. An increase in the maximum penalty for material support to terrorism
- D. The bulk collection of telephone data and internet metadata
Answer: A
NEW QUESTION # 99
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to do what?
- A. Determine which bodies will be involved in adjudication
- B. Decide if any enforcement actions are justified
- C. Appeal decisions made against it
- D. Adhere to its industry's code of conduct
Answer: D
Explanation:
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to adhere to its industry's code of conduct. Self-regulation is a process by which an industry or a group of companies voluntarily adopts and enforces standards or guidelines to protect consumers and promote fair competition.
The FTC encourages self-regulation as a way to complement its enforcement efforts and address emerging issues in the marketplace. The FTC also monitors self-regulatory programs and may take action against companies that fail to comply with their own codes of conduct or misrepresent their participation in such programs. References:
* Federal Trade Commission Act, Section 5 of
* Self-Regulation | Federal Trade Commission
* [IAPP CIPP/US Certified Information Privacy Professional Study Guide], Chapter 3, page 79
NEW QUESTION # 100
SCENARIO
Please use the following to answer the next QUESTION
Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in Californi a. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask Question:s about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements.
Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision.
Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. Celeste believes that even if the business grows a customer database of a few thousand, it's unlikely that a state agency would hassle an honest business if an accidental security incident were to occur.
In any case, Celeste feels that all they need is common sense - like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina.
Which law will be most relevant to Felicia's plan to ask applicants about drug addiction?
- A. The Americans with Disabilities Act (ADA).
- B. The Health Insurance Portability and Accountability Act (HIPAA).
- C. The Genetic Information Nondiscrimination Act of 2008.
- D. The Occupational Safety and Health Act (OSHA).
Answer: A
NEW QUESTION # 101
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portablehard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
Based on the scenario, what is the most likely way Declan's supervisor would answer his question about the hospital's use of a billing company?
- A. By pointing out that contracts are in place to help ensure the observance of minimum security standards
- B. By describing how the billing system is integrated into the hospital's electronic health records (EHR) system
- C. By suggesting that Declan look at the hospital's publicly posted privacy policy
- D. By assuring Declan that third parties are prevented from seeing Private Health Information (PHI)
Answer: A
Explanation:
HIPAA requires covered entities, such as hospitals, to enter into contracts with their business associates, such as billing companies, that access, use, or disclose protected health information (PHI). These contracts, known as business associate agreements (BAAs), must specify the permitted and required uses and disclosures of PHI by the business associate, as well as the safeguards, reporting, and termination procedures that the business associate must follow to protect the privacy and security of PHI. By having these contracts in place, the hospital can ensure that the billing company is complying with HIPAA and observing the minimum security standards required by law. References:
* HIPAA Rules for Medical Billing - Compliancy Group
* HIPAA Compliance for Billing Companies: Easy Guide - iFax
NEW QUESTION # 102
......
Real Updated CIPP-US Questions & Answers Pass Your Exam Easily: https://www.testkingfree.com/IAPP/CIPP-US-practice-exam-dumps.html
Easily To Pass New CIPP-US Verified & Correct Answers: https://drive.google.com/open?id=1x81zQPbavArDPxA2MDdGg3WLDUvQlF4-