IAPP CIPM Exam Actual Questions
Certified Information Privacy Manager (Page 3 )

Updated On: 19-Jul-2026

Which statement is FALSE regarding the use of technical security controls?

  1. Technical security controls are part of a data governance strategy.
  2. Technical security controls deployed for one jurisdiction often satisfy another jurisdiction.
  3. Most privacy legislation lists the types of technical security controls that must be implemented.
  4. A person with security knowledge should be involved with the deployment of technical security controls.

Answer(s): C

Explanation:

Justification
Technical security controls (e.g., encryption, access-control lists, intrusion-detection systems) are designed to protect data assets and are integral to a privacy-by-design approach.
A – True. Technical controls are one of the core pillars of a data-governance framework, alongside policies and processes, ensuring that data is protected throughout its lifecycle. B – True. Controls that meet the stringent requirements of one jurisdiction (e.g., GDPR’s “appropriate technical and organisational measures”) can often be reused in other jurisdictions, provided they satisfy the local legal thresholds. C – False . Privacy statutes rarely prescribe specific technical controls; they set risk-based expectations (e.g., “appropriate measures”) rather than enumerating mandatory technologies.
What is required varies by context, risk assessment, and the data controller’s own policies. D – True. Deployment of technical controls must be overseen by staff with security expertise to ensure proper configuration, integration, and ongoing effectiveness.
Hence, the false statement is C .
Sensitivity Score: Medium – The question tests understanding of the generic, non-prescriptive nature of privacy legislation regarding technical controls, which is a nuanced but not highly controversial concept.


Reference:

1. EU GDPR Recital 78 – https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
(describes “appropriate technical and organisational measures” without listing specific controls). 2. NIST Privacy Framework – https://www.nist.gov/privacy-framework (provides risk-based guidance,
emphasizing implementation tailored to organizational needs rather than a fixed checklist).
Selected Answers (JSON format):
"answer":"C"



An organization's privacy officer was just notified by the benefits manager that she accidentally sent out the retirement enrollment report of all employees to a wrong vendor.
Which of the following actions should the privacy officer take first?

  1. Perform a risk of harm analysis.
  2. Report the incident to law enforcement.
  3. Contact the recipient to delete the email.
  4. Send firm-wide email notification to employees.

Answer(s): C

Explanation:

Why option C is the optimal first step
Immediate containment – contacting the vendor who received the email is the quickest way to limit further distribution of the sensitive retirement-enrollment data. A direct request to delete the message and any copies stops the data from propagating. Preserves evidence – by reaching out promptly, the privacy officer can document the vendor’s response (e.g., confirmation of deletion), which is essential for later investigative and reporting activities. Maintains a documented chain-of-custody – early engagement creates a clear audit trail showing that the organization acted responsibly before escalating the incident.
Why the other options are inappropriate as the first action
Option A – Perform a risk of harm analysis – This assessment is necessary, but it must be performed after the incident is contained; otherwise the organization cannot accurately gauge exposure while the data may still be circulating. Option B – Report the incident to law enforcement – Law-enforcement involvement is typically warranted only when criminal conduct is suspected or when mandated by regulation. It is not the immediate response to an accidental email disclosure. Option D – Send a firm-wide email notification to employees – Mass notification can cause unnecessary anxiety and may inadvertently highlight the breach, whereas the priority is to mitigate the technical exposure first and assess business impact internally.
Correct sequence in a privacy incident response
1. Contain – contact the external recipient to halt further dissemination (Option C). 2. Assess impact – conduct a risk/harm analysis to determine the scope of exposure (Option A). 3. Escalate – involve appropriate internal stakeholders and, if required, report to regulators or law-enforcement. 4. Communicate – issue notifications to affected individuals or employees only after the above steps have been completed.


Reference:

NIST Special Publication 800-61 Rev. 2 – Computer Security Incident Handling Guide: outlines containment, eradication, and post-incident activities. https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final GDPR Article 33 – Notification of a personal data breach to the supervisory authority : requires timely reporting after initial containment and assessment. https://gdpr.eu/article-33-notification-of-a-breach-to-the-supervisory-authority/



SCENARIO -Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found some degree of disorganization after touring the company headquarters. His uncle Henry had always focused on production – not data processing – and Anton is concerned. In several storage rooms, he has found paper files, disks, and old computers that appear to contain the personal data of current and former employees and customers. Anton knows that a single break-in could irrevocably damage the company's relationship with its loyal customers. He intends to set a goal of guaranteed zero loss of personal information. To this end, Anton originally planned to place restrictions on who was admitted to the physical premises of the company. However, Kenneth – his uncle's vice president and longtime confidante – wants to hold off on Anton's idea in favor of converting any paper records held at the company to electronic storage. Kenneth believes this process would only take one or two years. Anton likes this idea; he envisions a password-protected system that only he and Kenneth can access. Anton also plans to divest the company of most of its subsidiaries. Not only will this make his job easier, but it will simplify the management of the stored data. The heads of subsidiaries like the art gallery and kitchenware store down the street will be responsible for their own information management. Then, any unneeded subsidiary data still in Anton's possession can be destroyed within the next few years. After learning of a recent security incident, Anton realizes that another crucial step will be notifying customers. Kenneth insists that two lost hard drives in question are not cause for concern; all of the data was encrypted and not sensitive in nature. Anton does not want to take any chances, however. He intends on sending notice letters to all employees and customers to be safe. Anton must also check for compliance with all legislative, regulatory, and market requirements related to privacy protection. Kenneth oversaw the development of the company's online presence about ten years ago, but Anton is not confident about his understanding of recent online marketing laws. Anton is assigning another trusted employee with a law background the task of the compliance assessment. After a thorough analysis, Anton knows the company should be safe for another five years, at which time he can order another check. Documentation of this analysis will show auditors due diligence. Anton has started down a long road toward improved management of the company, but he knows the effort is worth it. Anton wants his uncle's legacy to continue for many years to come. To improve the facility's system of data security, Anton should consider following through with the plan for which of the following?

  1. Customer communication.
  2. Employee access to electronic storage.
  3. Employee advisement regarding legal matters.
  4. Controlled access at the company headquarters.

Answer(s): D

Explanation:

Correct Option – D. Controlled access at the company headquarters
Risk-focused mitigation: The scenario centers on 防⽌ unauthorized exposure of personal data stored in paper files, disks, and legacy systems located on-site. Implementing controlled physical and logical access (e.g., badge readers, biometric verification, perimeter monitoring) directly reduces the likelihood that intruders can retrieve those records, thereby preserving confidentiality and integrity of the data. Compliance linkage: Regulatory frameworks such as GDPR, CCPA, and industry-specific privacy statutes require demonstrable access-control measures as part of the “security of processing” obligation. Controlled headquarters access satisfies audit evidence of segregation of duties and limits insider threats. Scope alignment with Anton’s goals: Anton’s objective (“guaranteed zero loss of personal information”) is met when only authorized personnel can enter the storage areas and interact with the data. This contrasts with broader initiatives that do not specifically restrict physical access. Scalability & sustainability: A controlled-access program can be expanded incrementally (e.g., adding multi-factor authentication) without delaying the transition to electronic storage, allowing Anton to merge both security dimensions smoothly.
Why the other options are less suitable

A: Customer communication.
While notification is important after an incident, it is a reactive measure. Anton’s primary goal is proactive prevention of data loss, and communication alone does not prevent unauthorized physical access. B. Employee access to electronic storage. This focuses mainly on logical controls for data already digitized. The immediate risk stems from unsecured paper and legacy media; restricting electronic-only access ignores the heterogeneous data formats currently at the premises. C. Employee advisement regarding legal matters. Legal counseling is valuable but does not directly enforce the security posture required to protect physical records. It addresses compliance interpretation rather than implementing tangible barriers to data theft.
In summary , establishing controlled access at the company headquarters directly tackles the most imminent threat (unauthorized physical intrusion), aligns with privacy-regulatory requirements, and supports Anton’s zero-loss objective, making it the most defensible choice.


Reference:

International Association of Privacy Professionals (IAPP). Privacy Program Fundamentals. https://iapp.org/resources/privacy-program-fundamentals/ NIST. Special Publication 800-53 Rev. 5 – Security and Privacy Controls for Information Systems and Organizations. https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final



SCENARIO -Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found some degree of disorganization after touring the company headquarters. His uncle Henry had always focused on production – not data processing – and Anton is concerned. In several storage rooms, he has found paper files, disks, and old computers that appear to contain the personal data of current and former employees and customers. Anton knows that a single break-in could irrevocably damage the company's relationship with its loyal customers. He intends to set a goal of guaranteed zero loss of personal information. To this end, Anton originally planned to place restrictions on who was admitted to the physical premises of the company. However, Kenneth – his uncle's vice president and longtime confidante – wants to hold off on Anton's idea in favor of converting any paper records held at the company to electronic storage. Kenneth believes this process would only take one or two years. Anton likes this idea; he envisions a password-protected system that only he and Kenneth can access. Anton also plans to divest the company of most of its subsidiaries. Not only will this make his job easier, but it will simplify the management of the stored data. The heads of subsidiaries like the art gallery and kitchenware store down the street will be responsible for their own information management. Then, any unneeded subsidiary data still in Anton's possession can be destroyed within the next few years. After learning of a recent security incident, Anton realizes that another crucial step will be notifying customers. Kenneth insists that two lost hard drives in question are not cause for concern; all of the data was encrypted and not sensitive in nature. Anton does not want to take any chances, however. He intends on sending notice letters to all employees and customers to be safe. Anton must also check for compliance with all legislative, regulatory, and market requirements related to privacy protection. Kenneth oversaw the development of the company's online presence about ten years ago, but Anton is not confident about his understanding of recent online marketing laws. Anton is assigning another trusted employee with a law background the task of the compliance assessment. After a thorough analysis, Anton knows the company should be safe for another five years, at which time he can order another check. Documentation of this analysis will show auditors due diligence. Anton has started down a long road toward improved management of the company, but he knows the effort is worth it. Anton wants his uncle's legacy to continue for many years to come.
Which of Anton's plans for improving the data management of the company is most unachievable?

  1. His initiative to achieve regulatory compliance.
  2. His intention to transition to electronic storage.
  3. His objective for zero loss of personal information.
  4. His intention to send notice letters to customers and employees.

Answer(s): C

Explanation:

Technical Justification
Option C – Zero loss of personal information is fundamentally unachievable. In any operational environment involving storage of personal data (paper files, disks, legacy computers), loss can occur through accidental deletion, hardware failure, theft, natural disasters, or insider threats. Even with multiple redundant systems, encryption, and strict access controls, zero-loss assurance is a theoretical ideal rather than a practical guarantee. The scenario describes uncontrolled legacy media, insufficient asset oversight, and a single break-in that could compromise all records—conditions that make a true “zero loss” objective unrealistic.
Option A – Achieving regulatory compliance can be attained through documented assessments, policies, and periodic reviews. Anton is already delegating compliance oversight to a qualified employee and planning periodic audits, a feasible and widely-accepted approach.
Option B – Transitioning to electronic storage is practical over a one- to two-year horizon. Modern migration strategies (e.g., secure cloud or on-premises repositories, standardized migration protocols, and data-validation steps) are routinely executed in similar organizations.
Option D – Sending notice letters is straightforward once an incident is identified. Draft templates, mailing procedures, and notification timelines are standard privacy-incident response practices.
Therefore, the most unachievable goal is the pursuit of absolute zero loss of personal information .


Reference:

IAPP CIPM Body of Knowledge – Principles of data loss prevention and incident response: https://iapp.org/resources/article/cipm-body-of-knowledge/ National Institute of Standards and Technology (NIST) Privacy Framework – Guidance on managing privacy risk and achieving compliance: https://www.privacyframework.org/



SCENARIO -Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found some degree of disorganization after touring the company headquarters. His uncle Henry had always focused on production – not data processing – and Anton is concerned. In several storage rooms, he has found paper files, disks, and old computers that appear to contain the personal data of current and former employees and customers. Anton knows that a single break-in could irrevocably damage the company's relationship with its loyal customers. He intends to set a goal of guaranteed zero loss of personal information. To this end, Anton originally planned to place restrictions on who was admitted to the physical premises of the company. However, Kenneth – his uncle's vice president and longtime confidante – wants to hold off on Anton's idea in favor of converting any paper records held at the company to electronic storage. Kenneth believes this process would only take one or two years. Anton likes this idea; he envisions a password-protected system that only he and Kenneth can access. Anton also plans to divest the company of most of its subsidiaries. Not only will this make his job easier, but it will simplify the management of the stored data. The heads of subsidiaries like the art gallery and kitchenware store down the street will be responsible for their own information management. Then, any unneeded subsidiary data still in Anton's possession can be destroyed within the next few years. After learning of a recent security incident, Anton realizes that another crucial step will be notifying customers. Kenneth insists that two lost hard drives in question are not cause for concern; all of the data was encrypted and not sensitive in nature. Anton does not want to take any chances, however. He intends on sending notice letters to all employees and customers to be safe. Anton must also check for compliance with all legislative, regulatory, and market requirements related to privacy protection. Kenneth oversaw the development of the company's online presence about ten years ago, but Anton is not confident about his understanding of recent online marketing laws. Anton is assigning another trusted employee with a law background the task of the compliance assessment. After a thorough analysis, Anton knows the company should be safe for another five years, at which time he can order another check. Documentation of this analysis will show auditors due diligence. Anton has started down a long road toward improved management of the company, but he knows the effort is worth it. Anton wants his uncle's legacy to continue for many years to come.
Which important principle of Data Lifecycle Management (DLM) will most likely be compromised if Anton executes his plan to limit data access to himself and Kenneth?

  1. Practicing data minimalism.
  2. Ensuring data retrievability.
  3. Implementing clear policies.
  4. Ensuring adequacy of infrastructure.

Answer(s): B

Explanation:

Answer(s): B – Ensuring data retrievability
Limiting data access to only Anton and Kenneth concentrates control in two individuals.
While it may reduce immediate exposure to unauthorized viewing, it creates a single point of failure for data availability. Retrieval of records—whether for day-to-day operations, audit requests, or litigation holds—requires timely extraction, validation, and distribution. If the two custodians are unavailable, overloaded, or make a mistake, critical information can become inaccessible , jeopardizing business continuity and regulatory reporting. This directly conflicts with the DLM principle that data must remain readily retrievable throughout its lifecycle .
Why the other options are less relevant

A: Practicing data minimalism – This principle focuses on collecting and retaining only what is necessary. Anton’s plan does not reduce the volume of retained data; it merely restricts who sees it, so minimalism is not the primary risk. C. Implementing clear policies – Although access control should be documented, the central issue is not the absence of policy but the practical limitation on who can actually obtain the data when needed . Policies can still state “only two people may access,” but they cannot guarantee retrieval success. D. Ensuring adequacy of infrastructure – Infrastructure concerns hardware, storage capacity, and security controls. Anton’s scheme does not inherently weaken the physical or technical infrastructure; it merely adds a narrow access policy, so infrastructure adequacy remains intact.
Thus, the most likely compromised DLM principle is ensuring data retrievability (B) .


Reference:

International Association of Privacy Professionals, CIPP Body of Knowledge – Data Lifecycle Management (2023) – https://iapp.org/resources/cipp-body-of-knowledge/ European Union Agency for Cybersecurity (ENISA), Data Lifecycle Management – Best Practices for Secure Retrieval (2022) – https://www.enisa.europa.eu/publications/data-lifecycle-management-best-practices



SCENARIO -Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found some degree of disorganization after touring the company headquarters. His uncle Henry had always focused on production – not data processing – and Anton is concerned. In several storage rooms, he has found paper files, disks, and old computers that appear to contain the personal data of current and former employees and customers. Anton knows that a single break-in could irrevocably damage the company's relationship with its loyal customers. He intends to set a goal of guaranteed zero loss of personal information. To this end, Anton originally planned to place restrictions on who was admitted to the physical premises of the company. However, Kenneth – his uncle's vice president and longtime confidante – wants to hold off on Anton's idea in favor of converting any paper records held at the company to electronic storage. Kenneth believes this process would only take one or two years. Anton likes this idea; he envisions a password-protected system that only he and Kenneth can access. Anton also plans to divest the company of most of its subsidiaries. Not only will this make his job easier, but it will simplify the management of the stored data. The heads of subsidiaries like the art gallery and kitchenware store down the street will be responsible for their own information management. Then, any unneeded subsidiary data still in Anton's possession can be destroyed within the next few years. After learning of a recent security incident, Anton realizes that another crucial step will be notifying customers. Kenneth insists that two lost hard drives in question are not cause for concern; all of the data was encrypted and not sensitive in nature. Anton does not want to take any chances, however. He intends on sending notice letters to all employees and customers to be safe. Anton must also check for compliance with all legislative, regulatory, and market requirements related to privacy protection. Kenneth oversaw the development of the company's online presence about ten years ago, but Anton is not confident about his understanding of recent online marketing laws. Anton is assigning another trusted employee with a law background the task of the compliance assessment. After a thorough analysis, Anton knows the company should be safe for another five years, at which time he can order another check. Documentation of this analysis will show auditors due diligence. Anton has started down a long road toward improved management of the company, but he knows the effort is worth it. Anton wants his uncle's legacy to continue for many years to come. In terms of compliance with regulatory and legislative changes, Anton has a misconception regarding?

  1. The timeline for monitoring.
  2. The method of recordkeeping.
  3. The use of internal employees.
  4. The type of required qualifications.

Answer(s): A

Explanation:

Technical Justification
Correct option – A. The timeline for monitoring Anton assumes that a single compliance assessment will remain valid for five years, implying a static “once-every-five-years” monitoring approach. Modern privacy regulations (e.g., GDPR, CCPA, state-level data-security statutes) typically require continuous or periodic monitoring aligned with the frequency of data-processing changes, breach reporting obligations, and updates to legal obligations. Treating compliance as a five-year snapshot can create gaps where new regulatory requirements or business-process changes are not addressed in a timely manner, exposing the organization to regulatory penalties and loss of customer trust.
Option B – The method of recordkeeping Anton’s plan to convert paper records to electronic storage and to protect them with password-controlled access correctly addresses how records are maintained. The misconception does not revolve around storage format or access controls, but rather when and how often those controls are verified.
Option C – The use of internal employees Delegating a law-trained employee to perform the compliance assessment is appropriate and reflects a best-practice use of internal expertise. The issue is not who conducts the assessment but the frequency and rigor of monitoring those assessments.
Option D – The type of required qualifications Requiring a qualified individual to perform the assessment aligns with regulatory expectations for competence. Anton’s misunderstanding does not involve credential specifications; it concerns the schedule for reassessment.
Conclusion Anton’s primary misconception lies in how often compliance monitoring must occur , not in how data are stored, who performs the review, or what qualifications are needed. A static five-year interval conflicts with the dynamic nature of privacy law and best-practice governance, making option A the most accurate answer.


Reference:

International Association of Privacy Professionals (IAPP) – Fundamentals of GDPR ( https://iapp.org/resources/gdpr-fundamentals ) National Institute of Standards and Technology (NIST) – NIST Privacy Framework ( https://www.nist.gov/privacy-framework )



SCENARIO -Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found some degree of disorganization after touring the company headquarters. His uncle Henry had always focused on production – not data processing – and Anton is concerned. In several storage rooms, he has found paper files, disks, and old computers that appear to contain the personal data of current and former employees and customers. Anton knows that a single break-in could irrevocably damage the company's relationship with its loyal customers. He intends to set a goal of guaranteed zero loss of personal information. To this end, Anton originally planned to place restrictions on who was admitted to the physical premises of the company. However, Kenneth – his uncle's vice president and longtime confidante – wants to hold off on Anton's idea in favor of converting any paper records held at the company to electronic storage. Kenneth believes this process would only take one or two years. Anton likes this idea; he envisions a password-protected system that only he and Kenneth can access. Anton also plans to divest the company of most of its subsidiaries. Not only will this make his job easier, but it will simplify the management of the stored data. The heads of subsidiaries like the art gallery and kitchenware store down the street will be responsible for their own information management. Then, any unneeded subsidiary data still in Anton's possession can be destroyed within the next few years. After learning of a recent security incident, Anton realizes that another crucial step will be notifying customers. Kenneth insists that two lost hard drives in question are not cause for concern; all of the data was encrypted and not sensitive in nature. Anton does not want to take any chances, however. He intends on sending notice letters to all employees and customers to be safe. Anton must also check for compliance with all legislative, regulatory, and market requirements related to privacy protection. Kenneth oversaw the development of the company's online presence about ten years ago, but Anton is not confident about his understanding of recent online marketing laws. Anton is assigning another trusted employee with a law background the task of the compliance assessment. After a thorough analysis, Anton knows the company should be safe for another five years, at which time he can order another check. Documentation of this analysis will show auditors due diligence. Anton has started down a long road toward improved management of the company, but he knows the effort is worth it. Anton wants his uncle's legacy to continue for many years to come.
What would the company's legal team most likely recommend to Anton regarding his planned communication with customers?

  1. To send consistent communication.
  2. To shift to electronic communication.
  3. To delay communications until local authorities are informed.
  4. To consider under what circumstances communication is necessary.

Answer(s): D

Explanation:

Answer(s): D – To consider under what circumstances communication is necessary.
Why D is the best choice
Data-privacy law and best-practice frameworks (e.g., ISO 27701, NIST 800-53) require that notification be triggered only when the breach involves personal data that is likely to cause harm or when a breach exceeds regulatory thresholds (e.g., loss of encrypted data that remains protected). Anton’s own analysis shows the encrypted hard-drives “are not cause for concern,” suggesting the breach may not meet the statutory criteria for mandatory notification. Accordingly, the legal team would advise a risk-based assessment of the breach—evaluating data type, sensitivity, encryption status, and potential impact—before deciding whether to notify customers.
Why the other options are less appropriate

A: “To send consistent communication.”
Consistency is important, but the timing and necessity of communication are governed by legal thresholds, not by a blanket need for “consistent” messaging.
B: “To shift to electronic communication.”
Moving to electronic channels does not resolve the core compliance question of whether a breach must be disclosed; it merely changes the medium.
C: “To delay communications until local authorities are informed.”
Notification to regulators should follow the organization’s own risk assessment, not automatically precede any customer communication. Premature delay could expose the company to liability if disclosure were actually required.
Key legal considerations referenced
Many privacy statutes (e.g., GDPR Art. 33, US state breach-notification laws) require notification only after a risk assessment , not automatically. The “least intrusive” approach—communicating only when required—is the standard guidance from privacy regulators.


Reference:

1. UK Information Commissioner’s Office (ICO) – Guidance on personal data breach notification –
https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-gdpr/personal-data-breaches/ 2. National Institute of Standards and Technology (NIST) – Special Publication 800-53 Revision 5 –
Privacy Controls – https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
These documents underline that notification must be evaluated against the circumstances of the breach , confirming that option D aligns with the recommended legal approach.



Why were the nongovernmental privacy organizations, Electronic Frontier Foundation (EFF) and Electronic Privacy Information Center (EPIC), established?

  1. To promote consumer confidence in the Internet industry.
  2. To improve the user experience during online shopping.
  3. To protect civil liberties and raise consumer awareness.
  4. To promote security on the Internet through strong encryption.

Answer(s): C

Explanation:

Answer(s): C – “To protect civil liberties and raise consumer awareness.”
Mission alignment: Both the Electronic Frontier Foundation (EFF) and the Electronic Privacy Information Center (EPIC) were founded to safeguard fundamental rights—particularly freedom of expression, privacy, and due process—related to emerging digital technologies. Their core activities (litigation, policy advocacy, public education) are explicitly aimed at defending these civil liberties. Scope of work: EFF’s and EPIC’s publicly documented strategies focus on influencing legislation, filing amicus briefs, and conducting outreach that advance privacy and civil-rights protections. This directly matches option C. Why the other choices are insufficient:
A – Promote consumer confidence in the Internet industry – While both groups may indirectly affect confidence, their primary purpose is not to market-oriented brand trust but to defend rights. B – Improve the user experience during online shopping – Neither organization centers its advocacy on e-commerce usability; their focus is broader, encompassing governmental and corporate surveillance, data-retention practices, and constitutional protections. D – Promote security on the Internet through strong encryption – Although encryption is a tool they support, the promotion of security is a means, not the overarching goal; the central aim remains the protection of civil liberties and informed public awareness.


Reference:

Electronic Frontier Foundation – About EFF: https://www.eff.org/about Electronic Privacy Information Center – About EPIC: https://epic.org/about/



Viewing page 3 of 47
Viewing questions 17 - 24 out of 361 questions


Post your Comments and Discuss IAPP CIPM exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!