IAPP CIPT Exam Prep
Certified Information Privacy Technologist (CIPT) (Page 2 )

Updated On: 12-Sep-2026

What would be an example of an organization transferring the risks associated with a data breach?

  1. Using a third-party service to process credit card transactions.
  2. Encrypting sensitive personal data during collection and storage
  3. Purchasing insurance to cover the organization in case of a breach.
  4. Applying industry standard data handling practices to the organization' practices.

Answer(s): C

Explanation:

Why option C is the correct example of risk transfer
Purchasing breach-related insurance shifts the financial impact of a data breach to an insurer. The organization pays a premium, and the insurer reimburses covered losses (e.g., notification costs, legal fees, remediation, reputational damage). This is a classic risk-transfer mechanism: the organization retains the operational responsibility for preventing breaches, but the monetary consequences are moved to a third-party insurer. Insurance contracts explicitly define coverage limits, deductibles, and exclusions, making the transfer quantifiable and auditable—key criteria for formal risk-transfer strategies identified in privacy frameworks such as ISO/IEC 27701 and the NIST Privacy Framework.
Why the other options are not risk-transfer actions
A – Using a third-party to process credit-card transactions primarily reduces the organization’s own processing scope and may lower technical risk, but the liability for a breach may still rest with the organization (or be shared via contractual clauses). It is more a risk-mitigation or outsourcing choice than a pure transfer of financial risk. B – Encrypting sensitive personal data during collection and storage is a risk-reduction (risk-mitigation) control that lowers the likelihood or severity of a breach, but it does not shift the financial or legal consequences of a breach to another party. D – Applying industry-standard data-handling practices improves overall security posture and compliance, yet it remains an internal control measure; it does not involve transferring risk to an external entity.
Conclusion – The only option that explicitly transfers the financial risk of a data breach to another party is C – Purchasing insurance to cover the organization in case of a breach .


Reference:

1. ISO/IEC 27701:2019 – Privacy Information Management System (PIMS) – Requirements and Guidance – Section 5.3 “Risk treatment options including risk transfer”. https://www.iso.org/standard/75175.html 2. National Institute of Standards and Technology (NIST) – Privacy Framework – Chapter 3 “Risk Management”, which describes transferring privacy risks via contractual mechanisms such as insurance. https://www.nist.gov/publications/privacy-framework-version-100
These documents provide the standards and guidance that recognize insurance-based risk transfer as a valid approach for managing the financial impact of privacy-related incidents.



Which of the following is considered a client-side IT risk?

  1. Security policies focus solely on internal corporate obligations.
  2. An organization increases the number of applications on its server.
  3. An employee stores his personal information on his company laptop.
  4. IDs used to avoid the use of personal data map to personal data in another database.

Answer(s): C

Explanation:

Why option C is the correct client-side IT risk
Personal data stored on a corporate device creates a direct privacy exposure at the endpoint: the data is under the employee’s control, may be accessed locally, and can be exfiltrated or lost without the organization’s oversight. This scenario involves data subject consent, purpose limitation, and security controls that must be enforced on the client device, which is a classic “client-side” risk described in privacy-by-design and data-minimization principles. Regulations such as GDPR require that personal data be protected wherever it is processed, including on devices that are not fully managed by the organization, making the storage of personal info on a company laptop a clear client-side risk.
Why the other options are not client-side risks
A – Security policies focused solely on internal corporate obligations describes a governance gap, but it is a policy-level issue , not a technical exposure that occurs on the client side. B – Adding more applications to a server impacts the server-side attack surface and architecture, not the client device where personal data might reside. D – Using IDs that map to personal data in another database concerns data linkage across systems , which is a data-integration or cross-database risk rather than a risk confined to the client environment.


Reference:

IAPP – Certified Information Privacy Technologist (CIPT) Study Guide, Chapter 3: Privacy-by-Design and Secure Architecture. https://iapp.org/certificate/c ipt/ NIST Special Publication 800-53 Revision 5, “Privacy Controls for Federal Information Systems and Organizations.” https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final



SCENARIO

Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.

As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!"

But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.

At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. "Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should."

Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase."

Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"

`I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy."

Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."


What type of principles would be the best guide for Jane's ideas regarding a new data management program?

  1. Collection limitation principles.
  2. Vendor management principles.
  3. Incident preparedness principles.
  4. Fair Information Practice Principles

Answer(s): D

Explanation:

Selected Answer: D – Fair Information Practice Principles (FIPPs)
Why D is the Best Choice
FIPPs embody a comprehensive set of privacy-centric concepts— collection limitation, data quality, purpose specification, use limitation, security, openness, individual participation, and accountability —that directly address the issues raised in the scenario. Jane’s concerns involve protecting customer personal information, ensuring the ability of individuals to control how their data are used, and establishing sound data-management practices ; these are precisely the domains covered by FIPPs. Applying FIPPs enables the design of a data-management program that respects privacy, provides transparency, and implements safeguards (e.g., secure storage, consent mechanisms, data-subject rights), which is essential when integrating with a third-party vendor’s systems.
Why the Other Options Are Less Suitable

A: Collection limitation principles – Focuses mainly on restricting what data are collected and how it is gathered.
While relevant, it does not address the broader set of controls required for data quality, purpose specification, security, and individual rights that Jane must implement. B. Vendor management principles – Concerned with managing relationships and performance of external providers. This is useful for overseeing the outsourced online-sales vendor but does not encompass the privacy-centric framework needed to govern how personal information is handled overall. C. Incident preparedness principles – Deal with planning for and responding to data breaches or security incidents. Although important, they are reactive measures; Jane’s primary need is a proactive, privacy-by-design program that embeds protection into everyday operations.


Reference:

1. International Association of Privacy Professionals (IAPP) – “Fair Information Practice Principles (FIPPs)” https://iapp.org/resources/article/fair-information-practice-principles/
2. U.S. Federal Trade Commission (FTC) – “Protecting Personal Information: A Guide for Business” (covers core privacy principles aligned with FIPPs) https://www.ftc.gov/tips-advice/business-guide/privacy/security/protecting-personal-information-guide-businesses
Prepared for CIPT certification exam review; emphasizes precise, exam-style justification.



SCENARIO
Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.

As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!"

But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.

At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. "Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should."

Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase."

Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"

`I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy."

Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."


Which regulator has jurisdiction over the shop's data management practices?

  1. The Federal Trade Commission.
  2. The Department of Commerce.
  3. The Data Protection Authority.
  4. The Federal Communications Commission.

Answer(s): A

Explanation:

Why the Federal Trade Commission (FTC) has jurisdiction
The FTC is the primary federal regulator that enforces Section 5 of the FTC Act , which prohibits unfair or deceptive acts or practices in commerce, including shortcomings in privacy and data-security practices .
When a business collects, stores, or shares personal information (names, addresses, phone numbers, email addresses) from consumers, the FTC expects reasonable safeguards and transparent notice—standards that Sam’s “safe-deposit-only” approach failed to meet. The FTC’s authority extends to both online and offline consumer-facing activities of a U.S. merchant, regardless of whether the operation is a boutique or an online sales channel. The FTC has issued numerous guidance documents (e.g., “Protecting Personal Information: A 10-Step
Checklist”) that require reasonable security measures and consumer control over the collection and use of personal data —both of which Sam and later Jane needed to implement.
Why the other options are less appropriate
B: Department of Commerce – Responsible for census, economic data collection, and trade promotion; it does not regulate privacy or enforce consumer-privacy protections for commercial entities. C. Data Protection Authority – Such bodies (e.g., GDPR supervisory authorities) exist primarily in the European Union and certain state-level frameworks (e.g., California Consumer Privacy Act enforcement). The United States does not have a single overarching “Data Protection Authority” with nationwide jurisdiction over commercial privacy practices. D. Federal Communications Commission (FCC) – Regulates interstate and international communications (radio, TV, broadband, telephone).
While it can touch on privacy in the communications context, its primary mandate is not consumer-privacy enforcement for general retail or e-commerce activities.
Conclusion Given that Sam’s and Jane’s operations involved the collection of personal consumer data (names, addresses, contact information) and the need to implement reasonable privacy safeguards , the FTC is the agency with statutory authority to oversee and enforce those data-management practices.


Reference:

Federal Trade Commission – Bureau of Consumer Protection: https://www.ftc.gov/about-ftc/organization-and-mission/bureau-consumer-protection FTC – “Protecting Personal Information: A 10-Step Checklist”: https://www.ftc.gov/tips-advice/complaint-resolution/0131-protecting-personal-information-10-step-checklist



SCENARIO
Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.

As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!"

But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.

At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. "Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should."

Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase."

Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"

`I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy."

Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."

When initially collecting personal information from customers, what should Jane be guided by?

  1. Onward transfer rules.
  2. Digital rights management.
  3. Data minimization principles.
  4. Vendor management principles

Answer(s): C

Explanation:

Justification
The scenario describes Jane’s responsibility to handle personal data that the business collects directly from customers (names, addresses, phone numbers) before any processing or transfer occurs. The foundational privacy principle that governs this initial collection is data-minimization : only the data that is necessary and adequate for the specified purpose should be gathered, and it should be limited to what is required. Jane must therefore ensure that the information collected is strictly relevant to the business’s purposes (e.g., order fulfillment, communication) and that no extraneous data is captured. This principle also informs downstream decisions such as how long to retain the data and how it can be used.
Onward transfer rules (Option A) pertain to the disposal or sharing of data after it has been collected and processed, not to the initial act of collection. Digital rights management (Option B) is a technical method for protecting copyrighted digital content; it does not address the scope or limits of personal data collection. Vendor management principles (Option D) involve overseeing third-party processors and ensuring they meet contractual and security obligations—again, a concern that arises after data has been collected, not during the collection stage.
Thus, when initially collecting personal information from customers, Jane should be guided primarily by data-minimization principles .


Reference:

1. International Association of Privacy Professionals – Data Minimization overview: https://iapp.org/resources/data-minimization/ 2. U.S. Federal Trade Commission – Privacy & Data Security: A Practical Guide (Chapter on Data Minimization): https://www.ftc.gov/tips-advice/business-center/privacy-and-security/privacy-and-security-best-practices



Viewing page 2 of 66
Viewing questions 6 - 10 out of 325 questions


Post your Comments and Discuss IAPP CIPT exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!