IAPP CIPT Exam Prep
Certified Information Privacy Technologist (CIPT) (Page 7 )

Updated On: 12-Sep-2026

Which of the following statements describes an acceptable disclosure practice?

  1. An organization's privacy policy discloses how data will be used among groups within the organization itself.
  2. With regard to limitation of use, internal disclosure policies override contractual agreements with third parties.
  3. Intermediaries processing sensitive data on behalf of an organization require stricter disclosure oversight than vendors.
  4. When an organization discloses data to a vendor, the terms of the vendor' privacy notice prevail over the organization' privacy notice.

Answer(s): A

Explanation:

Why option A is correct
The organization’s own privacy policy can describe internal information flows and purposes without breaching any external obligation. It simply documents how data is used within the entity , which is permissible and often required for transparency.
Why the other options are unsuitable
B – Internal policies do not override contractual limits imposed on third-party use; contractual terms must still be respected. C – Both intermediaries and vendors handling sensitive data must be subject to adequate safeguards; the distinction is not that intermediaries automatically require stricter disclosure oversight. D – The organization’s privacy notice generally governs the relationship; the vendor’s notice may supplement but cannot supersede the organization’s disclosed purposes.


Reference:

IAPP – “Privacy Notice Best Practices”: https://www.iapp.org/resources/article/privacy-notice-best-practices/ IAPP – “Contractual Provisions for Data Processing Agreements”: https://www.iapp.org/resources/article/data-processing-agreement/



How should the sharing of information within an organization be documented?

  1. With a binding contract.
  2. With a data flow diagram.
  3. With a disclosure statement.
  4. With a memorandum of agreement.

Answer(s): B

Explanation:

B is correct because a data flow diagram (DFD) visually maps the movement of personal data across internal processes, storage, and third-party exchanges, fulfilling CIPP-IT documentation expectations; alternatives such as a binding contract (A) only sets legal obligations without tracing data flows, a disclosure statement (C) is merely a notice to data subjects, and a memorandum of agreement (D) is a bilateral contract that does not detail technical pathways highlighted;


Reference:

https://www.iso.org/standard/62040.html https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final Is there anything else I can help with?



What can be used to determine the type of data in storage without exposing its contents?

  1. Collection records.
  2. Data mapping.
  3. Server logs.
  4. Metadata.

Answer(s): D

Explanation:



What must be done to destroy data stored on "write once read many" (WORM) media?

  1. The data must be made inaccessible by encryption.
  2. The erase function must be used to remove all data.
  3. The media must be physically destroyed.
  4. The media must be reformatted.

Answer(s): C

Explanation:

Correct answer – C. The media must be physically destroyed.
WORM (Write-Once-Read-Many) media is designed so that once data is written it cannot be altered or overwritten by normal software mechanisms. Because the media’s physical structure prevents overwriting, standard logical erase or re-format operations are ineffective. The only reliable way to guarantee that the data can never be reconstructed is to render the media unrecoverable, which is achieved by physically destroying it (e.g., shredding, crushing, or incinerating). This is explicitly recommended in authoritative guidance (see NIST SP 800-88 Rev. 1 and ISO/IEC 27040).
Why the other options are unsuitable
A – Encryption only makes the data inaccessible, not destroyed. Encryption protects confidentiality but does not remove the bits; a forensic analyst with the correct key could still recover the data, so it does not meet the requirement for destruction.
B – The erase function cannot reliably remove data on WORM media. The erase command only clears the logical address map; the physically written cells remain intact and can be read with specialized hardware, meaning the data is not truly destroyed.
D – Reformatting merely rewrites the file system metadata; on WORM media the underlying cells are immutable, so a reformat cannot delete the original payload.
Resulting impact – Physical destruction provides deterministic, verifiable assurance that no residual data can be reconstructed, which is the standard expected for WORM media retirement in privacy-by-design and data-lifecycle-management frameworks.


Reference:

1. National Institute of Standards and Technology – Guide for Media Sanitization (SP 800-88 Rev. 1), https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final 2. International Organization for Standardization – Information technology – Security techniques – Encryption processing – Part 5: Data at rest encryption (ISO/IEC 27040), https://www.iso.org/standard/72745.html



Which of the following would best improve an organization' s system of limiting data use?

  1. Implementing digital rights management technology.
  2. Confirming implied consent for any secondary use of data.
  3. Applying audit trails to resources to monitor company personnel.
  4. Instituting a system of user authentication for company personnel.

Answer(s): C

Explanation:

Correct option:
C – Applying audit trails to resources to monitor company personnel
Enforces policy through visibility – Audit trails record who accessed what data and when, allowing the organization to verify that data is used only for authorized purposes and to spot deviations instantly.
Enables timely remediation – Detected misuse can be investigated and corrected before broader compliance impact, reinforcing the principle of “use limitation.” Supports accountability – Traceable actions create a deterrent effect and facilitate forensic analysis, which is essential for demonstrating compliance during audits. Directly ties to data-use control mechanisms – By monitoring access and actions on data-containing resources, the organization can enforce purpose-specific controls without altering the data itself.
Why the other options are less suitable
A – Digital Rights Management (DRM) focuses on protecting content from unauthorized copying or distribution, but it does not provide a systematic, personnel-level audit of actual data consumption within business applications.
B – Confirming implied consent for secondary use relies on legal consent rather than technical enforcement; it cannot guarantee that subsequent uses respect the intended purpose, especially when policy changes or exceptions are needed.
D – User authentication ensures that only authorized identities can log in, but it does not continuously monitor how authenticated personnel interact with data, leaving a gap in the assurance of purpose-specific use.


Reference:

NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations – Access Control (AU-6) – https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/final ISO/IEC 27001:2022 Annex A.12.4 – Monitoring and measurement of processes – https://www.iso.org/standard/75478.html



Viewing page 7 of 66
Viewing questions 31 - 35 out of 325 questions


Post your Comments and Discuss IAPP CIPT exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!