CIPP/A Exam Topics and Questions
These IAPP CIPP/A exam topics are organized according to official exam domains to help candidates quickly verify coverage and focus on assessment rather than theory. Each domain is paired with topic-wise CIPP/A sample questions that reflect how objectives are tested in the actual exam. This structure enables efficient review, targeted self-assessment, and rapid identification of weak areas when preparing for the IAPP Certified Information Privacy Professional/Asia certification exam.
Let's Practice Free IAPP CIPP/A Questions Aligned with Official Exam Topics
You start with the conceptual ground: what privacy means in law, how it is defined across jurisdictions, and which international instruments shape the rules you will encounter later. This topic establishes the vocabulary and the lineage of principle-based frameworks. Most candidates underestimate how often exam items turn on the precise wording of a definition or the scope of a term like "personal data" versus "personally identifiable information." The cost here is assuming that similar-sounding concepts are interchangeable. β International frameworks...
You start with the conceptual ground: what privacy means in law, how it is defined across jurisdictions, and which international instruments shape the rules you will encounter later. This topic establishes the vocabulary and the lineage of principle-based frameworks. Most candidates underestimate how often exam items turn on the precise wording of a definition or the scope of a term like "personal data" versus "personally identifiable information." The cost here is assuming that similar-sounding concepts are interchangeable.
β International frameworks and principles
The OECD Guidelines from 1980 and the APEC privacy principles form the backbone of many national regimes in the region. You need to recognise which principles appear in both, where they diverge, and how Fair Information Practices fit into the timeline. The Universal Declaration of Human Rights underpins the argument that privacy is a fundamental right, but exam items focus on how that declaration translates into enforceable obligations rather than its aspirational text. Understanding the hierarchy and the historical sequencing matters because questions often present a scenario and ask which framework applies or which principle was violated first. The examiner expects you to know not just the names but the practical boundaries of each instrument.
β Adequacy determinations and cross-border recognition
Adequacy is the mechanism by which one jurisdiction accepts another's data protection regime as equivalent. The GDPR model is the reference point, and you must know which Asia-Pacific countries have been deemed adequate by Europe and which have not. New Zealand, Canada, Israel, Argentina and Uruguay appear on the adequate list; Australia, Mexico, Korea and Taiwan do not. The EU-U.S. Privacy Shield is included here for context, though its status has shifted over time. Questions test whether you can identify when a transfer requires additional safeguards and when adequacy alone suffices. The trap is treating adequacy as a static list rather than a dynamic assessment tied to specific legal instruments.
β Definitions of personal information
What counts as personal data under EU and Singapore law is not identical to what the United States calls personally identifiable information, and India adds a distinct category for sensitive personal data information. The differences are not cosmetic. An item might describe a data set and ask whether it falls within scope in Hong Kong, Singapore or the EU, and the answer hinges on whether the definition requires identification or mere identifiability, whether it covers legal persons, and whether aggregation or pseudonymisation takes the data out of scope. Sensitive data has its own thresholds: health, biometrics, financial records and other categories trigger heightened obligations, but only if the jurisdiction in question recognises them as sensitive. Memorise the exact terms each regime uses and the boundaries they draw.
How Privacy Fundamentals is tested
Items present a cross-border scenario or a data set and ask you to apply the correct definition or framework. You might see a description of processing activity and be required to identify whether it involves personal data under the PDPA, personal information under Indian law, or personally identifiable information in a U.S. context. The examiner often pairs two jurisdictions and asks which one would treat the data as sensitive or whether adequacy applies. Another common pattern is a question that describes a principle from APEC or the OECD and asks which national law reflects it most closely. Candidates lose marks by conflating terms, by assuming that "personal data" means the same thing everywhere, or by forgetting that adequacy is a formal determination rather than a general judgment about a country's privacy culture. Read each definition carefully and match it to the jurisdiction named in the stem.
The practice test offers several hundred items, and roughly one in six draws on this topic. Because the definitions and frameworks overlap, a single weak spot can cascade into multiple misses. The PDF version lets you compare how different jurisdictions define the same concept side by side, which is faster than flipping between study guides. Both formats are included in one purchase, and a free demo is available so you can confirm the question style before committing.
The question below asks you to match a definition to the jurisdiction that uses it, testing whether you can distinguish personal data from personally identifiable information in context.
In Hong Kong's revised Breach Guidance Note of 2015, what course of action did the Commissioner recommend that companies take immediately after experiencing a breach?
Singapore's Personal Data Protection Act arrived in 2012, later than many regional statutes, and it reflects both APEC principles and a pragmatic approach to commercial data flows. The PDPA applies to private-sector organisations, with significant carve-outs for public agencies and specific activities. You will spend time on definitions, exemptions, and the obligations that attach to each stage of the data lifecycle. The Do Not Call Registry and the rules around business contact information are tested more heavily than their word...
Singapore's Personal Data Protection Act arrived in 2012, later than many regional statutes, and it reflects both APEC principles and a pragmatic approach to commercial data flows. The PDPA applies to private-sector organisations, with significant carve-outs for public agencies and specific activities. You will spend time on definitions, exemptions, and the obligations that attach to each stage of the data lifecycle. The Do Not Call Registry and the rules around business contact information are tested more heavily than their word count in the outline suggests, because they produce fact patterns that candidates misread.
β Structure, scope and key definitions
The PDPA grew out of the 2002 NIAC report, which proposed a model code for the private sector. Its extraterritorial reach is narrower than the GDPR's, but it does cover organisations outside Singapore that process data about Singapore residents in certain circumstances. Personal data is defined broadly; business contact information has a carve-out that candidates often misapply. A data intermediary processes data on behalf of another organisation and is subject to distinct obligations. Publicly available data is exempt, but the threshold for what counts as public is higher than many assume. Survivorship provisions address data about deceased individuals. The Do Not Call Registry governs specified messages, which include marketing by voice call, text and fax, but not all commercial communication. Employment settings have their own rules, and several exemptions remove entire categories of processing from the PDPA's scope: public-sector activity, emergency response, national interest, investigations, evaluative purposes, and journalism. Each exemption has boundaries, and exam items test where those boundaries lie.
β Core obligations and the data lifecycle
Organisations must appoint a data protection officer and train staff on PDPA requirements. Consent is the default basis for collection, use and disclosure, but exceptions exist for legitimate interests, contractual necessity and legal obligations. Use means doing something with the data for a purpose; disclosure means passing it to a third party. Safeguarding obligations require reasonable security measures, and accountability demands policies, documentation and the ability to demonstrate compliance. Openness requires that individuals can find out how their data is handled. Access and correction rights let individuals inspect and amend their records. Retention limits require deletion when data is no longer needed for a legal or business purpose. Transfer out of Singapore is permitted if the recipient provides a standard of protection comparable to the PDPA, and the APEC Cross-Border Privacy Rules and Privacy Recognition for Processors systems offer certification pathways. Data breach notification became mandatory for certain incidents, with prescribed timelines and content requirements.
β Enforcement, guidance and penalties
The Personal Data Protection Commission investigates complaints and conducts audits. It can issue directions, impose financial penalties up to a statutory cap, and publish decisions. The Monetary Authority of Singapore regulates financial institutions separately, issuing notices on anti-money-laundering that include data protection requirements and rules on outsourcing and customer data. Individuals can lodge complaints, and the PDPC can also initiate investigations without a complaint. Commissioner guidance covers consent management, opt-out mechanisms, documentation of purpose changes, and the limits of deemed consent. Penalties and sanctions have increased over successive amendments, and the PDPC's published decisions show a pattern of enforcement focused on security failures, unlawful disclosure, and inadequate consent practices. Policy development includes freedom-of-information legislation that intersects with the PDPA, and the doctrine of privity of contract affects how third-party data processors are held accountable.
How Singapore Privacy Laws and Practices is tested
Items describe a processing scenario and ask whether consent is required, whether an exemption applies, or whether a transfer out satisfies PDPA standards. Business contact information is a frequent trap: candidates assume it is always exempt, but the carve-out is narrow and does not cover all workplace data. The Do Not Call Registry questions test whether a message qualifies as specified and whether an organisation must check the registry before sending it. Data breach notification items ask whether the threshold is met, what must be reported, and to whom. Another pattern is a question that presents a PDPC decision or guidance and asks what obligation was breached or what remedy the commission ordered. The examiner expects you to know the difference between use and disclosure, to recognise when the public-sector exemption applies, and to apply the APEC CBPR framework correctly. Marks are lost by confusing the roles of the PDPC and the MAS, by overstating the scope of the journalism exemption, or by assuming that publicly available data includes anything findable online.
Singapore generates the largest single share of items in this exam, and the practice test reflects that. Working through the full bank lets you see how the PDPA's exemptions and definitions recur across different fact patterns, which is harder to spot when you answer one question at a time. Timed conditions help because the Do Not Call and business contact scenarios require fast reading to separate the relevant facts from the background detail.
The scenario that follows tests whether you can identify when business contact information falls outside the PDPA's main consent requirements and when it does not.
Which of the following topics was NOT addressed in India's Information Technology Act 2000 (IT Act)?
Hong Kong's Personal Data (Privacy) Ordinance predates Singapore's PDPA and has a different structure. The six Data Protection Principles form the core, and the 2012 amendment introduced mandatory rules for direct marketing. Exemptions are extensive, and the Office of the Privacy Commissioner operates with a combination of complaint-driven enforcement and published guidance. The PDPO applies to both public and private sectors, but the scope of the exemptions often narrows that reach in practice. You need to know the DPPs in...
Hong Kong's Personal Data (Privacy) Ordinance predates Singapore's PDPA and has a different structure. The six Data Protection Principles form the core, and the 2012 amendment introduced mandatory rules for direct marketing. Exemptions are extensive, and the Office of the Privacy Commissioner operates with a combination of complaint-driven enforcement and published guidance. The PDPO applies to both public and private sectors, but the scope of the exemptions often narrows that reach in practice. You need to know the DPPs in order, the major exemptions by name, and the commissioner's published positions on data transfer and erasure.
β Legal context and the PDPO framework
Hong Kong's legal system inherits common law traditions, and constitutional protections for privacy are limited. Social attitudes lean toward pragmatism rather than strict data minimisation. Surveillance and identification practices are widespread, and the HKID card is a central part of the infrastructure. The PDPO defines personal data broadly, covering any data relating to an identified or identifiable living individual. Publicly available data is not exempt simply because it is accessible; the test is whether it was lawfully made public. Sensitive personal data has no statutory definition, though the commissioner has issued guidance on categories that warrant extra care. Prescribed consent is required for direct marketing, and the 2012 amendment set out detailed rules for obtaining, recording and honouring that consent. Rights of the data subject include access and correction, but these are subject to exemptions.
β The six Data Protection Principles
DPP1 governs data collection: purpose must be lawful, collection must be necessary, and the individual must be informed. DPP2 requires accuracy and sets retention limits. DPP3 restricts use to the original purpose or a directly related purpose unless the individual consents. DPP4 imposes security obligations, requiring practical steps to prevent unauthorised access, processing, erasure or loss. DPP5 is openness: organisations must make their data policies available. DPP6 grants individuals the right to access their data and to request correction if it is inaccurate. The commissioner's Internet Data Guidance applies these principles to online activity, addressing cookies, tracking and cross-border data flows. The due diligence exemption permits limited processing during mergers and acquisitions without full compliance, but the scope is narrow and time-limited. Guidance on erasure and anonymisation sets out when data must be deleted and what techniques satisfy the standard for anonymisation.
β Exemptions and special cases
Staff planning and employment-related processing are exempt from some DPPs, as are personal references. The relevant process exemption covers evaluative activities like exam marking. Crime prevention and investigation are exempt, as are legal proceedings and legal professional privilege. Self-incrimination protections limit compelled disclosure. Health emergencies allow processing without consent. Statistics and research have a carve-out if the data is not used to make decisions about individuals. Journalism and news media are exempt from most obligations, but the exemption does not cover commercial marketing dressed up as editorial content. Each exemption has conditions, and questions test whether those conditions are met in a given scenario. Employment matters generate frequent misunderstanding because the exemption is partial, not blanket.
β Enforcement and cross-border transfer
The Office of the Privacy Commissioner for Personal Data investigates complaints, issues enforcement notices, and publishes decisions. The Octopus Rewards case is a landmark: the commissioner found that the company had used customer data for marketing without proper consent, and the decision clarified the limits of deemed consent. The commissioner's guidance on consent mechanisms, opt-out procedures and purpose changes is detailed and frequently cited in exam items. The Personal Data (Privacy) Advisory Committee advises on policy development. Section 33 of the PDPO restricts transfer of personal data outside Hong Kong unless the recipient jurisdiction provides adequate protection or the data subject consents. Data processors acting on behalf of data users are subject to contractual requirements, and model contracts are available. Law reform proposals include a third-party benefit exception to the privity rule, which would allow individuals to enforce processor obligations directly. Privacy incidents have prompted the commissioner to raise expectations around breach response, notification and remediation.
How Hong Kong Privacy Laws and Practices is tested
Items ask you to match a fact pattern to one of the six DPPs, to identify which exemption applies, or to determine whether a cross-border transfer satisfies Section 33. Direct marketing questions test whether prescribed consent was obtained correctly and whether the opt-out was honoured. The employment exemption is a common trap: candidates assume it covers all workplace data, but it is limited to specific purposes like staff planning and does not extend to marketing employees' personal data. Another frequent pattern is a scenario involving the Octopus Rewards decision or another published ruling, asking what the commissioner found or what remedy was ordered. Data erasure questions test whether retention was justified and whether anonymisation met the standard. Security breaches appear in items that ask whether DPP4 was satisfied or whether an enforcement notice was warranted. Marks are lost by confusing directly related purposes with new purposes, by overstating the scope of the journalism exemption, or by assuming that publicly available data is always exempt.
The Hong Kong section accounts for a substantial portion of the question bank, and the DPPs recur across multiple scenarios. The practice test lets you see how the same principle is tested in different contexts, which builds pattern recognition faster than isolated study. The PDF format is useful for reviewing the commissioner's published decisions and matching them to the relevant DPP or exemption.
The item below presents a data transfer scenario and asks whether Section 33 permits the transfer or whether additional steps are required.
India's Digital Personal Data Protection Act arrived in 2023, replacing the data protection provisions in the Information Technology Act. The DPDPA introduces a fiduciary model, grants enumerated rights to data principals, and establishes a Data Protection Board with enforcement powers. Children's data receives special treatment, and the rules issued under the DPDPA fill in operational detail on consent, security, breach notification and cross-border transfer. Exemptions are broad, especially for state agencies and public-interest processing. You must know the structure of...
India's Digital Personal Data Protection Act arrived in 2023, replacing the data protection provisions in the Information Technology Act. The DPDPA introduces a fiduciary model, grants enumerated rights to data principals, and establishes a Data Protection Board with enforcement powers. Children's data receives special treatment, and the rules issued under the DPDPA fill in operational detail on consent, security, breach notification and cross-border transfer. Exemptions are broad, especially for state agencies and public-interest processing. You must know the structure of the DPDPA, the rights it grants, and the enforcement mechanisms the Board can deploy.
β Constitutional and statutory foundations
India's legal system is federal, and privacy protections have evolved through constitutional interpretation and statute. Article 21 of the Constitution has been read to include a right to privacy, confirmed in the 2017 Puttaswamy judgment by the Supreme Court. The Right to Information Act 2005 and the Protection of Human Rights Act 1993 provide indirect protections. Surveillance and identification are central to the state's infrastructure: the Unique Identification Authority of India issues Aadhaar numbers, a biometric identity system that has been both challenged and upheld in court. The Credit Information Companies (Regulation) Act 2005 governs credit reporting. The Information Technology Act 2000 and its 2008 amendment introduced data protection obligations for body corporates, later replaced by the DPDPA. Social attitudes toward privacy are shaped by the tension between individual rights and state security, and the Puttaswamy decision is cited frequently in exam scenarios.
β The DPDPA framework and data principal rights
The DPDPA replaces Section 43A of the IT Act and applies to processing of digital personal data. Data principals have the right to access information about their data, to correct or erase it, to have grievances addressed, to nominate others to act on their behalf, and to withdraw consent. Children's data requires verifiable parental or guardian consent, with specific rules in the DPDPA Rules. Exemptions remove certain processing from the DPDPA's scope: publicly available personal data, research and statistical purposes including AI training, archiving, judicial and investigative activities, mergers and acquisitions, and non-digital data. The breadth of these exemptions is significant, and questions test where the boundaries lie. The public-sector exemption is particularly wide, and Rule 5 specifies when state agencies may process data without consent.
β DPDPA Rules and operational obligations
Rules 3 and 4 govern privacy notices and consent, setting out what information must be provided and in what form. Rule 5 lists exemptions for state agencies. Rules 6 and 7 require security safeguards and set notification procedures for data breaches, including timelines and the content of notifications. Rule 8 establishes retention periods and erasure obligations. Rule 9 requires contact information for the Data Protection Officer to be published. Rules 10 and 11 address parental consent for children and enumerate exceptions where consent is not required. Rule 12 mandates annual data protection impact assessments and audits for certain data fiduciaries. Rule 13 details how data principals exercise their rights to access, correct and delete data. Rule 14 regulates cross-border transfer, requiring that the recipient jurisdiction provide adequate protection or that the data principal consent. Rule 15 carves out research purposes. Rules 16 to 21 establish the Data Protection Board, its composition, procedures and the process for appeals. Rule 22 allows the government to request information from data fiduciaries for purposes listed in the Seventh Schedule. The Intermediary Guidelines and Digital Media Ethics Code Rules 2021 remain in force and intersect with the DPDPA on issues like content moderation and user data.
β Enforcement, regulators and penalties
The Ministry of Communication and Information Technology and the Department of Electronics and Information oversee digital policy. The Telecom Regulatory Authority of India operates the Do Not Call Registry and has issued rulings on net neutrality and services like Free Basics. The Data Protection Board, established under the DPDPA, hears complaints, conducts investigations and imposes penalties. Chapter VIII of the DPDPA sets out sanctions, which can be substantial. Grievance officers are required for certain intermediaries and must respond to complaints within prescribed timelines. Consent management includes opt-out mechanisms, documentation of purpose changes, and the limits of deemed consent. Policy development is ongoing, particularly around data transfers and the doctrine of privity for third parties. The public-sector exemption is a recurring issue in enforcement, as is the scope of the research exemption.
How India Privacy Law and Practices is tested
Items present a processing activity and ask whether it falls within the DPDPA's scope or is covered by an exemption. Children's data questions test whether parental consent was obtained correctly and whether any exception applies. Data breach notification items ask whether the threshold in Rules 6 and 7 is met, what must be reported, and to whom. Cross-border transfer questions test Rule 14, asking whether adequacy applies or whether consent is required. Another pattern is a scenario involving a state agency, asking whether the public-sector exemption or Rule 5 permits the processing. The Data Protection Board's powers and procedures appear in items that describe a complaint or an investigation and ask what remedy is available. The research exemption is a trap: candidates assume it is broad, but it is limited to processing that does not involve decisions about individuals. Marks are lost by confusing the DPDPA with the old IT Act regime, by overstating the scope of the publicly available data exemption, or by failing to recognise when the Intermediary Guidelines apply alongside the DPDPA.
India's DPDPA is new, and exam items test whether you can apply the rules rather than recite the statute. The question bank includes scenarios that isolate each of the exemptions and each data principal right, which is the fastest way to check whether you can distinguish them under time pressure. The demo version covers a representative sample so you can see the question style before you pay.
The scenario below asks whether a state agency's processing falls within the public-sector exemption or whether the DPDPA's consent requirements apply.
This topic pulls together the jurisdictions you have studied and asks you to compare their approaches to shared issues. Sensitive data, children's data, natural versus legal persons, breach notification, public registers, surveillance, data processing, export rules, intermediaries and extraterritorial reach all appear here. The outline also covers rights of the data subject and the scope of exemptions, particularly the domestic use carve-out and the treatment of publicly available information. The examiner expects you to move between jurisdictions fluently, recognising where...
This topic pulls together the jurisdictions you have studied and asks you to compare their approaches to shared issues. Sensitive data, children's data, natural versus legal persons, breach notification, public registers, surveillance, data processing, export rules, intermediaries and extraterritorial reach all appear here. The outline also covers rights of the data subject and the scope of exemptions, particularly the domestic use carve-out and the treatment of publicly available information. The examiner expects you to move between jurisdictions fluently, recognising where they align and where they diverge. Questions test whether you can apply the correct rule when a scenario involves multiple jurisdictions or when a single fact pattern could be answered differently depending on where the processing occurs.
β Protections for sensitive and special categories
Sensitive data protections vary by jurisdiction. India defines sensitive personal data information explicitly and imposes heightened obligations. Singapore and Hong Kong recognise certain categories as requiring extra care, but neither has a statutory definition of sensitive data equivalent to the GDPR's special categories. Children's data receives distinct treatment in all three jurisdictions: the DPDPA requires verifiable parental consent, Singapore's PDPA has rules for obtaining consent from minors, and Hong Kong's PDPO applies the general principles with commissioner guidance on age-appropriate communication. Natural persons are covered everywhere, but legal persons are generally excluded. The boundary matters when data relates to a sole trader or a small partnership, because some regimes treat that data as personal and others do not.
β Breach notification and public registers
Data breach notification is mandatory in Singapore and India, with prescribed timelines, thresholds and content requirements. Hong Kong does not have a statutory breach notification obligation, though the commissioner's guidance sets expectations for voluntary reporting. Public registers exist in all three jurisdictions, and the treatment of data drawn from them differs. Publicly available information is exempt from some obligations in Singapore, but the threshold is higher than candidates assume. Hong Kong applies a lawful publication test, and India's exemption for publicly available data is narrower still. Questions test whether data from a public register can be used for a new purpose without consent, and the answer depends on which jurisdiction's law applies.
β National identity systems and surveillance
Singapore's SingPass, Hong Kong's HKID and India's UIDAI all function as national identity systems, and each is governed by distinct rules. Hong Kong's Privacy Commissioner issued a Code of Practice on Identity Card Number and Other Personal Identifiers in 1997, limiting when organisations can demand the HKID number. Singapore's SingPass is used for government services, and its use by private organisations is restricted. India's Aadhaar has been the subject of constitutional challenges, and its use is now regulated by statute and Supreme Court rulings. Surveillance practices differ: Singapore permits extensive monitoring in public spaces, Hong Kong's surveillance is widespread but less centralised, and India's surveillance framework is shaped by security concerns and the Puttaswamy judgment.
β Data export, intermediaries and extraterritorial reach
Data processing and export rules require that the recipient jurisdiction provide adequate protection or that the data subject consent. Singapore uses the APEC CBPR system, Hong Kong applies Section 33, and India's Rule 14 sets the standard. Intermediaries are defined differently: Singapore's data intermediary, Hong Kong's data processor and India's data processor under the DPDPA all process data on behalf of another party, but the obligations and liabilities differ. Extraterritorial operations are narrowest in Hong Kong, broader in Singapore, and broadest in India, where the DPDPA can apply to processing outside India if it involves offering goods or services to data principals in India. Questions test whether a foreign organisation is subject to local law and whether a transfer satisfies the applicable standard.
β Rights of the data subject and exemptions
Domestic use exemptions exist in Hong Kong and Singapore, removing household processing from regulatory scope. The breadth of other exemptions varies significantly. Hong Kong exempts Chinese central government organisations and gives media a wide berth. Singapore's public-sector exemption is broad, covering public agencies and public authorities, and extends to certain businesses contracted by the government. Publicly available information is treated generously in Singapore, less so in Hong Kong and India. India's public-sector exemption is the widest, and Section 17(3) of the IT Act allowed the government to exempt specific businesses, including startups, from certain obligations. The DPDPA continues this pattern with exemptions for state agencies and research purposes. Each exemption has conditions, and questions test whether those conditions are met in a cross-jurisdictional scenario.
How Common themes among principle frameworks is tested
Items describe a scenario involving two or more jurisdictions and ask which rule applies, whether an exemption is available in one but not the other, or how the same fact pattern would be resolved differently depending on where the processing occurs. Sensitive data questions test whether a category is recognised in each jurisdiction and what obligations attach. Children's data items ask whether parental consent is required and whether the mechanism used satisfies the local standard. Breach notification questions test whether the obligation exists, what triggers it, and what must be reported. Data export scenarios ask whether adequacy applies, whether APEC CBPR certification suffices, or whether consent is required. Intermediary questions test whether the organisation is a processor or a controller and what liability follows. Extraterritorial reach items ask whether a foreign organisation is subject to local law and on what basis. Candidates lose marks by assuming that similar-sounding rules are identical, by forgetting which jurisdiction has a breach notification obligation, or by misapplying an exemption from one regime to another.
This topic draws on all four jurisdictions, and the practice test reflects that by mixing them within single scenarios. Seeing how the same issue is handled differently across Singapore, Hong Kong and India helps you avoid conflating the rules, which is the most common error in cross-jurisdictional items. The PDF lets you compare the exemptions and definitions side by side, which is faster than working from separate notes.
The question below presents a data export scenario involving two jurisdictions and asks whether the transfer satisfies both regimes or whether additional steps are required.
Ready to Start Practicing?
Access all questions and start your exam preparation journey
Upgrade to Full CIPP/A Exam Questions π