CIPP/US Exam Topics and Questions
These IAPP CIPP/US exam topics are organized according to official exam domains to help candidates quickly verify coverage and focus on assessment rather than theory. Each domain is paired with topic-wise CIPP/US sample questions that reflect how objectives are tested in the actual exam. This structure enables efficient review, targeted self-assessment, and rapid identification of weak areas when preparing for the IAPP Certified Information Privacy Professional/United States certification exam.
Let's Practice Free IAPP CIPP/US Questions Aligned with Official Exam Topics
This is where U.S. privacy starts to look different from the unified models you see elsewhere. The framework here is sectoral, not omnibus. There is no single privacy law, no single regulator, and no unified set of definitions. You work with overlapping statutes, competing enforcement agencies, and principles that shift depending on which sector you are operating in. Exam pressure comes from knowing which authority applies when, and from spotting the boundary where one regime ends and another begins. How...
This is where U.S. privacy starts to look different from the unified models you see elsewhere. The framework here is sectoral, not omnibus. There is no single privacy law, no single regulator, and no unified set of definitions. You work with overlapping statutes, competing enforcement agencies, and principles that shift depending on which sector you are operating in. Exam pressure comes from knowing which authority applies when, and from spotting the boundary where one regime ends and another begins.
How The U.S. Privacy Environment is tested
Questions pull you into scenarios where multiple frameworks could apply and ask you to identify which one governs. You will face fact patterns involving federal versus state authority, sectoral scope, and enforcement jurisdiction. The trap is assuming a single answer applies across contexts. A healthcare provider under HIPAA does not follow the same rules as a retailer under FTC oversight, even when both handle sensitive data. Candidates lose marks by defaulting to the most familiar law rather than reading the scenario carefully. You must recognise the structure of U.S. privacy law as fragmented by design, then apply the correct piece. Items test whether you can distinguish regulatory authority from common-law principles, and whether you understand that information management practices vary by sector and enforcement mechanism.
The practice test gives you early exposure to how these jurisdictional questions are framed. Seeing the pattern of sectoral splits across multiple items helps you build the reflex to ask which framework applies first, rather than jumping to substance. The PDF version lets you review coverage across all three sub-topics without committing to purchase.
The question below turns on distinguishing the scope of federal authority from the principles that guide information handling in practice.
When does the Telemarketing Sales Rule require an entity to share a do-not-call request across its organization?
Federal privacy law in the U.S. is built around sectors, not principles. Each industry has its own statute, its own definitions, and its own enforcement structure. The FTC operates through Section 5 unfairness and deception authority. Healthcare runs on HIPAA and the HITECH Act. Financial services answer to GLBA and a roster of banking regulators. Education is governed by FERPA. Telecommunications and marketing bring in the TCPA, CAN-SPAM, and COPPA. The cost is not in memorising these statutes; it is...
Federal privacy law in the U.S. is built around sectors, not principles. Each industry has its own statute, its own definitions, and its own enforcement structure. The FTC operates through Section 5 unfairness and deception authority. Healthcare runs on HIPAA and the HITECH Act. Financial services answer to GLBA and a roster of banking regulators. Education is governed by FERPA. Telecommunications and marketing bring in the TCPA, CAN-SPAM, and COPPA. The cost is not in memorising these statutes; it is in knowing where one stops and another starts, and in recognising which regulator has jurisdiction when a fact pattern crosses sector lines.
– FTC consumer protection and enforcement
The FTC does not enforce a privacy statute in the way HIPAA or GLBA operate. It enforces promises. If a company publishes a privacy notice and then acts inconsistently with it, that is deception. If a data practice causes substantial consumer harm that is not outweighed by benefits and is not reasonably avoidable, that is unfairness. Both theories support enforcement actions, consent decrees, and civil penalties. The FTC also has specific authority under COPPA for children's online privacy, requiring verifiable parental consent before collecting personal information from children under thirteen. The exam tests your ability to distinguish when conduct falls under deception versus unfairness, and to recognise the limits of FTC jurisdiction. It does not cover nonprofits, banks, or common carriers directly.
– Healthcare, financial services, education, and telecommunications
HIPAA applies to covered entities and business associates, not to all holders of health information. A fitness app or employer wellness programme may fall outside its scope entirely. GLBA requires financial institutions to provide privacy notices and offer opt-out rights for certain sharing, but the definitions of affiliate and nonaffiliated third party matter more than the notice itself. FERPA protects education records, but only at institutions receiving federal funding, and the consent requirement has exceptions that are frequently tested. The TCPA restricts automated calls and texts, with strict liability and statutory damages that make it a litigation favourite. CAN-SPAM sets rules for commercial email but does not create a private right of action. The exam will ask you to identify which law governs a scenario, what triggers its application, and where its boundaries lie. Mixing up scope or assuming broader coverage than the statute provides is the most common error.
How Federal Privacy Laws is tested
Items present a fact pattern and ask which statute applies, or whether a proposed action complies with a specific law. The difficulty is not in recalling that HIPAA exists; it is in determining whether the entity in the scenario is a covered entity, or whether the disclosure falls under a permitted use. You will see questions that hinge on the difference between a business associate and a vendor outside HIPAA's reach, or between an affiliate and a nonaffiliated third party under GLBA. The FTC questions test whether you can distinguish deception from unfairness, and whether you recognise the limits of FTC jurisdiction. FERPA items turn on consent exceptions. TCPA questions focus on what constitutes prior express written consent and which calls are exempt. Candidates lose marks by applying the wrong statute to the scenario, or by assuming a law covers more than it does. Read for the sector first, then for the specific trigger.
A full question bank lets you see how each statute is tested in isolation and in combination. The volume matters here because the exam rotates through five sectors, and you need enough repetitions to distinguish HIPAA scope questions from GLBA notice requirements from FERPA consent rules.
The scenario below requires you to identify which federal statute governs the activity described and whether a specific compliance obligation applies.
Why was the Privacy Protection Act of 1980 drafted?
Once data is in private hands, the question becomes who else can demand it. Law enforcement, national security agencies, and civil litigants all have pathways to access private-sector information, each with different procedural safeguards and different standards. The Fourth Amendment constrains government searches, but the third-party doctrine limits its protection. National security tools like FISA operate under separate rules. Civil discovery has its own framework, with privacy claims balanced against the right to evidence. The exam tests whether you know...
Once data is in private hands, the question becomes who else can demand it. Law enforcement, national security agencies, and civil litigants all have pathways to access private-sector information, each with different procedural safeguards and different standards. The Fourth Amendment constrains government searches, but the third-party doctrine limits its protection. National security tools like FISA operate under separate rules. Civil discovery has its own framework, with privacy claims balanced against the right to evidence. The exam tests whether you know which process applies, what standard must be met, and where privacy protections weaken or disappear entirely.
How Government and Court Access to Private-sector Information is tested
Questions describe a government request or subpoena and ask whether it is lawful, what standard applies, or what procedural step is required. You will see fact patterns involving warrants, administrative subpoenas, national security letters, and civil discovery requests. The trap is assuming that all government access requires a warrant, or that all private-sector data enjoys the same level of protection. The third-party doctrine means that information shared with a service provider may lose Fourth Amendment protection. National security letters come with gag orders and limited judicial review. Civil litigants can obtain discovery even when the data is sensitive, provided relevance and proportionality are met. Candidates lose marks by overstating privacy protections or by failing to distinguish law enforcement access from national security access. You must know which authority is being invoked and what legal standard governs it.
Timed practice helps here because these questions often present long fact patterns with multiple legal pathways. Working under exam conditions trains you to isolate the relevant authority quickly and apply the correct standard without second-guessing.
The fact pattern below involves a government demand for information. You must determine what legal process is required and whether the request is valid under the applicable framework.
Employment is where privacy expectations meet employer control, and the balance tilts heavily toward the employer. Federal law offers limited protection. Most workplace privacy rules come from state statutes, common-law claims, and sector-specific obligations. The exam focuses on what employers may do before, during, and after the employment relationship: background checks, monitoring, drug testing, biometric data collection, and post-termination data retention. The cost comes from failing to recognise when a state law or a specific statute like the FCRA imposes...
Employment is where privacy expectations meet employer control, and the balance tilts heavily toward the employer. Federal law offers limited protection. Most workplace privacy rules come from state statutes, common-law claims, and sector-specific obligations. The exam focuses on what employers may do before, during, and after the employment relationship: background checks, monitoring, drug testing, biometric data collection, and post-termination data retention. The cost comes from failing to recognise when a state law or a specific statute like the FCRA imposes a constraint that general employment-at-will principles do not.
How Workplace Privacy is tested
Items describe an employer practice and ask whether it is lawful, what notice or consent is required, or which statute applies. You will see scenarios involving pre-employment background checks under the FCRA, workplace monitoring of email or location, drug testing, and biometric timekeeping systems. The trap is assuming employees have broad privacy rights in the workplace. They do not, absent a specific statute or state law. The FCRA requires disclosure and consent before obtaining a consumer report for employment purposes, and adverse action procedures if the report is used to deny employment. State laws may require notice before electronic monitoring or restrict biometric data collection. Post-termination, retention obligations and data disposal rules apply. Candidates lose marks by overstating employee privacy rights or by missing the FCRA's procedural requirements. You must know when a statute imposes a duty that general employment law does not.
The PDF format is useful for this topic because you can review the full set of workplace scenarios in one pass and spot the recurring distinction between general employment authority and statutory limits like the FCRA.
The scenario below involves an employer decision about data collection or monitoring. You need to assess whether the practice is lawful and what compliance steps are required.
State law fills the gaps that federal sectoral statutes leave open. Every state can regulate privacy within its borders, and many have. The result is a patchwork of data security statutes, breach notification laws, and comprehensive privacy frameworks modeled on GDPR principles. California leads with the CCPA and CPRA, but other states have followed. The exam tests whether you understand the structure of state authority, the common elements of state privacy and security laws, and the mechanics of breach notification....
State law fills the gaps that federal sectoral statutes leave open. Every state can regulate privacy within its borders, and many have. The result is a patchwork of data security statutes, breach notification laws, and comprehensive privacy frameworks modeled on GDPR principles. California leads with the CCPA and CPRA, but other states have followed. The exam tests whether you understand the structure of state authority, the common elements of state privacy and security laws, and the mechanics of breach notification. The pressure is in knowing what triggers state law application, what obligations it imposes, and how notification timelines and content requirements vary.
How State Privacy Laws is tested
Questions present a data breach or a privacy practice and ask what state law requires, whether notification is mandatory, or what rights a consumer may exercise. You will see scenarios involving breach notification triggers, the definition of personal information, encryption as a safe harbor, notification timing, and content requirements. Comprehensive state privacy laws like the CCPA test your knowledge of consumer rights, opt-out mechanisms, and the definition of sale. The trap is assuming uniformity across states. Breach notification laws vary in scope, timing, and exemptions. Some states require notification to the attorney general or a credit bureau. Encryption may exempt a breach from notification in one state but not another. The CCPA and its successors impose rights that do not exist under federal law or in other states. Candidates lose marks by applying a generic rule instead of reading for the specific state law in the scenario. You must recognise what triggers the obligation, what the law requires, and where state law diverges from federal frameworks.
State law questions benefit from volume because the exam can pull from any state's breach notification statute or comprehensive privacy law. Repeated exposure across the question bank helps you internalise the common structure and spot the variations that matter.
The question below describes a data incident or privacy practice governed by state law. You must identify what the applicable state statute requires and whether the described action complies.
Ready to Start Practicing?
Access all questions and start your exam preparation journey
Upgrade to Full CIPP/US Exam Questions 🚀