What would be an example of an organization transferring the risks associated with a data breach?
Answer(s): C
Why option C is the correct example of risk transferPurchasing breach-related insurance shifts the financial impact of a data breach to an insurer. The organization pays a premium, and the insurer reimburses covered losses (e.g., notification costs, legal fees, remediation, reputational damage). This is a classic risk-transfer mechanism: the organization retains the operational responsibility for preventing breaches, but the monetary consequences are moved to a third-party insurer. Insurance contracts explicitly define coverage limits, deductibles, and exclusions, making the transfer quantifiable and auditable—key criteria for formal risk-transfer strategies identified in privacy frameworks such as ISO/IEC 27701 and the NIST Privacy Framework.Why the other options are not risk-transfer actionsA – Using a third-party to process credit-card transactions primarily reduces the organization’s own processing scope and may lower technical risk, but the liability for a breach may still rest with the organization (or be shared via contractual clauses). It is more a risk-mitigation or outsourcing choice than a pure transfer of financial risk. B – Encrypting sensitive personal data during collection and storage is a risk-reduction (risk-mitigation) control that lowers the likelihood or severity of a breach, but it does not shift the financial or legal consequences of a breach to another party. D – Applying industry-standard data-handling practices improves overall security posture and compliance, yet it remains an internal control measure; it does not involve transferring risk to an external entity.Conclusion – The only option that explicitly transfers the financial risk of a data breach to another party is C – Purchasing insurance to cover the organization in case of a breach .
1. ISO/IEC 27701:2019 – Privacy Information Management System (PIMS) – Requirements and Guidance – Section 5.3 “Risk treatment options including risk transfer”. https://www.iso.org/standard/75175.html 2. National Institute of Standards and Technology (NIST) – Privacy Framework – Chapter 3 “Risk Management”, which describes transferring privacy risks via contractual mechanisms such as insurance. https://www.nist.gov/publications/privacy-framework-version-100These documents provide the standards and guidance that recognize insurance-based risk transfer as a valid approach for managing the financial impact of privacy-related incidents.
Which of the following is considered a client-side IT risk?
Why option C is the correct client-side IT riskPersonal data stored on a corporate device creates a direct privacy exposure at the endpoint: the data is under the employee’s control, may be accessed locally, and can be exfiltrated or lost without the organization’s oversight. This scenario involves data subject consent, purpose limitation, and security controls that must be enforced on the client device, which is a classic “client-side” risk described in privacy-by-design and data-minimization principles. Regulations such as GDPR require that personal data be protected wherever it is processed, including on devices that are not fully managed by the organization, making the storage of personal info on a company laptop a clear client-side risk.Why the other options are not client-side risksA – Security policies focused solely on internal corporate obligations describes a governance gap, but it is a policy-level issue , not a technical exposure that occurs on the client side. B – Adding more applications to a server impacts the server-side attack surface and architecture, not the client device where personal data might reside. D – Using IDs that map to personal data in another database concerns data linkage across systems , which is a data-integration or cross-database risk rather than a risk confined to the client environment.
IAPP – Certified Information Privacy Technologist (CIPT) Study Guide, Chapter 3: Privacy-by-Design and Secure Architecture. https://iapp.org/certificate/c ipt/ NIST Special Publication 800-53 Revision 5, “Privacy Controls for Federal Information Systems and Organizations.” https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
SCENARIOCarol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!"But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. "Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should."Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase."Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"`I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy."Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."What type of principles would be the best guide for Jane's ideas regarding a new data management program?
Answer(s): D
Selected Answer: D – Fair Information Practice Principles (FIPPs)Why D is the Best ChoiceFIPPs embody a comprehensive set of privacy-centric concepts— collection limitation, data quality, purpose specification, use limitation, security, openness, individual participation, and accountability —that directly address the issues raised in the scenario. Jane’s concerns involve protecting customer personal information, ensuring the ability of individuals to control how their data are used, and establishing sound data-management practices ; these are precisely the domains covered by FIPPs. Applying FIPPs enables the design of a data-management program that respects privacy, provides transparency, and implements safeguards (e.g., secure storage, consent mechanisms, data-subject rights), which is essential when integrating with a third-party vendor’s systems.Why the Other Options Are Less SuitableA: Collection limitation principles – Focuses mainly on restricting what data are collected and how it is gathered. While relevant, it does not address the broader set of controls required for data quality, purpose specification, security, and individual rights that Jane must implement. B. Vendor management principles – Concerned with managing relationships and performance of external providers. This is useful for overseeing the outsourced online-sales vendor but does not encompass the privacy-centric framework needed to govern how personal information is handled overall. C. Incident preparedness principles – Deal with planning for and responding to data breaches or security incidents. Although important, they are reactive measures; Jane’s primary need is a proactive, privacy-by-design program that embeds protection into everyday operations.
1. International Association of Privacy Professionals (IAPP) – “Fair Information Practice Principles (FIPPs)” https://iapp.org/resources/article/fair-information-practice-principles/2. U.S. Federal Trade Commission (FTC) – “Protecting Personal Information: A Guide for Business” (covers core privacy principles aligned with FIPPs) https://www.ftc.gov/tips-advice/business-guide/privacy/security/protecting-personal-information-guide-businessesPrepared for CIPT certification exam review; emphasizes precise, exam-style justification.
SCENARIOCarol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!"But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. "Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should."Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase."Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"`I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy."Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."Which regulator has jurisdiction over the shop's data management practices?
Answer(s): A
Why the Federal Trade Commission (FTC) has jurisdictionThe FTC is the primary federal regulator that enforces Section 5 of the FTC Act , which prohibits unfair or deceptive acts or practices in commerce, including shortcomings in privacy and data-security practices . When a business collects, stores, or shares personal information (names, addresses, phone numbers, email addresses) from consumers, the FTC expects reasonable safeguards and transparent notice—standards that Sam’s “safe-deposit-only” approach failed to meet. The FTC’s authority extends to both online and offline consumer-facing activities of a U.S. merchant, regardless of whether the operation is a boutique or an online sales channel. The FTC has issued numerous guidance documents (e.g., “Protecting Personal Information: A 10-StepChecklist”) that require reasonable security measures and consumer control over the collection and use of personal data —both of which Sam and later Jane needed to implement.Why the other options are less appropriateB: Department of Commerce – Responsible for census, economic data collection, and trade promotion; it does not regulate privacy or enforce consumer-privacy protections for commercial entities. C. Data Protection Authority – Such bodies (e.g., GDPR supervisory authorities) exist primarily in the European Union and certain state-level frameworks (e.g., California Consumer Privacy Act enforcement). The United States does not have a single overarching “Data Protection Authority” with nationwide jurisdiction over commercial privacy practices. D. Federal Communications Commission (FCC) – Regulates interstate and international communications (radio, TV, broadband, telephone). While it can touch on privacy in the communications context, its primary mandate is not consumer-privacy enforcement for general retail or e-commerce activities.Conclusion Given that Sam’s and Jane’s operations involved the collection of personal consumer data (names, addresses, contact information) and the need to implement reasonable privacy safeguards , the FTC is the agency with statutory authority to oversee and enforce those data-management practices.
Federal Trade Commission – Bureau of Consumer Protection: https://www.ftc.gov/about-ftc/organization-and-mission/bureau-consumer-protection FTC – “Protecting Personal Information: A 10-Step Checklist”: https://www.ftc.gov/tips-advice/complaint-resolution/0131-protecting-personal-information-10-step-checklist
SCENARIOCarol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!"But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. "Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should."Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase."Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"`I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy."Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."When initially collecting personal information from customers, what should Jane be guided by?
JustificationThe scenario describes Jane’s responsibility to handle personal data that the business collects directly from customers (names, addresses, phone numbers) before any processing or transfer occurs. The foundational privacy principle that governs this initial collection is data-minimization : only the data that is necessary and adequate for the specified purpose should be gathered, and it should be limited to what is required. Jane must therefore ensure that the information collected is strictly relevant to the business’s purposes (e.g., order fulfillment, communication) and that no extraneous data is captured. This principle also informs downstream decisions such as how long to retain the data and how it can be used.Onward transfer rules (Option A) pertain to the disposal or sharing of data after it has been collected and processed, not to the initial act of collection. Digital rights management (Option B) is a technical method for protecting copyrighted digital content; it does not address the scope or limits of personal data collection. Vendor management principles (Option D) involve overseeing third-party processors and ensuring they meet contractual and security obligations—again, a concern that arises after data has been collected, not during the collection stage.Thus, when initially collecting personal information from customers, Jane should be guided primarily by data-minimization principles .
1. International Association of Privacy Professionals – Data Minimization overview: https://iapp.org/resources/data-minimization/ 2. U.S. Federal Trade Commission – Privacy & Data Security: A Practical Guide (Chapter on Data Minimization): https://www.ftc.gov/tips-advice/business-center/privacy-and-security/privacy-and-security-best-practices
A key principle of an effective privacy policy is that it should be?
Technical justificationCorrect answer – A – A privacy policy must be explicit, concrete, and grounded in the organization’s actual data practices . Detail enables data subjects to understand what information is collected, how it is used, with whom it is shared, and what safeguards are applied. This specificity supports informed consent, regulatory compliance, and accountability, and it reduces the risk of misleading statements that could trigger enforcement actions. The policy therefore needs to “cover the majority of likely scenarios” by mapping real-world processing activities to clear notice language.Why B is less suitable – A policy that is “general enough to maximize flexibility” may omit essential details, leaving data subjects unclear about legitimate processing purposes. While flexibility can be valuable during policy drafting, the final published notice must reflect concrete practices; otherwise it can be deemed insufficiently transparent under standards such as the GDPR’s Articles 5-6 and the California Consumer Privacy Act (CCPA).Why C is less suitable – Targeting “external parties as the intended audience” would misplace the primary purpose of a privacy policy. The core audience is the data subject (the individual whose data is being processed) , not third parties. External stakeholders may need summaries or reports, but the notice itself must speak directly to the individual to satisfy transparency requirements.Why D is less suitable – Although legal counsel often helps shape a privacy policy, the primary author should be a cross-functional privacy team that integrates technical, operational, and legal perspectives. Relying primarily on lawyers can produce a document that is legally compliant but technically inaccurate or non-operational, which defeats the policy’s functional purpose of informing data subjects.Conclusion The most appropriate design characteristic for an effective privacy policy is that it be written in enough detail to cover the majority of likely scenarios (Option A) , because only such specificity can satisfy legal transparency obligations, enable meaningful consent, and support demonstrable accountability.
IAPP – “Model Privacy Notice” (2023). https://iapp.org/resources/model-privacy-notice/ NIST Special Publication 800-53 Revision 5 – “Privacy Controls for Federal Information Systems and Organizations” (2020). https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/finalThese documents outline the principles of transparency, specificity, and audience-appropriate disclosure that underpin the recommended answer.
What was the first privacy framework to be developed?
Answer(s): C – Code of Fair Information Practice Principles (FIPPs)The Fair Information Practice Principles (FIPPs) were first formulated in the 1970s (initially by the U.S.Department of Health, Education, and Welfare and later refined by the OECD and other bodies). They represent the earliest systematic articulation of privacy concepts—collection limitation, data quality, purpose specification, security, and openness—that have shaped all later privacy frameworks. Consequently, FIPPs predate the OECD Privacy Principles (1980), the APEC Privacy Framework (2004), and the Generally Accepted Privacy Principles (GAPP, 2005).Option A – OECD Privacy Principles (1980): Although influential and widely cited, they were published after the initial FIPPs formulation. Option B – Generally Accepted Privacy Principles (GAPP) (2005): Developed by industry groups much later, building on earlier concepts such as FIPPs. Option D – APEC Privacy Framework (2004): Introduced after the OECD and GAPP models, focusing on cross-border data-flow rules within the Asia-Pacific region.Thus, the Code of Fair Information Practice Principles (FIPPs) holds the distinction of being the first dedicated privacy framework.
1. U.S. Department of Health, Education, and Welfare. “Records, Computers, and the rights of Individuals.” 1973. https://www.hhs.gov/hipaa/for-professionals/privacy/index.html 2. OECD. “Guidelines on the Protection of Privacy and Transborder Flows of Personal Data.” 1980. https://www.oecd.org/privacy-guidelines/These sources document the historical emergence of FIPPs as the foundational privacy framework.
Which of the following became a foundation for privacy principles and practices of countries and organizations across the globe?
Why option D is the most appropriateGlobal adoption : The Organisation for Economic Co-operation and Development (OECD) issued its Privacy Guidelines (commonly referred to as the OECD Privacy Principles) in 1980. These principles have been explicitly cited as the foundational reference for privacy legislation in dozens of countries, from Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) to Australia’s Privacy Act 1988 and numerous European member-state statutes. Design of privacy frameworks : The OECD Principles introduced the key concepts of collection limitation, data quality, purpose specification, use limitation, security safeguards, openness, cross-border data flow rules, and accountability. These concepts were later codified into many national privacy regimes and into the EU Data Protection Directive’s underlying architecture. Technical alignment with certification bodies : The International Association of Privacy Professionals (IAPP) and other certifying bodies explicitly cite the OECD Privacy Principles as the baseline for privacy program design, audit criteria, and risk-based assessments.Why the other options are less suitableA: The Personal Data Ordinance – This is a specific domestic law (e.g., Singapore’s Personal Data Protection Act analog) and does not serve as a global reference point; its influence is limited to one jurisdiction. B. The EU Data Protection Directive – While influential in Europe, the Directive is a regional regulatory instrument that builds on earlier global concepts (including those of the OECD). It cannot be regarded as the origin of privacy principles worldwide. C. The Code of Fair Information Practices – This set of concepts (collection, data quality, purpose specification, security, openness, and access/redress) helped shape modern privacy theory, but it originated as a set of guidelines for computer-based systems rather than an internationally recognized doctrinal framework. Its adoption was sporadic compared to the systematic uptake of the OECD Principles.Therefore, the OECD Privacy Principles constitute the foundational building block for privacy legislation and practices across the globe, making option D the correct answer.
OECD. Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. https://www.oecd.org/privacy/guideline.htm OECD. Privacy Principles. https://www.oecd.org/privacy/privacy-principles.htm
Share your comments for IAPP CIPT exam with other users:
data quality oecd