nerdexam
IAPP

CIPP-US · Question #88

CIPP-US Question #88: Real Exam Question with Answer & Explanation

Sign in or unlock CIPP-US to reveal the answer and full explanation for question #88. The question stem and answer options stay visible for context.

Question

SCENARIO Please use the following to answer the next question: Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asia. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework. Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the B. S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself. The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements. The Board has asked Otto whether the company will need to comply with the new California Consumer Privacy Law (CCPA). What should Otto tell the Board?

Options

  • AThat CCPA will apply to the company only after the California Attorney General determines that it
  • BThat the company is governed by CCPA, but does not need to take any additional steps because
  • CThat business contact information could be considered personal information governed by CCPA.
  • DThat CCPA only applies to companies based in California, which exempts the company from

Unlock CIPP-US to see the answer

You've previewed enough free CIPP-US questions. Unlock CIPP-US for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CIPP-US Practice