CIPP/US 2023 Exam Questions and
Answers
Fair Information Practices (FIP) - What three elements should organizations address
with regards of rights of individuals? - Answer-Notice
Choice & Consent
Data Subject Access
Notice (context: FIP) - Answer-provide notice of privacy policies/procedures and identify
purpose for which PI is collected, used, retained & disclosed
Choice & Consent (context: FIP) - Answer-describe choices available and get implicit or
explicit consent w/respect to collection, use, retention & disclosure of PI, particularly for
disclosure to other data controllers
Data Subject Access (context: FIP) - Answer-provide individuals w/access to their PI for
review & update
Information Life Cycle - what three elements should organizations address? - Answer-
Collection
Use and Retention
Disclosures
Management Administration - Answer-orgs should define, document, communicate, and
assign accountability for the privacy policies and procedures
US Health & Welfare FIPs (1973) - Answer-i) no secret PI recordkeeping system
ii) DS must be able to find out what PI is in record/how it's used
iii) DS can prevent purpose scope creep w/out consent
iv) DS can correct/amend
v) org must assure integrity and security
OECD (1980) - define - Answer-Organisation for Economic Co-operation and
Development Guidelines
OECD (1980) - scope - Answer-a) collection limitation
b) data quality (relevant to purpose)
c) purpose specification
d) use limitation
e) security safeguards
f) openness
g) individual participation
h) accountability
Answers
Fair Information Practices (FIP) - What three elements should organizations address
with regards of rights of individuals? - Answer-Notice
Choice & Consent
Data Subject Access
Notice (context: FIP) - Answer-provide notice of privacy policies/procedures and identify
purpose for which PI is collected, used, retained & disclosed
Choice & Consent (context: FIP) - Answer-describe choices available and get implicit or
explicit consent w/respect to collection, use, retention & disclosure of PI, particularly for
disclosure to other data controllers
Data Subject Access (context: FIP) - Answer-provide individuals w/access to their PI for
review & update
Information Life Cycle - what three elements should organizations address? - Answer-
Collection
Use and Retention
Disclosures
Management Administration - Answer-orgs should define, document, communicate, and
assign accountability for the privacy policies and procedures
US Health & Welfare FIPs (1973) - Answer-i) no secret PI recordkeeping system
ii) DS must be able to find out what PI is in record/how it's used
iii) DS can prevent purpose scope creep w/out consent
iv) DS can correct/amend
v) org must assure integrity and security
OECD (1980) - define - Answer-Organisation for Economic Co-operation and
Development Guidelines
OECD (1980) - scope - Answer-a) collection limitation
b) data quality (relevant to purpose)
c) purpose specification
d) use limitation
e) security safeguards
f) openness
g) individual participation
h) accountability