CIPM Practice Questions (Sample Questions)

Practice questions are indispensable for good exam preparation. Below you will find thirty IAPP style CIPM practice questions including two scenario questions. At the very bottom of the page you can download the questions in PDF.

The sample questions are part of our CIPM online training course.

Use the following scenario to answer questions 10-14.

Philip lives in the state of California and owns a gaming website. Most of his customers are between the age of 10 and 35. Philip is unfamiliar with privacy laws and wants to ensure that his business is compliant for operating in the US and especially California. A small number of customers live in the EU. Philip collects personal information for the purpose of directly marketing various games and accessories to his customers.

Philip has a privacy notice that he emails to new customers once they submit their email address at the start of membership sign-up. His notice contains information about his website, what information is processed, and how the data is used after collection.

Philip uses a popular credit card processing company for all his financial transactions and believes they are compliant regarding financial privacy laws so that he does not need to do anything additional to protect customers.

Philip needs a privacy professional to guide him through various California and other laws, so he understands his responsibilities regarding customer privacy on his website.

Use the following scenario to answer questions 26-30.

Maria is the new Data Protect Officer at her company. The DPO is also the privacy team leader. Maria has been given new business objectives that the company is focusing on for the next year. Maria wants to map each business objective to the existing reports produced throughout the company so she can see if there are gaps requiring new reports.

Maria also wants to check the reverse and determine if the teams are developing reports that are no longer tied to business objectives. There have been some recent issues of management making business decisions based on the available metrics when it is clear the managers making the decision did not fully understand the limitations of the metric.

Lastly, the company will have an external auditor at the end of the year for recertification. The audit is extremely important since nearly all the company’s biggest clients require TQM or ISO certification to be eligible to bid on projects.

