The CIPP-US exam, offered by IAPP (International Association of Privacy Professionals), validates your expertise in U.S. privacy law and regulations. This certification demonstrates that you understand the legal landscape governing data collection, use, and protection across federal and state jurisdictions. Whether you work in compliance, legal, technology, or business operations, the Certified Information Privacy Professional/United States credential signals competency to employers and peers. This page guides you through the exam syllabus, question formats, and a focused preparation strategy to help you pass with confidence.
Use this topic map to guide your study for IAPP CIPP-US (Certified Information Privacy Professional/United States) within the Certified Information Privacy Professional path.
The CIPP-US exam measures both foundational knowledge and the ability to apply privacy principles to realistic business situations. Questions progress in difficulty and require you to think critically about compliance decisions.
Questions become progressively harder as you advance, rewarding both breadth of knowledge and depth of practical reasoning.
An effective study routine maps the seven core topics to a realistic timeline, allowing you to build knowledge progressively and test yourself frequently. Dedicate time each week to a different topic, then integrate concepts across the broader privacy landscape.
Explore other IAPP certifications: view all IAPP exams.
Strengthen your preparation with up-to-date resources from validexamdumps.com. These materials align to CIPP-US and cover practical scenarios with clear explanations.
Visit the exam page to download the PDF, Online Practice Test, or get a bundle discount for both formats: Certified Information Privacy Professional/United States.
Federal Privacy Laws and State Privacy Laws typically represent the largest portion of the exam, reflecting their importance in daily compliance work. Government and Court Access to Private-Sector Information and Limits on Private-Sector Collection and Use of Data also carry significant weight. Balance your study time accordingly, spending more hours on these high-impact areas while ensuring you have solid foundational knowledge across all topics.
In practice, you start with federal baseline requirements (GLBA, HIPAA, FCRA), then layer on state-specific rules (CCPA, VCCPA), and finally apply industry-specific policies to Workplace Privacy and data handling. Government requests often trigger all three: you must know federal disclosure rules, state privacy law exemptions, and your own retention policies. Understanding these connections helps you answer scenario-based questions and handle actual compliance scenarios.
Direct experience with privacy policies, data handling procedures, or compliance audits strengthens your ability to apply exam concepts. If you lack hands-on experience, prioritize studying real-world case studies and scenario questions that show how laws apply to common business situations. Reading actual privacy policies and compliance frameworks (available online) also builds practical intuition without requiring a job change.
Candidates often confuse federal law scope with state law scope, miss exemptions and exceptions in statutes, or fail to distinguish between private-sector and government obligations. Another frequent error is misidentifying which law applies to a given fact pattern. Avoid these by carefully reading scenario details, noting keywords like "employee" or "health information," and reviewing exemption lists during practice.
In your final week, take one full-length timed practice test to simulate exam conditions and identify any remaining gaps. Spend the next three days reviewing only your weak topics and re-reading explanations for questions you missed. In the last two days, do a light review of high-weight topics (Federal and State Privacy Laws) without introducing new material. Get adequate sleep the night before the exam; fatigue hurts reasoning more than last-minute cramming helps.
Which of the following best describes an employer's privacy-related responsibilities to an employee who has left the workplace?
A financial services company install "bossware" software on its employees' remote computers to monitor performance. The software logs screenshots, mouse movements, and keystrokes to determine whether an employee is being productive. The software can also enable the computer webcams to record video footage.
Which of the following would best support an employee claim for an intrusion upon seclusion tort?
In this case, option A would best support an employee claim for an intrusion upon seclusion tort, because the webcam is enabled to record video any time the computer is turned on, regardless of whether the employee is working or not, or whether the employee is in a private or public place. This would be an intentional and highly offensive intrusion into the employee's seclusion or private affairs, and would likely cause the employee distress or anxiety.
The Family Educational Rights and Privacy Act (FERPA) requires schools to do all of the following EXCEPT?
FERPA requires schools to do all of the following:
FERPA does not require schools to do the following:
Therefore, the correct answer is D. Obtain student authorization before releasing directory information in their records.
Family Educational Rights and Privacy Act (FERPA)
IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 4: Federal Privacy Laws, Section 4.3: The Family Educational Rights and Privacy Act (FERPA)
A student has left high school and is attending a public postsecondary institution. Under what condition may a school legally disclose educational records to the parents of the student without consent?
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of students' educational records. FERPA generally requires schools to obtain written consent from students before disclosing their records to third parties, such as parents. However, FERPA allows some exceptions to this rule, such as when the disclosure is for health or safety emergencies, or when the student is still a dependent for tax purposes. According to FERPA, a school may disclose educational records to the parents of a student who is claimed as a dependent on the parents' most recent federal income tax return, without the student's consent. This exception applies regardless of the student's age or enrollment status at a postsecondary institution.Reference:
IAPP CIPP/US Body of Knowledge, Section III, C, 2
[IAPP CIPP/US Study Guide, Chapter 3, Section 3.5]
[FERPA, 34 CFR 99.31(a)(8)]
What is a key way that the Gramm-Leach-Bliley Act (GLBA) prevents unauthorized access into a person's back account?
The GLBA prohibits financial institutions from disclosing a consumer's account number or similar form of access number or access code to any nonaffiliated third party for use in telemarketing, direct mail marketing, or other marketing through electronic mail to the consumer. This restriction is intended to prevent unauthorized access to a person's bank account by third parties who may use the account number to initiate fraudulent transactions or identity theft. The GLBA also requires financial institutions to implement safeguards to protect the security, confidentiality, and integrity of customer information, and to notify customers and regulators in the event of a security breach involving such information.Reference:
IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 2: Limits on Private-sector Collection and Use of Data, Section 2.3: Financial Privacy, p. 49-50
IAPP CIPP/US Body of Knowledge, Domain II: Limits on Private-sector Collection and Use of Data, Objective II.C: Identify the privacy requirements for financial institutions, Subobjective II.C.2: Identify the restrictions on disclosure of account numbers, p. 14
IAPP CIPP/US Exam Blueprint, Domain II: Limits on Private-sector Collection and Use of Data, Objective II.C: Identify the privacy requirements for financial institutions, Subobjective II.C.2: Identify the restrictions on disclosure of account numbers, p. 5