exam questions

Exam CIPP-US All Questions

View all questions & answers for the CIPP-US exam

Exam CIPP-US topic 1 question 214 discussion

Actual exam question from IAPP's CIPP-US
Question #: 214
Topic #: 1
[All CIPP-US Questions]

SCENARIO -
Please use the following to answer the next question:

Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customers’ privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.

Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hires Janice, a privacy professional, to help her develop one.

After an initial assessment, Janice creates a first draft of a new policy. Cheryl reads through the draft and becomes concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer’s personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worries Cheryl, since stored personal information often helps her company to serve her customers, even if there are long gaps between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.

Janice understands Cheryl’s concerns and is already formulating some ideas for revision. She tries to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl is skeptical. It seems to her that classifying data and treating each type differently would cause undue difficulties in the company’s day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.

Even though the privacy policy is only a draft, Cheryl is beginning to see that changes within her company are going to be necessary. She tells Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She also expresses interest in employing a layered approach, creating documents listing applicable parts of the new policy for each department.


What is the best reason for Cheryl to follow Janice’s suggestion about classifying customer data?

  • A. It will help the company meet a federal mandate.
  • B. It will help Cheryl’s company to increase revenue.
  • C. It will increase the security of customers’ personal information (PI).
  • D. It will remove the risk of an unintentional disclosure of customer data.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
twiny
3 weeks, 3 days ago
Selected Answer: C
The correct answer is: C. It will increase the security of customers’ personal information (PI) This is the same question as Question #8, but with two choices being replaced. Regardless, the correct answer, in my opinion, is still C. It will increase the security of customers’ personal information (PI). This is because classifying customer data based on sensitivity levels is a foundational privacy practice that enhances data security. By categorizing data (e.g., health information, payment details, contact information), the company can implement tailored security measures for each category.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago