CIPP/US exam questions explained
CIPP/US practice questions help you identify the controlling privacy rule from a short fact pattern. Start with the free ten-question diagnostic, then build speed with the 90-question timed set. That is an average of 100 seconds per question. The main difficulty is choosing the controlling rule inside the United States' sectoral and state-based privacy system.
Before recalling a rule, identify the sector, entity, data, actor and jurisdiction. A familiar law is often the wrong answer because the facts place the record or organisation outside its scope.
The exam and this practice bank
| Measure | CIPP/US exam | Our independent practice material |
|---|---|---|
| Questions | 90 | 604 exam-style questions, including a 90-question timed set |
| Time | 150 minutes | Self-paced with a timed-exam interface |
| Question style | Multiple choice, including scenarios and labelled multi-select items | exam-style questions with worked explanations |
| Coverage | Public Body of Knowledge and blueprint | Federal, state, sector, workplace and government-access topics |
The practice-bank counts describe this site's own material on 29 August 2026. They are not IAPP statistics or a prediction of exam performance.
The scope matrix to build before test day
| Question | Examples to identify | Why it changes the answer |
|---|---|---|
| Which sector? | Health, finance, education, communications, employment | Different federal statutes regulate different activities |
| Which entity? | Covered entity, financial institution, school, employer, platform | A law may cover only defined organisations |
| Which data? | PHI, education record, consumer report, customer information | Protection often follows a defined record type |
| Which jurisdiction? | Federal, state, California or another state | Rights, thresholds and enforcement routes differ |
| Which actor? | FTC, HHS OCR, CFPB, state attorney general, private plaintiff | Authority and available remedies are not interchangeable |
A six-step method for CIPP/US scenarios
- Classify the organisation. Use the statutory entity definition, not its marketing label.
- Classify the record. Decide which legally defined information is involved.
- Identify the activity. Collection, use, disclosure, security, marketing and access can trigger different rules.
- Layer federal and state law. Check pre-emption, exemptions and whether both regimes operate.
- Name the enforcer. Distinguish agency authority, state enforcement and any private right of action.
- Choose the narrow conclusion. Apply only facts stated in the question.
Common distractors
- Every health record is HIPAA data. HIPAA applies to defined entities and information. School records may instead fall under FERPA.
- The FTC is the only privacy enforcer. Sector regulators and state attorneys general may control the scenario.
- A state exemption covers the whole business. Many exemptions attach to an entity, a record or a processing activity, not all three.
- A breach always creates a private claim. Notification, agency enforcement and private remedies must be analysed separately.
Answer in brief
Strong CIPP/US answers identify the regulated entity, data, activity, jurisdiction and enforcer before choosing an option. Read the IAPP CIPP/US certification page.
Apply this decision
A retailer receives a consumer request. Identify the applicable state law and business threshold before selecting the right, notice duty or remedy. Read the source context.
Common mistake
Treating every consumer request as if one nationwide privacy statute governs it.
Related free lessons
Use a repeatable CIPP/US question method
Identify the regulated entity, data, activity, jurisdiction and enforcer. Then compare the legal duties that the facts actually trigger.
Practical example
For a consumer request, determine the applicable state law and business threshold before selecting the right, notice duty or remedy.
Common mistake
Treating every consumer request as if one nationwide privacy statute governs it.
Sources
Related lessons
Continue your CIPP/US preparation
Question review worksheet
Use one row for every missed or uncertain question. Record the rule you needed, not the answer letter.
Nothing entered here is sent or saved by the site.
Primary sources
Reviewed 29 August 2026. This independent guide is not affiliated with IAPP and does not reproduce live exam questions.
Review a common scope problem in HIPAA versus FERPA, then use the 90-question timed practice set.
Sources and study method
This independent study material uses the current published CIPP/US outline, active recall, spaced retrieval and scenario practice. Read the full method. Current sources are identified in the article.
Frequently asked questions
How many questions are on the CIPP/US exam?
The IAPP currently lists 90 questions and 2.5 hours for the CIPP/US exam. Questions are multiple choice, and the IAPP FAQ says some are scenario-based or multi-select.
Are these actual CIPP/US exam questions?
No. This site's questions are exam-style and based on the public Body of Knowledge and primary legal sources. They do not reproduce confidential exam items.
What makes CIPP/US questions difficult?
A scenario may involve several regulators and laws. The candidate must identify the sector, entity, data, actor, jurisdiction and enforcement route before choosing the controlling rule.