Want to pass your Certified Information Privacy Professional/United States (CIPP/US) CIPP-US exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
A law enforcement agency subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?
A. SCA
B. ECPA
C. CALEA
D. USA FREEDOM Act
Which statute is considered part of U.S. federal privacy law?
A. The Fair Credit Reporting Act.
B. SB 1386.
C. The Personal Information Protection and Electronic Documents Act.
D. The e-Privacy Directive.
A company based in United States receives information about its UK subsidiary's employees in connection with the centralized HR service it provides. How can the UK company ensure an adequate level of data protection that would allow the restricted data transfer to continue?
A. By signing up to an approved code of conduct under UK GDPR to demonstrate compliance with its requirements, both for the parent and the subsidiary companies.
B. By revising the contract with the United States parent company incorporating EU SCCs, as it continues to be valid for restricted transfers under the UK regime.
C. By submitting to the ICO a new application for the UK BCRs using the UK BCR application forms, as their existing authorized EU BCRs are not recognized.
D. By allowing each employee the option to opt-out to the restricted transfer, as it is necessary to send their names in order to book the sales bonuses.