An unhandled error has occurred. Reload X
Skip to main content

Certified Information Privacy Professional/US (CIPP/US) Practice Test

161 questions available

The Certified Information Privacy Professional/United States (CIPP/US) credential, administered by the International Association of Privacy Professionals (IAPP), is the global standard for professionals responsible for US private-sector data privacy laws and regulations. This certification validates a comprehensive understanding of the complex American legal landscape governing data protection, including sectoral federal laws, evolving state-level regulations (notably the California Consumer Privacy Act and its successors), and the intricate frameworks for government access to information. Earning the CIPP/US demonstrates mastery of critical concepts such as data lifecycle management, consumer rights, regulatory enforcement, and compliance program development within the US context. It is recognized by employers, regulators, and courts as a benchmark of competency, signaling that the holder possesses the authoritative knowledge required to navigate compliance challenges, mitigate organizational risk, and implement effective privacy programs in one of the world's most dynamic regulatory environments.

Certification exam
90 Exam questions
2 hours 30 minutes Time Limit
Professional Level
Practice bank
161 Practice Questions
2 hours 41 minutes Practice Time
Start Practice
The bar to clear 300 Official passing score. Aim higher in practice before you book.
qf-import161 practice questions30 answers with a checkable referenceBlueprint 1.0Bank updated 2026-05-04

Sample Questions

Try a few questions to see what the full exam is like.

30 of 161 answers carry a checkable reference.

The U.S. Privacy Environment

In 2025, counsel for a university vendor supporting alumni analytics reviews a launch plan. A website incorrectly states that analytics cookies are disabled by default, and the misstatement affects whether users create accounts. the product owner wants the same workflow on mobile. Which response best addresses the CIPP/US issue involving materiality in deception?

The U.S. Privacy Environment

In 2025, counsel for a cloud service provider supporting a federal contractor reviews a launch plan. A news-style blog operated by a brand pairs a user photo with a headline implying the user bought addiction-treatment products, although the user only bought vitamins. the contract renewal is scheduled for the next quarter. Which response best addresses the CIPP/US issue involving false light?

State Privacy Laws

Under most state breach notification laws, an "encryption safe harbor" applies when breached data was encrypted. However, a company suffers a breach where encrypted data AND the encryption key were both stolen together in the same incident. Does the encryption safe harbor apply?

The U.S. Privacy Environment

In 2025, counsel for a health-tech startup outside HIPAA reviews a launch plan. Support logs containing ID scans are kept indefinitely because storage is cheap and deletion might require engineering work. the security team recently finished tabletop testing. Which response best addresses the CIPP/US issue involving retention limits?

Federal Privacy Laws

A credit-reporting agency (CRA) includes information in a consumer's credit report indicating the consumer had a judgment for $3,500 entered 8 years ago. The consumer disputes this entry as too old. Under the FCRA's maximum reporting period rules, is this entry permissible?

Why This Certification Opens Doors

In an era of heightened regulatory scrutiny and consumer awareness, the CIPP/US credential is a powerful differentiator for career advancement. It provides immediate industry recognition as a subject-matter expert in US privacy law, significantly enhancing credibility with employers, clients, and regulatory bodies. Holders are positioned for leadership roles in privacy, compliance, legal, and security functions, as the certification is frequently listed as a preferred or required qualification for senior positions. It signifies not just theoretical knowledge, but the practical ability to apply legal frameworks to real-world business scenarios, making certified professionals invaluable assets in managing legal risk and building trust. The CIPP/US is often the foundational credential for a privacy career, opening doors to advanced roles and specializations.

Exam Blueprint

01Federal Privacy Laws
02Government and Court Access to Private-sector Information
03State Privacy Laws
04The U.S. Privacy Environment
05Workplace Privacy

Exam Details CIPP-US | 2 hours 30 minutes

Exam Code CIPP-US
Vendor qf-import
Passing Score 300
Time Limit 2 hours 30 minutes
Exam questions 90

Frequently Asked Questions

What are the primary job roles for CIPP/US credential holders?

CIPP/US professionals are sought after for roles such as Privacy Officer/Manager, Compliance Analyst/Manager, Legal Counsel specializing in privacy, Information Security Manager, Data Protection Officer (for US operations), Risk Management Consultant, and Product Manager for privacy-centric features. The credential is applicable across industries including technology, finance, healthcare, retail, and consulting.

How does the CIPP/US differ from other privacy certifications?

The CIPP/US is jurisdiction-specific, offering deep, focused expertise on the United States' unique sectoral and state-based privacy regime. It complements broader, framework-based certifications like the CIPM (focus on program management) or CIPT (focus on technology). The CIPP/US is often the first step, providing the essential legal foundation upon which other specializations are built.

What is the exam format and how is it scored?

The exam consists of 90 multiple-choice questions to be completed in 150 minutes (2.5 hours). It is scored on a scale of 100-500, with a passing score of 300. The questions are a mix of knowledge-based items and scenario-based questions that test application and analysis. Results are provided immediately upon completion at a testing center.

Is professional experience required before taking the CIPP/US exam?

While the IAPP does not formally mandate prior work experience, it is strongly recommended. The exam content and scenario-based questions are designed for professionals who understand organizational context. Most successful candidates have at least 1-2 years of exposure to legal, compliance, IT, security, or related fields.

How long is the certification valid, and what are the maintenance requirements?

The CIPP/US credential is valid for two years from the date of certification. To maintain it, you must earn a minimum of 20 Continuing Privacy Education (CPE) credits every two years and pay a biennial maintenance fee. CPE credits can be obtained through IAPP events, chapter meetings, webinars, teaching, publishing, and other qualifying educational activities.