Die IAPP Certified Information Privacy Professional/United States (CIPP/US) gilt unter IT-Fachkräften als anspruchsvoll. Mit den Praxisfragen von EchteFrage arbeiten Sie sich auf das tatsächliche Niveau der CIPP-US Prüfung vor und betreten den Prüfungsraum deutlich selbstsicherer.
IAPP CIPP-US Prüfungsübersicht:
| Zertifizierungsanbieter: | IAPP (International Association of Privacy Professionals) |
|---|---|
| Prüfungsname: | Prüfung zum zertifizierten Datenschutzbeauftragten für die Vereinigten Staaten |
| Prüfungsnummer: | CIPP-US |
| Verwandte Zertifizierungen: | AIGP CIPP/E CIPT CIPM |
| Prüfungsformat: | Multiple-Choice-Fragen, Fallstudienbasierte Fragen |
| Anzahl der Fragen: | 90 (davon 75 bewertete und 15 nicht bewertete Fragen) |
| Prüfungsgebühr: | 550 USD bis 650 USD |
| Verfügbare Sprachen: | Englisch |
| Mindestpunktzahl: | 300 von 500 Punkten |
| Prüfungsdauer: | 150 Minuten |
| Gültigkeitsdauer des Zertifikats: | 2 Jahre |
| Empfohlenes Training: | Lehrbuch zum Thema Datenschutz im Privatsektor der Vereinigten Staaten: Recht und Praxis Offizielle Schulung zur CIPP/US-Zertifizierung |
| Prüfungsanmeldung: | Offizielle Anmeldung bei der IAPP |
| Beispielfragen: | ![]() |
| Prüfungsmethode: | Computergestützte Prüfung in zugelassenen Prüfungszentren oder als Online-Prüfung mit Aufsicht |
| Voraussetzungen: | Keine verbindlichen Teilnahmevoraussetzungen; empfohlen für Fachkräfte mit 1–2 Jahren Berufserfahrung im Bereich Datenschutz |
| Offizielle Syllabus-URL: | https://iapp.org/certify/cippus/ |
IAPP CIPP-US Prüfungsthemen:
| Abschnitt | Gewichtung | Ziele |
|---|---|---|
| Thema 1: Datenschutz am Arbeitsplatz | 5 % – 9 % | - Vorschriften zur Diskriminierungsverhütung und zum Datenschutz im Arbeitsrecht - Nach Beendigung des Arbeitsverhältnisses: Aufbewahrungs- und Offenlegungsgrenzen - Während des Beschäftigungsverhältnisses: Überwachung, Untersuchungen, Datenverarbeitung - Vor der Einstellung: Hintergrundprüfungen, automatisierte Entscheidungen |
| Thema 2: Zugriff von Behörden und Gerichten auf Informationen des Privatsektors | 3 % – 7 % | - Gesetze zur nationalen Sicherheit: FISA, USA PATRIOT Act - Zivilverfahren und elektronische Beweissicherung - CISA und der Austausch von Informationen - Voraussetzungen für den Zugriff durch Strafverfolgungsbehörden |
| Thema 3: Datenschutzgesetze der Einzelstaaten | 9 % – 15 % | - Verhältnis zwischen Bundesrecht und Landesrecht sowie Vorrangregeln - CCPA, CPRA, VCDPA, CPA und weitere Landesgesetze - Rechte der Verbraucher und Durchsetzungsmechanismen - Vorschriften zur Datensicherheit und zur Meldung von Datenschutzverletzungen |
| Thema 4: Grenzen der Erhebung und Nutzung von Daten im Privatsektor | 15 % – 25 % | - Ethische Grundsätze und Datensparsamkeit - COPPA, HIPAA, GLBA, GINA und branchenspezifische Vorschriften - FTC-Gesetz und zugehörige Durchsetzungsmaßnahmen - Vorschriften im Bereich Telekommunikation und Marketing |
| Thema 5: Der Datenschutzrahmen der Vereinigten Staaten | 27 % – 33 % | - Rechtlicher Rahmen und Struktur in den USA - Regeln für den internationalen Datentransfer - Aufsichtsbehörden und Durchsetzungsmaßnahmen - Grundsätze der Informationsverwaltung - Rechte der betroffenen Personen und Rechenschaftspflicht |
Alles Wichtige zur IAPP Certified Information Privacy Professional/United States (CIPP/US) im Überblick
Die CIPP-US Prüfung (Certified Information Privacy Professional/United States (CIPP/US)) ist eine offizielle Zertifizierungsprüfung von IAPP. Mit dem Bestehen erlangen Sie die Zertifizierung Certified Information Privacy Professional/United States (CIPP/US). Sie ist der Stufe Berufliche Ebene zugeordnet. In engem Zusammenhang stehen außerdem die Zertifizierungen CIPP/E, CIPM, CIPT, AIGP.
Die CIPP-US Prüfung umfasst 90 (davon 75 bewertete und 15 nicht bewertete Fragen) Fragen in 150 Minuten. Daraus ergibt sich ein straffes Antworttempo: Verlieren Sie sich nicht zu lange in einzelnen Fragen, markieren Sie unsichere Punkte und behalten Sie am Ende eine Zeitreserve für den zweiten Durchgang. Am wirksamsten trainieren Sie dieses Zeitmanagement, indem Sie die 228 Übungsfragen von EchteFrage mehrfach unter realen Zeitbedingungen durcharbeiten – die Desktop- und die Online Test Engine begleiten Sie dabei mit einem Zeitlimit wie im Prüfungszentrum.
Zum Bestehen der CIPP-US Prüfung benötigen Sie 300 von 500 Punkten. Die offizielle Prüfungsgebühr beträgt 550 USD bis 650 USD; beachten Sie, dass bei einem Nichtbestehen der volle Betrag für jeden Wiederholungsversuch erneut anfällt. Messen Sie daher Ihren Wissensstand vor der Anmeldung mit den Übungsfragen von EchteFrage: Liegen Ihre Ergebnisse in den Übungstests stabil über der Bestehensgrenze, ist der Prüfungstermin eine gut investierte Entscheidung.
Für die CIPP-US Prüfung gilt: Keine verbindlichen Teilnahmevoraussetzungen; empfohlen für Fachkräfte mit 1–2 Jahren Berufserfahrung im Bereich Datenschutz Da Hersteller ihre Zulassungsbedingungen gelegentlich anpassen, bestätigen Sie die aktuellen Vorgaben bitte vor der Anmeldung auf der offiziellen Seite von IAPP: Offizielle Prüfungsinformationen zur IAPP Certified Information Privacy Professional/United States (CIPP/US).
Die Anmeldung zur CIPP-US Prüfung erfolgt über die folgenden offiziellen Kanäle:
Zur Prüfungsform: Computergestützte Prüfung in zugelassenen Prüfungszentren oder als Online-Prüfung mit Aufsicht
IAPP empfiehlt zur Vorbereitung auf die IAPP Certified Information Privacy Professional/United States (CIPP/US) die folgenden offiziellen Trainings:
- Offizielle Schulung zur CIPP/US-Zertifizierung
- Lehrbuch zum Thema Datenschutz im Privatsektor der Vereinigten Staaten: Recht und Praxis
Ergänzend dazu bieten Ihnen die 228 Übungsfragen von EchteFrage die Möglichkeit, das Gelernte unter Prüfungsbedingungen anzuwenden und Wissenslücken gezielt zu schließen.
Ja. Laden Sie einfach die kostenlose PDF-Demo zur CIPP-US Prüfung herunter und prüfen Sie Qualität und Schwierigkeitsgrad der Fragen, bevor Sie sich entscheiden. Nach dem Kauf erhalten Sie außerdem 365 Tage lang kostenlose Updates: Sobald sich die Prüfungsinhalte ändern, sendet Ihnen EchteFrage die aktualisierte Version automatisch per E-Mail. Nach Ablauf des Jahres verlängern Sie den Update-Service mit 50 % Rabatt.
Sollten Sie die entsprechende Prüfung innerhalb von 60 Tagen nach dem Kauf nicht bestehen, erstatten wir Ihnen den Kaufpreis vollständig (100% Money Back Guarantee). Voraussetzungen: Die Prüfung wurde frühestens drei Tage nach dem Kauf abgelegt, der Name des Prüflings stimmt mit dem des Zahlenden überein, und Sie reichen innerhalb von zwei Tagen nach der Prüfung die Anmeldebestätigung (Enrollment Slip) als Scan sowie das offizielle Score Report als PDF ein – die Bearbeitung erfolgt innerhalb von sieben Tagen. Ausgenommen sind kostenlose Materialien und abgelaufene Bestellungen. Alternativ zur Rückerstattung können Sie kostenlos zwei gleichwertige Prüfungsvorbereitungen wählen und behalten dabei den Update-Service Ihres gekauften Produkts. Die Lieferung erfolgt unmittelbar nach Zahlungseingang als Sofort-Download: Ihre Unterlagen erreichen Sie innerhalb einer Minute per E-Mail; sollte die Nachricht nach zwei Stunden noch nicht eingegangen sein, wenden Sie sich bitte an unseren Kundendienst. Eine Begrenzung der Installationen auf verschiedenen Computern gibt es nicht.
Die CIPP-US Prüfung gliedert sich in 5 Themenbereiche. Zu den wichtigsten zählen:
- Datenschutz am Arbeitsplatz (5 % – 9 %)
- Grenzen der Erhebung und Nutzung von Daten im Privatsektor (15 % – 25 %)
- Datenschutzgesetze der Einzelstaaten (9 % – 15 %)
Die vollständige Aufstellung aller Bereiche samt Gewichtung finden Sie in der Prüfungsübersicht weiter oben auf dieser Seite.
IAPP Certified Information Privacy Professional/United States (CIPP/US) CIPP-US Prüfungsfragen mit Lösungen
Frage #1
SCENARIO
Please use the following to answer the next question:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Upon review, the data privacy leader discovers that the Company's documented data inventory is obsolete. What is the data privacy leader's next best source of information to aid the investigation?
A. Lists of all customers, sorted by country
B. Database schemas held by the retailer
C. Reports on recent purchase histories
D. Interviews with key marketing personnel
Frage #2
SCENARIO
Please use the following to answer the next question:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in statea.
HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo.
CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals ?ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
Which of the following would be HealthCo's best response to the attorney's discovery request?
A. Respond with a request for satisfactory assurances such as a qualified protective order
B. Turn over all of the compromised patient records to the plaintiff's attorney
C. Respond with a redacted document only relative to the plaintiff
D. Reject the request because the HIPAA privacy rule only permits disclosure for payment, treatment or healthcare operations
Frage #3
Which legislation provides protection to the media from government searches unless they have committed a crime or threaten to commit a crime?
A. Stored Communications Act
B. Privacy Protection Act
C. Cybersecurity Information Sharing Act
D. US Communications Assistance to Law Enforcement
Frage #4
SCENARIO
Please use the following to answer the next question:
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asia. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the B. S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
The Board has asked Otto whether the company will need to comply with the new California Consumer Privacy Law (CCPA). What should Otto tell the Board?
A. That the company is governed by CCPA, but does not need to take any additional steps because it follows CPBR.
B. That business contact information could be considered personal information governed by CCPA.
C. That CCPA only applies to companies based in California, which exempts the company from compliance.
D. That CCPA will apply to the company only after the California Attorney General determines that it will enforce the statute.
Frage #5
What important action should a health care provider take if the she wants to qualify for funds under the Health Information Technology for Economic and Clinical Health Act (HITECH)?
A. Keep electronic updates about the Health Insurance Portability and Accountability Act
B. Make electronic health records (EHRs) part of regular care
C. Send health information and appointment reminders to patients electronically
D. Bill the majority of patients electronically for their health care
Fragen und Antworten:
| Frage #1 Antwort: D | Frage #2 Antwort: A | Frage #3 Antwort: B | Frage #4 Antwort: B | Frage #5 Antwort: B |
722 Kundenrezensionen 




Dasbach -
Ich kann nicht glauben, die Studienführung auf einer Webseite können mir helfen, die CIPP-US zu bestehen. Mit ihrer Studienführung ist es leichter für mich, den Inhalt der CIPP-US zu verstehen. Ich bekomme das Zertifikat erfolgreich. Dieser Erfolg wird mein Leben verändern. Vielen Dank,EchteFrage!