15 real CIPP-US sample questions, each with a worked explanation and a rationale for every option, right and wrong. No account, no card. This is the reasoning the CIPP-US tests: knowing why the tempting answer is wrong, not just spotting the right one.
The real CIPP-US is 90 questions in 150 minutes, pass mark 300 / 500. For a domain-by-domain breakdown and a study plan, read the CIPP-US study guide. The full bank has 308 questions.
lock_openFree sampleLimits on Private-Sector Collection and Use of Datahard
Counsel is drafting the privacy representations and warranties for a stock purchase agreement covering a target that markets to California consumers. The buyer wants the representations to do real diligence work rather than merely paper over risk. Which drafting choice best serves the buyer's goal of allocating privacy risk to the seller?
- AA narrow representation that the target has a privacy policy posted on its website, with no statement about the accuracy of that policy or compliance with it.
- BA representation that the buyer has independently satisfied itself as to the target's privacy practices and waives reliance on any seller statement about data handling.
- CA representation limited to the statement that no data breach has been publicly disclosed in the past twelve months.
- DA broad representation that the target has at all times complied with all applicable privacy and data protection laws and its own published commitments, qualified only by a disclosure schedule of known exceptions.check_circle Correct
Understand that a broad law-and-commitments compliance representation with a disclosure schedule best shifts privacy risk from buyer to seller. Representations and warranties allocate risk by giving the buyer a contractual remedy if facts differ from what is represented; a broad compliance representation backed by a disclosure schedule both forces the seller to surface known issues and leaves the seller liable for undisclosed non-compliance.
Why A is wrong: This is tempting because it looks like a privacy representation, but mere existence of a posted policy says nothing about compliance, so it gives the buyer almost no protection and fails to allocate risk to the seller.
Why B is wrong: This sounds rigorous but actually waives the buyer's recourse, so a candidate confusing buyer diligence with risk allocation would choose it, while in fact it shifts risk onto the buyer rather than the seller.
Why C is wrong: Public-disclosure-only and a twelve-month window leave undisclosed breaches and broader compliance gaps untouched, so although it addresses one risk it is far too narrow to allocate privacy risk to the seller.
Why D is correct: Correct: a compliance representation tied to applicable law and the target's own commitments, backed by a disclosure schedule and indemnity, shifts unknown privacy exposure to the seller and surfaces known issues for pricing.
lock_openFree sampleLimits on Private-Sector Collection and Use of Datahard
A consumer reviews her credit report and notices a closed account wrongly listed as in default. She sends a written dispute to the consumer reporting agency. Under the Fair Credit Reporting Act, what is the agency's core obligation in response to a properly filed dispute about accuracy?
- ASuppress the disputed item from all future reports until a court rules on whether the entry was accurate.
- BRefer the dispute to the furnisher and take no further action, since the furnisher alone is responsible for accuracy.
- CProvide a risk-based pricing notice explaining how the disputed entry may affect the rates lenders offer her.
- DConduct a reasonable reinvestigation, usually within thirty days, and delete or correct information that is found to be inaccurate, incomplete, or unverifiable.check_circle Correct
State that FCRA requires a consumer reporting agency to reinvestigate a disputed item, typically within thirty days, and delete or correct unverifiable or inaccurate information. FCRA's dispute mechanism protects data accuracy: on receiving a dispute, the agency must reinvestigate, generally within thirty days, coordinate with the furnisher, and remove or fix information that is inaccurate, incomplete, or cannot be verified.
Why A is wrong: Tempting because consumers want the harmful item gone, but FCRA calls for reinvestigation rather than automatic suppression pending litigation, and items are corrected or deleted based on the investigation's findings.
Why B is wrong: Plausible because furnishers do have investigation duties, but the agency cannot simply hand off the matter; it must itself reinvestigate and resolve the dispute, not abdicate the outcome to the furnisher.
Why C is wrong: Tempting because pricing is what the consumer ultimately cares about, but risk-based pricing notices are a creditor's duty tied to credit offers, not the reporting agency's response to a dispute about accuracy.
Why D is correct: Correct: FCRA requires the agency to reinvestigate disputed items, generally within thirty days, forward relevant information to the furnisher, and delete or modify any information that cannot be verified or is shown to be inaccurate or incomplete.
lock_openFree sampleLimits on Private-Sector Collection and Use of Datamedium
A college contracts with an outside analytics company to host its learning management system, which stores grades, assignments, and attendance for enrolled students. The vendor will access these education records to operate the platform. The college wants to share the records with the vendor without collecting individual student consent. Under FERPA, which condition most directly allows this disclosure?
- AThe disclosure is allowed because the college first designated grades and attendance as directory information in its annual notice.
- BThe disclosure is allowed because the vendor signed a confidentiality agreement, which under FERPA converts any third party into an authorised recipient.
- CThe vendor qualifies as a school official because it performs an institutional service and is under the college's direct control regarding use of the records.check_circle Correct
- DThe disclosure is allowed because FERPA permits unconsented sharing with any contractor that processes records solely on the school's behalf for a fee.
Understand that FERPA's school official exception can cover outsourced vendors under the school's direct control. FERPA allows disclosure without consent to a school official with a legitimate educational interest, and an outsourced provider can qualify when it performs a function the school would otherwise do itself, is under the school's direct control over use of the records, and is limited in re-disclosure, which is the basis for sharing with the analytics vendor.
Why A is wrong: It is tempting because directory information avoids consent, but grades and attendance are not permissible directory items, so this exception cannot cover the sharing.
Why B is wrong: It is tempting because confidentiality terms are good practice, but a signed agreement alone does not create a FERPA exception, so it is not what authorises the disclosure.
Why C is correct: FERPA permits sharing without consent with a school official who has a legitimate educational interest, and a properly contracted outsourced service provider performing an institutional function under the school's direct control fits that definition.
Why D is wrong: It is tempting because it sounds like the outsourcing rule, but FERPA also requires the vendor to be under the school's direct control and limited in re-use, so a fee-based contract by itself is too loose a test.
lock_openFree sampleIntroduction to the U.S. Privacy Environmentmedium
A technology company has not violated any specific privacy statute, yet the Federal Trade Commission opens an enforcement action alleging the company misrepresented its data-sharing practices to consumers. On what legal source does the FTC most directly rely to bring this action?
- AThe common law tort of intrusion upon seclusion, which the FTC enforces on behalf of consumers in federal court.
- BIts statutory authority under Section 5 of the FTC Act to challenge unfair or deceptive acts or practices.check_circle Correct
- CA constitutional right to fair dealing implied by the Due Process Clause of the Fourteenth Amendment.
- DA self-regulatory code of conduct that the company adopted and the FTC enforces as binding federal regulation.
Identify Section 5 of the FTC Act as the statutory basis for FTC enforcement against deceptive privacy representations. The FTC's general enforcement power comes from Section 5 of the FTC Act, which bars unfair or deceptive acts or practices, allowing action against misrepresentations even absent a sector-specific privacy statute.
Why A is wrong: Tempting because intrusion is a privacy wrong, but it is a private tort claim brought by individuals, not a statutory power the FTC invokes for enforcement.
Why B is correct: Correct: Section 5 of the FTC Act prohibits unfair or deceptive acts or practices, letting the FTC act on a misrepresentation even where no specific privacy statute applies.
Why C is wrong: Tempting because due process sounds protective, but it limits government conduct toward individuals and is not the source of FTC authority over deceptive business practices.
Why D is wrong: Tempting because broken promises in a code can support a case, but the code is not itself the legal source, and the FTC's authority flows from the FTC Act.
lock_openFree sampleIntroduction to the U.S. Privacy Environmenthard
A US online genetic-testing service describes itself publicly as a trusted custodian of its customers' health data. A privacy advocate argues the firm should be treated as an information fiduciary. Which feature of the relationship between the firm and its customers most directly supports characterising the firm as an information fiduciary?
- AThe firm processes a large volume of records and therefore poses a heightened risk of a reportable security breach.
- BCustomers must depend on the firm's expertise and disclose sensitive data to receive the service, creating an asymmetry the firm could exploit.check_circle Correct
- CThe firm publishes a privacy notice and obtains opt-in consent before any secondary use of the genetic data.
- DThe firm is subject to the Federal Trade Commission's authority over unfair and deceptive practices.
Recognise that the information fiduciary concept is grounded in a relationship of trust, dependence, and data-handling asymmetry rather than data scale or consent. An information fiduciary is identified by the trust relationship: the customer must disclose sensitive data and depends on the firm, which holds power the customer cannot police, so loyalty and care duties are imposed to constrain that power.
Why A is wrong: Data volume and breach risk are tempting because scale feels significant, but the fiduciary concept turns on the trust and dependence in the relationship, not on the size of the data holdings or breach exposure.
Why B is correct: The information fiduciary theory rests on a relationship of trust and dependence in which one party must hand over sensitive data and cannot easily verify how it is used, mirroring the vulnerability that grounds traditional fiduciary duties.
Why C is wrong: Notice and consent look relevant because they govern data use, but consent-based processing is the notice-and-choice model the fiduciary theory is meant to supplement; consent alone does not create a fiduciary status.
Why D is wrong: FTC jurisdiction is attractive because it is the main US privacy enforcer, but being subject to Section 5 enforcement is true of most commercial firms and does not by itself make an entity a fiduciary.
lock_openFree sampleIntroduction to the U.S. Privacy Environmentmedium
A privacy counsel is briefing new analysts on how the four recognised sources of US law each shape privacy obligations and where their binding force comes from. Which two statements accurately describe how a source of US law operates? (Select TWO.)
- AFederal statutes acquire their operational detail because agencies write them and Congress later ratifies that drafting.
- BThe common law privacy torts derive their force from accumulated court decisions rather than from any enacted code.check_circle Correct
- CThe Fourth Amendment directly governs how a private retailer must handle customer data because it protects privacy generally.
- DThe common law privacy protections are uniform across every state because they were codified into a single federal scheme.
- EA regulation carries binding legal force when an agency issues it under authority that Congress has delegated to that agency.check_circle Correct
US privacy obligations flow from four distinct sources, and each source binds through its own mechanism: precedent, enactment, constitutional limit, or delegated rulemaking. Common law torts bind through judicial precedent and regulations bind through congressionally delegated rulemaking, so both statements describe a real source mechanism. The Fourth Amendment binds government, not private firms, under the state-action doctrine; statutes are enacted by legislatures rather than drafted by agencies; and common law is state-specific rather than federally codified.
Why A is wrong: It sounds plausible because statutes and regulations interact closely, but statutes are enacted by the legislature while agencies issue the detailed regulations beneath them, so the drafting attribution is reversed.
Why B is correct: Common law is judge-made law built case by case, so the privacy torts bind through judicial precedent rather than through a statute passed by a legislature.
Why C is wrong: It tempts candidates who treat constitutional privacy as universal, but the state-action doctrine means the Fourth Amendment constrains government conduct, not a private company's data handling.
Why D is wrong: It appeals to those who assume nationwide consistency, but common law privacy varies state by state and was never collapsed into one federal code.
Why E is correct: Regulatory law binds because Congress delegates rulemaking authority to an agency, which then issues regulations that have the force of law within that grant.
lock_openFree sampleState Privacy Lawshard
A bank that does business in several states uses a fully automated model to approve or deny consumer credit-line increases with no human involvement. Counsel is mapping which state comprehensive privacy laws give the consumer a right to opt out of this kind of profiling. Under the leading state comprehensive privacy model, what is the threshold that determines whether the consumer has an opt-out right over this automated decision?
- AWhether the automated model processes any personal data at all, since all automated processing triggers the profiling opt-out.
- BWhether the consumer has previously exercised a separate right to delete their personal data held by the bank.
- CWhether the profiling is carried out in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.check_circle Correct
- DWhether the bank has annual revenue above a fixed dollar figure set by each state's profiling provision.
Recognise that state comprehensive privacy laws tie the profiling opt-out to automated decisions producing legal or similarly significant effects on the consumer. Under the Virginia, Colorado, and Connecticut comprehensive privacy models, the consumer's right to opt out of profiling is limited to profiling in furtherance of decisions that produce legal or similarly significant effects, such as credit, housing, or employment outcomes, rather than to all automated processing.
Why A is wrong: It is tempting to assume any automated processing triggers the right, but the opt-out is tied to significant-effect profiling, not to processing generally, so this overstates the scope.
Why B is wrong: Deletion and profiling opt-out are independent rights, so making one a precondition of the other confuses two distinct consumer entitlements under these statutes.
Why C is correct: State comprehensive laws such as the Colorado, Connecticut, and Virginia models grant an opt-out of profiling specifically when it is in furtherance of decisions producing legal or similarly significant effects, which a credit-line decision is.
Why D is wrong: Revenue thresholds appear in the applicability sections of some privacy laws, but the profiling opt-out is defined by the nature of the decision and its effect, not by a revenue figure inside the profiling provision.
lock_openFree sampleState Privacy Lawshard
A subscription business collects a consumer's precise geolocation and uses it both to deliver the requested service and to infer the consumer's health condition for internal product research. The consumer submits a verifiable request asking the business to limit the use of this data. Under the CPRA, which obligation does the consumer's request invoke and what is its scope?
- AThe right to limit use and disclosure of sensitive personal information, which restricts use to what is necessary to provide the requested service and other narrowly permitted purposes.check_circle Correct
- BThe right to correct, which obliges the business to amend inaccurate precise geolocation records on file.
- CThe right to opt out of sale, which prevents the business from using the data for any internal research.
- DThe right to delete, which compels erasure of the precise geolocation and inferred health information immediately.
Identify that precise geolocation and health-revealing data are sensitive personal information subject to the CPRA right to limit use and disclosure. The CPRA defines sensitive personal information to include precise geolocation and data concerning health, and grants a right to limit that restricts processing to providing the requested service and a defined set of permitted business purposes rather than ending all use.
Why A is correct: Precise geolocation and data revealing health are sensitive personal information, and the CPRA created a right to limit that confines use and disclosure to delivering the requested service and a short list of permitted operational purposes.
Why B is wrong: Correction addresses inaccurate personal information, but the consumer here is objecting to how accurate data is used, so the correction right does not match the request.
Why C is wrong: This is tempting because both rights curb data use, but the sale opt-out only governs disclosures to third parties for consideration, not a business's own internal use of sensitive data.
Why D is wrong: Deletion removes data and carries exceptions, but the consumer asked to limit use rather than to erase, so the request invokes the narrower limit right rather than deletion.
lock_openFree sampleState Privacy Lawsmedium
Congress is debating a national consumer privacy bill that would set uniform rules and expressly bar states from imposing different requirements on the same conduct. A coalition of states with stronger existing laws objects. If enacted as drafted, what would the express provision most directly do to those stronger state laws?
- APreserve the stronger state laws as a floor, because federal privacy statutes by default allow states to keep more protective rules.
- BDisplace the stronger state laws to the extent they impose different requirements on the same conduct, because express preemption overrides conflicting state rules within its scope.check_circle Correct
- CLeave the stronger state laws untouched, because Congress cannot preempt state privacy regulation under its enumerated powers.
- DSuspend the stronger state laws only until a federal agency issues implementing regulations, after which the states could readopt them unchanged.
Recognise that an express federal preemption clause displaces stronger state privacy laws within the scope of conduct it covers. Express preemption works by the statute's own text declaring that state requirements differing from the federal rule are barred; where Congress has authority and writes such a clause, stronger state laws are displaced to the extent they impose different requirements on the covered conduct.
Why A is wrong: This reflects the common floor pattern, but the bill is drafted to bar differing state requirements, so the default floor assumption does not hold against express preemptive language.
Why B is correct: An express clause barring different state requirements on the same conduct preempts those state rules within its scope, so the stronger laws are displaced where they diverge.
Why C is wrong: This is tempting as a federalism argument, but commercial data practices fall within the commerce power, so Congress can preempt such state rules and the laws would not be untouched.
Why D is wrong: This invents a temporary-suspension mechanism; express statutory preemption operates by force of the statute itself and does not pause pending rulemaking or permit unchanged readoption.
lock_openFree sampleGovernment and Court Access to Private-Sector Informationhard
An FBI agent serves a provider with a National Security Letter and includes a nondisclosure requirement barring the provider from telling anyone, including the affected customer, that it received the NSL. The provider's counsel wants to know how the USA FREEDOM Act altered the legal posture of that nondisclosure requirement. Which statement is correct?
- AThe provider may seek judicial review of the nondisclosure requirement, and the government must periodically reassess whether continued secrecy remains justified.check_circle Correct
- BThe nondisclosure requirement is now permanent once imposed, and the provider has no statutory mechanism to seek its removal at any later time.
- CThe nondisclosure requirement was abolished entirely, so providers receiving NSLs may now freely publish the specific contents of any NSL they receive.
- DThe provider may disclose the NSL only after first obtaining written authorisation from the Foreign Intelligence Surveillance Court for each individual customer affected.
USA FREEDOM added judicial review and periodic reassessment for National Security Letter nondisclosure requirements rather than abolishing them. The USA FREEDOM Act left NSL authority intact but reformed the gag provisions, giving recipients access to judicial review and obliging the government to reassess and terminate nondisclosure when secrecy is no longer needed.
Why A is correct: Correct: USA FREEDOM established judicial-review procedures for NSL gag orders and reciprocal notice requiring the government to revisit whether nondisclosure is still warranted.
Why B is wrong: Tempting because NSL gag orders were historically open-ended, but USA FREEDOM created review and termination mechanisms, so the gag is not permanent and unchallengeable.
Why C is wrong: Tempting because reforms increased transparency, but USA FREEDOM did not abolish NSL gags; it added procedures and reciprocal-notice rules rather than removing them.
Why D is wrong: Tempting because the FISC oversees national security matters, but NSL nondisclosure review runs through ordinary judicial-review procedures, not per-customer FISC authorisation.
lock_openFree sampleGovernment and Court Access to Private-Sector Informationmedium
A regional retailer's general counsel learns that a former employee has filed a wrongful-termination suit and that litigation is now reasonably anticipated. The company runs an email system with a 90-day auto-deletion policy that purges mailboxes nightly. To meet its obligations under the Federal Rules of Civil Procedure, what is the counsel's most immediate and direct duty regarding the relevant electronically stored information?
- AIssue a litigation hold that suspends routine auto-deletion for the custodians and data sources likely to hold relevant information.check_circle Correct
- BWait until the opposing party serves a formal discovery request before taking any action to preserve the relevant mailboxes.
- CImmediately collect and produce all potentially relevant emails to opposing counsel to demonstrate good faith.
- DMigrate all company mailboxes to a new archive platform and apply the 90-day policy uniformly going forward.
Recognise that the duty to preserve relevant ESI attaches when litigation is reasonably anticipated, triggering a litigation hold that suspends routine deletion. The preservation duty under the FRCP framework is triggered by reasonable anticipation of litigation, not by service of a discovery request. A litigation hold operationalises that duty by suspending automated destruction for the custodians and systems likely to contain relevant ESI, preventing spoliation.
Why A is correct: Once litigation is reasonably anticipated, the duty to preserve attaches and counsel must suspend routine destruction by issuing a litigation hold to relevant custodians and systems, which is the immediate and direct preservation step.
Why B is wrong: This is tempting because formal requests do trigger production obligations, but the preservation duty attaches when litigation is reasonably anticipated, well before any request is served, so waiting risks spoliation.
Why C is wrong: This sounds proactive, but production happens during discovery on relevant, proportional material after meet-and-confer, not by dumping everything at the outset, and it does not address preservation of data still being purged.
Why D is wrong: Standardising retention may seem like sound governance, but continuing a 90-day purge would keep destroying relevant information that must be preserved, so this fails the preservation duty rather than satisfying it.
lock_openFree sampleGovernment and Court Access to Private-Sector Informationmedium
Two companies are preparing for the early discovery-planning conference required before broad discovery begins in their federal civil case. Each holds large volumes of electronically stored information across email, collaboration platforms, and databases. To comply with the Federal Rules of Civil Procedure, which topic must the parties address as part of this planning conference?
- AAny issues about preserving and disclosing electronically stored information, including its form of production.check_circle Correct
- BThe final dollar amount of damages that the plaintiff will be permitted to recover at trial.
- CThe selection of the trial jury and the procedure for striking prospective jurors.
- DThe assignment of the case to a specific appellate panel for any future review.
Recall that the FRCP discovery-planning conference must address preservation, disclosure, and the form of production of electronically stored information. The early planning conference requires the parties to develop a discovery plan that expressly covers issues about disclosing or producing ESI, including the form of production, and any preservation concerns. Addressing ESI form and preservation up front is a core requirement of the meet-and-confer process.
Why A is correct: The rules require the parties' discovery plan to address issues about disclosure and preservation of ESI and the form in which it will be produced, making this a mandatory conference topic.
Why B is wrong: Damages are resolved on the merits later in the case, not fixed at the discovery-planning conference, so this confuses the purpose of the early conference with trial outcomes.
Why C is wrong: Jury selection occurs at trial under separate procedures and has nothing to do with the discovery plan, so this is outside the scope of the early conference.
Why D is wrong: Appellate assignment is irrelevant to discovery planning and arises only after a final judgment is appealed, so it is not a topic for the parties' early conference.
lock_openFree sampleWorkplace Privacymedium
A staffing firm orders a report from a third-party agency that interviews a candidate's former neighbours and colleagues about the candidate's character, general reputation, and mode of living for a managerial role. Under the FCRA, how should this report be classified, and what extra duty does that classification trigger?
- AIt is an ordinary consumer report, so the standard stand-alone disclosure and authorisation fully satisfy every FCRA obligation for this type of inquiry.
- BIt is a credit report, which means the employer must certify a permissible purpose tied to the candidate's outstanding debts.
- CIt is an investigative consumer report, which obliges the employer to notify the candidate that such a report may be obtained and to disclose the nature and scope on request.check_circle Correct
- DIt is a public-record-only report, so the agency need not maintain procedures to ensure the interviewed information is accurate or current.
Reports gathering character or reputation data through personal interviews are investigative consumer reports, adding nature-and-scope disclosure duties under FCRA. The investigative consumer report category exists because interview-based opinions about a person are more subjective and intrusive than record data, so FCRA layers on a duty to disclose the inquiry's nature and scope when asked.
Why A is wrong: This is tempting because every investigative consumer report is also a consumer report, but the interview-based character information triggers the additional investigative disclosure duties that the ordinary process alone does not meet.
Why B is wrong: Candidates may assume any agency report is credit-based, but interviews about reputation are not credit data, so framing this as a credit report and a debt-related permissible purpose misreads the report type.
Why C is correct: When information about character, reputation, or mode of living is gathered through personal interviews, FCRA treats it as an investigative consumer report and adds a duty to give a clear and accurate disclosure of its nature and scope on request.
Why D is wrong: This sounds plausible because reputation feels like public knowledge, but interview-derived character information is not a public record and the agency still owes reasonable-procedure accuracy duties.
lock_openFree sampleWorkplace Privacymedium
An employer adopts an automated hiring tool that scores applicants from video interviews and resume data, and several jurisdictions where it recruits regulate automated employment decision tools. Setting aside any single jurisdiction's exact wording, which obligation most commonly arises across these automated decision-making rules for hiring?
- ARegistering the algorithm's source code with a federal privacy regulator before it may be used in any hiring decision.
- BNotifying candidates that an automated tool will be used to assess them and, in several jurisdictions, subjecting the tool to a bias audit before deployment.check_circle Correct
- CGuaranteeing that the automated tool produces identical scores for every demographic group regardless of role-related qualifications.
- DDeleting all applicant data within twenty-four hours of generating an automated score to limit retention exposure.
Automated employment decision-tool rules commonly require notifying candidates of the tool's use and, in several jurisdictions, an independent bias audit before deployment. These regimes target the opacity and discrimination risks of algorithmic hiring, so their shared core is making candidates aware the tool is used and testing it for disparate impact rather than mandating equal scores or code registration.
Why A is wrong: Source-code registration sounds rigorous, but no general federal regime requires filing hiring-algorithm code with a privacy regulator, so this overstates and federalises a duty that the rules do not impose.
Why B is correct: Emerging automated-employment-decision rules typically centre on transparency to candidates and independent bias auditing of the tool, making candidate notice plus a pre-deployment bias audit the recurring obligation across these regimes.
Why C is wrong: Equal outcomes seem like the goal of bias rules, but the laws require auditing and disclosure rather than guaranteeing identical scores, so this misstates an audit duty as an impossible parity mandate.
Why D is wrong: Short retention windows feel privacy-protective, but automated-decision hiring rules focus on notice and bias auditing rather than a uniform twenty-four-hour deletion deadline, so this invents a retention rule.
lock_openFree sampleWorkplace Privacymedium
A US company's reference policy lets managers speak freely about why employees left. A former employee sues after a manager told a recruiter the employee had been fired for theft, which was false. The manager believed it in good faith. Which factor most strongly determines whether the company can rely on a qualified privilege defence?
- AWhether the former employee signed a release waiving all reference-related claims at the time of separation.
- BWhether the recruiter actually relied on the statement when deciding not to hire the former employee.
- CWhether the statement was made with malice or reckless disregard for its truth rather than in good faith for a legitimate purpose.check_circle Correct
- DWhether the company had a written reference policy permitting managers to discuss reasons for departure.
Qualified privilege for references is defeated by malice or reckless disregard for the truth. Qualified privilege shields references made in good faith to someone with a legitimate interest, but it is lost when the speaker acts with malice or reckless disregard for truth, making that the controlling question.
Why A is wrong: A signed release would matter, but the question turns on the privilege itself, and many releases do not cover knowingly false statements, so this is not the strongest determining factor.
Why B is wrong: Reliance affects damages and causation, which is tempting to conflate with the defence, but it does not control whether qualified privilege applies, so it is not decisive.
Why C is correct: Qualified privilege protects good-faith statements to a party with a legitimate interest but is defeated by malice or reckless disregard, so this is the decisive factor in the defence.
Why D is wrong: A policy seems relevant to authorisation, but the existence of a policy does not create or defeat the privilege, which depends on the manager's state of mind, so it is wrong.
Examworthy is not affiliated with or endorsed by IAPP. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIPP-US and related marks belong to their respective owners.