CIPP-US domain - 23% of the exam

State Privacy Laws

State Privacy Laws is 23% of the Certified Information Privacy Professional/US (CIPP/US) exam. These are the objectives it covers, each with practice questions, with every answer explained.

The domain in numbers

66
Practice questions
5
Objectives
23
Medium
43
Hard

Where people go wrong

  • Confusing opt-in and opt-out sensitive-data models

    States do not share one approach to sensitive data. Virginia, Colorado, and Connecticut require opt-in consent before processing sensitive data, and under Colorado's law that includes precise geolocation and data revealing sexual orientation. California instead gives consumers a right to limit the use of sensitive data after collection. Applying one state's model to another misstates both frameworks.

    See it in a sample question
  • Reading a federal privacy floor as a ceiling

    A federal baseline does not cap what states may require. A federal statute that sets a minimum standard and does not preempt stronger protection is a floor, not a ceiling: states may add stricter timelines or broader rights, and a business must meet whichever requirement is stricter rather than treating the federal figure as a limit.

    See it in a sample question
  • Treating narrow preemption as full field preemption

    A federal statute that touches a subject does not automatically preempt the whole field. The FCRA instead uses narrow express preemption: its clause barring state furnisher duties preempts a state rule in the specific areas it addresses, while an unrelated state rule, such as limits on debt-collection call hours, still stands.

    See it in a sample question
  • Assuming a broad private right to sue

    Consumers cannot sue directly under every state privacy law. Virginia, Colorado, and Connecticut give consumers no private right of action at all: enforcement runs through the attorney general. California's own private right of action is also narrow, reaching only certain data breaches caused by unreasonable security, not general violations such as failures to honour access or opt-out requests.

Objectives in this domain

What to study

The official documents this domain's practice questions cite most.

Sample questions from this domain

Free sampleState Privacy Lawshard

A Colorado-based streaming service wants to process customers' precise geolocation and inferred sexual orientation to refine recommendations. Under the Colorado Privacy Act, what must the controller do before this processing?

  • AObtain the consumer's consent before processing, because precise geolocation and data revealing sexual orientation are sensitive data. Correct
  • BProvide a clear notice and allow the consumer to opt out of the processing at any point after it begins.
  • CConduct a data protection assessment and rely on legitimate interests, which substitutes for consent when processing sensitive data.
  • DRegister the processing activity with the Colorado Attorney General and wait for written approval before launch.
Identify that the Colorado Privacy Act requires opt-in consent before processing sensitive data such as precise geolocation or sexual orientation. The CPA treats categories like racial or ethnic origin, religious beliefs, health conditions, sexual orientation, citizenship status, genetic or biometric data, and precise geolocation as sensitive data, and bars processing them without the consumer's affirmative consent. Notice-and-opt-out is reserved for other processing categories.

Why A is correct: Correct: the CPA prohibits processing sensitive data without first obtaining consent, and both precise geolocation and data revealing sexual orientation fall within the Act's definition of sensitive data.

Why B is wrong: Tempting because opt-out applies to targeted advertising, sale, and certain profiling, but wrong: sensitive data under the CPA requires affirmative opt-in consent, not a notice-and-opt-out approach.

Why C is wrong: Tempting because the CPA does require assessments for high-risk processing, but wrong: an assessment does not replace the consent requirement that sensitive data triggers, and the CPA has no legitimate-interests exception to that consent.

Why D is wrong: Tempting because the CPA gives the Attorney General rulemaking and enforcement authority, but wrong: there is no pre-clearance or registration-and-approval step for processing sensitive data under the Act.

Free sampleState Privacy Lawsmedium

A federal sectoral privacy law sets a baseline duty for safeguarding certain records but says nothing about whether states may add stronger protections. A state then requires shorter breach-notice timelines and broader consumer rights than the federal baseline for the same records. How is the relationship between the two laws best characterised?

  • AThe federal law acts as a floor, so the state may impose stronger protections that operate alongside the federal baseline. Correct
  • BThe federal law acts as a ceiling, so the stronger state timelines are void because they exceed what Congress set as the maximum permissible protection.
  • CThe laws conflict irreconcilably, so the state law is automatically struck down under ordinary conflict preemption analysis.
  • DConcurrent jurisdiction is impossible here, so a covered entity must choose which single regime to follow for the records.
Understand that a non-preemptive federal sectoral standard acts as a floor, letting states layer stronger protections on top. A federal minimum standard that does not preempt more protective state law establishes a floor: states may go further, and a regulated entity satisfies both by meeting whichever requirement is stricter, which is why stronger state timelines survive rather than being displaced.

Why A is correct: When a federal statute sets a minimum standard and does not preempt more protective state law, states may build above the floor and the two regimes coexist.

Why B is wrong: This misreads the structure; a sectoral baseline that is silent on stronger state rules functions as a floor, not a ceiling, so exceeding it is generally allowed.

Why C is wrong: This is tempting, but offering more protection than a federal minimum does not make compliance with both impossible, so there is no true conflict to trigger conflict preemption.

Why D is wrong: Privacy law routinely involves concurrent federal and state regulation, and an entity must satisfy the stricter requirement rather than electing one regime, so this is incorrect.

Free sampleState Privacy Lawsmedium

A national lender complies with the federal Fair Credit Reporting Act when it furnishes consumer credit data. A state then enacts a statute imposing additional furnisher accuracy duties in an area the FCRA expressly addresses. Which principle best explains why the state requirement is most vulnerable to challenge?

  • AExpress preemption applies because the FCRA contains specific provisions barring state requirements in the particular areas Congress chose to occupy. Correct
  • BThe Supremacy Clause renders all state privacy statutes void whenever a federal privacy statute exists on the same general subject.
  • CField preemption applies because consumer reporting is an inherently national activity that Congress has reserved entirely to federal regulators.
  • DThe dormant Commerce Clause applies because the state law burdens an out-of-state lender that operates across multiple jurisdictions.
Recognise that the FCRA preempts state law only in the specific subject areas Congress expressly identified, making those state rules the most vulnerable. Express preemption operates where a federal statute states in its own text that state requirements in identified areas are barred; the FCRA does this for defined topics, so a state rule landing inside a covered area is displaced by the statute's own language rather than by any general supremacy of all federal law.

Why A is correct: The FCRA includes express preemption clauses covering defined subject areas such as furnisher duties, so a state rule in one of those covered areas is most vulnerable as expressly preempted.

Why B is wrong: This overstates the doctrine; the Supremacy Clause invalidates conflicting or expressly preempted state law, not every state statute that touches a subject Congress has also addressed.

Why C is wrong: This is tempting because credit reporting is interstate, but the FCRA preempts only enumerated areas and leaves room for state law elsewhere, so the field is not wholly occupied.

Why D is wrong: The dormant Commerce Clause addresses discrimination against interstate commerce, not a direct conflict with a federal statute's express preemption terms, so it is the wrong frame here.

Other domains in this exam

See also the CIPP-US cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.