CIPP-US - Introduction to the U.S. Privacy Environment - Section 1.5

Explain the concept of information fiduciary duty and its implications for organisations that collect and process personal data.

Define information fiduciary as a proposed legal framework that would impose a duty of loyalty and duty of care on entities that collect personal data from users who reasonably rely on them. Recognise how this theory would restrict using data against users' interests and how it differs from traditional property or contract-based privacy models.

Information fiduciaryDuty of loyaltyDuty of careTrust relationship

Practice question for this objective

Free sampleIntroduction to the U.S. Privacy Environmenthard

Counsel for a digital health start-up is briefing the board on how the information fiduciary duty of care would shape obligations if the company adopted a fiduciary posture. Which obligation best reflects the duty of care as distinct from the duty of loyalty?

  • ARefraining from selling user data to parties whose interests conflict with those of the users.
  • BTaking reasonable, competent steps to keep user data accurate and secure so users are not harmed by careless handling. Correct
  • CDisclosing in a privacy notice every third party with which user data is shared.
  • DObtaining renewed opt-in consent each time the company introduces a new processing purpose.
Distinguish the duty of care (competent, diligent safeguarding of entrusted data) from the duty of loyalty (not acting against users' interests). The duty of care imports a professional standard of competence: an information fiduciary must safeguard the data it holds against careless or foreseeable harm, which is a stewardship obligation separate from the loyalty bar on self-dealing.

Why A is wrong: Avoiding conflicted onward sales is a genuine fiduciary obligation, but it is an expression of loyalty (not acting against users' interests) rather than the competence-and-diligence focus of the duty of care.

Why B is correct: The duty of care obliges an information fiduciary to handle entrusted data competently and protect it from foreseeable harm, paralleling the professional standard of care owed by doctors and lawyers to those who depend on them.

Why C is wrong: Transparency about recipients is good practice and feels like a fiduciary act, but it reflects notice-and-choice transparency rather than the duty of care, which is about safeguarding competence, not disclosure lists.

Why D is wrong: Refreshing consent for new purposes is a defensible compliance habit, but it belongs to the consent model the fiduciary theory supplements; the duty of care concerns diligent stewardship, not consent collection.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all Introduction to the U.S. Privacy Environment objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.