CIPP-US - Introduction to the U.S. Privacy Environment (24% of the exam) - Section 1.5

Explain the concept of information fiduciary duty and its implications for organisations that collect and process personal data.

Define information fiduciary as a proposed legal framework that would impose a duty of loyalty and duty of care on entities that collect personal data from users who reasonably rely on them. Recognise how this theory would restrict using data against users' interests and how it differs from traditional property or contract-based privacy models.

Information fiduciaryDuty of loyaltyDuty of careTrust relationship

Practice question for this objective

Free sampleIntroduction to the U.S. Privacy Environmenthard

Counsel for a digital health start-up is briefing the board on how the information fiduciary duty of care would shape obligations if the company adopted a fiduciary posture. Which obligation best reflects the duty of care as distinct from the duty of loyalty?

  • ARefraining from selling user data to parties whose interests conflict with those of the users.
  • BTaking reasonable, competent steps to keep user data accurate and secure so users are not harmed by careless handling. Correct
  • CDisclosing in a privacy notice every third party with which user data is shared.
  • DObtaining renewed opt-in consent each time the company introduces a new processing purpose.
Distinguish the duty of care (competent, diligent safeguarding of entrusted data) from the duty of loyalty (not acting against users' interests). The duty of care imports a professional standard of competence: an information fiduciary must safeguard the data it holds against careless or foreseeable harm, which is a stewardship obligation separate from the loyalty bar on self-dealing.

Why A is wrong: Avoiding conflicted onward sales is a genuine fiduciary obligation, but it is an expression of loyalty (not acting against users' interests) rather than the competence-and-diligence focus of the duty of care.

Why B is correct: The duty of care obliges an information fiduciary to handle entrusted data competently and protect it from foreseeable harm, paralleling the professional standard of care owed by doctors and lawyers to those who depend on them.

Why C is wrong: Transparency about recipients is good practice and feels like a fiduciary act, but it reflects notice-and-choice transparency rather than the duty of care, which is about safeguarding competence, not disclosure lists.

Why D is wrong: Refreshing consent for new purposes is a defensible compliance habit, but it belongs to the consent model the fiduciary theory supplements; the duty of care concerns diligent stewardship, not consent collection.

See more CIPP-US practice questions, answers explained.

Exam traps in Introduction to the U.S. Privacy Environment

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-US bank for this domain.

  • It processes a special category of data without first completing a formal data protection impact assessment.

    Why it is wrong: Impact assessments are a recognised governance step, so this sounds responsible, but the fiduciary objection here is substantive rather than procedural; completing an assessment would not cure a use designed to exploit the user.

  • The duty of loyalty bars the firm from ever deriving any inference from member data, so the problem is the act of inference rather than the onward sale to the broker.

    Why it is wrong: Tempting because the harm flows from an inference, but the model does not prohibit drawing inferences as such, only using or sharing data disloyally, so locating the defect in inference itself misstates the duty.

  • The firm processes a large volume of records and therefore poses a heightened risk of a reportable security breach.

    Why it is wrong: Data volume and breach risk are tempting because scale feels significant, but the fiduciary concept turns on the trust and dependence in the relationship, not on the size of the data holdings or breach exposure.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.