Free demo, version-tracked updates emailed the moment they release, a year of free updates, and a written refund policy: TestPassKing builds long-term cooperation with 2026 CIPP-US candidates, one pass at a time.
IAPP CIPP-US Exam Overview:
| Certification Vendor: | IAPP (International Association of Privacy Professionals) |
|---|---|
| Exam Name: | Certified Information Privacy Professional/United States Exam |
| Exam Number: | CIPP-US |
| Exam Format: | Case study-based questions, Multiple choice |
| Passing Score: | 300 out of 500 |
| Certificate Validity Period: | 2 years |
| Exam Duration: | 150 minutes |
| Real Exam Qty: | 90 (75 scored, 15 unscored) |
| Exam Price: | USD 550 - USD 650 |
| Available Languages: | English |
| Related Certifications: | AIGP CIPP/E CIPT CIPM |
| Recommended Training: | U.S. Private-sector Privacy: Law and Practice Textbook CIPP/US Official Training |
| Exam Registration: | IAPP Official Registration |
| Sample Questions: | ![]() |
| Exam Way: | Computer-based at test centers or online proctored |
| Pre Condition: | No mandatory prerequisites; recommended for professionals with 1ā2 years of privacy experience |
| Official Syllabus URL: | https://iapp.org/certify/cippus/ |
IAPP CIPP-US Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Limits on Private-sector Collection and Use of Data | 15% - 25% | - COPPA, HIPAA, GLBA, GINA and sector-specific rules - Ethics and data minimization - FTC Act and enforcement actions - Telecommunications and marketing regulations |
| Topic 2: State Privacy Laws | 9% - 15% | - Consumer rights and enforcement mechanisms - Data security and breach notification laws - Federal vs. state authority and preemption - CCPA, CPRA, VCDPA, CPA and other state laws |
| Topic 3: Workplace Privacy | 5% - 9% | - Employment: monitoring, investigations, data handling - Post-employment: retention and disclosure limits - Anti-discrimination and labor privacy rules - Pre-employment: background checks, automated decisions |
| Topic 4: Government and Court Access to Private-sector Information | 3% - 7% | - CISA and information sharing - Law enforcement access requirements - National security laws: FISA, USA PATRIOT Act - Civil litigation and e-discovery |
| Topic 5: The U.S. Privacy Environment | 27% - 33% | - U.S. legal framework and structure - Regulatory authorities and enforcement - International data transfer rules - Data subject rights and accountability - Information management principles |
IAPP Certified Information Privacy Professional/United States (CIPP/US) FAQ: Tips, Versions, and Guarantees
IAPP Certified Information Privacy Professional/United States (CIPP/US) is an official IAPP (International Association of Privacy Professionals) exam, catalogued under exam code CIPP-US. Passing it awards the Certified Information Privacy Professional/United States (CIPP/US) certification at the Professional level. It also connects with CIPP/E, CIPM, CIPT, AIGP. It is built for candidates with ambitious aims, and the credential it grants is recognized accordingly.
IAPP Certified Information Privacy Professional/United States (CIPP/US) spans 5 official domains, led by State Privacy Laws (9% - 15%), Workplace Privacy (5% - 9%), and The U.S. Privacy Environment (27% - 33%). The complete outline sits above; before getting down to business, look through the whole contents quickly so every later practice session has context.
The IAPP Certified Information Privacy Professional/United States (CIPP/US) exam presents 90 (75 scored, 15 unscored) questions within 150 minutes. A practical tip from successful candidates: mark the most difficult questions during practice, exchange notes on them with friends, and repeat them until they stop being difficult. The TestPassKing engine makes that loop fast, and the clock stops being a threat.
Passing IAPP Certified Information Privacy Professional/United States (CIPP/US) requires 300 out of 500, and official registration costs USD 550 - USD 650. Retakes bill the full USD 550 - USD 650 again, so verify readiness before booking: when your TestPassKing practice scores clear the requirement repeatedly, including on questions you once marked as difficult, you are ready.
No mandatory prerequisites; recommended for professionals with 1ā2 years of privacy experience
Requirements change from time to time, so confirm the current conditions before registering on the official exam page.
IAPP Certified Information Privacy Professional/United States (CIPP/US) registration is handled through the official channels below.
When you schedule, note that the exam is delivered Computer-based at test centers or online proctored.
IAPP (International Association of Privacy Professionals) recommends the following training for IAPP Certified Information Privacy Professional/United States (CIPP/US) candidates.
Combine any training with the 228 practice questions in the TestPassKing CIPP-US package; one or two focused days of repeated practice after a course is often what locks the knowledge in.
Yes, a free demo of the IAPP Certified Information Privacy Professional/United States (CIPP/US) questions is available before purchase. Afterward, you can track freshness by the updating version number on the website, and whenever questions change we instantly email the details to you, free for 365 days. We even keep sending the latest questions after you pass, so you can follow every tiny change. After expiry, extending updates costs 50% of the regular price.
Your purchase carries a 100% money-back guarantee under clear conditions. Take the IAPP Certified Information Privacy Professional/United States (CIPP/US) exam within 60 days of purchase; if you fail, you may claim a full refund, provided the exam matches your product. Attempts within 3 days of purchase are ineligible, as are downloaded-but-unused products, free materials, and expired orders; the candidate name must match the payer name. Submit a scanned enrollment slip and the official Score Report PDF within 2 days of the exam, and claims are processed within 7 days. Alternatively, exchange for two other exam products of equal value, free, keeping the update service on your original purchase.
Delivery is instant: download after ordering, with an automatic email arriving within one minute. If nothing arrives within 2 hours, do not forget to check your junk mailbox, then contact customer service. Installation is unlimited across your computers.
IAPP Certified Information Privacy Professional/United States (CIPP/US) Sample Questions:
SCENARIO
Please use the following to answer the next question:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the most likely risk of Fitness Coach, Inc. adopting Janice's first draft of the privacy policy?
- A. Failing to meet the needs of customers who are concerned about privacy
- B. Leaving the company susceptible to violations by setting unrealistic goals
- C. Showing a lack of trust in the organization's privacy practices
- D. Not being in standard compliance with applicable laws
Correct Answer: B š³ļø
Explanation: Only visible for TestPassKing members. You can sign-up / login (it's free).
Which of the following is most likely to provide privacy protection to private-sector employees in the United States?
- A. State law, contract law, and tort law
- B. The Federal Trade Commission Act (FTC Act)
- C. Amendments one, four, and five of the U.S. Constitution
- D. The U.S. Department of Health and Human Services (HHS)
Correct Answer: A š³ļø
Explanation: Only visible for TestPassKing members. You can sign-up / login (it's free).
Which of the following data elements is most likely to be subject to comprehensive state data security and privacy laws?
- A. Contact details of individuals who report emergencies, maintained by local authorities
- B. Users' sexual orientations, maintained by a social media website
- C. Account holders' social security numbers, maintained by a bank.
- D. Individual drivers' license numbers, maintained by a state agency.
Correct Answer: C š³ļø
Explanation: Only visible for TestPassKing members. You can sign-up / login (it's free).
General health records data for private schools who accept no federal funding are subject to:
- A. HIPAA
- B. FERPA
- C. PPRA
- D. No Child Left Behind
Correct Answer: A š³ļø
Explanation: Only visible for TestPassKing members. You can sign-up / login (it's free).
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- A. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
- B. A bill of rights for individuals seeking access to their personal information.
- C. An international court ruling on personal information held in the commercial sector.
- D. A code of responsibilities for medical establishments to uphold privacy laws.
Correct Answer: C š³ļø
Explanation: Only visible for TestPassKing members. You can sign-up / login (it's free).




