Free CIPP-CN sample questions
Real questions from the Certified Information Privacy Professional - China practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A multinational pharmaceutical company operates a research center in Beijing. They intend to transfer clinical trial data involving genetic markers of 5,000 Chinese citizens to their headquarters in Switzerland. Which specific regulatory requirement governs the export of this specific category of data?
Under the Data Security Law (DSL), data is classified based on its potential impact on national security, public interest, and the legitimate rights of individuals or organizations. Which classification represents data that, if tampered with, destroyed, leaked, or illegally obtained, would directly harm national security, the economy, or major public interests?
A Beijing-based tech startup is developing a mobile application for children aged 10-13. The app collects geolocation data to enable a 'find my friends' feature. Which specific compliance steps are MANDATORY under the Provisions on the Cyber Protection of Children's Personal Information? (Select TWO)
An organization is conducting a Personal Information Protection Impact Assessment (PIA) as required by PIPL. Which of the following elements is NOT strictly required to be included in the PIA report according to PIPL Article 55?
Case Study: TechFin China TechFin China is a financial technology services provider headquartered in Shenzhen. They offer a mobile payment app used by 50 million active users. Recently, TechFin decided to partner with a credit scoring agency in Europe to enhance their fraud detection algorithms. This involves sending user transaction logs and device identifiers to the European partner. TechFin has been designated as a Critical Information Infrastructure Operator (CIIO) by the financial regulators due to its market share. They have never transferred data outside China before. Based on the scenario, what is the PRIMARY legal constraint TechFin faces regarding the data location before any transfer can occur?
Which government entity is the primary authority responsible for the overall planning and coordination of personal information protection and related supervision in China?
True or False: Under PIPL, if a company wishes to install facial recognition cameras in a shopping mall for the sole purpose of security monitoring, they are exempt from obtaining separate consent from each individual shopper, provided they post a prominent notice.
A developer is configuring a generative AI service that will be available to the general public in China. According to the 'Interim Measures for the Management of Generative Artificial Intelligence Services', which action is legally required regarding the training data used for the model?
You are advising a client on PIPL compliance. They need to understand the concept of 'Separate Consent'. In which of the following scenarios is obtaining Separate Consent explicitly REQUIRED by PIPL? (Select TWO)
10 more free samples are waiting
Create a free account to unlock the whole CIPP-CN sample bank, or get full access to all 170 practice questions in the simulator.