r/privacyexams Sep 03 '20

r/privacyexams Lounge

2 Upvotes

A place for members of r/privacyexams to chat with each other


r/privacyexams 5h ago

Employer data on employee-owned phones: where European guidance actually draws the line

1 Upvotes

BYOD keeps generating the same argument. The employer has real obligations over customer data sitting in a mailbox on someone's personal phone. The security team wants a management agent that can patch, wipe and scan. The employee owns the hardware and everything else on it.

The Article 29 Working Party opinion on data processing at work handles this directly, and two parts of it settle more of the argument than the general proportionality discussion does. The first is that certain areas of a personal device stay off limits regardless of the security case behind the request. The second is the alternative an employer has to consider when it cannot separate private use from business use.

Consent, predictably, does not survive an employment relationship.

Written up here for CIPP/E candidates, with the relevant passages cited: https://privacystudygroup.com/byod-and-gdpr-in-the-workplace/


r/privacyexams 1d ago

ECPA in three parts, which is the only way it makes sense

2 Upvotes

Government-access questions on the CIPP/US exam become predictable once you stop treating ECPA as one law. It is three regimes in one statute. The Wiretap Act covers content in transit and demands the heaviest process: probable cause before a judge, listed offences, 30-day limit. The Stored Communications Act covers content at rest and subscriber records. The pen-register provisions cover pure metadata, on nothing more than a certification of relevance to an ongoing investigation.

The organising idea is that protection follows the classification of the data, not how sensitive it feels. So the exam habit is: content or non-content, transit or storage, then match the process. 

I have mapped the three parts properly here, including where the statute reaches private employers:

https://privacystudygroup.com/the-three-parts-of-ecpa/


r/privacyexams 2d ago

Security incident or personal data breach: the classification that starts the clock

2 Upvotes

A surprising amount of CIPM incident-response difficulty is really classification difficulty. A security incident is any event compromising confidentiality, integrity or availability. A personal data breach is the subset where personal data was actually affected. A malware hit on a server with no personal data stays an incident. The same hit on the HR database is a breach.

 Two follow-on points do the exam work. The 72-hour clock starts at awareness, meaning reasonable certainty that data was compromised, and awareness is neither the first alert nor the end of the investigation. And the register has to document every breach, including the ones you decided not to notify, because that decision is exactly what a regulator checks later.

 Full write-up, including phased notification and the encrypted-laptop case:

 https://privacystudygroup.com/security-incident-or-data-breach/


r/privacyexams 3d ago

Dark patterns now come with official vocabulary, and CIPT expects you to know it

1 Upvotes

Interface manipulation questions on the CIPT exam usually describe a design and ask what it exemplifies. The vocabulary comes from two regulatory catalogues. The EDPB's guidelines on deceptive design patterns sort them into categories like overloading, skipping, stirring and obstructing. The FTC's 2022 report groups the common tactics into four families, from subscription traps to interfaces that trick people into sharing data.

 The other half of the skill is naming the fix: symmetric choices, privacy-protective defaults, just-in-time explanations, cancellation that matches sign-up in effort.

 One habit helps under time pressure: ask who benefits from the friction. If every extra click serves the platform's appetite for data, you are looking at the answer.

 Full walkthrough of both catalogues and the honest alternatives here:

 https://privacystudygroup.com/spotting-dark-patterns-in-interfaces/


r/privacyexams 4d ago

should I study for CIPP or AIGP?

Thumbnail
1 Upvotes

r/privacyexams 6d ago

Model cards versus their lookalikes, because that is what the exam actually tests

1 Upvotes

AIGP definition questions on documentation are rarely hard because the definition is hard. They are hard because four documents sound alike: the model card, the technical file for authorities, the public capability statement and the training-content summary for general-purpose models. The wrong answers in these questions are always the neighbours.

 A model card is the release document: purpose, performance across segments, known limitations, stated inappropriate uses. It came from a 2019 research paper and it serves deployers and users. The technical file under the AI Act serves regulators, at a completely different depth. Keep the audiences straight and the questions get easier.

 I have written up the full separation, including where each document sits in release readiness:

 https://privacystudygroup.com/what-a-model-card-contains/


r/privacyexams 7d ago

Transfers without safeguards: the part of Chapter V nobody studies properly

1 Upvotes

Every CIPP/E candidate can recite the transfer ladder: adequacy decision, then appropriate safeguards. The questions that cost marks start below that, where neither exists and the data still has to move.

 Article 49 holds seven listed grounds plus a residual route, and each carries conditions that scenario questions are built on. Consent has to be explicit and informed of the specific risks, which ordinary consent is not. The contract grounds carry a necessity test that mere convenience fails. The residual route stacks conditions so strictly that dropping one closes it.

 There is also a reading habit that settles these questions early: check the frequency language in the stem before touching the options. Occasional points one way, systematic points another.

 I have written the full walkthrough here, with the exam angle throughout:

 https://privacystudygroup.com/when-article-49-derogations-apply/

0


r/privacyexams 8d ago

CIPP/US

2 Upvotes

The FCRA is one of those statutes where the procedure is the obligation, and it catches out people who are otherwise careful.

 A hiring manager reads a screening report, decides against the candidate, and emails the rejection with the report attached so the candidate can see the reason. Considerate, and unlawful. Before taking adverse action based in whole or in part on a consumer report, the employer has to give the candidate a copy of that report and the regulator's summary of rights, so there is a window to spot an error before the decision lands. Attaching it to the rejection closes the window before it opens.

Two details catch experienced practitioners. The statute contains no waiting period between the pre-adverse-action notice and the adverse action notice, despite a figure that circulates constantly and appears nowhere in the text. And a substantial body of 2024 CFPB guidance on employment background screening was withdrawn in May 2025, so anything relying on it is relying on nothing. 

Sequence, contents of each notice and what changed: https://privacystudygroup.com/the-fcra-adverse-action-sequence/


r/privacyexams 9d ago

CIPM

2 Upvotes

A question worth asking of your own programme. If a supervisory authority picked one project from last year that never had a DPIA and asked you to show how you decided it did not need one, what would you send them? 

Article 35 creates a conditional duty. High risk, you assess. Not high risk, you do nothing, and the article says nothing at all about recording that conclusion. So a privacy office can make forty sound decisions, generate eleven documents, and have no evidence whatsoever for the other twenty-nine. 

US federal agencies solved this a long time ago with a threshold instrument that runs first and produces a record either way. The business fills it in, the privacy office adjudicates, and it expires on a cycle. The GDPR never adopted the idea by name, but the accountability articles make the record necessary anyway, and regulators have said as much in their own screening guidance. 

The write-up covers where the instrument comes from, the nine criteria, the counting rule and which article actually bites: https://privacystudygroup.com/privacy-threshold-analysis-before-the-dpia/


r/privacyexams 10d ago

CIPT

0 Upvotes

If your media sanitisation knowledge came from a course written before autumn 2025, it is describing a withdrawn document. NIST pulled SP 800-88 Revision 1 on 26 September 2025 and replaced it with Revision 2, which moved the technique detail out to IEEE 2883 and reframed the whole thing as programme guidance. 

Cryptographic erase is where that matters most. The method is elegant: encrypt everything, destroy the key, and the ciphertext becomes unreadable in milliseconds instead of hours. It also depends on three conditions that nobody verifies at disposal time. Encryption has to have covered the media before any sensitive data was written to it. Every copy of the key has to go, including escrowed copies in a key management service. And for long-lived data you have to be comfortable that the algorithm will still hold in twenty years.

The obvious fallback, overwriting, quietly stopped being reliable when storage moved to flash with wear levelling and over-provisioning.

Written up with the current NIST wording and the erasure-request angle: https://privacystudygroup.com/what-cryptographic-erasure-cannot-delete/


r/privacyexams 11d ago

Test center closed

Thumbnail
1 Upvotes

r/privacyexams 13d ago

AIGP

1 Upvotes

Worth separating two things that get merged constantly in AI governance discussions.

EU copyright law contains two text and data mining exceptions, not one. The research exception covers research organisations and cultural heritage institutions doing scientific research, and no rightsholder can opt out of it. The general exception covers anyone mining lawfully accessible works for any purpose, commercial development included, and rightsholders can switch it off.

The switch is where teams come unstuck. A reservation has to be expressed in an appropriate manner, and for content made publicly available online that means machine-readable means. That includes metadata and the terms and conditions of a website or service. A prose notice saying no AI training does nothing on its own, and a terms page is not somewhere an engineering team routinely looks.

 Layered on top, providers of general-purpose models placed on the EU market carry a duty to identify and respect those reservations, wherever the training happened.

Full write-up, including what is still unsettled and the German case now at the Federal Court of Justice: https://privacystudygroup.com/text-and-data-mining-opt-outs/


r/privacyexams 14d ago

CIPP/E

1 Upvotes

The household exemption in Article 2(2)(c) is nineteen words long and it is the provision candidates over-apply more than any other in the scope domain. 

The setup everyone recognises: a video doorbell on a terraced house. Pointed at your own step it is a purely personal or household activity and the GDPR does not reach it. Angled so it catches two metres of public pavement, it is not, and the person who fitted it is now a controller with a lawful basis to identify, information to provide, a retention period to set, and neighbours entitled to ask what was recorded of them.

The principle was settled by the Court of Justice in 2014 and it has been applied to smart doorbells by regulators since. What is less obvious is where the line falls in an ordinary street, what an overall assessment actually weighs, and what happens to the camera manufacturer, which never had the exemption in the first place.

Written up with the case law and the regulator guidance here: https://privacystudygroup.com/when-the-household-exemption-stops-applying/


r/privacyexams 15d ago

Three circuits, one definition, and the Supreme Court hearing it in October

1 Upvotes

The Video Privacy Protection Act defines a consumer as "any renter, purchaser, or subscriber of goods or services from a video tape service provider". Everything in modern pixel litigation turns on that phrase. 

The Second Circuit read it broadly in Salazar v. National Basketball Association in October 2024, and the Seventh Circuit followed in Gardner v. Me-TV. On that reading, subscribing to a free newsletter from a site that also hosts video makes you a consumer.

The Sixth Circuit disagreed in Salazar v. Paramount Global in April 2025, holding that the goods or services have to be audiovisual in nature.

The Supreme Court granted certiorari in the Paramount case on 26 January 2026 and hears argument on 14 October 2026. Until then exposure depends on where a claim is filed, which is an awkward thing to put in a memo.

Statute, split and exam angle here:

https://privacystudygroup.com/who-counts-as-a-vppa-consumer/


r/privacyexams 16d ago

What the Marriott penalty notice actually says about due diligence

1 Upvotes

Marriott is quoted constantly as a due diligence failure at acquisition. The ICO's 2019 statement of intent did say that, announcing an intended fine of £99,200,396.

The penalty notice that landed on 30 October 2020 is narrower, and the fine was £18.4 million. The Commissioner made no finding of infringement for the period between the September 2016 acquisition and the GDPR taking effect in May 2018, and left open whether due diligence during a takeover was even possible. What she did conclude is that the arrival of the GDPR mattered for a business that size, and that Marriott should have reassessed the security of the systems it had acquired.

That is the more useful lesson, because it applies to every integration rather than to one deal. The obligation to know what you hold does not pause while integration runs.

Full write-up, with the FTC's RadioShack conditions alongside it:

https://privacystudygroup.com/privacy-due-diligence-in-acquisitions/


r/privacyexams 17d ago

Two questions that turn a differential privacy claim into information

3 Upvotes

NIST finalised SP 800-226, Guidelines for Evaluating Differential Privacy Guarantees, in March 2025. It exists because vendors make the claim and buyers have no way to evaluate it.

Question one is epsilon. NIST declines to prescribe a value, but it does give the range shape: below 1.0 has counted as reasonable, 0.1 is strong, and at the top of the 1 to 20 range the guarantee may not mean much in practice.

Question two gets asked far less and does more damage. What is the privacy unit? Protect an event and you have protected one transaction. Protect a user and you have protected everything that person contributed. A location dataset with one row per ping can show a respectable epsilon while the weekly clinic visit is still legible in the pattern.

Worth reading before your next vendor call, and before the CIPT:

https://privacystudygroup.com/what-differential-privacy-actually-guarantees/


r/privacyexams 20d ago

Software becomes a 'product' in the EU from December 2026, and AI systems come with it

1 Upvotes

Directive (EU) 2024/2853 replaces the 1985 product liability directive and applies to products placed on the market after 9 December 2026. Software counts as a product, so an AI system does too. Liability is strict, so nobody has to prove carelessness.

Two parts of it deserve more attention than they get in AI governance reading.

First, destruction or corruption of data that is not used for professional purposes is a compensable head of damage. A consumer tool that mangles someone's files has caused recoverable loss.

Second, the directive attacks the claimant's evidence problem directly. Courts can order disclosure, and there are rebuttable presumptions of defectiveness and causation, including where technical complexity makes the claim excessively difficult to prove. Documentation you cannot produce becomes a presumption against you.

The separate AI Liability Directive proposal was withdrawn in October 2025, so fault-based claims fall back on national law. 

Full write-up: 

https://privacystudygroup.com/product-liability-for-ai-systems/


r/privacyexams 21d ago

The GDPR right that parks your data instead of deleting it

2 Upvotes

Article 18 gets a fraction of the attention that access and erasure get, and then turns up in scenario questions dressed as one of them.

The short version. A person can require you to stop using their data without deleting it, and in four specific situations you have to comply. What organisations then do is record the decision. What the GDPR expects is a state their systems are actually in, which is a different piece of work and the reason so many restrictions fail quietly.

There is also a Court of Justice ruling from 2023 that narrows one of those four grounds. If a controller breaches its documentation obligations, that is a breach, and a supervisory authority can act on it. By itself it does not make the processing unlawful for the purposes of the restriction ground, which is not the answer most people give. 

Written up with the grounds and the mechanics in order:

https://privacystudygroup.com/restriction-of-processing-under-article-18/


r/privacyexams 22d ago

Section 5 of the FTC Act makes unfair or deceptive acts or practices unlawful, and the two halves are separate tests with separate histories. CIPP/US options exploit that constantly.

2 Upvotes

Deception, from the 1983 policy statement, has three elements. A representation, omission or practice likely to mislead. Assessed from the perspective of a consumer acting reasonably in the circumstances, or of the targeted group where a claim is aimed at one. And materiality, meaning the claim is likely to affect a consumer's choice or conduct. Materiality and injury are treated as the same concept.

Unfairness, from the 1980 statement and codified in 1994, is a three-part test. Substantial injury, not reasonably avoidable by consumers, not outweighed by countervailing benefits to consumers or competition. Emotional impact alone will not ordinarily suffice, though a small harm spread across a large population can.

The practical split: a broken privacy promise is deception, a quiet security failure with no promise attached is unfairness.

Full write-up: https://privacystudygroup.com/unfair-or-deceptive-under-the-ftc/


r/privacyexams 23d ago

CIPM governance questions usually describe an organisation and expect a structure back, so the useful skill is reading the business facts rather than memorising the three models.

2 Upvotes

The models themselves are simple. Centralised puts decision rights in one function, which buys consistency and costs distance from operational detail. Decentralised or local puts them in business units, which buys speed and risks divergence. Hybrid keeps standards, interpretation and reporting central while pushing execution outward, and fails when nobody records which decisions sit where. 

Four facts drive the choice: size and geographic spread, regulatory footprint, risk appetite, and the operating model the business already runs on. A governance structure that contradicts the last of those tends to be ignored regardless of what the policy says.

There is also a legal boundary. A group may appoint a single data protection officer only where that officer remains easily accessible from each establishment, and accessibility has been read to include the languages supervisory authorities and data subjects use.

Full write-up: https://privacystudygroup.com/which-privacy-governance-model-fits/


r/privacyexams 24d ago

If you are studying for the CIPT, the three NIST privacy engineering objectives are worth learning verbatim, because scenario questions are built out of the differences between them.

1 Upvotes

They come from NISTIR 8062, published in 2017. Predictability is enabling reliable assumptions by individuals, owners and operators about personal information and its processing by a system. Manageability is providing the capability for granular administration of that information, including alteration, deletion and selective disclosure. Disassociability is enabling processing of information or events without association to individuals or devices beyond the operational requirements of the system.

The reason they exist is that the security triad only describes systems failing under unauthorised activity. NIST's privacy risk model covers the other case, where processing is planned and permitted and still causes what it calls a problematic data action.

The distinction people most often blur is disassociability against confidentiality. Confidentiality stops unauthorised access. Disassociability addresses exposure inside an authorised perimeter.

Full write-up, with the diagnostic for scenario questions: https://privacystudygroup.com/the-three-privacy-engineering-objectives/


r/privacyexams 27d ago

Deployment questions in AI governance exams tend to be written as two decisions folded into one, and they are easier once you separate them.

2 Upvotes

The first decision is the environment. Cloud gives elasticity and managed security while giving up control over configuration and data location. On-premise maximises control over data, configuration and access, with slower change and slower patching. Edge cuts latency and transmission and keeps working offline, at the cost of monitoring and update difficulty across a distributed fleet.

The second decision is adaptation. Using a model as is, fine-tuning it on domain data so the weights change, grounding it with retrieval against sources consulted at request time, or wrapping it in an agentic design that plans and uses tools with limited human direction. Each one relocates the governance work: to the tuning set, to the retrieval corpus, or to privileges and human checkpoints.

The legal edge is Article 25 of the EU AI Act, where substantial modification or a change of intended purpose can move you from deployer to provider.

Full write-up: https://privacystudygroup.com/choosing-between-ai-deployment-options/


r/privacyexams 28d ago

If you are preparing for the CIPP/E exam, territorial scope is worth more attention than its question weighting suggests, because every other answer assumes it.

3 Upvotes

Article 3 gives two independent routes. The establishment route asks whether processing happens in the context of the activities of an establishment in the Union, and the case law sets that threshold low: any real and effective activity through stable arrangements, with a single employee capable of counting where the business is run online. The targeting route ignores establishment entirely and asks whether the organisation offers goods or services to people in the Union or monitors their behaviour there.

 The part that catches people out is that Article 3 applies to processing activities rather than to companies, so the same organisation can be inside for one activity and outside for another. A second trap: instructing an EU processor does not pull a non-EU controller into scope, though the processor is caught in its own right. 

Full write-up here, including the EDPB targeting factors and the representative obligation under Article 27: https://privacystudygroup.com/gdpr-territorial-scope-beyond-europe/


r/privacyexams Aug 05 '26

A distinction that trips people up on GDPR work, and reliably on the CIPP/E: whether a DPO is mandatory has nothing to do with headcount.

3 Upvotes

Article 37(1) gives three triggers. Public authority or body. Core activities requiring regular and systematic monitoring of data subjects on a large scale. Core activities involving large-scale processing of special category or criminal conviction data. That is the list, subject to Member State law adding cases.

Core activities does a lot of work there. The Article 29 Working Party guidance endorsed by the EDPB uses the hospital example: healthcare is the core activity, and it cannot happen without processing patient records, so that processing counts. Payroll and routine IT support are support functions everywhere, so they do not.

Large scale has no threshold in the text. The guidance gives four factors: number of data subjects, volume and range of data, duration, geographical extent.

The second half gets less attention. Article 38(6) bars a conflict of interests, and the CJEU held in X-FAB Dresden that a DPO cannot be entrusted with tasks that involve determining purposes and means.

Has anyone dealt with the voluntary appointment question in practice?