CIPP/US
What should you ask in a CIPP/US interview, and how should candidates answer?
A CIPP/US says someone knows the US privacy patchwork: federal sector laws, FTC enforcement and fast-moving state laws. These questions test the five exam domains in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask a CIPP/US candidate?
Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
How is US privacy law structured compared with the GDPR?
Listen for: No single federal omnibus law: sector laws, FTC enforcement against unfair or deceptive practices, and a growing set of state laws.
Domain I: The U.S. Privacy Environment
What does the FTC expect from our privacy notice?
Listen for: That it is accurate and that we do what it says. Breaking a promise in a notice can be a deceptive practice.
Domain I: The U.S. Privacy Environment
We hold health data from a fitness app. Does HIPAA apply?
Listen for: Only if we are a covered entity or a business associate. Many consumer apps fall outside HIPAA, and FTC rules may apply instead.
Domain II: Federal Privacy Laws
What does COPPA require of us?
Listen for: Verifiable parental consent before collecting personal information from children under 13 on services directed to children or with actual knowledge.
Domain II: Federal Privacy Laws
Law enforcement asks for customer data. What do you do?
Listen for: Check the legal process and its scope, involve counsel, disclose only what is required, record it, and notify the customer where allowed.
Domain III: Government and Court Access
What can we check in background screening?
Listen for: Consumer reports under the FCRA need disclosure, written authorization and adverse action notices, and some states limit more.
Domain IV: Workplace Privacy
Which state privacy laws apply to us?
Listen for: The general state privacy laws whose thresholds we meet, starting with California's, and what rights they give consumers.
Domain V: State Privacy Laws
How do you handle a data breach that touches several states?
Listen for: Every state has a breach notification law, with different definitions, timelines and regulator notices, so track each one.
Domain V: State Privacy Laws
CIPP/US interview scorecard
CIPP/US interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How is US privacy law structured compared with the GDPR? | No single federal omnibus law: sector laws, FTC enforcement against unfair or deceptive practices, and a growing set of state laws. | |
| 2 | What does the FTC expect from our privacy notice? | That it is accurate and that we do what it says. Breaking a promise in a notice can be a deceptive practice. | |
| 3 | We hold health data from a fitness app. Does HIPAA apply? | Only if we are a covered entity or a business associate. Many consumer apps fall outside HIPAA, and FTC rules may apply instead. | |
| 4 | What does COPPA require of us? | Verifiable parental consent before collecting personal information from children under 13 on services directed to children or with actual knowledge. | |
| 5 | Law enforcement asks for customer data. What do you do? | Check the legal process and its scope, involve counsel, disclose only what is required, record it, and notify the customer where allowed. | |
| 6 | What can we check in background screening? | Consumer reports under the FCRA need disclosure, written authorization and adverse action notices, and some states limit more. | |
| 7 | Which state privacy laws apply to us? | The general state privacy laws whose thresholds we meet, starting with California's, and what rights they give consumers. | |
| 8 | How do you handle a data breach that touches several states? | Every state has a breach notification law, with different definitions, timelines and regulator notices, so track each one. |
Source: https://credentialpress.com/guides/cipp-us-interview-questions
Which questions should a CIPP/US candidate prepare for?
Why CIPP/US?
How to answer: It shows you can work through US sector and state laws. Name the sectors you know.
Which state laws have you put into practice?
How to answer: Name them and the operational change each one needed.
Tell me about a consumer rights request process you built or ran.
How to answer: Intake, verification, deadlines, and how you measured it.
How do you keep up with new state laws?
How to answer: Your sources, and a recent change you acted on.
What should a candidate ask the employer?
- Which states and sectors matter most to the business?
- Who handles consumer rights requests today?
- How do legal and engineering work together on privacy?
Where next?
Also free: the CIPP/US mind map, plus every other credential on our study tools page. For the full syllabus, the CIPP/US Exam Guide and the CIPP/US Practice Questions go domain by domain.
Frequently asked questions
What should an employer ask a CIPP/US candidate?
Questions that test each exam domain in practice, for example: How is US privacy law structured compared with the GDPR? What does the FTC expect from our privacy notice? We hold health data from a fitness app. Does HIPAA apply?
What should a CIPP/US candidate ask the employer?
Which states and sectors matter most to the business? Who handles consumer rights requests today? How do legal and engineering work together on privacy?
How should a candidate prepare for a CIPP/US interview?
It shows you can work through US sector and state laws. Name the sectors you know.
Which books go deeper on CIPP/US?

Certified Information Privacy Professional, United States. 20 chapters, 520 pages.

Practice questions with full rationales, weighted to the published blueprint. 217 pages.
Sources
Credential Press is independent of the IAPP.