# CIPP/US interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How is US privacy law structured compared with the GDPR? | No single federal omnibus law: sector laws, FTC enforcement against unfair or deceptive practices, and a growing set of state laws. | |
| 2 | What does the FTC expect from our privacy notice? | That it is accurate and that we do what it says. Breaking a promise in a notice can be a deceptive practice. | |
| 3 | We hold health data from a fitness app. Does HIPAA apply? | Only if we are a covered entity or a business associate. Many consumer apps fall outside HIPAA, and FTC rules may apply instead. | |
| 4 | What does COPPA require of us? | Verifiable parental consent before collecting personal information from children under 13 on services directed to children or with actual knowledge. | |
| 5 | Law enforcement asks for customer data. What do you do? | Check the legal process and its scope, involve counsel, disclose only what is required, record it, and notify the customer where allowed. | |
| 6 | What can we check in background screening? | Consumer reports under the FCRA need disclosure, written authorization and adverse action notices, and some states limit more. | |
| 7 | Which state privacy laws apply to us? | The general state privacy laws whose thresholds we meet, starting with California's, and what rights they give consumers. | |
| 8 | How do you handle a data breach that touches several states? | Every state has a breach notification law, with different definitions, timelines and regulator notices, so track each one. | |

Source: https://credentialpress.com/guides/cipp-us-interview-questions
