# CIPT interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How do you build privacy into a new product? | Requirements at design, a privacy review at key gates, defaults that protect users, and tests that prove it. | |
| 2 | When would you use pseudonymization rather than anonymization? | Pseudonymized data can be re-linked and is still personal data; anonymization removes that link and is hard to do well. | |
| 3 | How do you decide what data a feature should collect? | Start from the purpose, collect the minimum, and justify every field. | |
| 4 | How do you design consent and preference controls? | Clear choices, no dark patterns, easy withdrawal, and choices that actually change processing. | |
| 5 | What privacy risks does tracking on our website create? | Cookies and pixels sharing data with third parties, consent rules, and what partners do with the data. | |
| 6 | How would you set retention and deletion in our systems? | A retention schedule mapped to systems, automated deletion, and checks that it ran, including backups. | |
| 7 | How do you assess a third-party SDK? | What data it collects, where it sends it, the contract, and how to switch it off. | |
| 8 | How would you review an AI feature for privacy? | Training and input data, outputs that may reveal personal data, user notice, and opt-outs. | |

Source: https://credentialpress.com/guides/cipt-interview-questions
