All Practice Exams

100+ Free US DPO Practice Questions

Prepare for the PECB Certified U.S. Data Privacy Officer exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: US DPO Exam

80Q, 3 hours

Exam Format

PECB

70%

Passing Score

PECB

USD 1000 exam-only

Exam Fee

PECB

PECB Certified U.S. Data Privacy Officer certification exam evaluates candidates on official PECB domains and standards. Note: this practice set is an English-language MCQ study adaptation.

Sample US DPO Practice Questions

Try these sample questions to test your US DPO exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1How is data privacy primarily regulated in the United States?
A.By a single comprehensive federal privacy law that applies to all industries
B.Through a combination of federal, state, and sector-specific laws and regulations
C.Exclusively through self-regulatory industry codes of conduct
D.By a federal privacy agency that licenses all organizations processing personal data
Explanation: The U.S. has no single comprehensive federal privacy statute. Instead, privacy is governed by sector-specific federal laws (such as HIPAA for health data and GLBA for financial data), a growing set of state comprehensive privacy laws, and Federal Trade Commission enforcement against unfair or deceptive practices.
2Which entities must comply with the HIPAA Privacy Rule?
A.Any company that stores health-related information about its employees
B.All U.S. businesses above a revenue threshold
C.Covered entities (health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically) and their business associates
D.Only federal government health agencies
Explanation: HIPAA applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with certain transactions — and to business associates that handle protected health information (PHI) on their behalf. Employers acting purely as employers and most wellness apps fall outside HIPAA.
3The Children's Online Privacy Protection Act (COPPA) primarily requires operators of websites or online services directed at children to do what before collecting personal information from children under 13?
A.Obtain verifiable parental consent
B.Register with the Federal Trade Commission
C.Encrypt all collected data at rest
D.Publish an annual transparency report
Explanation: COPPA requires operators of online services directed at children under 13 (or with actual knowledge they are collecting from such children) to obtain verifiable parental consent before collecting, using, or disclosing a child's personal information. The FTC enforces COPPA through its implementing rule.
4Under the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, financial institutions must:
A.Obtain opt-in consent before any internal use of customer data
B.Store all customer information exclusively on systems located in the United States
C.Submit their security architecture to the FTC for annual approval
D.Develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards
Explanation: The GLBA Safeguards Rule requires financial institutions to maintain a written information security program appropriate to their size and complexity, including risk assessment, safeguards such as access controls and multi-factor authentication, a designated qualified individual, and periodic reporting to the board.
5A lender denies a consumer's credit application based on information in a consumer report. Under the Fair Credit Reporting Act (FCRA), the lender must:
A.Delete the consumer's entire credit file within 30 days
B.Provide an adverse action notice identifying the consumer reporting agency, the right to a free report within 60 days, and the right to dispute inaccurate information
C.Obtain the consumer's consent before using any consumer report
D.Pay statutory damages automatically upon any denial of credit
Explanation: When an adverse action is based wholly or partly on a consumer report, the FCRA requires an adverse action notice naming the consumer reporting agency (CRA), stating the CRA did not make the decision, and informing the consumer of the right to a free copy of the report within 60 days and the right to dispute inaccurate information.
6Which legal authority does the Federal Trade Commission most commonly use to bring privacy and data security enforcement actions against commercial companies?
A.The Privacy Act of 1974
B.The Computer Fraud and Abuse Act
C.Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices
D.The Electronic Communications Privacy Act
Explanation: Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in or affecting commerce. The FTC uses it to police broken privacy promises (deception) and inadequate data security that causes substantial consumer injury (unfairness) across most commercial sectors.
7Under FERPA, when do the privacy rights in a student's education records transfer from the parents to the student?
A.When the student turns 18 or attends a school beyond the high school level
B.When the student graduates from high school
C.When the student turns 21 in all cases
D.Never; parents always retain FERPA rights
Explanation: FERPA rights transfer to the student when he or she reaches age 18 or attends a postsecondary institution at any age; the student then becomes an 'eligible student.' Until that point, parents hold the rights to inspect records, seek amendment, and control disclosure of personally identifiable information.
8Under the HIPAA Breach Notification Rule, within what maximum period must affected individuals be notified after discovery of a breach of unsecured PHI?
A.24 hours
B.10 business days
C.30 calendar days
D.60 calendar days
Explanation: Covered entities must notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach of unsecured protected health information. Business associates must notify the covered entity without unreasonable delay and no later than 60 days as well.
9Under the GLBA Privacy Rule, before a financial institution shares nonpublic personal information with nonaffiliated third parties, it must generally:
A.File the proposed sharing with its federal regulator 30 days in advance
B.Provide a privacy notice and give consumers a reasonable opportunity to opt out of the sharing
C.Obtain signed written consent from every customer
D.Anonymize the information using the HIPAA Safe Harbor method
Explanation: GLBA's Privacy Rule requires financial institutions to give customers a clear privacy notice describing information-sharing practices and a reasonable means and opportunity to opt out before sharing nonpublic personal information with nonaffiliated third parties, subject to exceptions such as service providers under contract.
10A hospital discovers a breach of unsecured PHI affecting more than 500 residents of a single state. In addition to notifying the affected individuals, the HIPAA Breach Notification Rule requires the hospital to notify:
A.The Federal Trade Commission and the state attorney general
B.The Federal Bureau of Investigation
C.Prominent media outlets serving that state or jurisdiction, and the Secretary of Health and Human Services
D.No other parties; individual notice is sufficient
Explanation: For breaches affecting more than 500 residents of a state or jurisdiction, HIPAA requires notice to prominent media outlets serving that area, in addition to individual notice. Breaches involving 500 or more individuals must also be reported to the HHS Secretary contemporaneously (within 60 days of discovery), while smaller breaches are logged and reported annually.

About the US DPO Exam

The PECB Certified U.S. Data Privacy Officer certification evaluates professional competence in governance, implementation, auditing, and management according to PECB standards.

Questions

80 scored questions

Time Limit

3 hours

Passing Score

70%

Exam Fee

USD 1000 exam-only (PECB (Professional Evaluation and Certification Board))

US DPO Exam Content Outline

~20%

US Privacy Law Landscape & Governance Framework

Federal vs state privacy regulatory model, FTC enforcement, FTC Act Section 5, and establishing a US privacy program.

~25%

Comprehensive US State Privacy Statutes (CCPA/CPRA, CPA, VCDPA, etc.)

California Consumer Privacy Act / CPRA, Virginia VCDPA, Colorado CPA, consumer rights (opt-out, access, deletion), and GPC.

~25%

Sectoral US Privacy Regulations (HIPAA, GLBA, COPPA, FERPA)

Healthcare privacy (HIPAA Privacy & Security Rules), financial privacy (Gramm-Leach-Bliley Act), children's privacy (COPPA), and educational records.

~15%

Data Lifecycle Management & Privacy Operations

Data inventory and mapping, Privacy Impact Assessments (PIAs), vendor privacy risk management, and cross-border data transfer mechanisms.

~15%

Data Breach Response & Privacy Incident Management

US state data breach notification statutes, harm evaluation, regulatory notification timelines, consumer notice requirements, and IR coordination.

How to Pass the US DPO Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 80 questions
  • Time limit: 3 hours
  • Exam fee: USD 1000 exam-only

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

US DPO Study Tips from Top Performers

1Review the official PECB candidate handbook
2Practice scenario-based questions across all domains
3Pace yourself to answer all questions within the time limit

Frequently Asked Questions

What is the format of the PECB US Data Privacy Officer exam?

The official exam consists of 80 questions over 3 hours. This practice set provides 100 English-language MCQs as a study aid.

Is this practice test free?

Yes, 100% free with detailed explanations.