CIPP-CN Sample Questions & Answers
The Personal Information Protection Law, its processing requirements, individual rights, and cross-border transfer rules carry the biggest weight, alongside China's privacy framework and Cybersecurity Law, workplace rules, sensitive data, and AI-related regulations.
Launch the full CIPP-CN simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Introduction to Personal Information Protection in China · CSL Network Security
Case Study: TechFin China
TechFin China is a financial technology services provider headquartered in Shenzhen. They offer a mobile payment app used by 50 million active users. Recently, TechFin decided to partner with a credit scoring agency in Europe to enhance their fraud detection algorithms. This involves sending user transaction logs and device identifiers to the European partner.
TechFin has been designated as a Critical Information Infrastructure Operator (CIIO) by the financial regulators due to its market share. They have never transferred data outside China before.
Based on the scenario, what is the PRIMARY legal constraint TechFin faces regarding the data location before any transfer can occur?
Show answer & explanation
Correct answer: A
As a designated Critical Information Infrastructure Operator (CIIO), TechFin is subject to the strict data localization requirements of the Cybersecurity Law (CSL) and PIPL. CIIOs MUST store personal information and important data collected/generated in China locally. Any export requires a security assessment, but the primary constraint is the default localization requirement.
- Question 2Beginner
Introduction to Personal Information Protection in China · Chinese Privacy Regulatory Framework
Which government entity is the primary authority responsible for the overall planning and coordination of personal information protection and related supervision in China?
Show answer & explanation
Correct answer: D
The Cyberspace Administration of China (CAC) is the primary department responsible for the overall planning and coordination of personal information protection and related supervision and administration nationwide.
- Question 3Intermediate
Sectoral Regulations and Compliance · Sensitive Data Categories
True or False: Under PIPL, if a company wishes to install facial recognition cameras in a shopping mall for the sole purpose of security monitoring, they are exempt from obtaining separate consent from each individual shopper, provided they post a prominent notice.
Show answer & explanation
Correct answer: A
According to PIPL Article 26 and the Supreme People's Court interpretation, image capture in public places for the purpose of maintaining public safety is permitted without individual consent, provided prominent alert signage is displayed and the data is not used for other purposes (like marketing analysis).
- Question 4Intermediate
Sectoral Regulations and Compliance · AI and Algorithmic Governance
A developer is configuring a generative AI service that will be available to the general public in China. According to the 'Interim Measures for the Management of Generative Artificial Intelligence Services', which action is legally required regarding the training data used for the model?
Show answer & explanation
Correct answer: A
The Interim Measures mandate that providers must lawfully source training data and ensure it does not infringe on intellectual property rights or contain illegal content.
- Question 5IntermediateSelect 2
The Personal Information Protection Law · Personal Information Processing
You are advising a client on PIPL compliance. They need to understand the concept of 'Separate Consent'. In which of the following scenarios is obtaining Separate Consent explicitly REQUIRED by PIPL? (Select TWO)
Show answer & explanation
Correct answers: A, B
Article 23 of PIPL requires separate consent when providing personal information to another handler (third-party sharing).
PIPL explicitly requires 'separate consent' (or specific consent) for processing sensitive personal information (Article 29).
- Question 6Advanced
The Personal Information Protection Law · Individual Rights
A Data Protection Officer (DPO) is preparing a training session on individual rights under PIPL. A manager asks about the 'Right to Portability'. What are the specific conditions required for a data handler to be obligated to fulfill a portability request?
Show answer & explanation
Correct answer: B
PIPL Article 45 states that the right to portability applies when the request meets the conditions prescribed by the state cybersecurity and informatization department (CAC). This generally includes technical feasibility and identity verification.
- Question 7Intermediate
Introduction to Personal Information Protection in China · CSL Network Security
Regarding the Multi-Level Protection Scheme (MLPS) 2.0, which level of system requires a mandatory annual evaluation by a qualified third-party assessment agency?
Show answer & explanation
Correct answer: B
Under MLPS 2.0, systems classified as Level 3 or higher must undergo a测评 (assessment) at least once annually by a qualified agency. Level 2 systems generally require self-assessment or less frequent third-party review.
- Question 8Beginner
The Personal Information Protection Law · Compliance and Accountability
What is the correct command-line equivalent or procedural step for a company to officially appoint a Data Protection Officer (Person in Charge of Personal Information Protection) as required by PIPL for processors reaching the threshold?
Show answer & explanation
Correct answer: A
PIPL Article 52 requires processors reaching a certain volume threshold to appoint a person in charge and disclose their name and contact method to the authorities (filing/registration).
- Question 9Intermediate
The Personal Information Protection Law · Compliance and Accountability
A cloud service provider in China discovers a vulnerability that caused a data leak involving 50,000 user records. According to the CSL and PIPL, what is the notification timeline requirement for reporting this incident to the regulatory authorities?
Show answer & explanation
Correct answer: A
PIPL Article 57 requires personal information handlers to 'immediately' (立即) take remedial measures and notify the relevant departments and individuals. Unlike GDPR's 72-hour window, the Chinese requirement is 'immediate'.
- Question 10IntermediateSelect 3
The Personal Information Protection Law · Compliance and Accountability
Which of the following data processing activities requires the handler to conduct a Personal Information Protection Impact Assessment (PIA) beforehand? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
Entrusting processing, providing to other handlers, or disclosing publicly all trigger the PIA requirement.
Processing sensitive PI is a mandatory trigger for a PIA under PIPL Article 55.
Using PI for automated decision-making constitutes a high-risk activity requiring a PIA.
Ready for the real thing?
The full CIPP-CN simulator has every exam-style question, timed mode, and instant scoring.