Section 2: 35–45%I9
Confidentiality and Privacy
Exam insight
The exam draws a sharp line between confidentiality (protecting sensitive business data) and privacy (protecting personal data of individuals), and expects you to apply data classification, privacy principles, and de-identification techniques. Knowing which regulation and which technique fits a scenario is frequently tested.
What AICPA wants you to know
- 1Distinguish confidentiality from privacy.
- 2Apply data classification to determine handling requirements.
- 3Define PII and PHI and recognize examples.
- 4State the core privacy principles, including notice, consent, and data minimization.
- 5Summarize the scope of GDPR, CCPA, and HIPAA at a high level.
- 6Compare de-identification techniques: masking, anonymization, pseudonymization, tokenization, and encryption.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.