IAPP Exam 2026 CIPP-US Dumps Updated Questions UPDATED Jul-2026 [Q50-Q69]

Share

IAPP Exam 2026 CIPP-US Dumps Updated Questions UPDATED Jul-2026

Get The Most Updated CIPP-US Dumps To Certified Information Privacy Professional Certification


IAPP CIPP-US certification is an essential credential for anyone who is serious about working in the field of privacy and data protection. Whether you are just starting out in your career or are looking to take your skills to the next level, this certification is an important step in achieving your goals and advancing your professional development.

 

NEW QUESTION # 50
SCENARIO
Please use the following to answer the next QUESTION :
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal dat a. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Under the General Data Protection Regulation (GDPR), how would the U.S.-based startup company most likely be classified?

  • A. As a data manager
  • B. As a data supervisor
  • C. As a data processor
  • D. As a data controller

Answer: C

Explanation:
Processor is the answer and correct based on the fact that the EU retailer was collecting consents and sending data internationally to US. The distractor of lack of consent and the instruction somehow implied that it now needs to be adhered to by the processor despite controller EU Retailer messing up should be mindfully sidestepped. Supervisor and Controller are synonymous with both terms used in the GDPR. Data manager is not a term used in GDPR.


NEW QUESTION # 51
The CFO of a pharmaceutical company is duped by a phishing email and discloses many of the company's employee personnel files to an online predator. The files include employee contact information, job applications, performance reviews, discipline records, and job descriptions.
Which of the following state laws would be an affected employee's best recourse against the employer?

  • A. The state social security number confidentiality statute.
  • B. The state personnel record review statute.
  • C. The state data destruction statute.
  • D. The state UDAP statute.

Answer: D

Explanation:
The state UDAP statute, which stands for Unfair and Deceptive Acts and Practices, is a law that protects consumers from unfair or deceptive business practices. In this case, the employer's failure to protect the employee's personal information from a phishing attack could be considered an unfair or deceptive act or practice that harmed the employee. The employee could sue the employer under the state UDAP statute for damages, injunctive relief, or other remedies.


NEW QUESTION # 52
In 2012, the White House and the FTC both issued reports advocating a new approach to privacy enforcement that can best be described as what?

  • A. Comprehensive.
  • B. Self-regulatory.
  • C. Notice and choice.
  • D. Harm-based.

Answer: A

Explanation:
In 2012, the White House released a report titled "Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy", which proposed a Consumer Privacy Bill of Rights based on the Fair Information Practice Principles (FIPPs). The report called for a comprehensive privacy framework that would apply to all commercial sectors and all personal data, regardless of the technology or business model involved. The report also urged Congress to enact legislation to implement the framework and empower the FTC to enforce it. Similarly, the FTC released a report titled "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers", which outlined a set of best practices for businesses to protect consumer privacy and foster innovation. The report also advocated for a comprehensive privacy framework that would cover both online and offline data, and apply to all entities that collect or use consumer data that can be reasonably linked to a specific consumer, computer, or device. The report also recommended that Congress consider enacting baseline privacy legislation and giving the FTC rulemaking authority to implement it. Therefore, both reports can be described as advocating a comprehensive approach to privacy enforcement, rather than a harm-based, self-regulatory, or notice and choice approach. References: White House Report, FTC Report, IAPP CIPP/US Study Guide (p. 31-32)


NEW QUESTION # 53
According to the Family Educational Rights and Privacy Act (FERPA). when can a school disclose records without a student's consent?

  • A. If the disclosure Is not to be conducted through email to the third party
  • B. If the disclosure would not reveal a student's student identification number
  • C. If the disclosure is made to practitioners who are involved in a student's hearth care.
  • D. If the disclosure is for the purpose of providing transcripts to a school where a student intends to enroll.

Answer: D

Explanation:
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records. FERPA generally requires that schools obtain written consent from students (or their parents if the student is a minor) before disclosing personally identifiable information from education records. However, FERPA allows specific exceptions where disclosures can be made without consent.
One of these exceptions is when a school discloses education records to another school where the student seeks or intends to enroll. This allows educational institutions to share information for legitimate educational purposes, such as transferring transcripts between schools when a student moves or applies for enrollment elsewhere.


NEW QUESTION # 54
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators.
He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing.
The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
What is the most likely way that Declan might directly violate the Health Insurance Portability and Accountability Act (HIPAA)?

  • A. By ignoring the conversation about a potential breach
  • B. By being present when patients are checking in
  • C. By following through with his plans for his upcoming paper
  • D. By speaking to a patient without prior authorization

Answer: C

Explanation:
Declan might directly violate the HIPAA Privacy Rule by using John's name and personal health information (PHI) in his paper without his written authorization. The Privacy Rule protects the confidentiality of PHI that is created, received, maintained, or transmitted by a covered entity or its business associate. PHI includes any information that relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual, and that identifies the individual or for which there is a reasonable basis to believe can be used to identify the individual1. Declan, as a nursing assistant, is part of the covered entity's workforce and must comply with the Privacy Rule. He cannot disclose John's PHI to anyone, including his classmates or instructors, without John's authorization or a valid exception under the Privacy Rule. Even if he does not use John's full name, he may still reveal enough information to make John identifiable, such as his diagnosis, his father's condition, or his location. This would be an impermissible use and disclosure of PHI, and a potential HIPAA violation. Declan should either obtain John's written authorization to use his PHI in his paper, or de- identify the information according to the Privacy Rule's standards2. References:
* Summary of the HIPAA Privacy Rule
* Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule


NEW QUESTION # 55
A large online bookseller decides to contract with a vendor to manage Personal Information (PI). What is the least important factor for the company to consider when selecting the vendor?

  • A. The vendor's employee retention rates
  • B. The vendor's reputation
  • C. The vendor's employee training program
  • D. The vendor's financial health

Answer: A

Explanation:
While it is important for a company to consider the reputation and financial health of a vendor, as well as their employee training program, the retention rates of the vendor's employees are not a direct indicator of the vendor's ability to protect personal information. It is important for the company to ensure that the vendor has appropriate security measures in place to protect personal information, such as access controls, encryption, and data breach response procedures. The company should also consider the vendor's compliance with applicable privacy and data protection laws, as well as their experience working with sensitive personal information. Overall, while employee retention rates may indirectly reflect the quality of the vendor's services, they are not a direct factor in assessing the vendor's ability to manage personal information.


NEW QUESTION # 56
What is the most likely reason that states have adopted their own data breach notification laws?

  • A. Many lawmakers believe that federal enforcement of current laws has not been effective
  • B. Many types of organizations are not currently subject to federal laws regarding breaches
  • C. Many large businesses have intentionally breached the personal information of their customers
  • D. Many states have unique types of businesses that require specific legislation

Answer: B


NEW QUESTION # 57
SCENARIO
Please use the following to answer the next QUESTION:
Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop.
"Doing your network?" Matt asked hopefully.
"No," the boy said. "I'm filling out a survey."
Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking Questions about my opinions."
"Let me see," Matt said, and began reading the list of Questions that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read further he learned that kids who took the survey were automatically registered in a contest to win the first book in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer Questions about his favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities.
How does Matt come to the decision to report the marketer's activities?

  • A. The marketer failed to make an adequate attempt to provide Matt with information
  • B. The marketer seems to have distributed his son's information without Matt's permission
  • C. The marketer did not provide evidence that the prize books were appropriate for children
  • D. The marketer failed to identify himself and indicate the purpose of the messages

Answer: B

Explanation:
Matt's decision to report the marketer's activities is based on his suspicion that the marketer violated the Children's Online Privacy Protection Act (COPPA), which is a federal law that regulates the online collection, use, and disclosure of personal information from children under 13 years of age1. According to COPPA, operators of websites or online services that are directed to children or knowingly collect personal information from children must:
* Provide notice to parents about their information practices and obtain verifiable parental consent before collecting, using, or disclosing personal information from children12.
* Give parents the choice of consenting to the operator's collection and internal use of a child's information, but prohibiting the operator from disclosing that information to third parties (unless disclosure is integral to the site or service, in which case, this must be made clear to parents)12.
* Provide parents access to their child's personal information to review and/or have the information deleted and give parents the opportunity to prevent further use or online collection of a child's personal information12.
* Maintain the confidentiality, security, and integrity of information they collect from children, including by taking reasonable steps to release such information only to parties capable of maintaining its confidentiality and security12.
* Retain personal information collected online from a child for only as long as is necessary to fulfill the purpose for which it was collected and delete the information using reasonable measures to protect against its unauthorized access or use12.
* Establish and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children12.
In Matt's case, he did not receive any notice from the marketer about the survey or the contest, nor did he give his consent for the collection or disclosure of his son's personal information. He also did not have any access or control over his son's information or the ability to prevent further use or collection. Moreover, he noticed that his son's information seemed to have been shared with other marketers, as evidenced by the commercial emails in his son's inbox. These actions indicate that the marketer did not comply with COPPA's requirements and may have exposed his son's information to unauthorized or inappropriate parties. Therefore, Matt decided to report the marketer's activities to the proper authorities, such as the Federal Trade Commission (FTC), which enforces COPPA and can impose civil penalties for violations13. References: 1:
Children's Online Privacy Protection Act | Federal Trade Commission, 1. 2: 16 CFR Part 312 - Children's Online Privacy Protection Rule, 3. 3: Children's Online Privacy Protection Act - Wikipedia, 2.


NEW QUESTION # 58
SCENARIO
Please use the following to answer the next QUESTION
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated dat a. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
What could the company have done differently prior to the breach to reduce their risk?

  • A. Communicated requests for changes to users' preferences across the organization and with third parties.
  • B. Implemented a comprehensive policy for accessing customer information.
  • C. Looked for any persistent threats to security that could compromise the company's network.
  • D. Honored the promise of its privacy policy to acquire information by using an opt-in method.

Answer: B


NEW QUESTION # 59
What was the original purpose of the Federal Trade Commission Act?

  • A. To enforce antitrust laws
  • B. To protect consumers
  • C. To ensure privacy rights of U.S. citizens
  • D. To negotiate consent decrees with companies violating personal privacy

Answer: B


NEW QUESTION # 60
What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?

  • A. A judgment rider
  • B. A consent decree
  • C. Common law judgment
  • D. Stare decisis decree

Answer: B

Explanation:
A consent decree is a legal document that resolves a dispute between a governmental agency and an adverse party without admission of guilt or liability by either side. It is approved by a judge and has the force of a court order. A consent decree may include terms such as compliance, monitoring, reporting, or remediation. A consent decree is often used to settle civil enforcement actions brought by federal agencies such as the Federal Trade Commission (FTC), the Environmental Protection Agency (EPA), or the Department of Justice (DOJ). References:
* IAPP Glossary, entry for "consent decree"
* [IAPP CIPP/US Study Guide], p. 39, section 2.1.3
* [IAPP CIPP/US Body of Knowledge], p. 9, section B.1.a


NEW QUESTION # 61
Which of the following entities is the PRIMARY enforcer of the HIPAA Privacy Rule and can assess civil monetary penalties?

  • A. Federal Trade Commission
  • B. Office of Civil Rights
  • C. State Attorney General
  • D. US Department of Justice

Answer: B

Explanation:
The Office of Civil Rights (OCR) is the primary enforcer of the HIPAA Privacy Rule. The U.S.
Department of Justice (DOJ) has criminal enforcement authority. The FTC and state attorneys general can bring enforcement for unfair and deceptive practices.


NEW QUESTION # 62
SCENARIO
Please use the following to answer the next QUESTION:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A.
HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B.
As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most significant reason that the U.S. Department of Health and Human Services (HHS) might impose a penalty on HealthCo?

  • A. Because HealthCo did not require CloudHealth to implement appropriate physical and administrative measures to safeguard the ePHI
  • B. Because CloudHealth violated its contract with HealthCo by not encrypting the ePHI
  • C. Because HealthCo did not conduct due diligence to verify or monitor CloudHealth's security measures
  • D. Because HIPAA requires the imposition of a fine if a data breach of this magnitude has occurred

Answer: C


NEW QUESTION # 63
Which federal law or regulation preempts state law?

  • A. Health Insurance Portability and Accountability Act
  • B. Electronic Communications Privacy Act of 1986
  • C. Telemarketing Sales Rule
  • D. Controlling the Assault of Non-Solicited Pornography and Marketing Act

Answer: A

Explanation:
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a federal law that regulates the privacy and security of health information in the United States. HIPAA preempts state laws that are contrary to its provisions, unless the state laws provide more stringent protections for health information12 HIPAA establishes a floor of federal standards for health information privacy and security, but allows states to enact laws that are more protective of individuals' rights34 For example, some states may require more specific consent from individuals before disclosing their health information, or impose stricter penalties for violations of health information privacy and security. HIPAA also provides exceptions for certain state laws that serve a compelling public interest, such as public health, safety, or welfare.References: https://www.findlaw.com
/litigation/legal-system/the-supremacy-clause-and-the-doctrine-of-preemption.html
https://www.bonalaw.com/insights/legal-resources/when-does-federal-law-preempt-state-law


NEW QUESTION # 64
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?

  • A. Refrain from selling their personal information to third parties.
  • B. Correct their personal information.
  • C. Delete their personal information.
  • D. Disclose their personal information to them.

Answer: B


NEW QUESTION # 65
If an organization certified under Privacy Shield wants to transfer personal data to a third party acting as an agent, the organization must ensure the third party does all of the following EXCEPT?

  • A. Notifies the organization if it can no longer meet its requirements for proper data handling
  • B. Provides the same level of privacy protection as the organization
  • C. Uses the transferred data for limited purposes
  • D. Enters a contract with the organization that states the third party will process data according to the consent agreement

Answer: D


NEW QUESTION # 66
Under the Fair Credit Reporting Act (FCRA), what must a person who is denied employment based upon his credit history receive?

  • A. Information from several consumer reporting agencies (CRAs).
  • B. An opportunity to reapply with the employer.
  • C. A list of rights from the Consumer Financial Protection Bureau (CFPB).
  • D. A prompt notification from the employer.

Answer: D


NEW QUESTION # 67
Which of the following is NOT a principle found in the APEC Privacy Framework?

  • A. Integrity of Personal Information.
  • B. Preventing Harm.
  • C. Privacy by Design.
  • D. Access and Correction.

Answer: C

Explanation:
The APEC Privacy Framework is a set of non-binding principles adopted by the Asia-Pacific Economic Cooperation (APEC) that aim to promote electronic commerce and protect information privacy in the region. The Framework is consistent with the core values of the OECD Guidelines on the Protection of Privacy and Trans-Border Flows of Personal Data, and reaffirms the value of privacy to individuals and to the information society. The Framework consists of nine principles:
Preventing Harm, Notice, Collection Limitation, Use of Personal Information, Choice, Integrity of Personal Information, Security Safeguards, Access and Correction, and Accountability. Privacy by Design is not one of the principles in the APEC Privacy Framework, although it is a concept that is endorsed by the OECD Guidelines and other privacy frameworks.


NEW QUESTION # 68
SCENARIO
Please use the following to answer the next question:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
At this stage of the investigation, what should the data privacy leader review first?

  • A. The company's data privacy policies
  • B. The text of the original complaint
  • C. Prevailing regulation on this subject
  • D. Available data flow diagrams

Answer: D

Explanation:
Data flow diagrams are graphical representations of how data moves within an organization or between different entities. They can help identify the sources, destinations, and processing of personal data, as well as the legal basis, retention periods, and security measures for each data flow. Reviewing the available data flow diagrams can help the data privacy leader to quickly and accurately respond to the urgent request from the EU-based retail partner, as well as to assess the potential risks and compliance gaps in the data transfer process. Data flow diagrams are also a key component of data protection impact assessments (DPIAs), which are required by the GDPR for high-risk processing activities.


NEW QUESTION # 69
......


IAPP CIPP-US (Certified Information Privacy Professional/United States) Certification Exam is a credential certification that validates the knowledge and skills of privacy practitioners in the United States. It tests individuals on U.S. privacy laws and regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), the Children's Online Privacy Protection Act (COPPA), and the California Consumer Privacy Act (CCPA). Certified Information Privacy Professional/United States (CIPP/US) certification demonstrates that the holder has expertise in designing, implementing, and managing privacy programs in organizations across various industries.

 

IAPP Certified CIPP-US  Dumps Questions Valid CIPP-US Materials: https://www.pass4sures.top/Certified-Information-Privacy-Professional/CIPP-US-testking-braindumps.html

Current CIPP-US Exam Dumps [2026] Complete IAPP Exam Smoothly: https://drive.google.com/open?id=1e6tSk3xsWDZqRmEUH9YF24zkWkrVVkQy