Weekend Sale Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

IAPP CIPP-C Certified Information Privacy Professional/ Canada (CIPP/C) Exam Practice Test

Page: 1 / 8
Total 76 questions

Certified Information Privacy Professional/ Canada (CIPP/C) Questions and Answers

Question 1

To whom does the Privacy Commissioner of Canada report?

Options:

A.

Supreme Court of Canada and Prime Minister

B.

House of Commons and the Senate.

C.

Administrative tribunal.

D.

Auditor General.

Question 2

An Alberta resident has signed up for a health wellness "app" developed by a British Columbia based software provider that stores the data in British Columbia. The application has various non-healthcare related uses. The individual inputs their name and email address in the application to subscribe to health and wellness tips.

The collection and use of the individual’s name and email address by the British Columbia based scheduling app would fall under what legislation?

Options:

A.

Alberta’s Health Information Act (HIA).

B.

Alberta’s Personal Information Protection Act (PIPA).

C.

Alberta’s Freedom of Information and Protection of Privacy Act (FOIP).

D.

The Personal Information Protection and Electronic Documents Act (PIPEDA).

Question 3

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must maintain a record of every breach of security safeguards involving personal information for a minimum of?

Options:

A.

3 months.

B.

12 months.

C.

24 months.

D.

36 months

Question 4

According to the federal Privacy Commissioner, what protection is missing from the Privacy Act regarding outsourcing of government work that contains personal information?

Options:

A.

A statement preventing the vendor to whom the information is outsourced to subcontract its processing.

B.

A statement granting the Privacy Commissioner the right to issue orders following an investigation into a possible data breach.

C.

A statement requiring the government agency to complete a Privacy Impact Assessment (PIA) prior to outsourcing to a third party.

D.

A statement indicating that the government institution from which the information is outsourced remains accountable for its security.

Question 5

A boutique hotel in Montreal seeks to attract travelers from Europe but wants to avoid becoming subject to the GDPR’s requirements. Which of the following activities is most likely to result in a finding that the hotel is subject to the GDPR?

Options:

A.

Placing advertisements on travel websites accessible in Europe.

B.

Collecting contact information for foreign business leaders from public directories.

C.

Sending discount offers to guests who previously registered using a foreign address.

D.

Translating the hotel's registration page into German based on the visitor's IP address.

Question 6

Under the Freedom of Information and Protection of Privacy Acts (FIPPA), personal information includes all of the following EXCEPT?

Options:

A.

Information about an individual’s home business.

B.

Information about an individual’s creditworthiness.

C.

Information about an individual’s employment history.

D.

Information about an individual’s character references.

Question 7

According to PIPEDA, all of the following data is considered sensitive: physical disability, ethnicity, sexual orientation and?

Options:

A.

Age

B.

Gender

C.

Locality

D.

Religion

Question 8

What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?

Options:

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

Question 9

What can be concluded from the Blood Tribe case regarding the Privacy Commissioner's access to information?

Options:

A.

The commissioner cannot receive information unless it is gathered under oath.

B.

The commissioner cannot ask an organization to prove that a document is privileged.

C.

The commissioner can compel the production of all documents that are relevant to the investigation.

D.

The commissioner can officially request proof that desired information is subject to solicitor-client privilege.

Question 10

In which situation could a request for access to one’s personal information be denied under the Privacy Act?

Options:

A.

The personal information was collected by the Royal Canadian Mounted Police while performing policing services for a province or municipality.

B.

The personal information was obtained in confidence from a foreign state or agency which has consented to the disclosure of the information.

C.

The release of the personal information could reasonably be expected to cause injury to a protected species of wildlife.

D.

The personal information is more than 20 years old and relates to the detection or suppression of money laundering.

Question 11

According to the federal court ruling in the Eastman Case, video cameras in the workplace are considered to be collecting personal information?

Options:

A.

At the moment a recording occurs.

B.

When a camera is on, even if it is not yet recording.

C.

As soon as the data is saved to a workplace server.

D When someone within the nrnani7atinn views the recording

Question 12

Which organization was the primary influence in the development of Canadian privacy with their publication of a set of eight privacy principles?

Options:

A.

The Organization for Economic Co-operation and Development (OECD).

B.

The Canadian Institute of Chartered Accountants

C.

The Center for Democracy and Technology (CRT)

D.

The Canadian Standards Association (CSA).

Question 13

ABC Corp uses a third-party provider to perform data analytics and sends the following data sets to the third party to run some reports: name, customer ID, age, transaction activity, transaction date, location, outcome, customer type.

If ABC Corp wants the third party to send all the data sets to their US based marketing partner for a new use, they must?

Options:

A.

Encrypt data in transit.

B.

Anonymize the personal data before sending.

C.

Seek additional consent from their customers.

D.

Ensure the marketing partner has equal or stronger protections than Canada.

Question 14

In comparing British Columbia’s privacy laws with the health information privacy acts of the remaining provinces, BC’s privacy laws?

Options:

A.

Seek to create a more flexible regulatory system to manage the patient data itself

B.

Refer to health sector participants as trustees as opposed to custodians.

C.

Exclude laboratories, nursing homes and independent health facilities.

D.

Group data banks together rather than listing them separately.

Question 15

According to the Canadian Standards Association (CSA) Model Code, how long should personal information be retained?

Options:

A.

Personal information should not be retained at all.

B.

Personal information should be retained indefinitely as long as consent has been given.

C.

Personal information should be retained for at least two years after the last administrative use.

D.

Personal information should be retained as long as necessary for the fulfillment of the purpose of the collection.

Question 16

Which question is NOT part of the Office of the Privacy Commissioner of Canada’s (OPC’s) four-point test for establishing whether providing access to genetic testing results goes beyond what is necessary or reasonable?

Options:

A.

Are there less privacy-invasive alternatives?

B.

Are the collection and the use proportionate to the benefits gained?

C.

Are the validity and accuracy of individual test results guaranteed to be accurate?

D.

Is the personal information likely to be effective in achieving a legitimate business purpose?

Question 17

In 2007, four employees of TELUS Communications Corporation filed a complaint with the Privacy Commissioner of Canada in connection with the collection of what personal information?

Options:

A.

Voiceprint information.

B.

Drivers' licenses.

C.

Urine samples.

D.

Video images.

Question 18

Which of the following incidents will require reporting to OPC?

Options:

A.

A sales report with aggregated information that was sent to the wrong person internally.

B.

A file with client ID, sales amount and sales date that was sent to the wrong processors who cannot identify the clients.

C.

An organization’s point-of-sale system that was subject to an attempted hack that was blocked by the organization’s firewall.

D.

As part of a freedom of information request, a nursing home that released an e-mail with everybody’s e-mail address in the "to" section unredacted.

Question 19

In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.

Which of the following requests would the patient be most successful at pursuing?

Options:

A.

That a correction be made to change the diagnosis based on the patient's wishes.

B.

That the information be restricted from disclosure to other health care providers.

C.

That a copy of the record be kept by the patient for disclosure to physicians.

D.

That details of the diagnosis be deleted from the patient’s health record.

Question 20

The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?

Options:

A.

The Ministry of Health

B.

The Bank of Canada.

C.

Crown Corporations.

D.

The Cabinet.

Question 21

A new client is opening a Registered Retirement Savings Plan. Their investment advisor asks for their social insurance number (SIN). The advisor must tell the client that because they are opening a tax reporting product, their SIN is mandatory for tax reporting purposes and?

Options:

A.

Optional for identity verification purposes.

B.

Mandatory for identity verification purposes.

C.

Optional for secondary marketing purposes.

D.

Mandatory for secondary marketing purposes.

Question 22

In what situation is the federal Privacy Commissioner authorized to proceed to federal court?

Options:

A.

For a determination on a ruling regarding privacy matters relating to the Charter of Rights and Freedom.

B.

For a determination of whether or not personal information was properly withheld from release.

C.

For a determination on a ruling by an administrative tribunal regarding privacy.

D.

For a determination on a ruling by a provincial Privacy Commissioner.

Page: 1 / 8
Total 76 questions