Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > IAPP > Certified Information Privacy Professional > CIPP-C

CIPP-C Certified Information Privacy Professional/ Canada (CIPP/C) Question and Answers

Question # 4

What must a federal government department do before it implements an electronic service (e-service)?

A.

Conduct a preliminary PIA before acquiring the service

B.

Complete a PIA in accordance with Treasury Board guidelines.

C.

Publish a privacy statement in newspapers and on the government website.

D.

Determine if the Office of the Privacy Commissioner must be notified of the launch of this new e-service

Full Access
Question # 5

Work-product information is generally thought of as information about an individual that?

A.

Is required by an organization to establish an employment relationship.

B.

Includes internal investigation files and complaints filed about an employee.

C.

Includes intellectual property developed within the scope of an employee's job function.

D.

Is prepared or collected as part of that individual’s responsibilities or activities in connection to their job.

Full Access
Question # 6

ABC Corp uses a third-party provider to perform data analytics and sends the following data sets to the third party to run some reports: name, customer ID, age, transaction activity, transaction date, location, outcome, customer type.

If ABC Corp wants the third party to send all the data sets to their US based marketing partner for a new use, they must?

A.

Encrypt data in transit.

B.

Anonymize the personal data before sending.

C.

Seek additional consent from their customers.

D.

Ensure the marketing partner has equal or stronger protections than Canada.

Full Access
Question # 7

Which act also includes references to the Privacy Act?

A.

The Access to Information Act.

B.

The Children's Online Privacy Protection Act

C.

The Telecommunications Intercept and Access (TIA) Act.

D.

The Personal Information Protection and Electronic Documents Act

Full Access
Question # 8

A small commercial business in Canada was preparing a mailing to its customers when the letters and the envelopes were mismatched, causing 500 of 1000 letters to be sent to the wrong recipients. The letters contained the name and mailing address of the clients as well as account numbers and account balances.

The business has discovered this error as clients called to report receiving the wrong letter and expressing concern that their information has been breached. Which of the following is the most appropriate next step to take?

A.

All 1000 clients must be sent new letters.

B.

The 500 clients who were impacted must be immediately notified.

C.

The Office of the Privacy Commissioner (OPC) must be immediately notified.

D.

A risk assessment must be completed to determine the real risk of significant harm (RROSH) to the clients.

Full Access
Question # 9

What must an organization do to fulfill the Personal Information Protection and Electronic Documents Act’s (PIPEDA) transparency requirements when transferring personal information to a foreign country?

A.

Inform customers if data is to be transferred outside of Canada and solicit additional consent.

B.

Give individuals with an existing business relationship the right to refuse transfer of their information.

C.

Advise customers that their data may be accessed by another jurisdiction's courts or law enforcement.

D.

Provide new customers with a measure-by-measure comparison of relevant foreign laws with Canadian laws.

Full Access
Question # 10

To whom does the Privacy Commissioner of Canada report?

A.

Supreme Court of Canada and Prime Minister

B.

House of Commons and the Senate.

C.

Administrative tribunal.

D.

Auditor General.

Full Access
Question # 11

As response to TJX Winners - Homesense, why is "hashing" preferable to storing a personal identifier such as a driver’s license number?

A.

It scrambles information but can be unscrambled for later use.

B.

It automatically puts a lifespan on any identification that is stored.

C.

It randomizes all permanent identification within an organized database.

D.

It still provides customer identification, but in a form that would not reveal the real number.

Full Access
Question # 12

Why is biometric information considered sensitive personal information in almost all circumstances?

A.

It is user specific information that can easily be stored and accessed to identify an individual or group of individuals.

B.

It can be applied broadly to link many pieces of personal information and creates security vulnerabilities.

C.

It is distinctive, unlikely to vary overtime, difficult to change and largely unique to the individual.

D.

It is easy to recognize and reproduce with increasing computer processing power.

Full Access
Question # 13

After an investigation under the Privacy Act, the Privacy Commissioner could do any of the following EXCEPT?

A.

Proceed to federal court to determine if the institution improperly withheld information from an individual.

B.

Order an institution to take remedial action if it determines that the Act has been breached.

C.

Recommend solutions to institutions to address identified shortcomings.

D.

Compel institutions to give oral or written evidence.

Full Access
Question # 14

In Ontario, personal information can be withheld from disclosure in a Freedom of Information (FOI) request. The following information is included in a record that is the subject of a FOI request being handled by a hospital: employee name, employee title, employee designation, employee educational history, employee personal cell phone number, and feedback about the employee from a colleague.

Which of the following statements is accurate regarding what can be released?

A.

Employee name and title can only be released if the employee consents

B.

The employee designation is not to be released as it is considered employment history.

C.

Employee name, title, and designation can be released as it is not classified as personal information.

D.

No employee information can be released as it is information that was collected throughout the course of employment.

Full Access
Question # 15

The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?

A.

The Ministry of Health

B.

The Bank of Canada.

C.

Crown Corporations.

D.

The Cabinet.

Full Access
Question # 16

When a third country or specified entity is said to ensure an adequate level of protection essentially equivalent to that ensured within the European Union, it is awarded a(n)?

A.

Equivalency designation.

B.

Attestation designation.

C.

Adequacy designation.

D.

Protection designation.

Full Access
Question # 17

What is required through the "circle of care" concept under Canadian health information privacy law?

A.

Health information custodians or trustees be specified only by applicable law or regulation

B.

An individual's consent may be implied unless the individual has refused consent or if the purpose of the disclosure is not to provide health care.

C.

Notification to the individual be made in the event of a data breach of personal health information (PHI) by an organization that is based in Canada

D.

Consent must be expressed or implied when a custodian discloses personal health information (PHI) to another custodian for the purpose of providing health care.

Full Access
Question # 18

In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.

Which of the following requests would the patient be most successful at pursuing?

A.

That a correction be made to change the diagnosis based on the patient's wishes.

B.

That the information be restricted from disclosure to other health care providers.

C.

That a copy of the record be kept by the patient for disclosure to physicians.

D.

That details of the diagnosis be deleted from the patient’s health record.

Full Access
Question # 19

According to the Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, signatories commit to doing all of the following EXCEPT?

A.

Contributing to the development and application of Al standards.

B.

Sharing information and best practices of Al governance.

C.

Supporting public awareness and education on Al.

D.

Adopting low-risk uses of AI.

Full Access
Question # 20

What is critical to consider when an organization responsible for a large number of records wants to outsource the storage of those records?

A.

Determining if the personal information stored on the records will be used for data matching

B.

Putting into place a contractual agreement between the organization and the records storage company.

C.

Conducting a Privacy Impact Assessment (PIA) prior to establishing a relationship with the storage company.

D.

Establishing that consent gathered from individuals by the organization in order to store their personal information was informed and meaningful.

Full Access
Question # 21

What is required for a provincial law to be considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

A.

Consistency with at least eight of the ten privacy principles, an independent oversight body and a complaint handling mechanism.

B.

Consistency with the ten privacy principles, an independent oversight body and a process for accessing information.

C.

Consistency with the ten privacy principles, an independent oversight body and a redress mechanism.

D.

Consistency with the ten privacy principles, an appeal process and a redress mechanism.

Full Access
Question # 22

According to the Privacy Act, which of the following disclosures of personal information by a government institution would require the data subject’s consent?

A.

When disclosing to a law enforcement body.

B.

When disclosing to comply with a search warrant.

C.

When disclosing to a registered charitable organization.

D.

When disclosing to a member of parliament to assist in resolving a problem.

Full Access