Black Friday Special Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > IAPP > Certified Information Privacy Professional > CIPP-C

CIPP-C Certified Information Privacy Professional/ Canada (CIPP/C) Question and Answers

Question # 4

According to the Alberta Personal Information Protection Act, which of the following data breach reporting notifications to the commissioner is NOT automatically triggered when real risk of significant harm (RROSH) has been determined?

A.

Providing a description of the steps the organization will take to notify the affected individual(s).

B.

Providing a description of the steps the organization has taken to reduce or mitigate that harm.

C.

Providing an estimate of the number of individuals affected by the breach.

D.

Providing a description of the personal information involved in the breach.

Full Access
Question # 5

A private sector daycare’s portal for parents stores their children’s photos, allergy information and date of birth. A parent has asked about the portal’s security requirements and in three months still not has received an answer. What is missing from the daycare’s procedures?

A.

Ensuring transparency.

B.

Responding to the parent's request within 30 days.

C.

Ensuring strong encryption and security measures.

D.

Completing a real risk of significant harm assessment (RROSH).

Full Access
Question # 6

The movement toward comprehensive privacy and data protection laws can be attributed to a combination of three major factors: the need to remedy past injustices, the need to promote a digital economy and the need to ensure consistency with?

A.

Self-regulatory laws.

B.

Pan-European laws.

C.

Pan-Asian laws.

D.

Global laws.

Full Access
Question # 7

According to the Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, signatories commit to doing all of the following EXCEPT?

A.

Contributing to the development and application of Al standards.

B.

Sharing information and best practices of Al governance.

C.

Supporting public awareness and education on Al.

D.

Adopting low-risk uses of AI.

Full Access
Question # 8

In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.

Which of the following requests would the patient be most successful at pursuing?

A.

That a correction be made to change the diagnosis based on the patient's wishes.

B.

That the information be restricted from disclosure to other health care providers.

C.

That a copy of the record be kept by the patient for disclosure to physicians.

D.

That details of the diagnosis be deleted from the patient’s health record.

Full Access
Question # 9

What must a federal government department do before it implements an electronic service (e-service)?

A.

Conduct a preliminary PIA before acquiring the service

B.

Complete a PIA in accordance with Treasury Board guidelines.

C.

Publish a privacy statement in newspapers and on the government website.

D.

Determine if the Office of the Privacy Commissioner must be notified of the launch of this new e-service

Full Access
Question # 10

Which act also includes references to the Privacy Act?

A.

The Access to Information Act.

B.

The Children's Online Privacy Protection Act

C.

The Telecommunications Intercept and Access (TIA) Act.

D.

The Personal Information Protection and Electronic Documents Act

Full Access
Question # 11

In what situation is the federal Privacy Commissioner authorized to proceed to federal court?

A.

For a determination on a ruling regarding privacy matters relating to the Charter of Rights and Freedom.

B.

For a determination of whether or not personal information was properly withheld from release.

C.

For a determination on a ruling by an administrative tribunal regarding privacy.

D.

For a determination on a ruling by a provincial Privacy Commissioner.

Full Access
Question # 12

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), when engaging in a third-party transfer of personal information for processing, an organization is expected to have the technology to protect the information during transit and to?

A.

Establish a contract outlining the individual outsourcing arrangement.

B.

Obtain additional consent for the use of the information by the third party.

C.

Confirm the jurisdictional protections of the receiving organization are the same as PIPEDA.

D.

Review the cross-border data flow competed and approved by the Treasury Board of Canada Secretariat.

Full Access
Question # 13

Which is NOT a Canadian Standards Association (CSA) Privacy Principle?

A.

Personal information shall be protected by the same security safeguards regardless of the sensitivity of the information.

B.

The purpose for which personal information is collected shall be identified by the organization at or before the time the information is collected.

C.

The degree to which personal information must be kept accurate and complete is determined by whether its original purpose has been achieved.

D.

Upon request, an individual shall be informed of the existence, use and disclosure of their personal information and shall be given access to that information.

Full Access
Question # 14

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must maintain a record of every breach of security safeguards involving personal information for a minimum of?

A.

3 months.

B.

12 months.

C.

24 months.

D.

36 months

Full Access
Question # 15

Which province requires its government bodies to store and access personal information exclusively in Canada unless additional consent is obtained, or if outside storage is judged necessary?

A.

Nova Scotia

B.

Québec.

C.

Ontario.

D.

Alberta.

Full Access
Question # 16

Which of the following incidents will require reporting to OPC?

A.

A sales report with aggregated information that was sent to the wrong person internally.

B.

A file with client ID, sales amount and sales date that was sent to the wrong processors who cannot identify the clients.

C.

An organization’s point-of-sale system that was subject to an attempted hack that was blocked by the organization’s firewall.

D.

As part of a freedom of information request, a nursing home that released an e-mail with everybody’s e-mail address in the "to" section unredacted.

Full Access
Question # 17

According to the Canadian Standards Association (CSA) Model Code, how long should personal information be retained?

A.

Personal information should not be retained at all.

B.

Personal information should be retained indefinitely as long as consent has been given.

C.

Personal information should be retained for at least two years after the last administrative use.

D.

Personal information should be retained as long as necessary for the fulfillment of the purpose of the collection.

Full Access
Question # 18

Which of these employees would be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

A.

The staff of an airline offering flights across Canada.

B.

Underwriters for a New Brunswick insurance company.

C.

Clerks at a Montreal credit union based out of Montreal.

D.

The information technology department of the Saskatchewan Office of Residential Tenancies of Saskatchewan.

Full Access
Question # 19

Which health information custodians may NOT rely on an implied consent model under Ontario's Personal Health Information Protection Act (PHIPA)?

A.

Private insurance companies.

B.

Long-term care homes.

C.

Ambulance services.

D.

Pharmacies

Full Access
Question # 20

A new client is opening a Registered Retirement Savings Plan. Their investment advisor asks for their social insurance number (SIN). The advisor must tell the client that because they are opening a tax reporting product, their SIN is mandatory for tax reporting purposes and?

A.

Optional for identity verification purposes.

B.

Mandatory for identity verification purposes.

C.

Optional for secondary marketing purposes.

D.

Mandatory for secondary marketing purposes.

Full Access
Question # 21

What can be concluded from the Blood Tribe case regarding the Privacy Commissioner's access to information?

A.

The commissioner cannot receive information unless it is gathered under oath.

B.

The commissioner cannot ask an organization to prove that a document is privileged.

C.

The commissioner can compel the production of all documents that are relevant to the investigation.

D.

The commissioner can officially request proof that desired information is subject to solicitor-client privilege.

Full Access
Question # 22

What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

Full Access