Black Friday Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

CIPP-C Certified Information Privacy Professional/ Canada (CIPP/C) Questions and Answers

Questions 4

A private sector daycare’s portal for parents stores their children’s photos, allergy information and date of birth. A parent has asked about the portal’s security requirements and in three months still not has received an answer. What is missing from the daycare’s procedures?

Options:

A.

Ensuring transparency.

B.

Responding to the parent's request within 30 days.

C.

Ensuring strong encryption and security measures.

D.

Completing a real risk of significant harm assessment (RROSH).

Buy Now
Questions 5

Which of these employees would be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

Options:

A.

The staff of an airline offering flights across Canada.

B.

Underwriters for a New Brunswick insurance company.

C.

Clerks at a Montreal credit union based out of Montreal.

D.

The information technology department of the Saskatchewan Office of Residential Tenancies of Saskatchewan.

Buy Now
Questions 6

What is a difference between the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Personal Information Privacy Act (PIPA) of both Alberta and British Columbia?

Options:

A.

PIPEDA applies to personal information about individuals employed by government institutions; PIPA applies to personal information about individuals employed by public-sector organizations within the provinces.

B.

The enforcement powers of the federal Privacy Commissioner of Canada under PIPEDA are greater than those of the provincial privacy commissioners under PIPA.

C.

PIPEDA applies to federal undertakings and to inter-provincial organizations engaged in commercial activities; PIPA applies to private organizations.

D.

The person in charge of oversight of PIPEDA is a privacy commissioner; the person in charge of oversight of PIPA is an ombudsman.

Buy Now
Questions 7

What must happen before an individual requester can commence a court application relating to the denial of access to personal information under the control of a federal government institution?

Options:

A.

The Privacy Commissioner of Canada must have completed an investigation and issued a report.

B.

The Privacy Commissioner of Canada must have completed an investigation and found in favor of the requester.

C.

The requester must have made a formal Privacy Act request to a government institution for access to personal information.

D.

The requester must have lodged a complaint with the Office of the Privacy Commissioner (OPC) within 60 days of having received a response to a formal Privacy Act request.

Buy Now
Questions 8

Under the Freedom of Information and Protection of Privacy Acts (FIPPA), personal information includes all of the following EXCEPT?

Options:

A.

Information about an individual’s home business.

B.

Information about an individual’s creditworthiness.

C.

Information about an individual’s employment history.

D.

Information about an individual’s character references.

Buy Now
Questions 9

What is required for a provincial law to be considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

Options:

A.

Consistency with at least eight of the ten privacy principles, an independent oversight body and a complaint handling mechanism.

B.

Consistency with the ten privacy principles, an independent oversight body and a process for accessing information.

C.

Consistency with the ten privacy principles, an independent oversight body and a redress mechanism.

D.

Consistency with the ten privacy principles, an appeal process and a redress mechanism.

Buy Now
Questions 10

According to the federal Privacy Act, before collecting personal information, public-sector organizations are required to ensure that any of the following are met EXCEPT?

Options:

A.

Collection directly relates to, and is necessary for, operating a program of that organization.

B.

Collection is for the purposes of a law enforcement action.

C.

Collection is expressly authorized under an act.

D.

Collection is authorized by consent.

Buy Now
Questions 11

Which statement is TRUE regarding health information privacy laws in Canada?

Options:

A.

Obligations regarding accountability for health information are transferred when control is outsourced to a third party.

B Emphasis is given lo personal information protection over the maintenance of the publicly funded healthcare system

B.

There is a significant amount of variation among provinces regarding the definition of consent and how the consent requirement is addressed.

C.

In provinces where there are no health information privacy statutes, a combination of the public health regulations and the private sector privacy legislation apply.

Buy Now
Questions 12

What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?

Options:

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

Buy Now
Questions 13

A company wants to invest in DEI initiatives within their organization and plans to survey employees by asking for locality, age, salary, gender, ethnicity, religion, sexual orientation, physical/mental disabilities, department, and job level.

The best solution to protect the personal information collected in the survey is to?

Options:

A.

Use a pseudonym to identify employees.

B.

Choose a survey tool located in Canada.

C.

Encrypt the sensitive information collected and stored.

D Adjust all survey question so that no identifying information nan he collected

Buy Now
Questions 14

Which of the following incidents will require reporting to OPC?

Options:

A.

A sales report with aggregated information that was sent to the wrong person internally.

B.

A file with client ID, sales amount and sales date that was sent to the wrong processors who cannot identify the clients.

C.

An organization’s point-of-sale system that was subject to an attempted hack that was blocked by the organization’s firewall.

D.

As part of a freedom of information request, a nursing home that released an e-mail with everybody’s e-mail address in the "to" section unredacted.

Buy Now
Questions 15

To whom does the Privacy Commissioner of Canada report?

Options:

A.

Supreme Court of Canada and Prime Minister

B.

House of Commons and the Senate.

C.

Administrative tribunal.

D.

Auditor General.

Buy Now
Questions 16

How would an individual determine whether their personal information was used by the federal government for data matching?

Options:

A.

By submitting written requests to the third party conducting data matching for the government

B.

By noting the description of the Personal Information Banks available through Info Source.

C.

By proposing a Privacy Impact Assessment (PIA) within the specific government body.

D.

By reviewing the Privacy Commissioner's annual report.

Buy Now
Questions 17

Which of the following existing frameworks is least effective in addressing emerging AI issues while specific AI legislation is being decided?

Options:

A.

The Canada Consumer Product Safety Act.

B.

The Motor Vehicle Safety Act.

C.

The Copyright Act.

D.

The Criminal Code.

Buy Now
Questions 18

The movement toward comprehensive privacy and data protection laws can be attributed to a combination of three major factors: the need to remedy past injustices, the need to promote a digital economy and the need to ensure consistency with?

Options:

A.

Self-regulatory laws.

B.

Pan-European laws.

C.

Pan-Asian laws.

D.

Global laws.

Buy Now
Questions 19

Which action will help a business prove compliance under Canada’s Anti-Spam Legislation (CASL)?

Options:

A.

Demonstrating the dissolution of a personal relationship before communication was sent.

B.

Keeping records of express and implied consent of commercial electronic messages.

C.

Posting a list of CASL guidelines on a company's website for customers to read.

D.

Providing an opt-out mechanism.

Buy Now
Questions 20

A boutique hotel in Montreal seeks to attract travelers from Europe but wants to avoid becoming subject to the GDPR’s requirements. Which of the following activities is most likely to result in a finding that the hotel is subject to the GDPR?

Options:

A.

Placing advertisements on travel websites accessible in Europe.

B.

Collecting contact information for foreign business leaders from public directories.

C.

Sending discount offers to guests who previously registered using a foreign address.

D.

Translating the hotel's registration page into German based on the visitor's IP address.

Buy Now
Questions 21

In 2007, four employees of TELUS Communications Corporation filed a complaint with the Privacy Commissioner of Canada in connection with the collection of what personal information?

Options:

A.

Voiceprint information.

B.

Drivers' licenses.

C.

Urine samples.

D.

Video images.

Buy Now
Questions 22

Which of the following describes a difference between the federal Privacy Commissioner and provincial commissioners?

Options:

A.

Provincial commissioners can order an organization to act.

B.

Provincial commissioners are limited to recommending actions.

C.

The federal commissioner has the power to make an organization comply.

D.

The federal commissioner must receive complaints from a legislative representative.

Buy Now
Exam Code: CIPP-C
Exam Name: Certified Information Privacy Professional/ Canada (CIPP/C)
Last Update: Nov 21, 2024
Questions: 76

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now CIPP-C testing engine

PDF (Q&A)

$36.75  $104.99
buy now CIPP-C pdf