Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtreat

CIPP-C Certified Information Privacy Professional/ Canada (CIPP/C) Questions and Answers

Questions 4

The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?

Options:

A.

The Ministry of Health

B.

The Bank of Canada.

C.

Crown Corporations.

D.

The Cabinet.

Buy Now
Questions 5

Under the Freedom of Information and Protection of Privacy Acts (FIPPA), personal information includes all of the following EXCEPT?

Options:

A.

Information about an individual’s home business.

B.

Information about an individual’s creditworthiness.

C.

Information about an individual’s employment history.

D.

Information about an individual’s character references.

Buy Now
Questions 6

Work-product information is generally thought of as information about an individual that?

Options:

A.

Is required by an organization to establish an employment relationship.

B.

Includes internal investigation files and complaints filed about an employee.

C.

Includes intellectual property developed within the scope of an employee's job function.

D.

Is prepared or collected as part of that individual’s responsibilities or activities in connection to their job.

Buy Now
Questions 7

Under the Privacy Act, when government institutions collect personal information?

Options:

A.

Data subject consent is required.

B.

The collection must be directly from a data subject.

C.

The collection must relate to an operating program or activity.

D.

Information collected must be made anonymous where technologically possible

Buy Now
Questions 8

According to the Canadian Standards Association (CSA) Model Code, how long should personal information be retained?

Options:

A.

Personal information should not be retained at all.

B.

Personal information should be retained indefinitely as long as consent has been given.

C.

Personal information should be retained for at least two years after the last administrative use.

D.

Personal information should be retained as long as necessary for the fulfillment of the purpose of the collection.

Buy Now
Questions 9

What is the main reason a country might adopt an "ombudsman" model of privacy oversight?

Options:

A.

It provides a more streamlined process of complaint resolution.

B.

It increases the power of the commissioner to enforce decisions.

C.

It reduces the perception that compliance is a confrontational process.

D.

It provides a more detailed set of guidelines regarding possible violations.

Buy Now
Questions 10

Which action will help a business prove compliance under Canada’s Anti-Spam Legislation (CASL)?

Options:

A.

Demonstrating the dissolution of a personal relationship before communication was sent.

B.

Keeping records of express and implied consent of commercial electronic messages.

C.

Posting a list of CASL guidelines on a company's website for customers to read.

D.

Providing an opt-out mechanism.

Buy Now
Questions 11

To whom does the Privacy Commissioner of Canada report?

Options:

A.

Supreme Court of Canada and Prime Minister

B.

House of Commons and the Senate.

C.

Administrative tribunal.

D.

Auditor General.

Buy Now
Questions 12

Which of the following provincial health acts is NOT considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

Options:

A.

New Brunswick's Personal Health Information Privacy and Access Act (PHIPAA)

B.

Ontario's Personal Health Information Protection Act (PHIPAA)

C.

Nova Scotia's Personal Health Information Act (PHIPAA)

D.

lAberta's Health Information Act (PHIA)

Buy Now
Questions 13

What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?

Options:

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

Buy Now
Questions 14

A commercial business in Canada is allowed to collect personal information without the knowledge or consent of the individual in all of the following circumstances EXCEPT when?

Options:

A.

The collection is for journalistic or literary purposes.

B.

The collection is in the interests of the individual and the consent cannot be obtained in a timely way.

C.

The collection would lead to the creation of products that would benefit the public and consent would be difficult to obtain.

D.

The collection, with the knowledge of the individual, would compromise the availability and accuracy of the information and the collection is reasonable for the purposes related to investigating

Buy Now
Questions 15

Under PIPEDA, each of the following are considered to be personal information EXCEPT?

Options:

A.

A public official's salary published on a government web site.

B.

A person's telephone number published in a public directory.

C.

A photograph taken in public and published in a newspaper.

D.

Information about a defendant contained in court records.

Buy Now
Questions 16

What is the primary motivation for a federal government entity to complete a Privacy Impact Assessment (PIA)?

Options:

A.

Introducing new legislation in the House of Commons

B.

Receiving program approvals from the Treasury Board of Canada.

C.

Obtaining program expertise from the Privacy Commissioner of Canada.

D.

Improving collection methods through its information technology systems.

Buy Now
Questions 17

Safeguarding and securing information that is considered sensitive under privacy legislation generally falls into three categories: Administrative, Technical and?

Options:

A.

Legal.

B.

Physical.

C.

Personal.

D.

Logistical.

Buy Now
Questions 18

After an investigation under the Privacy Act, the Privacy Commissioner could do any of the following EXCEPT?

Options:

A.

Proceed to federal court to determine if the institution improperly withheld information from an individual.

B.

Order an institution to take remedial action if it determines that the Act has been breached.

C.

Recommend solutions to institutions to address identified shortcomings.

D.

Compel institutions to give oral or written evidence.

Buy Now
Questions 19

According to the Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, signatories commit to doing all of the following EXCEPT?

Options:

A.

Contributing to the development and application of Al standards.

B.

Sharing information and best practices of Al governance.

C.

Supporting public awareness and education on Al.

D.

Adopting low-risk uses of AI.

Buy Now
Questions 20

Which of the following existing frameworks is least effective in addressing emerging AI issues while specific AI legislation is being decided?

Options:

A.

The Canada Consumer Product Safety Act.

B.

The Motor Vehicle Safety Act.

C.

The Copyright Act.

D.

The Criminal Code.

Buy Now
Questions 21

A private sector daycare’s portal for parents stores their children’s photos, allergy information and date of birth. A parent has asked about the portal’s security requirements and in three months still not has received an answer. What is missing from the daycare’s procedures?

Options:

A.

Ensuring transparency.

B.

Responding to the parent's request within 30 days.

C.

Ensuring strong encryption and security measures.

D.

Completing a real risk of significant harm assessment (RROSH).

Buy Now
Questions 22

Which of the following specifically differentiates between regular personal information and employee-related or work-product information?

Options:

A.

The Privacy Act.

B.

The Quebec Act.

C.

British Columbia's Personal Information Protection Act

D.

Personal Information Protection and Electronic Documents Act (PIPEDA).

Buy Now
Exam Code: CIPP-C
Exam Name: Certified Information Privacy Professional/ Canada (CIPP/C)
Last Update: May 16, 2024
Questions: 76
CIPP-C pdf

CIPP-C PDF

$28  $80
CIPP-C Engine

CIPP-C Testing Engine

$33.25  $95
CIPP-C PDF + Engine

CIPP-C PDF + Testing Engine

$45.5  $130