Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

IAPP CIPP-C - Certified Information Privacy Professional/ Canada (CIPP/C)

Page: 1 / 3
Total 76 questions

Which province requires its government bodies to store and access personal information exclusively in Canada unless additional consent is obtained, or if outside storage is judged necessary?

A.

Nova Scotia

B.

Québec.

C.

Ontario.

D.

Alberta.

To whom does the Privacy Commissioner of Canada report?

A.

Supreme Court of Canada and Prime Minister

B.

House of Commons and the Senate.

C.

Administrative tribunal.

D.

Auditor General.

Which of the following existing frameworks is least effective in addressing emerging AI issues while specific AI legislation is being decided?

A.

The Canada Consumer Product Safety Act.

B.

The Motor Vehicle Safety Act.

C.

The Copyright Act.

D.

The Criminal Code.

According to the federal court ruling in the Eastman Case, video cameras in the workplace are considered to be collecting personal information?

A.

At the moment a recording occurs.

B.

When a camera is on, even if it is not yet recording.

C.

As soon as the data is saved to a workplace server.

D When someone within the nrnani7atinn views the recording

According to the Alberta Personal Information Protection Act, which of the following data breach reporting notifications to the commissioner is NOT automatically triggered when real risk of significant harm (RROSH) has been determined?

A.

Providing a description of the steps the organization will take to notify the affected individual(s).

B.

Providing a description of the steps the organization has taken to reduce or mitigate that harm.

C.

Providing an estimate of the number of individuals affected by the breach.

D.

Providing a description of the personal information involved in the breach.

According to the federal Privacy Commissioner, what protection is missing from the Privacy Act regarding outsourcing of government work that contains personal information?

A.

A statement preventing the vendor to whom the information is outsourced to subcontract its processing.

B.

A statement granting the Privacy Commissioner the right to issue orders following an investigation into a possible data breach.

C.

A statement requiring the government agency to complete a Privacy Impact Assessment (PIA) prior to outsourcing to a third party.

D.

A statement indicating that the government institution from which the information is outsourced remains accountable for its security.

What is required through the "circle of care" concept under Canadian health information privacy law?

A.

Health information custodians or trustees be specified only by applicable law or regulation

B.

An individual's consent may be implied unless the individual has refused consent or if the purpose of the disclosure is not to provide health care.

C.

Notification to the individual be made in the event of a data breach of personal health information (PHI) by an organization that is based in Canada

D.

Consent must be expressed or implied when a custodian discloses personal health information (PHI) to another custodian for the purpose of providing health care.

What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

How would an individual determine whether their personal information was used by the federal government for data matching?

A.

By submitting written requests to the third party conducting data matching for the government

B.

By noting the description of the Personal Information Banks available through Info Source.

C.

By proposing a Privacy Impact Assessment (PIA) within the specific government body.

D.

By reviewing the Privacy Commissioner's annual report.

Which of the following describes a difference between the federal Privacy Commissioner and provincial commissioners?

A.

Provincial commissioners can order an organization to act.

B.

Provincial commissioners are limited to recommending actions.

C.

The federal commissioner has the power to make an organization comply.

D.

The federal commissioner must receive complaints from a legislative representative.