Labour Day Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CIPP-C Exam Dumps - Certified Information Privacy Professional/ Canada (CIPP/C)

Question # 4

Under the Freedom of Information and Protection of Privacy Acts (FIPPA), personal information includes all of the following EXCEPT?

A.

Information about an individual’s home business.

B.

Information about an individual’s creditworthiness.

C.

Information about an individual’s employment history.

D.

Information about an individual’s character references.

Full Access
Question # 5

Which of the following existing frameworks is least effective in addressing emerging AI issues while specific AI legislation is being decided?

A.

The Canada Consumer Product Safety Act.

B.

The Motor Vehicle Safety Act.

C.

The Copyright Act.

D.

The Criminal Code.

Full Access
Question # 6

In 2007, four employees of TELUS Communications Corporation filed a complaint with the Privacy Commissioner of Canada in connection with the collection of what personal information?

A.

Voiceprint information.

B.

Drivers' licenses.

C.

Urine samples.

D.

Video images.

Full Access
Question # 7

A private organization called Vision 3072 must verify the information they are collecting is up to date in order to avoid misinformed actions or decisions. Which privacy principle is intended to make sure this verification is happening?

A.

Integrity.

B.

Accuracy.

C.

Accountability.

D.

Limiting purposes.

Full Access
Question # 8

Why is biometric information considered sensitive personal information in almost all circumstances?

A.

It is user specific information that can easily be stored and accessed to identify an individual or group of individuals.

B.

It can be applied broadly to link many pieces of personal information and creates security vulnerabilities.

C.

It is distinctive, unlikely to vary overtime, difficult to change and largely unique to the individual.

D.

It is easy to recognize and reproduce with increasing computer processing power.

Full Access
Question # 9

Under PIPEDA, each of the following situations requires an organization to obtain express consent to use personal information EXCEPT?

A.

If the use is outside of the reasonable expectations of an individual.

B.

If the information is publicly available as defined by the regulation.

C.

If the use is inconsistent with the original purpose.

D.

If there is no risk of significant harm.

Full Access
Question # 10

What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

Full Access
Question # 11

After an investigation under the Privacy Act, the Privacy Commissioner could do any of the following EXCEPT?

A.

Proceed to federal court to determine if the institution improperly withheld information from an individual.

B.

Order an institution to take remedial action if it determines that the Act has been breached.

C.

Recommend solutions to institutions to address identified shortcomings.

D.

Compel institutions to give oral or written evidence.

Full Access
Question # 12

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), when engaging in a third-party transfer of personal information for processing, an organization is expected to have the technology to protect the information during transit and to?

A.

Establish a contract outlining the individual outsourcing arrangement.

B.

Obtain additional consent for the use of the information by the third party.

C.

Confirm the jurisdictional protections of the receiving organization are the same as PIPEDA.

D.

Review the cross-border data flow competed and approved by the Treasury Board of Canada Secretariat.

Full Access
Question # 13

ABC Corp uses a third-party provider to perform data analytics and sends the following data sets to the third party to run some reports: name, customer ID, age, transaction activity, transaction date, location, outcome, customer type.

If ABC Corp wants the third party to send all the data sets to their US based marketing partner for a new use, they must?

A.

Encrypt data in transit.

B.

Anonymize the personal data before sending.

C.

Seek additional consent from their customers.

D.

Ensure the marketing partner has equal or stronger protections than Canada.

Full Access
Question # 14

In what situation is the federal Privacy Commissioner authorized to proceed to federal court?

A.

For a determination on a ruling regarding privacy matters relating to the Charter of Rights and Freedom.

B.

For a determination of whether or not personal information was properly withheld from release.

C.

For a determination on a ruling by an administrative tribunal regarding privacy.

D.

For a determination on a ruling by a provincial Privacy Commissioner.

Full Access
Question # 15

How would an individual determine whether their personal information was used by the federal government for data matching?

A.

By submitting written requests to the third party conducting data matching for the government

B.

By noting the description of the Personal Information Banks available through Info Source.

C.

By proposing a Privacy Impact Assessment (PIA) within the specific government body.

D.

By reviewing the Privacy Commissioner's annual report.

Full Access
Question # 16

Which of the following specifically differentiates between regular personal information and employee-related or work-product information?

A.

The Privacy Act.

B.

The Quebec Act.

C.

British Columbia's Personal Information Protection Act

D.

Personal Information Protection and Electronic Documents Act (PIPEDA).

Full Access
Question # 17

A commercial business in Canada is allowed to collect personal information without the knowledge or consent of the individual in all of the following circumstances EXCEPT when?

A.

The collection is for journalistic or literary purposes.

B.

The collection is in the interests of the individual and the consent cannot be obtained in a timely way.

C.

The collection would lead to the creation of products that would benefit the public and consent would be difficult to obtain.

D.

The collection, with the knowledge of the individual, would compromise the availability and accuracy of the information and the collection is reasonable for the purposes related to investigating

Full Access
Question # 18

What must an organization do to fulfill the Personal Information Protection and Electronic Documents Act’s (PIPEDA) transparency requirements when transferring personal information to a foreign country?

A.

Inform customers if data is to be transferred outside of Canada and solicit additional consent.

B.

Give individuals with an existing business relationship the right to refuse transfer of their information.

C.

Advise customers that their data may be accessed by another jurisdiction's courts or law enforcement.

D.

Provide new customers with a measure-by-measure comparison of relevant foreign laws with Canadian laws.

Full Access
Question # 19

In which circumstance do private sector privacy laws permit collection of information without consent?

A.

When timely consent cannot be obtained by the organization and the collection is clearly in the individual's interests.

B.

When the collection is necessary for the organization to complete a profile of the individual.

C.

When the collection is reasonable for purposes related to the organization's mandate.

D.

When the individual expressly waives their right to give consent.

Full Access
Question # 20

According to PIPEDA, all of the following data is considered sensitive: physical disability, ethnicity, sexual orientation and?

A.

Age

B.

Gender

C.

Locality

D.

Religion

Full Access
Question # 21

According to the Privacy Act, which of the following disclosures of personal information by a government institution would require the data subject’s consent?

A.

When disclosing to a law enforcement body.

B.

When disclosing to comply with a search warrant.

C.

When disclosing to a registered charitable organization.

D.

When disclosing to a member of parliament to assist in resolving a problem.

Full Access
Question # 22

In comparing British Columbia’s privacy laws with the health information privacy acts of the remaining provinces, BC’s privacy laws?

A.

Seek to create a more flexible regulatory system to manage the patient data itself

B.

Refer to health sector participants as trustees as opposed to custodians.

C.

Exclude laboratories, nursing homes and independent health facilities.

D.

Group data banks together rather than listing them separately.

Full Access