Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free IAPP CIPP-C Practice Exam with Questions & Answers | Set: 2

Questions 11

Which statement is TRUE regarding health information privacy laws in Canada?

Options:
A.

Obligations regarding accountability for health information are transferred when control is outsourced to a third party.

B Emphasis is given lo personal information protection over the maintenance of the publicly funded healthcare system

B.

There is a significant amount of variation among provinces regarding the definition of consent and how the consent requirement is addressed.

C.

In provinces where there are no health information privacy statutes, a combination of the public health regulations and the private sector privacy legislation apply.

IAPP CIPP-C Premium Access
Questions 12

In which circumstance do private sector privacy laws permit collection of information without consent?

Options:
A.

When timely consent cannot be obtained by the organization and the collection is clearly in the individual's interests.

B.

When the collection is necessary for the organization to complete a profile of the individual.

C.

When the collection is reasonable for purposes related to the organization's mandate.

D.

When the individual expressly waives their right to give consent.

Questions 13

Which of the following specifically differentiates between regular personal information and employee-related or work-product information?

Options:
A.

The Privacy Act.

B.

The Quebec Act.

C.

British Columbia's Personal Information Protection Act

D.

Personal Information Protection and Electronic Documents Act (PIPEDA).

Questions 14

Oversight authorities allow the following types of consent EXCEPT?

Options:
A.

Implied consent at the time of collection.

B.

Verbal consent given to the person collecting the information.

C.

Written consent included with the information that is collected.

D.

General consent covering all activities associated with the personal information.

Questions 15

A company wants to invest in DEI initiatives within their organization and plans to survey employees by asking for locality, age, salary, gender, ethnicity, religion, sexual orientation, physical/mental disabilities, department, and job level.

The best solution to protect the personal information collected in the survey is to?

Options:
A.

Use a pseudonym to identify employees.

B.

Choose a survey tool located in Canada.

C.

Encrypt the sensitive information collected and stored.

D Adjust all survey question so that no identifying information nan he collected

Questions 16

An Alberta woman finds errors about her personal information while reviewing paperwork at a local real estate firm. According to Canadian Standards Association (CSA) principles, how should the firm respond to these errors?

Options:
A.

File an error report describing the nature of the errors.

B.

Amend any information that the woman finds to be erroneous.

C.

Request that the woman complete a new set of forms with correct information

D.

Provide the woman with the names of any third parties who have had access to her information.

Questions 17

What is required for a provincial law to be considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

Options:
A.

Consistency with at least eight of the ten privacy principles, an independent oversight body and a complaint handling mechanism.

B.

Consistency with the ten privacy principles, an independent oversight body and a process for accessing information.

C.

Consistency with the ten privacy principles, an independent oversight body and a redress mechanism.

D.

Consistency with the ten privacy principles, an appeal process and a redress mechanism.

Questions 18

According to the Alberta Personal Information Protection Act, which of the following data breach reporting notifications to the commissioner is NOT automatically triggered when real risk of significant harm (RROSH) has been determined?

Options:
A.

Providing a description of the steps the organization will take to notify the affected individual(s).

B.

Providing a description of the steps the organization has taken to reduce or mitigate that harm.

C.

Providing an estimate of the number of individuals affected by the breach.

D.

Providing a description of the personal information involved in the breach.

Questions 19

Which of the following provincial health acts is NOT considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

Options:
A.

New Brunswick's Personal Health Information Privacy and Access Act (PHIPAA)

B.

Ontario's Personal Health Information Protection Act (PHIPAA)

C.

Nova Scotia's Personal Health Information Act (PHIPAA)

D.

lAberta's Health Information Act (PHIA)

Questions 20

According to the federal Privacy Act, before collecting personal information, public-sector organizations are required to ensure that any of the following are met EXCEPT?

Options:
A.

Collection directly relates to, and is necessary for, operating a program of that organization.

B.

Collection is for the purposes of a law enforcement action.

C.

Collection is expressly authorized under an act.

D.

Collection is authorized by consent.

Exam Code: CIPP-C
Certification Provider: IAPP
Exam Name: Certified Information Privacy Professional/ Canada (CIPP/C)
Last Update: Jul 10, 2025
Questions: 76
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

IAPP Free Exams

IAPP Free Exams
Prepare effectively for IAPP certification exams with free study resources and practice tests from Examstrack.