ExamGecko
Home Home / IAPP / CIPP-C

IAPP CIPP-C Practice Test - Questions Answers

Question list
Search
Search

List of questions

Search

Related questions











Which is NOT a Canadian Standards Association (CSA) Privacy Principle?

A.

Personal information shall be protected by the same security safeguards regardless of the sensitivity of the information.

A.

Personal information shall be protected by the same security safeguards regardless of the sensitivity of the information.

Answers
B.

The purpose for which personal information is collected shall be identified by the organization at or before the time the information is collected.

B.

The purpose for which personal information is collected shall be identified by the organization at or before the time the information is collected.

Answers
C.

The degree to which personal information must be kept accurate and complete is determined by whether its original purpose has been achieved.

C.

The degree to which personal information must be kept accurate and complete is determined by whether its original purpose has been achieved.

Answers
D.

Upon request, an individual shall be informed of the existence, use and disclosure of their personal information and shall be given access to that information.

D.

Upon request, an individual shall be informed of the existence, use and disclosure of their personal information and shall be given access to that information.

Answers
Suggested answer: C

In 2007, four employees of TELUS Communications Corporation filed a complaint with the Privacy Commissioner of Canada in connection with the collection of what personal information?

A.

Voiceprint information.

A.

Voiceprint information.

Answers
B.

Drivers' licenses.

B.

Drivers' licenses.

Answers
C.

Urine samples.

C.

Urine samples.

Answers
D.

Video images.

D.

Video images.

Answers
Suggested answer: C

Of the key principles in the Personal Information Protection and Electronic Documents Act (PIPEDA), which principle in particular contributes to the increase in privacy policies in recent years?

A.

Limiting Use, Disclosure, and Retention.

A.

Limiting Use, Disclosure, and Retention.

Answers
B.

Individual Access.

B.

Individual Access.

Answers
C.

Openness.

C.

Openness.

Answers
D.

Accuracy

D.

Accuracy

Answers
Suggested answer: C

A federally regulated company based in Ontario has customers in Ontario, Quebec, New Brunswick, Alberta and British Columbia. Unfortunately, a third-party vendor that provides marketing support to the company experiences a privacy breach which impacts the personal information of all its customers across the provinces where it operates.

The Privacy Officer determines that the breach causes a real risk of significant harm to their customers and is tasked with reporting the breach to the relevant regulators.

With which provincial privacy regulators does the company have to file a report?

A.

It is unnecessary to file a report with any provinces because the company is federally regulated

A.

It is unnecessary to file a report with any provinces because the company is federally regulated

Answers
B.

All of the provinces where its customers are located

B.

All of the provinces where its customers are located

Answers
C.

New Brunswick and British Columbia only

C.

New Brunswick and British Columbia only

Answers
D.

Quebec and Alberta only

D.

Quebec and Alberta only

Answers
Suggested answer: A

Which of the following specifically differentiates between regular personal information and employee-related or work-product information?

A.

The Privacy Act.

A.

The Privacy Act.

Answers
B.

The Quebec Act.

B.

The Quebec Act.

Answers
C.

British Columbia's Personal Information Protection Act

C.

British Columbia's Personal Information Protection Act

Answers
D.

Personal Information Protection and Electronic Documents Act (PIPEDA).

D.

Personal Information Protection and Electronic Documents Act (PIPEDA).

Answers
Suggested answer: D

Under PIPEDA, each of the following situations requires an organization to obtain express consent to use personal information EXCEPT?

A.

If the use is outside of the reasonable expectations of an individual.

A.

If the use is outside of the reasonable expectations of an individual.

Answers
B.

If the information is publicly available as defined by the regulation.

B.

If the information is publicly available as defined by the regulation.

Answers
C.

If the use is inconsistent with the original purpose.

C.

If the use is inconsistent with the original purpose.

Answers
D.

If there is no risk of significant harm.

D.

If there is no risk of significant harm.

Answers
Suggested answer: B

What is required for a provincial law to be considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

A.

Consistency with at least eight of the ten privacy principles, an independent oversight body and a complaint handling mechanism.

A.

Consistency with at least eight of the ten privacy principles, an independent oversight body and a complaint handling mechanism.

Answers
B.

Consistency with the ten privacy principles, an independent oversight body and a process for accessing information.

B.

Consistency with the ten privacy principles, an independent oversight body and a process for accessing information.

Answers
C.

Consistency with the ten privacy principles, an independent oversight body and a redress mechanism.

C.

Consistency with the ten privacy principles, an independent oversight body and a redress mechanism.

Answers
D.

Consistency with the ten privacy principles, an appeal process and a redress mechanism.

D.

Consistency with the ten privacy principles, an appeal process and a redress mechanism.

Answers
Suggested answer: C

A boutique hotel in Montreal seeks to attract travelers from Europe but wants to avoid becoming subject to the GDPR's requirements. Which of the following activities is most likely to result in a finding that the hotel is subject to the GDPR?

A.

Placing advertisements on travel websites accessible in Europe.

A.

Placing advertisements on travel websites accessible in Europe.

Answers
B.

Collecting contact information for foreign business leaders from public directories.

B.

Collecting contact information for foreign business leaders from public directories.

Answers
C.

Sending discount offers to guests who previously registered using a foreign address.

C.

Sending discount offers to guests who previously registered using a foreign address.

Answers
D.

Translating the hotel's registration page into German based on the visitor's IP address.

D.

Translating the hotel's registration page into German based on the visitor's IP address.

Answers
Suggested answer: D

The movement toward comprehensive privacy and data protection laws can be attributed to a combination of three major factors: the need to remedy past injustices, the need to promote a digital economy and the need to ensure consistency with?

A.

Self-regulatory laws.

A.

Self-regulatory laws.

Answers
B.

Pan-European laws.

B.

Pan-European laws.

Answers
C.

Pan-Asian laws.

C.

Pan-Asian laws.

Answers
D.

Global laws.

D.

Global laws.

Answers
Suggested answer: D

A private organization called Vision 3072 must verify the information they are collecting is up to date in order to avoid misinformed actions or decisions. Which privacy principle is intended to make sure this verification is happening?

A.

Integrity.

A.

Integrity.

Answers
B.

Accuracy.

B.

Accuracy.

Answers
C.

Accountability.

C.

Accountability.

Answers
D.

Limiting purposes.

D.

Limiting purposes.

Answers
Suggested answer: B
Total 76 questions
Go to page: of 8