ExamGecko
Home Home / IAPP / CIPP-C

IAPP CIPP-C Practice Test - Questions Answers, Page 2

Question list
Search
Search

List of questions

Search

Related questions











Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must maintain a record of every breach of security safeguards involving personal information for a minimum of?

A.

3 months.

A.

3 months.

Answers
B.

12 months.

B.

12 months.

Answers
C.

24 months.

C.

24 months.

Answers
D.

36 months

D.

36 months

Answers
Suggested answer: C

In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient's record. The patient later regrets revealing certain facts and doesn't want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.

Which of the following requests would the patient be most successful at pursuing?

A.

That a correction be made to change the diagnosis based on the patient's wishes.

A.

That a correction be made to change the diagnosis based on the patient's wishes.

Answers
B.

That the information be restricted from disclosure to other health care providers.

B.

That the information be restricted from disclosure to other health care providers.

Answers
C.

That a copy of the record be kept by the patient for disclosure to physicians.

C.

That a copy of the record be kept by the patient for disclosure to physicians.

Answers
D.

That details of the diagnosis be deleted from the patient's health record.

D.

That details of the diagnosis be deleted from the patient's health record.

Answers
Suggested answer: B

The Government of Canada's Directive on Privacy Impact Assessments applies to all of the following EXCEPT?

A.

The Ministry of Health

A.

The Ministry of Health

Answers
B.

The Bank of Canada.

B.

The Bank of Canada.

Answers
C.

Crown Corporations.

C.

Crown Corporations.

Answers
D.

The Cabinet.

D.

The Cabinet.

Answers
Suggested answer: D

Which falls under the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA)?

A.

Personal information collected by private businesses for journalistic or artistic purposes.

A.

Personal information collected by private businesses for journalistic or artistic purposes.

Answers
B.

Personal health information (PHI) handled by private enterprises in provinces that have adopted substantially similar legislation.

B.

Personal health information (PHI) handled by private enterprises in provinces that have adopted substantially similar legislation.

Answers
C.

Personal information disclosed across provincial or national borders by organizations such as credit reporting agencies or list marketers.

C.

Personal information disclosed across provincial or national borders by organizations such as credit reporting agencies or list marketers.

Answers
D.

Personal information such as names, titles and contact information used by businesses to communicate with employees regarding their profession.

D.

Personal information such as names, titles and contact information used by businesses to communicate with employees regarding their profession.

Answers
Suggested answer: C

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), when engaging in a third-party transfer of personal information for processing, an organization is expected to have the technology to protect the information during transit and to?

A.

Establish a contract outlining the individual outsourcing arrangement.

A.

Establish a contract outlining the individual outsourcing arrangement.

Answers
B.

Obtain additional consent for the use of the information by the third party.

B.

Obtain additional consent for the use of the information by the third party.

Answers
C.

Confirm the jurisdictional protections of the receiving organization are the same as PIPEDA.

C.

Confirm the jurisdictional protections of the receiving organization are the same as PIPEDA.

Answers
D.

Review the cross-border data flow competed and approved by the Treasury Board of Canada Secretariat.

D.

Review the cross-border data flow competed and approved by the Treasury Board of Canada Secretariat.

Answers
Suggested answer: A

According to the Privacy Act, which of the following disclosures of personal information by a government institution would require the data subject's consent?

A.

When disclosing to a law enforcement body.

A.

When disclosing to a law enforcement body.

Answers
B.

When disclosing to comply with a search warrant.

B.

When disclosing to comply with a search warrant.

Answers
C.

When disclosing to a registered charitable organization.

C.

When disclosing to a registered charitable organization.

Answers
D.

When disclosing to a member of parliament to assist in resolving a problem.

D.

When disclosing to a member of parliament to assist in resolving a problem.

Answers
Suggested answer: C

Under PIPEDA, each of the following are considered to be personal information EXCEPT?

A.

A public official's salary published on a government web site.

A.

A public official's salary published on a government web site.

Answers
B.

A person's telephone number published in a public directory.

B.

A person's telephone number published in a public directory.

Answers
C.

A photograph taken in public and published in a newspaper.

C.

A photograph taken in public and published in a newspaper.

Answers
D.

Information about a defendant contained in court records.

D.

Information about a defendant contained in court records.

Answers
Suggested answer: A

How would an individual determine whether their personal information was used by the federal government for data matching?

A.

By submitting written requests to the third party conducting data matching for the government

A.

By submitting written requests to the third party conducting data matching for the government

Answers
B.

By noting the description of the Personal Information Banks available through Info Source.

B.

By noting the description of the Personal Information Banks available through Info Source.

Answers
C.

By proposing a Privacy Impact Assessment (PIA) within the specific government body.

C.

By proposing a Privacy Impact Assessment (PIA) within the specific government body.

Answers
D.

By reviewing the Privacy Commissioner's annual report.

D.

By reviewing the Privacy Commissioner's annual report.

Answers
Suggested answer: B

Which health information custodians may NOT rely on an implied consent model under Ontario's Personal Health Information Protection Act (PHIPA)?

A.

Private insurance companies.

A.

Private insurance companies.

Answers
B.

Long-term care homes.

B.

Long-term care homes.

Answers
C.

Ambulance services.

C.

Ambulance services.

Answers
D.

Pharmacies

D.

Pharmacies

Answers
Suggested answer: A

In what situation is the federal Privacy Commissioner authorized to proceed to federal court?

A.

For a determination on a ruling regarding privacy matters relating to the Charter of Rights and Freedom.

A.

For a determination on a ruling regarding privacy matters relating to the Charter of Rights and Freedom.

Answers
B.

For a determination of whether or not personal information was properly withheld from release.

B.

For a determination of whether or not personal information was properly withheld from release.

Answers
C.

For a determination on a ruling by an administrative tribunal regarding privacy.

C.

For a determination on a ruling by an administrative tribunal regarding privacy.

Answers
D.

For a determination on a ruling by a provincial Privacy Commissioner.

D.

For a determination on a ruling by a provincial Privacy Commissioner.

Answers
Suggested answer: B
Total 76 questions
Go to page: of 8