ExamGecko
Home Home / IAPP / CIPP-C

IAPP CIPP-C Practice Test - Questions Answers, Page 5

Question list
Search
Search

Related questions











To whom does the Privacy Commissioner of Canada report?

A.

Supreme Court of Canada and Prime Minister

A.

Supreme Court of Canada and Prime Minister

Answers
B.

House of Commons and the Senate.

B.

House of Commons and the Senate.

Answers
C.

Administrative tribunal.

C.

Administrative tribunal.

Answers
D.

Auditor General.

D.

Auditor General.

Answers
Suggested answer: B

In which situation could a request for access to one's personal information be denied under the Privacy Act?

A.

The personal information was collected by the Royal Canadian Mounted Police while performing policing services for a province or municipality.

A.

The personal information was collected by the Royal Canadian Mounted Police while performing policing services for a province or municipality.

Answers
B.

The personal information was obtained in confidence from a foreign state or agency which has consented to the disclosure of the information.

B.

The personal information was obtained in confidence from a foreign state or agency which has consented to the disclosure of the information.

Answers
C.

The release of the personal information could reasonably be expected to cause injury to a protected species of wildlife.

C.

The release of the personal information could reasonably be expected to cause injury to a protected species of wildlife.

Answers
D.

The personal information is more than 20 years old and relates to the detection or suppression of money laundering.

D.

The personal information is more than 20 years old and relates to the detection or suppression of money laundering.

Answers
Suggested answer: C

What is the Canadian Courts' role in reviewing decisions by provincial oversight authorities?

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

Answers
B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

Answers
C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

Answers
D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

Answers
Suggested answer: C

According to the Canadian Standards Association (CSA) Model Code, how long should personal information be retained?

A.

Personal information should not be retained at all.

A.

Personal information should not be retained at all.

Answers
B.

Personal information should be retained indefinitely as long as consent has been given.

B.

Personal information should be retained indefinitely as long as consent has been given.

Answers
C.

Personal information should be retained for at least two years after the last administrative use.

C.

Personal information should be retained for at least two years after the last administrative use.

Answers
D.

Personal information should be retained as long as necessary for the fulfillment of the purpose of the collection.

D.

Personal information should be retained as long as necessary for the fulfillment of the purpose of the collection.

Answers
Suggested answer: D

What is the main reason a country might adopt an 'ombudsman' model of privacy oversight?

A.

It provides a more streamlined process of complaint resolution.

A.

It provides a more streamlined process of complaint resolution.

Answers
B.

It increases the power of the commissioner to enforce decisions.

B.

It increases the power of the commissioner to enforce decisions.

Answers
C.

It reduces the perception that compliance is a confrontational process.

C.

It reduces the perception that compliance is a confrontational process.

Answers
D.

It provides a more detailed set of guidelines regarding possible violations.

D.

It provides a more detailed set of guidelines regarding possible violations.

Answers
Suggested answer: C

According to the Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, signatories commit to doing all of the following EXCEPT?

A.

Contributing to the development and application of Al standards.

A.

Contributing to the development and application of Al standards.

Answers
B.

Sharing information and best practices of Al governance.

B.

Sharing information and best practices of Al governance.

Answers
C.

Supporting public awareness and education on Al.

C.

Supporting public awareness and education on Al.

Answers
D.

Adopting low-risk uses of AI.

D.

Adopting low-risk uses of AI.

Answers
Suggested answer: D

What must a federal government department do before it implements an electronic service (e-service)?

A.

Conduct a preliminary PIA before acquiring the service

A.

Conduct a preliminary PIA before acquiring the service

Answers
B.

Complete a PIA in accordance with Treasury Board guidelines.

B.

Complete a PIA in accordance with Treasury Board guidelines.

Answers
C.

Publish a privacy statement in newspapers and on the government website.

C.

Publish a privacy statement in newspapers and on the government website.

Answers
D.

Determine if the Office of the Privacy Commissioner must be notified of the launch of this new e-service

D.

Determine if the Office of the Privacy Commissioner must be notified of the launch of this new e-service

Answers
Suggested answer: B

In comparing British Columbia's privacy laws with the health information privacy acts of the remaining provinces, BC's privacy laws?

A.

Seek to create a more flexible regulatory system to manage the patient data itself

A.

Seek to create a more flexible regulatory system to manage the patient data itself

Answers
B.

Refer to health sector participants as trustees as opposed to custodians.

B.

Refer to health sector participants as trustees as opposed to custodians.

Answers
C.

Exclude laboratories, nursing homes and independent health facilities.

C.

Exclude laboratories, nursing homes and independent health facilities.

Answers
D.

Group data banks together rather than listing them separately.

D.

Group data banks together rather than listing them separately.

Answers
Suggested answer: A

ABC Corp uses a third-party provider to perform data analytics and sends the following data sets to the third party to run some reports: name, customer ID, age, transaction activity, transaction date, location, outcome, customer type.

If ABC Corp wants the third party to send all the data sets to their US based marketing partner for a new use, they must?

A.

Encrypt data in transit.

A.

Encrypt data in transit.

Answers
B.

Anonymize the personal data before sending.

B.

Anonymize the personal data before sending.

Answers
C.

Seek additional consent from their customers.

C.

Seek additional consent from their customers.

Answers
D.

Ensure the marketing partner has equal or stronger protections than Canada.

D.

Ensure the marketing partner has equal or stronger protections than Canada.

Answers
Suggested answer: C

Under the Privacy Act, when government institutions collect personal information?

A.

Data subject consent is required.

A.

Data subject consent is required.

Answers
B.

The collection must be directly from a data subject.

B.

The collection must be directly from a data subject.

Answers
C.

The collection must relate to an operating program or activity.

C.

The collection must relate to an operating program or activity.

Answers
D.

Information collected must be made anonymous where technologically possible

D.

Information collected must be made anonymous where technologically possible

Answers
Suggested answer: C
Total 76 questions
Go to page: of 8