IAPP CIPP-C Practice Test - Questions Answers, Page 6
List of questions
Related questions
An Alberta woman finds errors about her personal information while reviewing paperwork at a local real estate firm. According to Canadian Standards Association (CSA) principles, how should the firm respond to these errors?
File an error report describing the nature of the errors.
Amend any information that the woman finds to be erroneous.
Request that the woman complete a new set of forms with correct information
Provide the woman with the names of any third parties who have had access to her information.
What can be concluded from the Blood Tribe case regarding the Privacy Commissioner's access to information?
The commissioner cannot receive information unless it is gathered under oath.
The commissioner cannot ask an organization to prove that a document is privileged.
The commissioner can compel the production of all documents that are relevant to the investigation.
The commissioner can officially request proof that desired information is subject to solicitor-client privilege.
Work-product information is generally thought of as information about an individual that?
Is required by an organization to establish an employment relationship.
Includes internal investigation files and complaints filed about an employee.
Includes intellectual property developed within the scope of an employee's job function.
Is prepared or collected as part of that individual's responsibilities or activities in connection to their job.
As response to TJX Winners - Homesense, why is 'hashing' preferable to storing a personal identifier such as a driver's license number?
It scrambles information but can be unscrambled for later use.
It automatically puts a lifespan on any identification that is stored.
It randomizes all permanent identification within an organized database.
It still provides customer identification, but in a form that would not reveal the real number.
Which of these employees would be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA)?
The staff of an airline offering flights across Canada.
Underwriters for a New Brunswick insurance company.
Clerks at a Montreal credit union based out of Montreal.
The information technology department of the Saskatchewan Office of Residential Tenancies of Saskatchewan.
Which statement is TRUE regarding health information privacy laws in Canada?
Obligations regarding accountability for health information are transferred when control is outsourced to a third party. B Emphasis is given lo personal information protection over the maintenance of the publicly funded healthcare system
There is a significant amount of variation among provinces regarding the definition of consent and how the consent requirement is addressed.
In provinces where there are no health information privacy statutes, a combination of the public health regulations and the private sector privacy legislation apply.
What is a difference between the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Personal Information Privacy Act (PIPA) of both Alberta and British Columbia?
PIPEDA applies to personal information about individuals employed by government institutions; PIPA applies to personal information about individuals employed by public-sector organizations within the provinces.
The enforcement powers of the federal Privacy Commissioner of Canada under PIPEDA are greater than those of the provincial privacy commissioners under PIPA.
PIPEDA applies to federal undertakings and to inter-provincial organizations engaged in commercial activities; PIPA applies to private organizations.
The person in charge of oversight of PIPEDA is a privacy commissioner; the person in charge of oversight of PIPA is an ombudsman.
Under the Freedom of Information and Protection of Privacy Acts (FIPPA), personal information includes all of the following EXCEPT?
Information about an individual's home business.
Information about an individual's creditworthiness.
Information about an individual's employment history.
Information about an individual's character references.
What must happen before an individual requester can commence a court application relating to the denial of access to personal information under the control of a federal government institution?
The Privacy Commissioner of Canada must have completed an investigation and issued a report.
The Privacy Commissioner of Canada must have completed an investigation and found in favor of the requester.
The requester must have made a formal Privacy Act request to a government institution for access to personal information.
The requester must have lodged a complaint with the Office of the Privacy Commissioner (OPC) within 60 days of having received a response to a formal Privacy Act request.
According to the federal Privacy Act, before collecting personal information, public-sector organizations are required to ensure that any of the following are met EXCEPT?
Collection directly relates to, and is necessary for, operating a program of that organization.
Collection is for the purposes of a law enforcement action.
Collection is expressly authorized under an act.
Collection is authorized by consent.
Question