ExamGecko
Home Home / IAPP / CIPP-C

IAPP CIPP-C Practice Test - Questions Answers, Page 8

Question list
Search
Search

Related questions











The process of de-identification where new data elements are substituted for identifying information is?

A.

Shuffling.

A.

Shuffling.

Answers
B.

Encryption.

B.

Encryption.

Answers
C.

Anonymization.

C.

Anonymization.

Answers
D.

Pseudonymization.

D.

Pseudonymization.

Answers
Suggested answer: D

Which organization was the primary influence in the development of Canadian privacy with their publication of a set of eight privacy principles?

A.

The Organization for Economic Co-operation and Development (OECD).

A.

The Organization for Economic Co-operation and Development (OECD).

Answers
B.

The Canadian Institute of Chartered Accountants

B.

The Canadian Institute of Chartered Accountants

Answers
C.

The Center for Democracy and Technology (CRT)

C.

The Center for Democracy and Technology (CRT)

Answers
D.

The Canadian Standards Association (CSA).

D.

The Canadian Standards Association (CSA).

Answers
Suggested answer: D

When a third country or specified entity is said to ensure an adequate level of protection essentially equivalent to that ensured within the European Union, it is awarded a(n)?

A.

Equivalency designation.

A.

Equivalency designation.

Answers
B.

Attestation designation.

B.

Attestation designation.

Answers
C.

Adequacy designation.

C.

Adequacy designation.

Answers
D.

Protection designation.

D.

Protection designation.

Answers
Suggested answer: C

A commercial business in Canada is allowed to collect personal information without the knowledge or consent of the individual in all of the following circumstances EXCEPT when?

A.

The collection is for journalistic or literary purposes.

A.

The collection is for journalistic or literary purposes.

Answers
B.

The collection is in the interests of the individual and the consent cannot be obtained in a timely way.

B.

The collection is in the interests of the individual and the consent cannot be obtained in a timely way.

Answers
C.

The collection would lead to the creation of products that would benefit the public and consent would be difficult to obtain.

C.

The collection would lead to the creation of products that would benefit the public and consent would be difficult to obtain.

Answers
D.

The collection, with the knowledge of the individual, would compromise the availability and accuracy of the information and the collection is reasonable for the purposes related to investigating

D.

The collection, with the knowledge of the individual, would compromise the availability and accuracy of the information and the collection is reasonable for the purposes related to investigating

Answers
Suggested answer: C

Oversight authorities allow the following types of consent EXCEPT?

A.

Implied consent at the time of collection.

A.

Implied consent at the time of collection.

Answers
B.

Verbal consent given to the person collecting the information.

B.

Verbal consent given to the person collecting the information.

Answers
C.

Written consent included with the information that is collected.

C.

Written consent included with the information that is collected.

Answers
D.

General consent covering all activities associated with the personal information.

D.

General consent covering all activities associated with the personal information.

Answers
Suggested answer: D

A small commercial business in Canada was preparing a mailing to its customers when the letters and the envelopes were mismatched, causing 500 of 1000 letters to be sent to the wrong recipients. The letters contained the name and mailing address of the clients as well as account numbers and account balances.

The business has discovered this error as clients called to report receiving the wrong letter and expressing concern that their information has been breached. Which of the following is the most appropriate next step to take?

A.

All 1000 clients must be sent new letters.

A.

All 1000 clients must be sent new letters.

Answers
B.

The 500 clients who were impacted must be immediately notified.

B.

The 500 clients who were impacted must be immediately notified.

Answers
C.

The Office of the Privacy Commissioner (OPC) must be immediately notified.

C.

The Office of the Privacy Commissioner (OPC) must be immediately notified.

Answers
D.

A risk assessment must be completed to determine the real risk of significant harm (RROSH) to the clients.

D.

A risk assessment must be completed to determine the real risk of significant harm (RROSH) to the clients.

Answers
Suggested answer: D
Total 76 questions
Go to page: of 8