Black Friday Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

CIPP-C Sample Questions Answers

Questions 4

In Ontario, personal information can be withheld from disclosure in a Freedom of Information (FOI) request. The following information is included in a record that is the subject of a FOI request being handled by a hospital: employee name, employee title, employee designation, employee educational history, employee personal cell phone number, and feedback about the employee from a colleague.

Which of the following statements is accurate regarding what can be released?

Options:

A.

Employee name and title can only be released if the employee consents

B.

The employee designation is not to be released as it is considered employment history.

C.

Employee name, title, and designation can be released as it is not classified as personal information.

D.

No employee information can be released as it is information that was collected throughout the course of employment.

Buy Now
Questions 5

Which of the following provincial health acts is NOT considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

Options:

A.

New Brunswick's Personal Health Information Privacy and Access Act (PHIPAA)

B.

Ontario's Personal Health Information Protection Act (PHIPAA)

C.

Nova Scotia's Personal Health Information Act (PHIPAA)

D.

lAberta's Health Information Act (PHIA)

Buy Now
Questions 6

When a third country or specified entity is said to ensure an adequate level of protection essentially equivalent to that ensured within the European Union, it is awarded a(n)?

Options:

A.

Equivalency designation.

B.

Attestation designation.

C.

Adequacy designation.

D.

Protection designation.

Buy Now
Questions 7

What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?

Options:

A.

Review all the investigative notes of the oversight authority, such as would be gathered during interviews.

B.

Impose a prison sentence only, such as when an employee sells personal health information (PHI) for their own gain.

C.

Look at specific types of errors made by the oversight authority such as a misinterpretation of a term in the legislation

D.

Review and compare the oversight authority's decision or recommendation against those of other oversight authorities across Canada.

Buy Now
Questions 8

Work-product information is generally thought of as information about an individual that?

Options:

A.

Is required by an organization to establish an employment relationship.

B.

Includes internal investigation files and complaints filed about an employee.

C.

Includes intellectual property developed within the scope of an employee's job function.

D.

Is prepared or collected as part of that individual’s responsibilities or activities in connection to their job.

Buy Now
Questions 9

What is required of a private sector organization that is subject to a finding by a Canadian federal or

Options:

A.

In Québec, comply with the finding as a binding decision.

B.

Comply with findings of the Privacy Commissioner of Canada only.

C.

In all jurisdictions, adopt and apply the finding within 30 days of the published report.

D.

In Ontario only, apply for judicial review within a provincial court in order to accept or refute the finding.

Buy Now
Questions 10

What is critical to consider when an organization responsible for a large number of records wants to outsource the storage of those records?

Options:

A.

Determining if the personal information stored on the records will be used for data matching

B.

Putting into place a contractual agreement between the organization and the records storage company.

C.

Conducting a Privacy Impact Assessment (PIA) prior to establishing a relationship with the storage company.

D.

Establishing that consent gathered from individuals by the organization in order to store their personal information was informed and meaningful.

Buy Now
Questions 11

A private sector daycare’s portal for parents stores their children’s photos, allergy information and date of birth. A parent has asked about the portal’s security requirements and in three months still not has received an answer. What is missing from the daycare’s procedures?

Options:

A.

Ensuring transparency.

B.

Responding to the parent's request within 30 days.

C.

Ensuring strong encryption and security measures.

D.

Completing a real risk of significant harm assessment (RROSH).

Buy Now
Questions 12

As response to TJX Winners - Homesense, why is "hashing" preferable to storing a personal identifier such as a driver’s license number?

Options:

A.

It scrambles information but can be unscrambled for later use.

B.

It automatically puts a lifespan on any identification that is stored.

C.

It randomizes all permanent identification within an organized database.

D.

It still provides customer identification, but in a form that would not reveal the real number.

Buy Now
Questions 13

All items below could be considered sensitive personal information, EXCEPT?

Options:

A.

Credit score.

B.

Date of birth.

C.

Medical history.

D.

Educational transcripts.

Buy Now
Questions 14

In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.

Which of the following requests would the patient be most successful at pursuing?

Options:

A.

That a correction be made to change the diagnosis based on the patient's wishes.

B.

That the information be restricted from disclosure to other health care providers.

C.

That a copy of the record be kept by the patient for disclosure to physicians.

D.

That details of the diagnosis be deleted from the patient’s health record.

Buy Now
Questions 15

According to the federal court ruling in the Eastman Case, video cameras in the workplace are considered to be collecting personal information?

Options:

A.

At the moment a recording occurs.

B.

When a camera is on, even if it is not yet recording.

C.

As soon as the data is saved to a workplace server.

D When someone within the nrnani7atinn views the recording

Buy Now
Questions 16

Which province requires its government bodies to store and access personal information exclusively in Canada unless additional consent is obtained, or if outside storage is judged necessary?

Options:

A.

Nova Scotia

B.

Québec.

C.

Ontario.

D.

Alberta.

Buy Now
Questions 17

According to the Canadian Standards Association (CSA) Model Code, how long should personal information be retained?

Options:

A.

Personal information should not be retained at all.

B.

Personal information should be retained indefinitely as long as consent has been given.

C.

Personal information should be retained for at least two years after the last administrative use.

D.

Personal information should be retained as long as necessary for the fulfillment of the purpose of the collection.

Buy Now
Questions 18

In which situation could a request for access to one’s personal information be denied under the Privacy Act?

Options:

A.

The personal information was collected by the Royal Canadian Mounted Police while performing policing services for a province or municipality.

B.

The personal information was obtained in confidence from a foreign state or agency which has consented to the disclosure of the information.

C.

The release of the personal information could reasonably be expected to cause injury to a protected species of wildlife.

D.

The personal information is more than 20 years old and relates to the detection or suppression of money laundering.

Buy Now
Questions 19

Safeguarding and securing information that is considered sensitive under privacy legislation generally falls into three categories: Administrative, Technical and?

Options:

A.

Legal.

B.

Physical.

C.

Personal.

D.

Logistical.

Buy Now
Questions 20

Which of these employees would be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA)?

Options:

A.

The staff of an airline offering flights across Canada.

B.

Underwriters for a New Brunswick insurance company.

C.

Clerks at a Montreal credit union based out of Montreal.

D.

The information technology department of the Saskatchewan Office of Residential Tenancies of Saskatchewan.

Buy Now
Questions 21

Of the key principles in the Personal Information Protection and Electronic Documents Act (PIPEDA), which principle in particular contributes to the increase in privacy policies in recent years?

Options:

A.

Limiting Use, Disclosure, and Retention.

B.

Individual Access.

C.

Openness.

D.

Accuracy

Buy Now
Questions 22

An Alberta woman finds errors about her personal information while reviewing paperwork at a local real estate firm. According to Canadian Standards Association (CSA) principles, how should the firm respond to these errors?

Options:

A.

File an error report describing the nature of the errors.

B.

Amend any information that the woman finds to be erroneous.

C.

Request that the woman complete a new set of forms with correct information

D.

Provide the woman with the names of any third parties who have had access to her information.

Buy Now
Exam Code: CIPP-C
Exam Name: Certified Information Privacy Professional/ Canada (CIPP/C)
Last Update: Nov 22, 2024
Questions: 76
$57.75  $164.99
$43.75  $124.99
$36.75  $104.99
buy now CIPP-C