Pass the IAPP Certified Information Privacy Professional CIPP-C Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which case, brought before the Federal Court, helped determine that the Office of the Privacy Commissioner of Canada (OPC) had jurisdiction to investigate complaints about United States companies collecting, using and disclosing the personal information of individuals within Canada?

Options:

A.

TJX Winners - Homesense.


B.

Facebook: 2019.


C.

Blood Tribe.


D.

Abika.com.


Expert Solution
Questions # 12:

In which situation could a request for access to one’s personal information be denied under the Privacy Act?

Options:

A.

The personal information was collected by the Royal Canadian Mounted Police while performing policing services for a province or municipality.


B.

The personal information was obtained in confidence from a foreign state or agency which has consented to the disclosure of the information.


C.

The release of the personal information could reasonably be expected to cause injury to a protected species of wildlife.


D.

The personal information is more than 20 years old and relates to the detection or suppression of money laundering.


Expert Solution
Questions # 13:

Which of the following describes a difference between the federal Privacy Commissioner and provincial commissioners?

Options:

A.

Provincial commissioners can order an organization to act.


B.

Provincial commissioners are limited to recommending actions.


C.

The federal commissioner has the power to make an organization comply.


D.

The federal commissioner must receive complaints from a legislative representative.


Expert Solution
Questions # 14:

What is the Generally Accepted Privacy Principles (GAPP) framework?

Options:

A.

An information management model that is widely recognized across many Canadian industries.


B.

A comprehensive guide for industry best practices as delineated by the Canadian federal Privacy Commissioner.


C.

A template for Privacy Impact Assessments (PIAs) that are conducted within private sector organizations in Canada.


D.

A principles-based privacy approach advocated by Canada’s leading accounting industry group and its U.S.-based counterpart.


Expert Solution
Questions # 15:

In comparing British Columbia’s privacy laws with the health information privacy acts of the remaining provinces, BC’s privacy laws?

Options:

A.

Seek to create a more flexible regulatory system to manage the patient data itself


B.

Refer to health sector participants as trustees as opposed to custodians.


C.

Exclude laboratories, nursing homes and independent health facilities.


D.

Group data banks together rather than listing them separately.


Expert Solution
Questions # 16:

Of the key principles in the Personal Information Protection and Electronic Documents Act (PIPEDA), which principle in particular contributes to the increase in privacy policies in recent years?

Options:

A.

Limiting Use, Disclosure, and Retention.


B.

Individual Access.


C.

Openness.


D.

Accuracy


Expert Solution
Questions # 17:

The process of de-identification where new data elements are substituted for identifying information is?

Options:

A.

Shuffling.


B.

Encryption.


C.

Anonymization.


D.

Pseudonymization.


Expert Solution
Questions # 18:

As response to TJX Winners - Homesense, why is "hashing" preferable to storing a personal identifier such as a driver’s license number?

Options:

A.

It scrambles information but can be unscrambled for later use.


B.

It automatically puts a lifespan on any identification that is stored.


C.

It randomizes all permanent identification within an organized database.


D.

It still provides customer identification, but in a form that would not reveal the real number.


Expert Solution
Questions # 19:

According to the federal Privacy Commissioner, what protection is missing from the Privacy Act regarding outsourcing of government work that contains personal information?

Options:

A.

A statement preventing the vendor to whom the information is outsourced to subcontract its processing.


B.

A statement granting the Privacy Commissioner the right to issue orders following an investigation into a possible data breach.


C.

A statement requiring the government agency to complete a Privacy Impact Assessment (PIA) prior to outsourcing to a third party.


D.

A statement indicating that the government institution from which the information is outsourced remains accountable for its security.


Expert Solution
Questions # 20:

According to the Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, signatories commit to doing all of the following EXCEPT?

Options:

A.

Contributing to the development and application of Al standards.


B.

Sharing information and best practices of Al governance.


C.

Supporting public awareness and education on Al.


D.

Adopting low-risk uses of AI.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions