PassFish

CIPP-C practice questions — 10 free

Certified Information Privacy Professional/Canada · every answer carries the reasoning, and why each other option fails.
101 questions
8 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

A commercial business in Canada is allowed to collect personal information without the knowledge or consent of the individual in all of the following circumstances EXCEPT when?

Why C is correct

PIPEDA s. 7(1) lists a limited set of exceptions under which a commercial organization may collect personal information without the knowledge or consent of the individual, including: collection for journalistic, artistic or literary purposes (corresponding to option A); collection that is clearly in the interests of the individual and consent cannot be obtained in a timely way (corresponding to option B); and collection where obtaining consent with the individual's knowledge would compromise the availability or accuracy of the information, and the collection is reasonable for purposes related to investigating a breach of federal law (corresponding to option D). These exceptions are all explicitly enumerated in the statute and therefore are not what "EXCEPT" refers to. By contrast, "collection would lead to the creation of products that benefit the public and consent would be difficult to obtain" is not an exception provided under PIPEDA s. 7(1). Simply invoking "the product benefits the public" or "consent is hard to obtain" as grounds for waiving the consent requirement has no legal basis and does not appear among the ten fair information principles in Schedule 1 of PIPEDA or the specific list of exceptions in s. 7. Option C is therefore the situation in which collecting personal information without consent is not permitted.

Question 2 of 10

According to Ontario’s Personal Health Information Protection Act (PHIPA), which of the following organizations is not allowed to use the implied consent model for handling personal health information?

Why A is correct

The Personal Health Information Protection Act (PHIPA) governs the collection, use, and sharing of personal health information (PHI) in Ontario. It outlines strict rules that apply to health information custodians, which include doctors, hospitals, clinics, pharmacies, ambulance services, and long-term care homes. One key aspect of PHIPA is the implied consent model, which allows certain custodians to share and use health data within the circle of care without needing explicit permission in each instance. Let’s evaluate each option to determine who may or may not rely on implied consent. Option A, private insurance companies, is the correct answer because they are not considered health information custodians under PHIPA in the same way healthcare providers are. Since they are typically not part of the patient’s direct circle of care, they are required to obtain explicit consent from individuals before collecting, using, or disclosing their health information. This is critical in protecting patient data from unauthorized use in non-clinical contexts, such as insurance underwriting or claims processing. Option B, long-term care homes, are included in PHIPA’s definition of health information custodians. They are permitted to rely on implied consent when handling personal health information for treatment, care, and service delivery. This is considered reasonable because the health information is used directly for the benefit of the individual under their care. Option C, ambulance services, also fall under the umbrella of healthcare providers. In emergency situations, where explicit consent is impractical or impossible, implied consent is essential and expected. It allows paramedics and emergency medical teams to share necessary health information with hospitals and other healthcare providers to ensure proper care. Option D, pharmacies, are directly involved in delivering health services. When a person submits a prescription, it is understood that their personal health information will be used to process and dispense medication. Therefore, implied consent applies here as well. However, pharmacies must still obtain explicit consent for non-care-related uses like marketing. In conclusion, only private insurance companies cannot use implied consent under PHIPA. They must request clear and documented permission before accessing or using an individual's personal health information for any reason. This legal safeguard ensures that sensitive health data remains confidential and is only used with full awareness and permission from the individual.

Question 3 of 10

An organization is establishing a mission statement for its privacy program. Which of the following statements would be the best to use?

Why A is correct

A good mission statement for a privacy program should clearly and concisely articulate the program's core goal and the means of achieving it, while avoiding exaggerated or unrealistic promises. The statement "the goal of the privacy program is to protect the privacy of all individuals who support our organization; to meet this goal, we must work to comply with all applicable privacy laws" accurately defines the subject of protection (all relevant individuals), the core goal (privacy protection), and the means of achieving it (compliance with applicable law), in language that is practical, measurable, and consistent with the clarity and actionability a privacy program mission statement should have. By contrast, promising to "stop all data breaches" or setting unrealistic quantitative targets and timelines are both overpromises that privacy professionals should avoid, since no privacy program can guarantee a "zero breach" absolute outcome — such statements, if they cannot be fulfilled, will damage the organization's credibility, and are inconsistent with the good-governance principle of setting achievable goals.

Question 4 of 10

Of the key principles in the Personal Information Protection and Electronic Documents Act (PIPEDA), which principle in particular contributes to the increase in privacy policies in recent years?

Why C is correct

Among PIPEDA's ten Fair Information Principles, the Openness principle (Principle 4.8) requires an organization to make readily available to individuals specific, understandable information about its policies and practices relating to the management of personal information, so that individuals can, in a relatively accessible way, learn how the organization collects, uses, and discloses personal information. It is precisely this principle that has directly driven the significant increase in the number and thoroughness of corporate privacy policies in recent years, since organizations must publish privacy policies to fulfill this specific compliance requirement of "openness," clearly explaining their data-processing practices to the public.

Question 5 of 10

What is a difference between the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Personal Information Privacy Act (PIPA) of both Alberta and British Columbia?

Why C is correct

A key distinction between PIPEDA and the PIPA statutes of Alberta and British Columbia lies in their scope of application: PIPEDA applies to personal information handled by federal works, undertakings and businesses (federally regulated entities such as banks, telecommunications, airlines, and railways) and to organizations engaged in inter-provincial or international commercial activities in the course of that activity; the provincial PIPA statutes apply to private-sector organizations carrying on commercial activities within that province (once a province's legislation is deemed "substantially similar," PIPEDA no longer applies to intra-provincial commercial activity in that province). This reflects the division of jurisdiction under Canada's federal privacy law scheme: the federal level governs inter-provincial/international commerce and federally regulated industries, while the provincial level governs commercial activity within the province. PIPEDA itself does not apply to information about employees of government institutions (that falls under the federal Privacy Act), nor does it involve a provincial comparison of "public-sector organization" employee information, so the analogy in option A is incorrect.

Question 6 of 10

What must a data controller do in order to make personal data pseudonymous?

Why B is correct

Under GDPR Article 4(5), "pseudonymisation" means processing personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person. Therefore, the key obligation of a data controller in making data pseudonymous is to keep the "additional information" that would allow re-identification of the data subject (i.e., the correlation information used to link the pseudonymous identifier to the real identity, such as a key or mapping table) stored separately from the pseudonymized data itself, and to apply appropriate protective measures to that additional information to prevent unauthorized re-identification. This differs from anonymisation — anonymised data no longer falls within the scope of the GDPR, whereas pseudonymised data remains "personal data," because re-identification remains technically possible.

Question 7 of 10

Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?

Why D is correct

The APEC Privacy Framework consists of nine principles and is a voluntary, non-binding framework intended to provide a consistent approach to personal information protection among APEC member economies. Its core content can be understood as a set of principled statements built around a range of rights individuals hold with respect to their own personal information (such as notice, access, correction, etc.); therefore, characterizing it as "a bill of rights" regarding personal information rights most aptly captures the nature of the framework — it is a principled, declaratory rights framework, not a specific industry operational standard, nor is it limited to marketing opt-out mechanisms, nor does it carry the binding enforcement effect of a court ruling.

Question 8 of 10

Which statement is TRUE regarding health information privacy laws in Canada?

Why B is correct

In Canada's system of health information privacy laws, including provincial health information legislation such as Ontario's PHIPA (Personal Health Information Protection Act), the general legislative purpose is to strike a balance between protecting the privacy of personal health information and maintaining the efficient operation of the publicly funded healthcare system, and in practice these laws often prioritize ensuring the continuity of the healthcare system and the flow of information, to support diagnosis and treatment, public health surveillance, and system management, rather than placing the protection of personal information above the operation of the system alone. This differs somewhat from the GDPR-style orientation of the EU, which centers absolutely on individual rights, and reflects the pragmatic character of Canada's health information legislation. Although options A, C, and D each touch on certain features of health information legislation, none of them accurately captures the overall orientation of the regime.

Question 9 of 10

Which statute is Alberta's dedicated health-sector privacy law?

Why C is correct

Canada has no single national health privacy law; strong regulatory authority rests at the provincial level: Ontario has the Personal Health Information Protection Act (PHIPA), while Alberta has the Health Information Act (HIA). When preparing for the exam, it is important to be able to match each province to its corresponding law, since questions often use a scenario such as "a health care facility in a certain province" to test which law applies in that province.

Question 10 of 10

Beyond rights protection, what economic rationale drove the EU to adopt comprehensive privacy legislation rather than a sector-by-sector approach?

Why B is correct

As a single market, the EU needed a uniform standard so that personal data could move freely across member state borders without being blocked by differing national standards — a purely economic-integration consideration. The drive toward comprehensive privacy legislation has two threads: historical lessons (the rights perspective) and the need for market integration (the economic perspective), and both must be understood.

These 10 are a sample

See the full bank