CIPP-C CIPP/Canada Practice Questions
Prepare for CIPP-C with more than an answer.
- Exam fee
- $550 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 4
- Introduction to Privacy in Canada25%
- Canadian Privacy Laws and Practices – Private Sector35%
- Canadian Privacy Laws and Practices – Public Sector25%
- Canadian Privacy Laws and Practices – Health Sector15%
- 1
A hospital in Ontario discovers that an employee, out of personal curiosity, accessed the electronic health records of a celebrity patient. The hospital terminates the employee and contains the breach internally. The hospital determines there is no 'real risk of significant harm' because the information was not copied or shared outside the hospital. What is the hospital's primary reporting obligation under PHIPA?
Show answer details
Correct answer: C
Under Ontario's PHIPA, there are specific categories of breaches that MUST be reported to the Commissioner, regardless of the risk of harm assessment. One of these categories is when personal health information is used or disclosed without authority (e.g., employee snooping). Therefore, even if the risk of harm is low, the hospital has a statutory duty to report this type of privacy breach to the IPC.
- 2
The division of powers between the federal and provincial governments is a key concept in Canadian law. Privacy legislation is enacted under which heads of power in the Constitution Act, 1867? (Select ALL that apply)
Show answer details
Correct answer: A, C
PIPEDA, the federal private-sector law, is founded on the federal government's jurisdiction over trade and commerce, particularly for interprovincial and international data flows.
Provincial privacy laws (both public and private sector) are based on the provinces' jurisdiction over property and civil rights within the province, as this covers most commercial and contractual relationships.
- 3
A federal government employee makes a request under the Privacy Act to access their own performance evaluation file. The manager provides the file but has redacted comments attributed to the employee's colleagues, citing that releasing this information would reveal personal information about other individuals. Is this redaction permissible under the Privacy Act?
Show answer details
Correct answer: C
Yes, this redaction is permissible and often required. The Privacy Act [Section 26] contains a mandatory exemption preventing the disclosure of personal information about an individual other than the person who made the request. The manager must sever (redact) the third-party personal information before releasing the file to the requester.
- 4
Under Quebec's Law 25, organizations are required to conduct a Privacy Impact Assessment (PIA) in certain situations. Which of the following scenarios would MOST likely trigger the mandatory PIA requirement?
flowchart TD A[Start: New Project Proposal] --> B{Involves Personal Information?} B -->|No| C[No PIA Required] B -->|Yes| D{Project Type?} D -->|Data System Creation| E[PIA Required] D -->|Data Transfer Outside Quebec| E[PIA Required] D -->|Routine Update| F[Review, but maybe no full PIA]Show answer details
Correct answer: B
Quebec's Law 25 requires a PIA for any project involving the acquisition, development, or redesign of an information system or electronic service delivery system involving personal information. Crucially, it also mandates a PIA before disclosing personal information outside of Quebec. Migrating a database to a cloud provider in Ontario constitutes such a disclosure and would trigger the requirement.
- 5
True or False: Under PIPEDA, an organization that suffers a data breach is only required to notify the affected individuals if the breach was caused by a malicious external attack.
Show answer details
Correct answer: B
This statement is false. The trigger for breach notification under PIPEDA is whether the breach creates a 'real risk of significant harm' (RROSH) to individuals. The cause of the breach (e.g., malicious attack, accidental disclosure, human error, lost device) is irrelevant to the notification obligation. Any breach that meets the RROSH threshold requires notification to the affected individuals and the Privacy Commissioner.
- 6
A federally regulated telecommunications company in Canada launches a new mobile application. To enhance user experience, the app collects geolocation data, even when running in the background. The initial consent banner simply states, 'This app collects data to improve services.' The Office of the Privacy Commissioner of Canada (OPC) launches an investigation. Which core principle of PIPEDA is most likely the primary focus of the OPC's findings of non-compliance?
Show answer details
Correct answer: C
The primary issue is the lack of meaningful consent. The 'Knowledge and Consent' principle requires organizations to inform individuals of the purposes for the collection, use, or disclosure of personal information in a clear and understandable manner. A vague statement like 'improve services' does not adequately explain the collection of sensitive geolocation data, especially when collected in the background. The OPC's guidelines on meaningful consent emphasize clarity on what is being collected, for what purpose, and with whom it will be shared.
- 7
A Vancouver-based technology startup processes all its customer data, including personal information of EU residents, using cloud servers located in Ontario. The company suffers a data breach affecting individuals in both British Columbia and Germany. Under which regulations does the company have a mandatory breach notification obligation? (Select TWO)
Show answer details
Correct answer: A, D
As the company is based in British Columbia, it is subject to BC's Personal Information Protection Act (PIPA) for the personal information of BC residents. BC PIPA includes mandatory breach notification requirements if a breach creates a real risk of significant harm.
The General Data Protection Regulation (GDPR) has extraterritorial reach and applies to any organization, regardless of location, that processes the personal data of individuals in the EU. Since German residents were affected, the company has a mandatory breach notification obligation under GDPR.
- 8
A new federal government program is being developed to provide digital identity services to Canadian citizens. This program will involve collecting sensitive biometric data and linking it to various other government databases. According to the Treasury Board of Canada's policies, what is the primary privacy compliance tool that must be completed before the program is launched?
Show answer details
Correct answer: B
The Treasury Board Directive on Privacy Impact Assessment makes it mandatory for federal government institutions to conduct a PIA for new or substantially modified programs and activities involving personal information. Given the collection of sensitive biometrics and data linkage, a PIA is the required tool to identify and mitigate privacy risks before launch.
- 9
In Ontario, a patient is treated by a specialist at a hospital. The specialist shares the patient's diagnostic results with the patient's family physician to ensure continuity of care. The patient had not explicitly forbidden this sharing but also did not provide express written consent. This sharing of information is permissible under PHIPA based on what concept?
Show answer details
Correct answer: B
Ontario's Personal Health Information Protection Act (PHIPA) allows health information custodians to assume a patient's implied consent to share personal health information with other custodians involved in the patient's care, unless the patient has expressly withheld or withdrawn that consent. This concept is known as the 'circle of care'.
- 10
True or False: The Canadian Charter of Rights and Freedoms explicitly contains a right to privacy, which is the primary source of all privacy legislation in Canada.
Show answer details
Correct answer: B
This statement is false. The Canadian Charter of Rights and Freedoms does not contain an explicit, standalone right to privacy. Instead, privacy rights have been interpreted by the courts as being implicitly protected under Section 7 ('the right to life, liberty and security of the person') and Section 8 ('the right to be secure against unreasonable search or seizure'). Privacy legislation like PIPEDA and the Privacy Act are the primary statutory sources.
