Certified Information Privacy Professional/Canada Free Sample Questions

20 free sample questions207 in the full practice test

Try simulator

CIPP-C Sample Questions

  1. Question 1

    A federally regulated telecommunications company in Canada launches a new mobile application. To enhance user experience, the app collects geolocation data, even when running in the background. The initial consent banner simply states, 'This app collects data to improve services.' The Office of the Privacy Commissioner of Canada (OPC) launches an investigation. Which core principle of PIPEDA is most likely the primary focus of the OPC's findings of non-compliance?

    Answer and explanation

    Correct answer: C

    The primary issue is the lack of meaningful consent. The 'Knowledge and Consent' principle requires organizations to inform individuals of the purposes for the collection, use, or disclosure of personal information in a clear and understandable manner. A vague statement like 'improve services' does not adequately explain the collection of sensitive geolocation data, especially when collected in the background. The OPC's guidelines on meaningful consent emphasize clarity on what is being collected, for what purpose, and with whom it will be shared.

  2. Question 2

    Multiple answers

    A Vancouver-based technology startup processes all its customer data, including personal information of EU residents, using cloud servers located in Ontario. The company suffers a data breach affecting individuals in both British Columbia and Germany. Under which regulations does the company have a mandatory breach notification obligation? (Select TWO)

    Answer and explanation

    Correct answers: A, D

    As the company is based in British Columbia, it is subject to BC's Personal Information Protection Act (PIPA) for the personal information of BC residents. BC PIPA includes mandatory breach notification requirements if a breach creates a real risk of significant harm.

    The General Data Protection Regulation (GDPR) has extraterritorial reach and applies to any organization, regardless of location, that processes the personal data of individuals in the EU. Since German residents were affected, the company has a mandatory breach notification obligation under GDPR.

  3. Question 3

    A new federal government program is being developed to provide digital identity services to Canadian citizens. This program will involve collecting sensitive biometric data and linking it to various other government databases. According to the Treasury Board of Canada's policies, what is the primary privacy compliance tool that must be completed before the program is launched?

    Answer and explanation

    Correct answer: B

    The Treasury Board Directive on Privacy Impact Assessment makes it mandatory for federal government institutions to conduct a PIA for new or substantially modified programs and activities involving personal information. Given the collection of sensitive biometrics and data linkage, a PIA is the required tool to identify and mitigate privacy risks before launch.

  4. Question 4

    In Ontario, a patient is treated by a specialist at a hospital. The specialist shares the patient's diagnostic results with the patient's family physician to ensure continuity of care. The patient had not explicitly forbidden this sharing but also did not provide express written consent. This sharing of information is permissible under PHIPA based on what concept?

    Answer and explanation

    Correct answer: B

    Ontario's Personal Health Information Protection Act (PHIPA) allows health information custodians to assume a patient's implied consent to share personal health information with other custodians involved in the patient's care, unless the patient has expressly withheld or withdrawn that consent. This concept is known as the 'circle of care'.

  5. Question 5

    True or False: The Canadian Charter of Rights and Freedoms explicitly contains a right to privacy, which is the primary source of all privacy legislation in Canada.

    Answer and explanation

    Correct answer: B

    This statement is false. The Canadian Charter of Rights and Freedoms does not contain an explicit, standalone right to privacy. Instead, privacy rights have been interpreted by the courts as being implicitly protected under Section 7 ('the right to life, liberty and security of the person') and Section 8 ('the right to be secure against unreasonable search or seizure'). Privacy legislation like PIPEDA and the Privacy Act are the primary statutory sources.

  6. Question 6

    An organization based in Quebec is updating its privacy policies to comply with Law 25. The new law requires the designation of a person in charge of the protection of personal information. By default, who holds this title if no one is formally designated?

    Answer and explanation

    Correct answer: C

    Quebec's Law 25 mandates that the person with the highest authority within the organization, such as the Chief Executive Officer (CEO), is by default the person in charge of the protection of personal information. This responsibility can be delegated in writing to another person.

  7. Question 7

    A marketing firm in Toronto sends out a monthly newsletter via email. A recipient, who has an existing business relationship with the firm from a transaction 18 months ago, clicks the 'unsubscribe' link. The firm's system fails to process the request, and the recipient receives another newsletter the following month. Which Canadian law has the firm most likely violated?

    Answer and explanation

    Correct answer: C

    Canada's Anti-Spam Legislation (CASL) governs the sending of Commercial Electronic Messages (CEMs). While the initial message may have been sent under implied consent from an existing business relationship (valid for two years), CASL requires that all unsubscribe requests be honored without delay, and at the latest within 10 business days. Failing to process the request is a direct violation of CASL.

  8. Question 8

    A journalist working for a national newspaper obtains personal information about a politician from a confidential source and includes it in a published article. The politician files a complaint with the Privacy Commissioner, alleging a violation of PIPEDA. What is the most likely outcome of this complaint?

    Answer and explanation

    Correct answer: B

    PIPEDA contains a specific exemption for personal information that is collected, used, or disclosed for journalistic, artistic, or literary purposes and for no other purpose. This exemption is intended to balance privacy rights with freedom of expression. Therefore, the complaint would likely be dismissed as the activity falls outside PIPEDA's jurisdiction.

  9. Question 9

    Case Study

    A national Canadian retail chain, 'MapleLeaf Mart,' headquartered in Ontario, operates stores across Canada, including in Alberta, British Columbia, and Quebec. The company wants to implement a new cloud-based Human Resources platform to manage employee data, including performance reviews, payroll information, and health benefits claims. The chosen vendor is based in the United States, and data will be processed and stored on servers in Virginia.

    The project team is aware of the cross-border data transfer but is unsure of the specific compliance steps required. The Chief Privacy Officer (CPO) has been tasked with creating a compliance plan. The primary goals are to ensure employee data is protected to a Canadian standard and to meet all legal obligations.

    Which of the following actions is the MOST critical first step for the CPO to take to ensure compliance under PIPEDA?

    Answer and explanation

    Correct answer: C

    Under PIPEDA's Accountability principle, when an organization transfers personal information to a third party for processing, it remains responsible for that information. The OPC's guidance explicitly states that the organization must use contractual or other means to provide a comparable level of protection. This includes safeguards, access rights, and limitations on use. This contract is the foundational element for ensuring compliance in a cross-border transfer scenario.

  10. Question 10

    The CSA Model Code for the Protection of Personal Information forms the basis of Schedule 1 of PIPEDA. Its principles were derived from a set of internationally recognized guidelines. What is the name of this original set of guidelines?

    Answer and explanation

    Correct answer: B

    The Canadian Standards Association (CSA) Model Code, which is the foundation of PIPEDA's privacy principles, was based on the 1980 Organisation for Economic Co-operation and Development (OECD) Guidelines. These guidelines established the foundational Fair Information Practice Principles (FIPPs) that are now common in privacy laws worldwide.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 207 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon