10 free IAPP CIPP/C practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 76 questions. Work through them, then open each answer to check your reasoning.
Get all 76 questions (US$39) · Download these 10 as a PDF
Question 1
In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing.
Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.
Which of the following requests would the patient be most successful at pursuing?
Show answer and explanation
Correct answer: B. That the information be restricted from disclosure to other health care providers.
other health care providers. Under Ontario's health privacy legislation, patients have the right to request restrictions on the disclosure of their health information to other parties, even if the diagnosis itself is accurate. The patient cannot compel deletion of accurate diagnostic information from the record, nor can she change a correct diagnosis based on her wishes after acknowledging the information was accurate. Restricting disclosure to other healthcare providers is a recognized patient right that balances privacy interests with the necessity of maintaining accurate medical records.
Why the other options are wrong
- A. A patient cannot force correction of accurate diagnostic information based solely on personal preference or regret.
- C. While patients may request copies of their records, this does not address the patient's primary concern about limiting access to this sensitive information.
- D. Accurate medical information cannot be deleted from health records; patients may only restrict access to it, not erase it.
Question 2
The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?
Show answer and explanation
Correct answer: B. The Bank of Canada.
The Government of Canada's Directive on Privacy Impact Assessments applies to federal government institutions and entities under federal jurisdiction. The Bank of Canada, while a Crown Corporation established by federal legislation, operates as an independent central bank and is not subject to the same Treasury Board directives that apply to government departments and most Crown Corporations engaged in government business. The Ministry of Health, Crown Corporations involved in government operations, and the Cabinet are all subject to the directive.
Why the other options are wrong
- A. The Ministry of Health, as a federal government department, is subject to the directive.
- C. Crown Corporations engaged in government business are subject to the Privacy Impact Assessment Directive.
- D. The Cabinet and its operations fall under federal government privacy directives.
Question 3
Which falls under the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA)?
Show answer and explanation
Correct answer: C. Personal information disclosed across provincial or national borders by organizations such as credit reporting agencies or list marketers.
national borders by organizations such as credit reporting agencies or list marketers. PIPEDA applies to personal information disclosed across provincial or national borders by organizations such as credit reporting agencies and list marketers engaged in commercial activities. This is a core application of PIPEDA's interprovincial and international scope. Options A and B are excluded from PIPEDA (journalistic purposes and provincial health information legislation respectively), and Option D relates to employee contact information in a professional context, which may fall outside PIPEDA depending on specific circumstances, but cross-border commercial data flows are clearly within PIPEDA's jurisdiction.
Why the other options are wrong
- A. Personal information collected for journalistic or artistic purposes is explicitly excluded from PIPEDA.
- B. Personal health information handled by private enterprises in provinces with substantially similar legislation is excluded under PIPEDA's provincial exemption.
- D. Employee contact information used for professional communications may not constitute personal information requiring PIPEDA protection in certain contexts.
Question 4
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), when engaging in a third-party transfer of personal information for processing, an organization is expected to have the technology to protect the information during transit and to?
Show answer and explanation
Correct answer: A. Establish a contract outlining the individual outsourcing arrangement.
outsourcing arrangement. Under PIPEDA, when an organization engages a third party to process personal information on its behalf, it must establish a written contract that outlines the arrangement, including security obligations and permissible uses. This contractual requirement is a fundamental principle of PIPEDA that ensures accountability and defines the responsibilities of both parties. While technology protections are necessary, the contractual framework is the specific expectation for managing third-party relationships.
Why the other options are wrong
- B. Additional consent from the individual is not required if the third party is processing information on behalf of the organization under a proper contract.
- C. Organizations are not required to confirm that the third party's jurisdiction has identical protections to PIPEDA; the contract and organizational accountability are the governing standards.
- D. Cross-border data flows do not require Treasury Board approval under PIPEDA; the organization remains accountable for ensuring appropriate protections.
Question 5
According to the Privacy Act, which of the following disclosures of personal information by a government institution would require the data subject’s consent?
Show answer and explanation
Correct answer: C. When disclosing to a registered charitable organization.
organization. Under the Privacy Act, disclosure of personal information to a registered charitable organization typically requires the consent of the data subject, as this does not fall within the standard exemptions for law enforcement, legal compliance, or government operations. Disclosures to law enforcement bodies, pursuant to search warrants, and to Members of Parliament assisting constituents are all expressly permitted under the Privacy Act without consent, but charitable organizations do not have a statutory right to access government-held personal information without the individual's authorization.
Why the other options are wrong
- A. Disclosure to law enforcement bodies is permitted under Privacy Act exemptions without requiring consent.
- B. Compliance with a search warrant is a lawful basis for disclosure that does not require data subject consent.
- D. Disclosure to a Member of Parliament to assist in resolving a constituent's problem is permitted under the Privacy Act without consent.
Question 6
Under PIPEDA, each of the following are considered to be personal information EXCEPT?
Show answer and explanation
Correct answer: A. A public official’s salary published on a government web site.
web site. A public official's salary published on a government website is publicly available information that is not considered personal information under PIPEDA because it is already in the public domain and the individual cannot be reasonably identified in a manner that would trigger privacy protections. Information that is already publicly disclosed loses the characteristic of being personal information requiring protection. Telephone numbers in public directories, photographs in newspapers, and court records all relate to identifiable individuals or circumstances but retain some privacy consideration, whereas government salary information published officially is treated as public data.
Why the other options are wrong
- B. A person's telephone number published in a public directory is still considered personal information under PIPEDA.
- C. A photograph taken in public and published in a newspaper can still constitute personal information if it identifies an individual.
- D. Information about a defendant in court records is considered personal information despite its public nature.
Question 7
How would an individual determine whether their personal information was used by the federal government for data matching?
Show answer and explanation
Correct answer: B. By noting the description of the Personal Information Banks available through Info Source.
Banks available through Info Source. Individuals can determine whether their personal information was used by the federal government for data matching by reviewing the descriptions of Personal Information Banks available through Info Source, which is the Government of Canada's official inventory of personal information holdings. Info Source provides detailed descriptions of the purposes for which personal information is collected and used, including data matching activities conducted by federal institutions. This is the mechanism established under the Privacy Act to provide transparency about government data practices.
Why the other options are wrong
- A. Individuals cannot effectively submit requests to third parties for this information; the federal government maintains records of its own data matching activities.
- C. Proposing a Privacy Impact Assessment is not the mechanism for determining past data matching; PIAs are forward-looking tools for new initiatives.
- D. While the Privacy Commissioner's annual report provides general information about privacy issues, Info Source is the specific tool for checking personal information bank descriptions.
Question 8
Which health information custodians may NOT rely on an implied consent model under Ontario's Personal Health Information Protection Act (PHIPA)?
Show answer and explanation
Correct answer: A. Private insurance companies.
Under Ontario's Personal Health Information Protection Act (PHIPA), private insurance companies cannot rely on an implied consent model; they must obtain explicit consent from individuals before collecting, using, or disclosing personal health information. Insurance companies are not healthcare providers and do not have the same relationship with patients that permits reliance on implied consent. Long-term care homes, ambulance services, and pharmacies, as health information custodians providing direct care or health services, may rely on implied consent in appropriate circumstances under PHIPA.
Why the other options are wrong
- B. Long-term care homes, as health information custodians providing care, may rely on implied consent under PHIPA.
- C. Ambulance services, as providers of emergency health services, may rely on implied consent under PHIPA.
- D. Pharmacies, as healthcare providers dispensing medications, may rely on implied consent under PHIPA.
Question 9
In what situation is the federal Privacy Commissioner authorized to proceed to federal court?
Show answer and explanation
Correct answer: B. For a determination of whether or not personal information was properly withheld from release.
information was properly withheld from release. The federal Privacy Commissioner is authorized to proceed to federal court for a determination of whether or not personal information was properly withheld from release. This reflects the Commissioner's jurisdiction under the Access to Information Act and Privacy Act to challenge decisions by federal institutions regarding disclosure of personal information. The other options describe situations outside the Commissioner's direct court jurisdiction, Charter matters fall to other judicial processes, administrative tribunal rulings have their own appeal mechanisms, and provincial commissioners operate under separate provincial legislation.
Why the other options are wrong
- A. Charter-related privacy determinations are not within the Privacy Commissioner's scope to take to federal court.
- C. Administrative tribunal rulings follow separate appellate processes and are not the Commissioner's direct court mandate.
- D. Provincial Privacy Commissioners operate independently under provincial law and are not subject to federal Commissioner court proceedings.
Question 10
What is the primary motivation for a federal government entity to complete a Privacy Impact Assessment (PIA)?
Show answer and explanation
Correct answer: B. Receiving program approvals from the Treasury Board of Canada.
Board of Canada. The primary motivation for a federal government entity to complete a Privacy Impact Assessment is receiving program approvals from the Treasury Board of Canada. PIAs are a mandatory requirement in the federal approval and governance process; Treasury Board directives require PIAs for new or modified programs and systems that handle personal information. While PIAs may inform other activities, the formal requirement and primary driver is Treasury Board approval and compliance with federal governance frameworks.
Why the other options are wrong
- A. While new legislation may benefit from privacy analysis, introducing legislation is not the primary motivation for conducting a PIA.
- C. Obtaining expertise from the Privacy Commissioner is not the primary motivation; the Commissioner is independent and reactive to complaints rather than proactively advising on PIAs.
- D. Improving IT collection methods is a potential outcome but not the primary motivation driving PIA completion.
That was 10 of 76.
The full IAPP CIPP/C pack has all 76 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
