Free CIPP-C Practice Test Questions and Answers (2026)

Last Update Check

View Mode
Q: 1
In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis. Which of the following requests would the patient be most successful at pursuing?
Options
25 comments in the community discussion
4
B. not D. Saw similar in practice questions for CIPP-C.
1
I don’t think the patient could get details actually deleted if the info is accurate, even if they regret sharing it. Isn’t restricting disclosure (B) more in line with Ontario privacy law rules? D seems like a common trap here.
Q: 2
The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?
Options
17 comments in the community discussion
C vs D? Seen similar in official guide, pretty sure the Cabinet (D) is exempt under the Directive. Practice questions line up with that too, but if anyone remembers a rule about Crown Corporations let me know.
C
Q: 3
Why is biometric information considered sensitive personal information in almost all circumstances?
Options
20 comments in the community discussion
5
Option C is the best fit. Biometric data stands out because it's unique and hard to change, so if compromised, you can't just reset it like a password. Option D sounds plausible but is actually less relevant here.
4
C . Biometrics are super sensitive because they're unique and permanent, so if your fingerprint or iris data gets leaked, you can't just reset it like a password. Makes sense regulators flag that as high risk. Anyone see an argument for B here?
Q: 4
Which act also includes references to the Privacy Act?
Options
19 comments in the community discussion
3
A. D looks tempting since it's privacy-related, but only A actually references the Privacy Act. Can double-check, but pretty sure that's right.
2
A . The Access to Information Act specifically cites the Privacy Act, which is why it stands out from the others. D is only about privacy in the private sector and doesn't directly mention the Privacy Act. Pretty sure that's what they want here, but open to challenge if I'm missing something.
Q: 5
A private organization called Vision 3072 must verify the information they are collecting is up to date in order to avoid misinformed actions or decisions. Which privacy principle is intended to make sure this verification is happening?
Options
18 comments in the community discussion
1
B
1
B fits best because the accuracy principle directly covers keeping data up to date and correct, which is exactly what the question asks for. Integrity, on the other hand, is more about protecting against unauthorized changes, not validating if the info is current. I think B is right but let me know if anyone sees it di
Q: 6
Of the key principles in the Personal Information Protection and Electronic Documents Act (PIPEDA), which principle in particular contributes to the increase in privacy policies in recent years?
Options
29 comments in the community discussion
3
Option C here, since Openness leads to more published policies. That's what the question is after imo. Agree?
2
Had something like this in a mock, pretty sure it's about C (Openness) since that principle requires organizations to make their privacy practices public. That's what leads to all the extra policies popping up recently. Anyone disagree?
Q: 7
A federally regulated company based in Ontario has customers in Ontario, Quebec, New Brunswick, Alberta and British Columbi a. Unfortunately, a third-party vendor that provides marketing support to the company experiences a privacy breach which impacts the personal information of all its customers across the provinces where it operates. The Privacy Officer determines that the breach causes a real risk of significant harm to their customers and is tasked with reporting the breach to the relevant regulators. With which provincial privacy regulators does the company have to file a report?
Options
24 comments in the community discussion
2
A imo
1
A not B
Q: 8
What is required of a private sector organization that is subject to a finding by a Canadian federal or
Options
22 comments in the community discussion
1
Not C, it's A. Only Quebec's authority issues binding decisions for private sector orgs, none of the others do.
1
A is right, not B. Quebec's privacy authority actually issues binding decisions for private sector orgs, so they have to comply-it's not just a suggestion like with the federal Privacy Commissioner. Pretty sure that's unique to Quebec under their law. If anyone disagrees let me know, but that's how I've always under
Q: 9

A private sector daycare’s portal for parents stores their children’s photos, allergy information date of birth. A parent has asked about the portal’s security requirements and in three months still not has received an answer. What is missing from the daycare’s procedures?

Options
26 comments in the community discussion
6
Yeah that's a clear miss on responding within 30 days.
5
B, since the 30 day response window is a hard PIPEDA rule here.
Q: 10
An Alberta resident has signed up for a health wellness "app" developed by a British Columbia based software provider that stores the data in British Columbi a. The application has various non-healthcare related uses. The individual inputs their name and email address in the application to subscribe to health and wellness tips. The collection and use of the individual’s name and email address by the British Columbia based scheduling app would fall under what legislation?
Options
20 comments in the community discussion
2
Maybe D. Since the app is commercial and collects personal info from someone in Alberta but the company is in BC, that's interprovincial so PIPEDA usually covers it. Doesn't sound like health info under HIA, and it's not a public body (so not FOIP). Not 100% sure since apps can get tricky, anyone see it another way?
1
D , FOIP and HIA are red herrings, B only if entirely local and not interprovincial, but here PIPEDA applies.
Q: 11
Which of the following existing frameworks is least effective in addressing emerging AI issues while specific AI legislation is being decided?
Options
18 comments in the community discussion
3
Option B. The Motor Vehicle Safety Act is just too limited since it focuses on car safety, doesn't really touch general AI concerns at all. Other options still have broader impacts on digital or IP issues, so B makes sense here imo.
2
Option B
Q: 12
The process of de-identification where new data elements are substituted for identifying information is?
Options
22 comments in the community discussion
4
D . Substituting identifiers matches pseudonymization since you could undo it with the original mapping. If the process was truly irreversible, C would be right instead. Saw this twist in some practice sets.
D that's pseudonymization. Since it's just substitution and not full anonymization, pretty sure that's what IAPP wants here.
Q: 13

According to the federal court ruling in the Eastman Case, video cameras in the workplace are considered to be collecting personal information?

Options
19 comments in the community discussion
1
A
1
A
Q: 14
In which situation could a request for access to one’s personal information be denied under the Privacy Act?
Options
20 comments in the community discussion
7
Option C makes sense here, but not totally sure. I think injury to a protected species is a valid ground for refusal under the Privacy Act, at least from what I remember in study notes. Other options don't really fit. Does anyone have the section ref?
1
C or A. I was leaning toward A since the RCMP's collection on behalf of a province or municipality might be exempt, but C talks about injury to protected wildlife which seems more directly aligned with Privacy Act exemptions. Not 100% sure though, maybe missing something in the RCMP clause?
Q: 15
In which circumstance do private sector privacy laws permit collection of information without consent?
Options
20 comments in the community discussion
1
A imo. Private sector laws like PIPEDA allow collection without consent if it's urgent and clearly in the individual's benefit, so 'timely consent cannot be obtained' fits. The other choices don't have the same legal basis, I think.
1
Its A
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top