Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must maintain a record of every breach of security safeguards involving personal information for a minimum of?

A.

3 months.

B.

12 months.

C.

24 months.

D.

36 months

Which organization was the primary influence in the development of Canadian privacy with their publication of a set of eight privacy principles?

A.

The Organization for Economic Co-operation and Development (OECD).

B.

The Canadian Institute of Chartered Accountants

C.

The Center for Democracy and Technology (CRT)

D.

The Canadian Standards Association (CSA).

Which falls under the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA)?

A.

Personal information collected by private businesses for journalistic or artistic purposes.

B.

Personal health information (PHI) handled by private enterprises in provinces that have adopted substantially similar legislation.

C.

Personal information disclosed across provincial or national borders by organizations such as credit reporting agencies or list marketers.

D.

Personal information such as names, titles and contact information used by businesses to communicate with employees regarding their profession.

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), when engaging in a third-party transfer of personal information for processing, an organization is expected to have the technology to protect the information during transit and to?

A.

Establish a contract outlining the individual outsourcing arrangement.

B.

Obtain additional consent for the use of the information by the third party.

C.

Confirm the jurisdictional protections of the receiving organization are the same as PIPEDA.

D.

Review the cross-border data flow competed and approved by the Treasury Board of Canada Secretariat.

Which of the following incidents will require reporting to OPC?

A.

A sales report with aggregated information that was sent to the wrong person internally.

B.

A file with client ID, sales amount and sales date that was sent to the wrong processors who cannot identify the clients.

C.

An organization’s point-of-sale system that was subject to an attempted hack that was blocked by the organization’s firewall.

D.

As part of a freedom of information request, a nursing home that released an e-mail with everybody’s e-mail address in the "to" section unredacted.

Which act also includes references to the Privacy Act?

A.

The Access to Information Act.

B.

The Children's Online Privacy Protection Act

C.

The Telecommunications Intercept and Access (TIA) Act.

D.

The Personal Information Protection and Electronic Documents Act

What is required of a private sector organization that is subject to a finding by a Canadian federal or

A.

In Québec, comply with the finding as a binding decision.

B.

Comply with findings of the Privacy Commissioner of Canada only.

C.

In all jurisdictions, adopt and apply the finding within 30 days of the published report.

D.

In Ontario only, apply for judicial review within a provincial court in order to accept or refute the finding.

Which province requires its government bodies to store and access personal information exclusively in Canada unless additional consent is obtained, or if outside storage is judged necessary?

A.

Nova Scotia

B.

Québec.

C.

Ontario.

D.

Alberta.

A private sector daycare’s portal for parents stores their children’s photos, allergy information and date of birth. A parent has asked about the portal’s security requirements and in three months still not has received an answer. What is missing from the daycare’s procedures?

A.

Ensuring transparency.

B.

Responding to the parent's request within 30 days.

C.

Ensuring strong encryption and security measures.

D.

Completing a real risk of significant harm assessment (RROSH).

What must an organization do to fulfill the Personal Information Protection and Electronic Documents Act’s (PIPEDA) transparency requirements when transferring personal information to a foreign country?

A.

Inform customers if data is to be transferred outside of Canada and solicit additional consent.

B.

Give individuals with an existing business relationship the right to refuse transfer of their information.

C.

Advise customers that their data may be accessed by another jurisdiction's courts or law enforcement.

D.

Provide new customers with a measure-by-measure comparison of relevant foreign laws with Canadian laws.