
[Jul-2024] 100% Guarantee Download CIPP-C Exam Dumps PDF Q&A
Kickstart your Career with Real Updated Questions
NEW QUESTION # 13
The U.S. Supreme Court has recognized an individual's right to privacy over personal issues, such as contraception, by acknowledging which of the following?
- A. The doctrine of stare decisis, which allows the U.S. Supreme Court to follow the precedent of previously decided case law.
- B. Federal preemption of state constitutions that expressly recognize an individual right to privacy.
- C. An interpretation of the U.S. Constitution's explicit definition of privacy that extends to personal issues.
- D. A "penumbra" of unenumerated constitutional rights as well as more general protections of due process of law.
Answer: D
NEW QUESTION # 14
What is required through the "circle of care" concept under Canadian health information privacy law?
- A. An individual's consent may be implied unless the individual has refused consent or if the purpose of the disclosure is not to provide health care.
- B. Health information custodians or trustees be specified only by applicable law or regulation
- C. Consent must be expressed or implied when a custodian discloses personal health information (PHI) to another custodian for the purpose of providing health care.
- D. Notification to the individual be made in the event of a data breach of personal health information (PHI) by an organization that is based in Canada
Answer: C
Explanation:
The "circle of care" concept under Canadian health information privacy law refers to the ability of health information custodians to assume implied consent when disclosing personal health information (PHI) to other health information custodians for the purpose of providing health care. This concept allows for the seamless sharing of PHI among providers like doctors, nurses, and pharmacists, who are directly involved in the care of the individual, without requiring express consent for each exchange of information within this circle. The principle is based on the assumption that the disclosure is made in the patient's best interests for their ongoing care. Therefore, the correct answer is D, "Consent must be expressed or implied when a custodian discloses personal health information (PHI) to another custodian for the purpose of providing health care."
NEW QUESTION # 15
Which federal law or regulation preempts state law?
- A. Controlling the Assault of Non-Solicited Pornography and Marketing Act
- B. Electronic Communications Privacy Act of 1986
- C. Telemarketing Sales Rule
- D. Health Insurance Portability and Accountability Act
Answer: D
NEW QUESTION # 16
What are banks required to do under the Gramm-Leach-Bliley Act (GLBA)?
- A. Provide consumers with the opportunity to opt out of receiving telemarketing phone calls
- B. Offer an Opt-Out before transferring PI to an unaffiliated third party for the latter's own use
- C. Conduct annual consumer surveys regarding satisfaction with user preferences
- D. Process requests for changes to user preferences within a designated time frame
Answer: B
NEW QUESTION # 17
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to do what?
- A. Appeal decisions made against it
- B. Adhere to its industry's code of conduct
- C. Decide if any enforcement actions are justified
- D. Determine which bodies will be involved in adjudication
Answer: D
NEW QUESTION # 18
Under state breach notification laws, which is NOT typically included in the definition of personal information?
- A. State identification number
- B. Medical Information
- C. First and last name
- D. Social Security number
Answer: B
NEW QUESTION # 19
A private organization called Vision 3072 must verify the information they are collecting is up to date in order to avoid misinformed actions or decisions. Which privacy principle is intended to make sure this verification is happening?
- A. Integrity.
- B. Accuracy.
- C. Accountability.
- D. Limiting purposes.
Answer: B
NEW QUESTION # 20
More than half of U.S. states require telemarketers to?
- A. Obtain written consent from potential customers
- B. Register with the state before conducting business
- C. Provide written contracts for customer transactions
- D. identify themselves at the beginning of a call
Answer: C
NEW QUESTION # 21
A federally regulated company based in Ontario has customers in Ontario, Quebec, New Brunswick, Alberta and British Columbia. Unfortunately, a third-party vendor that provides marketing support to the company experiences a privacy breach which impacts the personal information of all its customers across the provinces where it operates.
The Privacy Officer determines that the breach causes a real risk of significant harm to their customers and is tasked with reporting the breach to the relevant regulators.
With which provincial privacy regulators does the company have to file a report?
- A. Quebec and Alberta only
- B. It is unnecessary to file a report with any provinces because the company is federally regulated
- C. New Brunswick and British Columbia only
- D. All of the provinces where its customers are located
Answer: B
NEW QUESTION # 22
What term BEST describes the European model for data protection?
- A. Sectoral
- B. Market-based
- C. Comprehensive
- D. Self-regulatory
Answer: A
NEW QUESTION # 23
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?
- A. If obtaining consent is deemed voluntary by local legislation.
- B. If the company's status as a documentary provider allows it to claim legitimate interest.
- C. If obtaining consent is deemed to involve disproportionate effort.
- D. If the company limits the footage to data subjects solely of legal age.
Answer: A
NEW QUESTION # 24
All of the following common law torts are relevant to employee privacy under US law EXCEPT?
- A. Defamation
- B. Infliction of emotional distress.
- C. Conversion.
- D. Intrusion upon seclusion.
Answer: D
NEW QUESTION # 25
Under the Privacy Act, when government institutions collect personal information?
- A. The collection must relate to an operating program or activity.
- B. Data subject consent is required.
- C. The collection must be directly from a data subject.
- D. Information collected must be made anonymous where technologically possible
Answer: A
Explanation:
Under the Privacy Act, which governs the handling of personal information by federal government institutions in Canada, there is a stipulation that the collection of personal information must relate directly to an operating program or activity of the government institution. This requirement ensures that any personal data collected is directly relevant and necessary for a legitimate governmental function or service, thus preventing the unnecessary collection of personal information. This principle is meant to limit government institutions to collecting only that information which is strictly necessary for carrying out their legally authorized functions, aligning with privacy protection objectives. Option C accurately represents this requirement.
NEW QUESTION # 26
Under the Data Protection Law Enforcement Directive of the EU, a government can carry out covert investigations involving personal data, as long it is set forth by law and constitutes a measure that is both necessary and what?
- A. DPA-approved.
- B. Prudent.
- C. Proportionate.
- D. Important.
Answer: C
NEW QUESTION # 27
Which health information custodians may NOT rely on an implied consent model under Ontario's Personal Health Information Protection Act (PHIPA)?
- A. Ambulance services.
- B. Private insurance companies.
- C. Long-term care homes.
- D. Pharmacies
Answer: B
Explanation:
Under Ontario's Personal Health Information Protection Act (PHIPA), health information custodians may rely on implied consent in situations where the information is used for the provision of healthcare unless the patient explicitly opts out. However, private insurance companies do not directly provide healthcare and typically require explicit consent to collect, use, or disclose health information. This is because their primary role involves assessing insurance claims and risk, rather than delivering healthcare services. Long-term care homes, ambulance services, and pharmacies, on the other hand, are directly involved in the provision of care and can typically operate under an implied consent model when sharing information for healthcare purposes.
NEW QUESTION # 28
Safeguarding and securing information that is considered sensitive under privacy legislation generally falls into three categories: Administrative, Technical and?
- A. Physical.
- B. Logistical.
- C. Personal.
- D. Legal.
Answer: A
NEW QUESTION # 29
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What would MOST effectively assist Zandelay in conducting their data protection impact assessment?
- A. Information about DPIAs found in Articles 38 through 40 of the GDPR.
- B. Existing DPIA guides published by local supervisory authorities.
- C. Records of processing activities that data controllers are required to maintain.
- D. Data breach documentation that data controllers are required to maintain.
Answer: A
NEW QUESTION # 30
Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?
- A. The entity must be registered in the state
- B. The entity must conduct business in the state
- C. The entity must have employees in the state
- D. The entity must be an information broker
Answer: B
NEW QUESTION # 31
According to the GDPR, what is the main task of a Data Protection Officer (DPO)?
- A. To create procedures for notification of personal data breaches to competent supervisory authorities.
- B. To create and maintain records of processing activities.
- C. To monitor compliance with other local or European data protection provisions.
- D. To conduct Privacy Impact Assessments on behalf of the controller or processor.
Answer: D
NEW QUESTION # 32
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- A. A bill of rights for individuals seeking access to their personal information.
- B. An international court ruling on personal information held in the commercial sector.
- C. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
- D. A code of responsibilities for medical establishments to uphold privacy laws.
Answer: A
NEW QUESTION # 33
Which of the following existing frameworks is least effective in addressing emerging AI issues while specific AI legislation is being decided?
- A. The Canada Consumer Product Safety Act.
- B. The Motor Vehicle Safety Act.
- C. The Criminal Code.
- D. The Copyright Act.
Answer: B
Explanation:
In addressing emerging AI issues, frameworks that are specific to product safety, copyright, or criminal behavior may provide some indirect governance, but their applicability is limited compared to more direct regulatory mechanisms. Among the options listed, the Motor Vehicle Safety Act is the least effective in addressing AI issues as this act is specifically targeted towards the safety regulations of motor vehicles and is less applicable to broader AI issues that may involve data privacy, ethical considerations, and other non-vehicle-specific technologies. Therefore, while AI can be involved in vehicle safety, this act is less equipped to broadly address emerging AI issues beyond automotive safety standards. Hence, the correct answer is B, "The Motor Vehicle Safety Act."
NEW QUESTION # 34
......
Earn Quick And Easy Success With CIPP-C Dumps: https://www.pass4suresvce.com/CIPP-C-pass4sure-vce-dumps.html
Top-Class CIPP-C Question Answers Study Guide: https://drive.google.com/open?id=1TVlWXjRv3Dw5Yfa3vVc93Gn0eJYGUydf