To whom does the Privacy Commissioner of Canada report?
An Alberta resident has signed up for a health wellness "app" developed by a British Columbia based software provider that stores the data in British Columbia. The application has various non-healthcare related uses. The individual inputs their name and email address in the application to subscribe to health and wellness tips.
The collection and use of the individual’s name and email address by the British Columbia based scheduling app would fall under what legislation?
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must maintain a record of every breach of security safeguards involving personal information for a minimum of?
According to the federal Privacy Commissioner, what protection is missing from the Privacy Act regarding outsourcing of government work that contains personal information?
A boutique hotel in Montreal seeks to attract travelers from Europe but wants to avoid becoming subject to the GDPR’s requirements. Which of the following activities is most likely to result in a finding that the hotel is subject to the GDPR?
Under the Freedom of Information and Protection of Privacy Acts (FIPPA), personal information includes all of the following EXCEPT?
According to PIPEDA, all of the following data is considered sensitive: physical disability, ethnicity, sexual orientation and?
What is the Canadian Courts’ role in reviewing decisions by provincial oversight authorities?
What can be concluded from the Blood Tribe case regarding the Privacy Commissioner's access to information?
In which situation could a request for access to one’s personal information be denied under the Privacy Act?
According to the federal court ruling in the Eastman Case, video cameras in the workplace are considered to be collecting personal information?
Which organization was the primary influence in the development of Canadian privacy with their publication of a set of eight privacy principles?
ABC Corp uses a third-party provider to perform data analytics and sends the following data sets to the third party to run some reports: name, customer ID, age, transaction activity, transaction date, location, outcome, customer type.
If ABC Corp wants the third party to send all the data sets to their US based marketing partner for a new use, they must?
In comparing British Columbia’s privacy laws with the health information privacy acts of the remaining provinces, BC’s privacy laws?
According to the Canadian Standards Association (CSA) Model Code, how long should personal information be retained?
Which question is NOT part of the Office of the Privacy Commissioner of Canada’s (OPC’s) four-point test for establishing whether providing access to genetic testing results goes beyond what is necessary or reasonable?
In 2007, four employees of TELUS Communications Corporation filed a complaint with the Privacy Commissioner of Canada in connection with the collection of what personal information?
Which of the following incidents will require reporting to OPC?
In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.
Which of the following requests would the patient be most successful at pursuing?
The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?
A new client is opening a Registered Retirement Savings Plan. Their investment advisor asks for their social insurance number (SIN). The advisor must tell the client that because they are opening a tax reporting product, their SIN is mandatory for tax reporting purposes and?
In what situation is the federal Privacy Commissioner authorized to proceed to federal court?