CIPP-C Exam Details

  • Exam Code
    :CIPP-C
  • Exam Name
    :Certified Information Privacy Professional/ Canada (CIPP/C)
  • Certification
    :IAPP Certifications
  • Vendor
    :IAPP
  • Total Questions
    :226 Q&As
  • Last Updated
    :Jan 11, 2026

IAPP CIPP-C Online Questions & Answers

  • Question 1:

    Which of the following laws is NOT involved in the regulation of employee background checks?

    A. The Civil Rights Act.
    B. The Gramm-Leach-Bliley Act (GLBA).
    C. The U.S. Fair Credit Reporting Act (FCRA).
    D. The California Investigative Consumer Reporting Agencies Act (ICRAA).

  • Question 2:

    SCENARIO

    Please use the following to answer the next QUESTION:

    A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.

    The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if

    the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company."

    This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.

    As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.

    Under the GDPR, the complainant's request regarding her personal information is known as what?

    A. Right of Access
    B. Right of Removal
    C. Right of Rectification
    D. Right to Be Forgotten

  • Question 3:

    Which of the following would NOT constitute an exception to the authorization requirement under the HIPAA Privacy Rule?

    A. Disclosing health information for public health activities.
    B. Disclosing health information to file a child abuse report.
    C. Disclosing health information needed to treat a medical emergency.
    D. Disclosing health information needed to pay a third party billing administrator.

  • Question 4:

    In what way is the Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act intended to help consumers?

    A. By providing consumers with free spam-filtering software.
    B. By requiring a company to receive an opt-in before sending any advertising e-mails.
    C. By prohibiting companies from sending objectionable content through unsolicited e-mails.
    D. By requiring companies to allow consumers to opt-out of future e-mails.

  • Question 5:

    Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?

    A. Delete their personal information.
    B. Correct their personal information.
    C. Disclose their personal information to them.
    D. Refrain from selling their personal information to third parties.

  • Question 6:

    Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?

    A. Announcing the tracking of online behavior for advertising purposes.
    B. Integrating privacy protections during product development.
    C. Allowing consumers to opt in before collecting any data.
    D. Mitigating harm to consumers after a security breach.

  • Question 7:

    Which of the following is an example of federal preemption?

    A. The Payment Card Industry's (PCI) ability to self-regulate and enforce data security standards for payment card data.
    B. The U.S. Federal Trade Commission's (FTC) ability to enforce against unfair and deceptive trade practices across sectors and industries.
    C. The California Consumer Privacy Act (CCPA) regulating businesses that have no physical brick-and-mortal presence in California, but which do business there.
    D. The U.S. Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act prohibiting states from passing laws that impose greater obligations on senders of email marketing.

  • Question 8:

    The Cable Communications Policy Act of 1984 requires which activity?

    A. Delivery of an annual notice detailing how subscriber information is to be used
    B. Destruction of personal information a maximum of six months after it is no longer needed
    C. Notice to subscribers of any investigation involving unauthorized reception of cable services
    D. Obtaining subscriber consent for disseminating any personal information necessary to render cable services

  • Question 9:

    Read this notice:

    Our website uses cookies. Cookies allow us to identify the computer or device you're using to access the site, but they don't identify you personally. For instructions on setting your Web browser to refuse cookies, click here.

    What type of legal choice does not notice provide?

    A. Mandatory
    B. Implied consent
    C. Opt-in
    D. Opt-out

  • Question 10:

    What was the original purpose of the Federal Trade Commission Act?

    A. To ensure privacy rights of U.S. citizens
    B. To protect consumers
    C. To enforce antitrust laws
    D. To negotiate consent decrees with companies violating personal privacy

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only IAPP exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CIPP-C exam preparations and IAPP certification application, do not hesitate to visit our Vcedump.com to find your solutions here.