IAPP CIPP-C Exam
Certified Information Privacy Professional/ Canada (CIPP/C) (Page 5 )

Updated On: 30-Jan-2026

Which law provides employee benefits, but often mandates the collection of medical information?

  1. The Occupational Safety and Health Act.
  2. The Americans with Disabilities Act.
  3. The Employee Medical Security Act.
  4. The Family and Medical Leave Act.

Answer(s): B


Reference:

https://www.dph.illinois.gov/covid19/community-guidance/workplace-health-and-safety-guidance/employee-employer-rights-and-safety



If an organization maintains data classified as high sensitivity in the same system as data classified as low sensitivity, which of the following is the most likely outcome?

  1. The organization will still be in compliance with most sector-specific privacy and security laws.
  2. The impact of an organizational data breach will be more severe than if the data had been segregated.
  3. Temporary employees will be able to find the data necessary to fulfill their responsibilities.
  4. The organization will be able to address legal discovery requests efficiently without producing more information than necessary.

Answer(s): D



Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?

  1. Implied consent from a minor’s parent or guardian, or affirmative consent from the minor.
  2. Affirmative consent from a minor’s parent or guardian before collecting the minor’s personal information online.
  3. Implied consent from a minor’s parent or guardian before collecting a minor’s personal information online, such as when they permit the minor to use the internet.
  4. Affirmative consent of a parent or guardian before collecting personal information of a minor offline (e.g., in person), which also satisfies any requirements for online consent.

Answer(s): B


Reference:

https://www.ftc.gov/tips-advice/business-center/guidance/complying-coppa-frequently- asked- Questions-0



What is the most important action an organization can take to comply with the FTC position on retroactive changes to a privacy policy?

  1. Describing the policy changes on its website.
  2. Obtaining affirmative consent from its customers.
  3. Publicizing the policy changes through social media.
  4. Reassuring customers of the security of their information.

Answer(s): B


Reference:

https://iapp.org/news/a/what-does-the-ccpas-purpose-limitation-mean-for-businesses/



What role does the U.S. Constitution play in the area of workplace privacy?

  1. It provides enforcement resources to large employers, but not to small businesses
  2. It provides legal precedent for physical information security, but not for electronic security
  3. It provides contractual protections to members of labor unions, but not to employees at will
  4. It provides significant protections to federal and state governments, but not to private-sector employment

Answer(s): B



Viewing page 5 of 31
Viewing questions 21 - 25 out of 150 questions



Post your Comments and Discuss IAPP CIPP-C exam prep with other Community members:

Join the CIPP-C Discussion