Which health information custodians may NOT rely on an implied consent model under Ontario's Personal Health Information Protection Act (PHIPA)?
After an investigation under the Privacy Act, the Privacy Commissioner could do any of the following EXCEPT?
According to the federal Privacy Act, before collecting personal information, public-sector organizations are required to ensure that any of the following are met EXCEPT?
In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.
Which of the following requests would the patient be most successful at pursuing?
The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?
What is critical to consider when an organization responsible for a large number of records wants to outsource the storage of those records?
According to the Canadian Standards Association (CSA) Model Code, how long should personal information be retained?
Which of these employees would be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA)?
What is required of a private sector organization that is subject to a finding by a Canadian federal or
Safeguarding and securing information that is considered sensitive under privacy legislation generally falls into three categories: Administrative, Technical and?
In which instance is your personal information deemed publicly available?
What must an organization do to fulfill the Personal Information Protection and Electronic Documents Act’s (PIPEDA) transparency requirements when transferring personal information to a foreign country?
According to the Alberta Personal Information Protection Act, which of the following data breach reporting notifications to the commissioner is NOT automatically triggered when real risk of significant harm (RROSH) has been determined?
Which of the following provincial health acts is NOT considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?
A federally regulated company based in Ontario has customers in Ontario, Quebec, New Brunswick, Alberta and British Columbia. Unfortunately, a third-party vendor that provides marketing support to the company experiences a privacy breach which impacts the personal information of all its customers across the provinces where it operates.
The Privacy Officer determines that the breach causes a real risk of significant harm to their customers and is tasked with reporting the breach to the relevant regulators.
With which provincial privacy regulators does the company have to file a report?
To whom does the Privacy Commissioner of Canada report?
In what situation is the federal Privacy Commissioner authorized to proceed to federal court?
What is required for a provincial law to be considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?
Which is NOT a Canadian Standards Association (CSA) Privacy Principle?
Of the key principles in the Personal Information Protection and Electronic Documents Act (PIPEDA), which principle in particular contributes to the increase in privacy policies in recent years?
According to the Privacy Act, which of the following disclosures of personal information by a government institution would require the data subject’s consent?
The movement toward comprehensive privacy and data protection laws can be attributed to a combination of three major factors: the need to remedy past injustices, the need to promote a digital economy and the need to ensure consistency with?