What is critical to consider when an organization responsible for a large number of records wants to outsource the storage of those records?
As response to TJX Winners - Homesense, why is "hashing" preferable to storing a personal identifier such as a driver’s license number?
Which health information custodians may NOT rely on an implied consent model under Ontario's Personal Health Information Protection Act (PHIPA)?
The Government of Canada’s Directive on Privacy Impact Assessments applies to all of the following EXCEPT?
The movement toward comprehensive privacy and data protection laws can be attributed to a combination of three major factors: the need to remedy past injustices, the need to promote a digital economy and the need to ensure consistency with?
After an investigation under the Privacy Act, the Privacy Commissioner could do any of the following EXCEPT?
In Ontario, a patient attends an appointment with a physician and reveals information about some new symptoms that she has been experiencing. Based on this information, the physician diagnoses the patient with a condition and prepares the report detailing the applicable history and diagnosis. The report is added to the patient’s record. The patient later regrets revealing certain facts and doesn’t want anyone else to know about these symptoms or the diagnosis. She acknowledges that the information she provided was correct and does not question the diagnosis.
Which of the following requests would the patient be most successful at pursuing?
In comparing British Columbia’s privacy laws with the health information privacy acts of the remaining provinces, BC’s privacy laws?
What is the primary motivation for a federal government entity to complete a Privacy Impact Assessment (PIA)?
According to the Alberta Personal Information Protection Act, which of the following data breach reporting notifications to the commissioner is NOT automatically triggered when real risk of significant harm (RROSH) has been determined?
Work-product information is generally thought of as information about an individual that?
Which of the following existing frameworks is least effective in addressing emerging AI issues while specific AI legislation is being decided?
In what situation is the federal Privacy Commissioner authorized to proceed to federal court?
Which of the following provincial health acts is NOT considered substantially similar to the Personal Information Protection and Electronic Documents Act (PIPEDA)?
A private sector daycare’s portal for parents stores their children’s photos, allergy information and date of birth. A parent has asked about the portal’s security requirements and in three months still not has received an answer. What is missing from the daycare’s procedures?
ABC Corp uses a third-party provider to perform data analytics and sends the following data sets to the third party to run some reports: name, customer ID, age, transaction activity, transaction date, location, outcome, customer type.
If ABC Corp wants the third party to send all the data sets to their US based marketing partner for a new use, they must?
What must an organization do to fulfill the Personal Information Protection and Electronic Documents Act’s (PIPEDA) transparency requirements when transferring personal information to a foreign country?