1. Home
  2. IAPP
  3. CIPP/C Exam

CIPP/C Exam Topics and Questions

Let's Practice Free IAPP CIPP/C Questions Aligned with Official Exam Topics

Follows IAPP's official outline Updated 11 Sep, 2026 4 Topics
Reviewed by James Wilson, IAPP CIPP-C Certified Professional
Topic Content

This topic establishes the constitutional and conceptual ground on which everything else stands. You need to know how federalism splits privacy authority between Ottawa and the provinces, where the modern privacy framework came from, and when international rules bind Canadian organizations. The cost comes when a scenario crosses jurisdictional lines or when you must choose between competing principles without a clear statutory answer. – Constitutional structure and jurisdiction Canada's federal structure determines which privacy law applies to a given situation....

See More

The question below tests whether you can identify the correct jurisdictional basis for a privacy obligation when an organization operates across multiple legal frameworks.

Sample Questions for Topic 1 : Introduction to Privacy in Canada
Q1

What must an organization do to fulfill the Personal Information Protection and Electronic Documents Act's (PIPEDA) transparency requirements when transferring personal information to a foreign country?

Topic Content

Private-sector privacy turns on PIPEDA and its provincial equivalents, and the exam will test whether you know when one applies instead of the other. You also need to understand CASL, which sits alongside privacy law but serves a different purpose. The challenge is recognizing that substantially similar provincial legislation displaces PIPEDA, and that commercial electronic messages have their own consent regime. Misreading the scope of either statute costs marks. – PIPEDA principles and their application PIPEDA embeds ten fair information...

See More

The question that follows asks you to determine which consent standard applies when an organization uses customer data for a purpose not disclosed at the time of collection.

Sample Questions for Topic 2 : Canadian Privacy Laws and Practices: Private Sector
Q2

What must a federal government department do before it implements an electronic service (e-service)?

Topic Content

Public-sector privacy law governs how federal and provincial government institutions handle personal information. The Privacy Act applies to federal institutions, while each province and territory has its own freedom of information and protection of privacy legislation. Privacy impact assessments are a procedural tool, and the exam expects you to know when they are required and what they must contain. The difficulty lies in distinguishing between access rights and privacy protections, and in recognizing when a provincial FIPPA applies instead of...

See More

The question below turns on whether a federal institution may disclose personal information under one of the statutory exceptions, and whether the proposed use meets the consistency test.

Topic Content

Health privacy is governed by sector-specific legislation in most provinces and territories, and the exam expects you to know when those statutes apply instead of PIPEDA or a general FIPPA. The challenge is recognizing that health information is defined broadly, that custodians have distinct obligations, and that consent rules differ from those in other sectors. The statutes were written to accommodate the reality of clinical care, where information must move quickly among providers, and the exam tests whether you understand...

See More

The question that follows asks you to identify the correct legal authority for a health information custodian's disclosure and whether the proposed sharing falls within the permitted purposes.

Ready to Start Practicing?

Access all questions and start your exam preparation journey

Upgrade to Full CIPP/C Exam Questions πŸš€
Exams Made Simple. Success Made Possible.