CIPP/C Exam Topics and Questions
These IAPP CIPP/C exam topics are organized according to official exam domains to help candidates quickly verify coverage and focus on assessment rather than theory. Each domain is paired with topic-wise CIPP/C sample questions that reflect how objectives are tested in the actual exam. This structure enables efficient review, targeted self-assessment, and rapid identification of weak areas when preparing for the IAPP Certified Information Privacy Professional/ Canada certification exam.
Let's Practice Free IAPP CIPP/C Questions Aligned with Official Exam Topics
This topic establishes the constitutional and conceptual ground on which everything else stands. You need to know how federalism splits privacy authority between Ottawa and the provinces, where the modern privacy framework came from, and when international rules bind Canadian organizations. The cost comes when a scenario crosses jurisdictional lines or when you must choose between competing principles without a clear statutory answer. β Constitutional structure and jurisdiction Canada's federal structure determines which privacy law applies to a given situation....
This topic establishes the constitutional and conceptual ground on which everything else stands. You need to know how federalism splits privacy authority between Ottawa and the provinces, where the modern privacy framework came from, and when international rules bind Canadian organizations. The cost comes when a scenario crosses jurisdictional lines or when you must choose between competing principles without a clear statutory answer.
β Constitutional structure and jurisdiction
Canada's federal structure determines which privacy law applies to a given situation. You need to recognize when federal legislation governs and when a province has occupied the field. The division of powers means that federally regulated industries follow one set of rules while provincially regulated sectors may follow another, and the interplay matters when an organization operates in multiple provinces or when data crosses borders. Questions will test whether you can identify the correct legislative regime based on the nature of the organization and the activity in question. The exam assumes you understand that privacy is not a single national regime but a patchwork shaped by constitutional authority.
β Privacy principles and their evolution
The principles that underpin Canadian privacy law trace back to internationally recognized frameworks, and the exam expects you to know how those principles were adapted and codified. You should understand the role of fair information practices, the influence of OECD guidelines, and the way consent, accountability, and transparency became statutory requirements. The development is not just history: it explains why certain obligations exist and how courts and regulators interpret them. When a question asks you to apply a principle to a novel fact pattern, your answer depends on recognizing which foundational concept is in play. The evolution also matters when you assess whether a new technology or business model fits within existing rules or demands a fresh interpretation.
How Introduction to Privacy in Canada is tested
Items from this topic ask you to identify the correct legal regime for a given scenario or to apply a privacy principle to a fact pattern that straddles jurisdictions. The trap is assuming that one law covers all situations or that principles are interchangeable. You lose marks when you default to federal law without checking whether the organization is provincially regulated, or when you apply an international standard without confirming its relevance in Canada. The exam also tests your ability to distinguish between a principle that is legally binding and one that is merely aspirational. Scenarios may present cross-border data flows or multi-provincial operations, and the correct answer turns on knowing which authority has primacy. Candidates who treat this topic as background reading rather than applied jurisdiction analysis will struggle when the facts demand precision.
The practice test includes scenarios that require you to choose between federal and provincial regimes, and the volume of items lets you see the pattern of how jurisdiction questions are constructed. The PDF demo shows you the style before you commit, and working through the full bank under timed conditions helps you develop the speed needed to parse complex fact patterns on exam day.
The question below tests whether you can identify the correct jurisdictional basis for a privacy obligation when an organization operates across multiple legal frameworks.
What must an organization do to fulfill the Personal Information Protection and Electronic Documents Act's (PIPEDA) transparency requirements when transferring personal information to a foreign country?
Private-sector privacy turns on PIPEDA and its provincial equivalents, and the exam will test whether you know when one applies instead of the other. You also need to understand CASL, which sits alongside privacy law but serves a different purpose. The challenge is recognizing that substantially similar provincial legislation displaces PIPEDA, and that commercial electronic messages have their own consent regime. Misreading the scope of either statute costs marks. β PIPEDA principles and their application PIPEDA embeds ten fair information...
Private-sector privacy turns on PIPEDA and its provincial equivalents, and the exam will test whether you know when one applies instead of the other. You also need to understand CASL, which sits alongside privacy law but serves a different purpose. The challenge is recognizing that substantially similar provincial legislation displaces PIPEDA, and that commercial electronic messages have their own consent regime. Misreading the scope of either statute costs marks.
β PIPEDA principles and their application
PIPEDA embeds ten fair information principles, and the exam expects you to apply them to workplace scenarios, customer data handling, and third-party disclosures. Consent is central, but the statute recognizes exceptions, and you must know when implied consent suffices and when express consent is mandatory. Accountability means the organization remains responsible even when it outsources processing, and that principle is tested through vendor management scenarios. The purposes for which data is collected must be identified before or at the time of collection, and using information for a new purpose without fresh consent is a common trap. Openness requires that privacy policies be meaningful, and the exam will ask you to spot deficiencies in notice language or accessibility. Safeguards are not optional, and you need to recognize when security measures fall short of what a reasonable person would expect given the sensitivity of the data.
β Provincial private-sector laws and PIPEDA displacement
Alberta, British Columbia, and Quebec have enacted private-sector privacy laws that the federal government has declared substantially similar to PIPEDA. When one of those laws applies, PIPEDA does not. The exam tests whether you can determine which law governs based on the location of the organization, the nature of its business, and the type of data involved. Quebec's law is the most distinct, with broader territorial scope and stricter consent requirements, and questions will probe whether you know when it applies to out-of-province organizations. You also need to understand that substantially similar status is not automatic and that the federal government can withdraw recognition if a province amends its law in a way that weakens protection.
β CASL and commercial electronic messages
CASL regulates commercial electronic messages, not personal information as such, but it overlaps with privacy law because sending a message often requires collecting contact details. The exam expects you to know when express consent is required, when implied consent is available, and how long each type lasts. The definition of a commercial electronic message is broader than most candidates assume, and the law applies even when the message is not purely promotional. Existing business relationships create implied consent, but only for a limited time, and you need to recognize when that relationship has lapsed. Unsubscribe mechanisms must be functional and conspicuous, and the exam will test whether you can spot non-compliant designs. CASL also has private right of action provisions, and understanding the enforcement landscape helps you assess risk in scenario-based questions.
How Canadian Privacy Laws and Practices: Private Sector is tested
Questions in this area present fact patterns involving customer data, marketing campaigns, vendor relationships, or cross-provincial operations, and ask you to identify which law applies or which principle is breached. The most common mistake is assuming PIPEDA applies everywhere or that consent is always required. The exam will give you scenarios where implied consent is sufficient, and you must recognize them. Another trap is failing to account for CASL when a privacy question involves electronic messages: the two regimes coexist, and both may apply to the same activity. You also lose marks if you treat all provincial laws as identical to PIPEDA, especially when Quebec law is in play. Scenarios often involve multiple steps, and the correct answer depends on spotting the point at which the organization's obligation changes, such as when a purpose shifts or a business relationship ends.
Because this topic spans three distinct legal regimes, the question bank gives you enough coverage to see how PIPEDA, provincial laws, and CASL interact across different scenarios. The practice test lets you work through consent and accountability questions until you can distinguish the regimes by reflex, which matters when the exam clock is running.
The question that follows asks you to determine which consent standard applies when an organization uses customer data for a purpose not disclosed at the time of collection.
What must a federal government department do before it implements an electronic service (e-service)?
Public-sector privacy law governs how federal and provincial government institutions handle personal information. The Privacy Act applies to federal institutions, while each province and territory has its own freedom of information and protection of privacy legislation. Privacy impact assessments are a procedural tool, and the exam expects you to know when they are required and what they must contain. The difficulty lies in distinguishing between access rights and privacy protections, and in recognizing when a provincial FIPPA applies instead of...
Public-sector privacy law governs how federal and provincial government institutions handle personal information. The Privacy Act applies to federal institutions, while each province and territory has its own freedom of information and protection of privacy legislation. Privacy impact assessments are a procedural tool, and the exam expects you to know when they are required and what they must contain. The difficulty lies in distinguishing between access rights and privacy protections, and in recognizing when a provincial FIPPA applies instead of federal law.
β The Privacy Act and federal obligations
The Privacy Act sets out how federal government institutions collect, use, disclose, and retain personal information. Unlike PIPEDA, it does not rest on consent: government authority to collect is statutory, and the individual's control comes through access and correction rights rather than through agreement. The Act limits disclosure without consent to a closed list of exceptions, and you need to know when those exceptions apply. Consistent uses are permitted without fresh authority, but the definition of consistency is narrower than most candidates assume. The Act also requires that personal information banks be described in Info Source, and questions may test whether you understand the transparency obligation. Retention and disposal rules are mandatory, and failing to apply them correctly is a breach even when no harm results.
β Privacy impact assessments
A privacy impact assessment identifies privacy risks in a new program, system, or initiative and proposes mitigation. The Treasury Board Secretariat requires PIAs for federal institutions in specified circumstances, and the exam expects you to recognize those triggers. A PIA is not a checklist: it must assess necessity, proportionality, and the adequacy of safeguards, and it must be completed before the initiative goes live. The exam tests whether you can identify when a PIA is mandatory, what it must cover, and who must approve it. You also need to understand that a PIA is not a one-time exercise: material changes to the initiative require reassessment. The purpose is not to block the project but to ensure that privacy is considered at the design stage, and questions will probe whether you know the difference between a meaningful assessment and a pro forma document.
β Provincial and territorial FIPPA legislation
Every province and territory has enacted freedom of information and protection of privacy legislation that applies to its own public bodies. The statutes share a common structure but differ in detail, and the exam expects you to understand the general framework without memorizing every jurisdiction's quirks. Collection must be authorized by law and limited to what is necessary. Use and disclosure follow the same exception-based model as the federal Privacy Act, and you need to recognize when an exception permits sharing and when it does not. Access rights are subject to exemptions, and the exam may test whether you can distinguish between a mandatory exemption and a discretionary one. The statutes also create information and privacy commissioners with order-making or ombudsman powers, and understanding the role of the commissioner helps you assess how disputes are resolved.
How Canadian Privacy Laws and Practices: Public Sector is tested
Questions in this topic present scenarios involving government data handling, access requests, or program design, and ask you to identify the applicable law or the correct procedure. The most common error is assuming that consent governs public-sector privacy the way it does in the private sector. You lose marks when you treat a discretionary disclosure exception as mandatory, or when you assume that a consistent use is always permissible without checking the statutory definition. PIA questions test whether you know when an assessment is required and what it must address, and candidates often fail by treating the PIA as a post-launch formality. Access and privacy are intertwined in the statutes, and the exam will test whether you can balance them when an access request implicates third-party privacy. Scenarios may involve multiple jurisdictions, and the correct answer depends on knowing which FIPPA applies based on the nature of the public body.
The full question bank covers federal and provincial public-sector scenarios in enough depth that you can identify your weak areas without re-reading the statutes. The timed practice test helps you develop the speed needed to parse multi-step access and disclosure questions, which are common in this topic.
The question below turns on whether a federal institution may disclose personal information under one of the statutory exceptions, and whether the proposed use meets the consistency test.
Health privacy is governed by sector-specific legislation in most provinces and territories, and the exam expects you to know when those statutes apply instead of PIPEDA or a general FIPPA. The challenge is recognizing that health information is defined broadly, that custodians have distinct obligations, and that consent rules differ from those in other sectors. The statutes were written to accommodate the reality of clinical care, where information must move quickly among providers, and the exam tests whether you understand...
Health privacy is governed by sector-specific legislation in most provinces and territories, and the exam expects you to know when those statutes apply instead of PIPEDA or a general FIPPA. The challenge is recognizing that health information is defined broadly, that custodians have distinct obligations, and that consent rules differ from those in other sectors. The statutes were written to accommodate the reality of clinical care, where information must move quickly among providers, and the exam tests whether you understand when sharing is permitted and when it requires patient authorization. Each jurisdiction has its own health privacy act, and while the principles overlap, the details vary enough that you cannot assume one statute mirrors another. You need to know the general framework and be prepared to apply it to fact patterns involving patient records, research, and third-party access.
How Canadian Privacy Laws and Practices: Health Sector is tested
Questions in this area present clinical or administrative scenarios and ask you to determine which law applies, whether consent is required, or whether a disclosure is authorized. The most common mistake is applying PIPEDA to a situation governed by provincial health privacy legislation, or assuming that a custodian may share information freely with another provider without checking whether the statutory conditions are met. The exam will test whether you know when implied consent suffices for treatment purposes and when express consent is mandatory, such as for research or marketing. You also need to recognize that health information includes more than clinical records: it extends to billing data, appointment details, and anything that identifies an individual in a health context. Scenarios may involve multiple custodians, and the correct answer depends on understanding the circle of care concept and its limits. Candidates lose marks when they treat health privacy as identical to private-sector or public-sector rules, or when they fail to account for the heightened sensitivity that health statutes reflect.
The practice test includes enough health-sector scenarios that you can verify your understanding of when provincial health privacy acts displace PIPEDA and when implied consent operates. Working through the full bank lets you see how custodian obligations and circle-of-care rules are tested across different fact patterns.
The question that follows asks you to identify the correct legal authority for a health information custodian's disclosure and whether the proposed sharing falls within the permitted purposes.
Ready to Start Practicing?
Access all questions and start your exam preparation journey
Upgrade to Full CIPP/C Exam Questions π