Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP/C Exam - Topic 2 Question 77 Discussion

A small commercial business in Canada was preparing a mailing to its customers when the letters and the envelopes were mismatched, causing 500 of 1000 letters to be sent to the wrong recipients. The letters contained the name and mailing address of the clients as well as account numbers and account balances.The business has discovered this error as clients called to report receiving the wrong letter and expressing concern that their information has been breached. Which of the following is the most appropriate next step to take?
D) A risk assessment must be completed to determine the real risk of significant harm (RROSH) to the clients.
A) All 1000 clients must be sent new letters.
B) The 500 clients who were impacted must be immediately notified.
C) The Office of the Privacy Commissioner (OPC) must be immediately notified.

IAPP CIPP/C Exam - Topic 2 Question 77 Discussion

Actual exam question for IAPP's CIPP/C exam
Question #: 77
Topic #: 2
[All CIPP/C Questions]

A small commercial business in Canada was preparing a mailing to its customers when the letters and the envelopes were mismatched, causing 500 of 1000 letters to be sent to the wrong recipients. The letters contained the name and mailing address of the clients as well as account numbers and account balances.

The business has discovered this error as clients called to report receiving the wrong letter and expressing concern that their information has been breached. Which of the following is the most appropriate next step to take?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Hershel
1 day ago
I think option B is best.
upvoted 0 times
...
Ozell
6 days ago
This is a tough situation.
upvoted 0 times
...
Odelia
11 days ago
I agree with B, but all clients should be informed eventually.
upvoted 0 times
...
Jillian
17 days ago
A risk assessment sounds like a good idea, but is it really the first step?
upvoted 0 times
...
Tequila
22 days ago
Surprised this even happened, how do you mix up letters like that?
upvoted 0 times
...
Marguerita
27 days ago
I think C is important too, gotta keep the OPC in the loop.
upvoted 0 times
...
Solange
1 month ago
Definitely B, those 500 clients need to know ASAP!
upvoted 0 times
...
Helga
1 month ago
I recall a case study where all clients were notified regardless of impact, but that seemed excessive. I think focusing on the impacted clients is more appropriate.
upvoted 0 times
...
Annabelle
3 months ago
I feel like we talked about risk assessments in class, but I’m not sure if that’s the immediate step here. It seems like the clients need to be informed first.
upvoted 0 times
...
Noelia
3 months ago
I’m not entirely sure, but I think we practiced a similar question where we had to consider the legal obligations. Shouldn't the OPC be notified too?
upvoted 0 times
...
Emeline
3 months ago
I remember discussing the importance of notifying affected clients first in case of a data breach, so I think option B might be the right choice.
upvoted 0 times
...

Save Cancel