Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

DSCI DCPP-01 DSCI certified Privacy Professional (DCPP) Exam Practice Test

Page: 1 / 12
Total 122 questions

DSCI certified Privacy Professional (DCPP) Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

A public domain or freely accessible piece of information cannot be construed as sensitive personal data or information under Indian law.

Options:

A.

FALSE

B.

TRUE

Question 2

According to the EU-US Safe Harbour Framework, which of the following is not required when transferring personal information from EU member nations to the US?

Options:

A.

Contracts with EU data exporters should include standard contractual clauses

B.

Safe harbor principles must be followed

C.

The self-certification process with the Federal Trade Commission

D.

Privacy information publicly disclosed

Question 3

Which of the following are needed for projects like DNA profiling, UIDAI, and statistical collection of individuals ?

Options:

A.

Established a service which guarantees citizens' privacy only online

B.

Protect the privacy of individuals

C.

The need for a comprehensive privacy legislation at national level

D.

None of the above

Question 4

APPI, the Act for the Protection of Personal Information, applies to:

Options:

A.

Government entities using personal information

B.

Personal Information about an individual that is used by a business

C.

None of the above

Question 5

Which of the following activities form part of an organization’s Visibility over Personal Information (VPI) initiative, according to DSCI Privacy Framework (DPF©)?

Options:

A.

‘Data processing environment’ analysis of industry peers

B.

‘Data processing environment’ analysis of the country

C.

‘Data processing environment’ analysis of the organization and associated third parties

D.

‘Data processing environment’ analysis of the organization only

Question 6

One of the main objectives of ‘Do Not Track’ technology is to

Options:

A.

Opt out from the web based analytics services, advertising networks and social platforms

B.

Opt out from call back services by e-commerce companies

C.

Opt out from monitoring and surveillance programs of governments, intelligence and Law Enforcement Agencies

D.

None of the above

Question 7

Which of the following statements are true about the privacy statement of an organization?

Options:

A.

Content of the online privacy statement of an organization will depend upon the applicable laws, and may need to address requirements across geographical boundaries and legal jurisdictions

B.

As per privacy laws generally it is mandatory to mention the phone contact details of the owner of organization in the online privacy statement where customers can reach out in case of a grievance or incident

C.

Online privacy statement is an instrument to demonstrate to stakeholders how the organization gathers, uses, discloses, and manages personal data

D.

India’s Information Technology (Amendment) Act, 2008 does not require that privacy policy be published on the website

Question 8

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

Which of the following are not mandatory pre-requisite before transferring sensitive personal data to its Asian branches?

Options:

A.

Notifying the data subject

B.

Conducting risk assessment for the processing involved

C.

Determining adequacy status of the country

D.

Self-certifying to Safe Harbor practices and reporting to Federal Trade Commission

Question 9

After the rules were notified under section 43A of the IT (Amendment) Act, 2008, a clarification was issued by the government which exempted the service providers, which get access to/processes Sensitive Personal Data or information (SPDI) under contractual agreement with a legal entity located within or outside India. Which privacy principle provisions notified under Sec 43A were exempted for the service providers?

Options:

A.

Consent

B.

Privacy policy (which is published)

C.

Access and Correction

D.

Disclosure of information

Question 10

XYZ is a successful startup that acquired a respectable size & scale of operations in last 3 years, handling business process services for small & medium scale enterprises, largely in US & Europe. They are at the stage of closing a deal with a new banking client and working out the details of privacy related obligations in contract. Ensuring effective enforcement of which of the below listed privacy principles is client’s accountability, even after outsourcing its loan approval process to XYZ?

I. Notice

II. Choice and Consent

III. Collection Limitation

IV. Use Limitation

V. Access and Correction

VI. Security

VII. Disclosure to third Party

Please select the correct set of principles from below listed options:

Options:

A.

None of the above, since they are outsourcing the work to XYZ who will carry the liability going forward

B.

All except V and VI

C.

All except III

D.

All of the above listed privacy principles

Question 11

A US IT company has created a cloud based application for Canadian consumers only, with servers located in Vancouver, Canada. The application allows its users to publish their short stories, essays or e-books. The purpose of the application, i.e. literary work, is clearly stated in the terms and conditions which are mandatorily acknowledged by each user. With respect to this application, the company must ensure compliance with:

Options:

A.

PIPEDA

B.

US Consumer Privacy Bill of Rights

C.

EU Data Protection Directive

D.

None of the above

Question 12

Which of the following legislations/ guidelines do not cover the concept of trans-border data flow?

Options:

A.

OECD

B.

IT (Amendment) Act, 2008

C.

PIPEDA

D.

None of the above

Question 13

A government agency collecting biometrics of citizens can deny sharing such information with Law Enforcement Agencies (LEAs) on which of the following basis?

Options:

A.

The purpose of collecting the biometrics is different than what LEAs intent to use it for

B.

The consent of data subjects has not been taken

C.

Government agencies would share the biometrics with LEAs on one condition if LEA properly notify the citizens

D.

None of the above, as government agencies would never deny any LEA for sharing such information for the purpose of mass surveillance

Question 14

Choose the correct statement:

Projects like DNA profiling, UIDAI, collection of individual’s statistics, etc.

Options:

A.

Are executed with a sole aim to ensure that privacy of individuals is maintained

B.

Have been initiated to provide services to citizens for maintaining their online privacy only

C.

Have raised the need for a comprehensive privacy legislation at national level

D.

Have enforced a privacy legislation at national level

Question 15

In the history of human evolution, erection of walls and fences around one’s living spaces is interpreted as arrival of which type of privacy consciousness?

Options:

A.

Data privacy

B.

Physical privacy

C.

Organizational privacy

D.

Communication privacy

Question 16

Which of the following doesn’t contribute, or contributes the least, to the growing data privacy challenges in today’s digital age?

Options:

A.

Social media

B.

Mass surveillance

C.

Use of secure wireless connections

D.

Increase in digitization of personal information

Question 17

When an individual has choice to decide on who else can have access to their personal information, it is called

Options:

A.

Information Privacy

B.

Physical Privacy

C.

Social Privacy

D.

Psychological Privacy

Question 18

Which one of the following is considered as the first step of evolution in the formation of today’s concept of privacy?

Options:

A.

Fundamental civil liberty

B.

Universal declaration of human rights

C.

Right to be left alone

D.

Binding corporate rules

Page: 1 / 12
Total 122 questions