Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

DSCI DCPP-01 - DSCI certified Privacy Professional (DCPP)

Page: 2 / 4
Total 122 questions

Which of the following mechanisms or steps are likely to be taken by an organization for implementing privacy program?

i Deploying physical and technology safeguards to protect personal information assets

ii. Privacy consideration in product and service design

iii. Privacy implementation to focus only on projects impacted by privacy breaches

iv. Benchmarking against industry peers’ privacy implementation

v. Installing privacy enhancing tools and technologies for the projects dealing with organization’s intellectual property

Please select the correct set of statements from the below options:

A.

All

B.

All except iii

C.

Only i, and ii

D.

Only i, ii and iv

As a newly-appointed privacy officer of an IT company gearing up for DSCI’s privacy certification, you are trying to understand what data elements are involved in each of the business process, function and if these data elements can be classified as sensitive personal information. What is being accomplished with this effort?

A.

Organization to get “Visibility” over its exposure to sensitive personal information

B.

It is a part of the annual exercise per the organization’s privacy policy/ processes

C.

Information security controls for confidential information being reviewed

D.

Gathering inputs to restructure privacy function

Which of the following privacy principle deals with informed consent of the data subject before sharing the personal information (of the data subject) to third parties for processing?

A.

Collection limitation

B.

Purpose limitation

C.

Disclosure of information

D.

Accountability

Indian constitution does not expressly provide for the “right to privacy” to its citizens. However, there were various judicial pronouncements of the apex court which finally established the “right to privacy” as a fundamental right subsumed under Article 21 of the constitution of India. Article 21 inter alia provides and protects the __________________.

A.

Right to Life and Personal liberty

B.

Right to Opportunity

C.

Right to Freedom of Speech and Expression

D.

Right to Equality before law

Which of the following categories of information are generally protected under privacy laws?

A.

Personally Identifiable Information (PII)

B.

Sensitive Personal Information (SPI)

C.

Trademark, copyright and patent information

D.

Organizations’ confidential business information

Which of the following legislations/ guidelines do not cover the concept of trans-border data flow?

A.

OECD

B.

IT (Amendment) Act, 2008

C.

PIPEDA

D.

None of the above

A ministry under government of India plans to collect citizens’ information related to their education, medical condition, economic status, caste and religion. As per the privacy requirements mentioned under Sec 43A of IT (Amendment) Act, 2008, the citizens’ ‘Consent’ would be mandatory for which of the following elements before their collection?

A.

Educational records

B.

Medical condition

C.

Caste and religion

D.

Sec 43A may not be applicable

Which of the following is not required by an organization in US, resorting to EU-US Safe Harbor provisions, to transfer personal information from EU member nation to US?

A.

Adherence to the seven safe harbor principles

B.

Disclose their privacy policy publicly

C.

Sign standard contractual clauses with data exporters in EU

D.

Notify FTC of the self-certification

A US IT company has created a cloud based application for Canadian consumers only, with servers located in Vancouver, Canada. The application allows its users to publish their short stories, essays or e-books. The purpose of the application, i.e. literary work, is clearly stated in the terms and conditions which are mandatorily acknowledged by each user. With respect to this application, the company must ensure compliance with:

A.

PIPEDA

B.

US Consumer Privacy Bill of Rights

C.

EU Data Protection Directive

D.

None of the above

With reference to APEC privacy framework, when personal information is to be transferred to another person or organization, whether domestically or internationally, “the ______________ should obtain the consent of the individual and exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with APEC information privacy principles”.

A.

Personal Information Owner

B.

Personal Information Controller

C.

Personal Information Processor

D.

Personal Information Auditor