Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

DCPP-01 DSCI certified Privacy Professional (DCPP) Questions and Answers

Questions 4

For negligence in implementing and maintaining the reasonable security practices and procedures for protecting Sensitive Personal Data or Information (SPDI) as mentioned in Section 43A and associated rules under IT (Amendment) Act, 2008, a corporate entity may be liable to pay compensation of up to___________

Options:

A.

Rs. 50,000,000

B.

Rs. 500,000,000

C.

Rs. 5,000,000

D.

Upper limit not defined

Buy Now
Questions 5

Please select the incorrect statement in context of “Online Privacy”:

Options:

A.

A person’s act of ‘Selective disclosure” (of themselves) in an online environment

B.

A person’s concern over usage of information that were collected during an online activity

C.

A person’s control over collection of information during an online activity

D.

A person’s concern on the software licensing agreement they sign with any organization

Buy Now
Questions 6

Under which of the following conditions can a company in India may transfer sensitive personal information (SPI) to any other company or a person in India, or located in any other country?

Options:

A.

Transfer of information is allowed to those who ensure the same level of data protection that is adhered to by the company as provided for under the Indian laws

B.

The transfer of information is allowed only after taking approval of Chief Information Commissioner of India

C.

The transfer of information is allowed only after taking approval of DeitY (Department of Electronics & Information Technology) in India

D.

The transfer may be allowed only if it is necessary for the performance of the lawful contract or where the data subject has consented to data transfer

Buy Now
Questions 7

What are the roles an organization can play from privacy perspective?

i. Data Controller – determines the means and purpose of processing of data which is collected from its end customers

ii. Data Controller – determines the means and purpose of processing of data which is collected from its employees

iii. Data Sub-Processor – processes personal data on behalf of data processor

iv. Joint Controller – determines the means and purpose of data processing along with other data controller

Please select correct option:

Options:

A.

i, ii and iii

B.

ii, iii and iv

C.

i, iii and iv

D.

i, ii, iii and iv

Buy Now
Questions 8

Which of the following laid foundation for the development of OECD privacy principles for the promotion of free international trade and trans border data flows?

Options:

A.

Fair information Privacy Practices of US, 1974

B.

EU Data Protection Directive

C.

Safe Harbor Framework

D.

WTO’s Free Trade Agreement

Buy Now
Questions 9

Company A collects and stores information from people X & Y on behalf of company B. Which of the following statements are true?

Options:

A.

A is the data controller since it collects data directly from X & Y

B.

B is the data controller while A is the sub processor as B has outsourced the data collection and processing to A

C.

B is the data controller that uses A as data processor to collect and process data of data subjects X and Y

D.

Both A & B are data controllers since both need to maintain highest principles of data protection

Buy Now
Questions 10

Which type of data qualify as Sensitive Personal Data or Information under Section 43A of IT (Amendment) Act, 2008?

Options:

A.

Sexual orientation

B.

Political affiliation

C.

Religion and caste

D.

Call Data Records (CDRs)

Buy Now
Questions 11

Which of the following doesn’t contribute, or contributes the least, to the growing data privacy challenges in today’s digital age?

Options:

A.

Social media

B.

Mass surveillance

C.

Use of secure wireless connections

D.

Increase in digitization of personal information

Buy Now
Questions 12

Which of the following does not fall under the category of Personal Financial Information (PFI)?

Options:

A.

Credit card number with expiry date

B.

Bank account Information

C.

Loan account Information

D.

Income tax return file acknowledgement number

Buy Now
Questions 13

Rising economic value of personal information has stressed the need for a comprehensive __________ legislation in India.

Options:

A.

Right to Internet

B.

Privacy

C.

Right to Information

D.

Dispute resolution

Buy Now
Questions 14

Choose the correct statement:

Projects like DNA profiling, UIDAI, collection of individual’s statistics, etc.

Options:

A.

Are executed with a sole aim to ensure that privacy of individuals is maintained

B.

Have been initiated to provide services to citizens for maintaining their online privacy only

C.

Have raised the need for a comprehensive privacy legislation at national level

D.

Have enforced a privacy legislation at national level

Buy Now
Questions 15

In India, who among the following would be the authorized legal entities to monitor and intercept communication of individuals?

Options:

A.

“Intermediaries” as defined under the IT (Amendment) Act, 2008

B.

Telecom Service Providers

C.

Intelligence and Law Enforcement Agencies

D.

Directorate of Revenue Intelligence (DRI)

Buy Now
Questions 16

In the history of human evolution, erection of walls and fences around one’s living spaces is interpreted as arrival of which type of privacy consciousness?

Options:

A.

Data privacy

B.

Physical privacy

C.

Organizational privacy

D.

Communication privacy

Buy Now
Questions 17

Which of the following is not a driver for increased privacy-related concerns and subsequent regulatory responses from various governments around the world?

Options:

A.

Outsourcing and trans-border data flows in globalized world

B.

Increasing economic value of personal information

C.

Rising demand of data privacy professionals

D.

Phenomenal rise in use of social networking sites, where a lot of personal information is shared with others

Buy Now
Questions 18

Which of the following legislations/ guidelines do not cover the concept of trans-border data flow?

Options:

A.

OECD

B.

IT (Amendment) Act, 2008

C.

PIPEDA

D.

None of the above

Buy Now
Questions 19

A ministry under government of India plans to collect citizens’ information related to their education, medical condition, economic status, caste and religion. As per the privacy requirements mentioned under Sec 43A of IT (Amendment) Act, 2008, the citizens’ ‘Consent’ would be mandatory for which of the following elements before their collection?

Options:

A.

Educational records

B.

Medical condition

C.

Caste and religion

D.

Sec 43A may not be applicable

Buy Now
Questions 20

You are part of a team that has been created by Indian government to create India’s privacy law based on recommendations in Justice AP Shah’s Report. Which of the following provisions should be addressed in the law?

Options:

A.

Privacy as an explicit fundamental constitutional right

B.

Offences, penalties and remedies

C.

National privacy principles

D.

Setup of a national data controller registry

Buy Now
Questions 21

After the rules were notified under section 43A of the IT (Amendment) Act, 2008, a clarification was issued by the government which exempted the service providers, which get access to/processes Sensitive Personal Data or information (SPDI) under contractual agreement with a legal entity located within or outside India. Which privacy principle provisions notified under Sec 43A were exempted for the service providers?

Options:

A.

Consent

B.

Privacy policy (which is published)

C.

Access and Correction

D.

Disclosure of information

Buy Now
Questions 22

Choose from the options below to group privacy principles into user centric (requiring people ' s involvement) and organization centric (restricted to processes within the organization) categories:

Options:

A.

User Centric: Choice, Collection Limitation, Access and Correction Organization Centric: Notice, Use Limitation, Security, Disclosure to third party, Accountability

B.

User Centric: Notice, Consent, Collection Limitation, Access and Correction Organization Centric: Choice, Use Limitation, Security, Disclosure to third party, Openness, Accountability

C.

User Centric: Notice, Openness, Accountability Organization Centric: Consent, Choice, Collection Limitation, Use Limitation, Security, Disclosure to third party, Access & Correction

D.

User Centric: Notice, Consent, Choice, Access & Correction Organization Centric: Consent, Collection Limitation, Use Limitation, Security, Disclosure to third party, Openness, Accountability

Buy Now
Questions 23

Which of the following is not required by an organization in US, resorting to EU-US Safe Harbor provisions, to transfer personal information from EU member nation to US?

Options:

A.

Adherence to the seven safe harbor principles

B.

Disclose their privacy policy publicly

C.

Sign standard contractual clauses with data exporters in EU

D.

Notify FTC of the self-certification

Buy Now
Questions 24

With reference to APEC privacy framework, when personal information is to be transferred to another person or organization, whether domestically or internationally, “the ______________ should obtain the consent of the individual and exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with APEC information privacy principles”.

Options:

A.

Personal Information Owner

B.

Personal Information Controller

C.

Personal Information Processor

D.

Personal Information Auditor

Buy Now
Questions 25

Which of the following categories of information are generally protected under privacy laws?

Options:

A.

Personally Identifiable Information (PII)

B.

Sensitive Personal Information (SPI)

C.

Trademark, copyright and patent information

D.

Organizations’ confidential business information

Buy Now
Questions 26

XYZ is a successful startup that acquired a respectable size & scale of operations in last 3 years, handling business process services for small & medium scale enterprises, largely in US & Europe. They are at the stage of closing a deal with a new banking client and working out the details of privacy related obligations in contract. Ensuring effective enforcement of which of the below listed privacy principles is client’s accountability, even after outsourcing its loan approval process to XYZ?

I. Notice

II. Choice and Consent

III. Collection Limitation

IV. Use Limitation

V. Access and Correction

VI. Security

VII. Disclosure to third Party

Please select the correct set of principles from below listed options:

Options:

A.

None of the above, since they are outsourcing the work to XYZ who will carry the liability going forward

B.

All except V and VI

C.

All except III

D.

All of the above listed privacy principles

Buy Now
Questions 27

According to IT (Amendment) Act,2008, who should designate a grievance officer to redress grievance(s) of provider of information?

Options:

A.

Data processor

B.

Third party agency collecting personal information

C.

Body corporate, which determines the means and purpose of data processing

D.

Natural person sharing his/her information

Buy Now
Questions 28

According to RTI Act, under which conditions can a government department refuse to release information?

Options:

A.

National security adversely affected by such information

B.

This information is detrimental to the stability of the ruling party in government

C.

Detrimental effect on the public image of government agencies

D.

In the absence of a public interest, such information may adversely impact the privacy of its officials

Buy Now
Questions 29

Historically, which of these events led to the formation of our current concept of privacy?

Options:

A.

Civil rights are fundamental liberties

B.

Declaration of human rights

C.

The right to be left alone

D.

A binding corporate rule

Buy Now
Questions 30

A company collects personal information about its employees and requests them to provide accurate information in order to avail benefits such as life insurance and medical insurance. Employees of the company have raised concerns about use of their personal information. Due to the concerns, the company has decided to create a privacy policy. What all should the company include in its privacy policy to address the raised concerns?

Options:

A.

The purpose of collection of personal data

B.

The principle of presumed consent for data disclosure to avail benefits

C.

Information about how personal information is processed and used, specifically

D.

Contact details of Law Enforcement Agencies (LEA) to whom information is disclosed

Buy Now
Questions 31

When sharing personal information (of the data subject) with third parties for processing, which of the following privacy principles includes informed consent?

Options:

A.

Disclosure of information

B.

Collection limitation

C.

Accountability

D.

Purpose limitation

Buy Now
Questions 32

When you ' re based in the EU and willing to share data outside the EU/EEA, then you can use model contracts. In reference to the above statement, which of the following is true?

Options:

A.

Directive on EU e-commerce mentions it as a requirement

B.

EU Data Protection Directive states that it is a requirement

C.

OECD ' s Privacy Framework mentions it as a requirement

D.

Neither of the above

Buy Now
Questions 33

It is essential for an entity to comply with US requirements if it operates a website designed for kids or a website for general audiences that gathers information from individuals known to be under 13 years old. Which of the below regulations is applicable?

Options:

A.

Gramm-Leach-Bliley Act, 1999

B.

Child online protection Act, 1998

C.

Personal Information Protection and Electronic Documents Act (PIPEDA)

D.

Sarbanes-Oxley Act, 2000

Buy Now
Questions 34

A Privacy Impact Assessment (PIA) should ideally accomplish which of the following goals?

Options:

A.

To determine the risks and effects of collecting, storing and distributing personal information

B.

To evaluate processes for handling personal information for mitigating potential privacy risks

C.

To acknowledge the organization’s role in collecting personal identifiable information

D.

To comply with ISO 27001:2013 standard

Buy Now
Questions 35

The Qatar Concerning Privacy and Protection of Personal Data Act, 2016 addresses different types of personal data, including:

Options:

A.

Only manual processing of personal data

B.

Only electronic processing of personal data

C.

The electronic or manual processing of personal information

D.

None of the above

Buy Now
Questions 36

Under the OECD Privacy Guidelines, 1980, which of the following was not a privacy principle?

Options:

A.

Purpose Specification

B.

Security Safeguard

C.

Openness

D.

Data minimization

Buy Now
Exam Code: DCPP-01
Exam Name: DSCI certified Privacy Professional (DCPP)
Last Update: May 15, 2026
Questions: 122

PDF + Testing Engine

$64.99  $185.69

Testing Engine

$49.99  $142.83
buy now DCPP-01 testing engine

PDF (Q&A)

$54.99  $157.11
buy now DCPP-01 pdf