Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

DCPP-01 Exam Dumps - DSCI certified Privacy Professional (DCPP)

Go to page:
Question # 9

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

Which of the following are not mandatory pre-requisite before transferring sensitive personal data to its Asian branches?

A.

Notifying the data subject

B.

Conducting risk assessment for the processing involved

C.

Determining adequacy status of the country

D.

Self-certifying to Safe Harbor practices and reporting to Federal Trade Commission

Full Access
Question # 10

Indian constitution does not expressly provide for the “right to privacy” to its citizens. However, there were various judicial pronouncements of the apex court which finally established the “right to privacy” as a fundamental right subsumed under Article 21 of the constitution of India. Article 21 inter alia provides and protects the __________________.

A.

Right to Life and Personal liberty

B.

Right to Opportunity

C.

Right to Freedom of Speech and Expression

D.

Right to Equality before law

Full Access
Question # 11

A public domain or freely accessible piece of information cannot be construed as sensitive personal data or information under Indian law.

A.

FALSE

B.

TRUE

Full Access
Question # 12

Specifically, what section of the IT (Amendment) Act, 2008 lays down the provisions for punishment for the offense of wrongful disclosure of personal information with the intention of causing loss or gain to another?

A.

Section 72A

B.

Section 65

C.

Section 72

D.

Section 43A

Full Access
Question # 13

Which law does not require notification of personal data breaches?

A.

Japanese Act on the Protection of Personal Information

B.

UK Data Protection Act, 2018

C.

General Data Protection Regulation, 2016

D.

Information Technology (Amendment) Act, 2008

Full Access
Question # 14

Regarding projects such as Aadhaar, the National Population Register (NPR), etc. that involve national government projects specific to India, which of the following statements is accurate?

A.

Citizens can choose not to submit their biometric details to the environment and can complete the process without providing their biometrics

B.

Prior to and during collection of data, data subjects are not properly notified

C.

In India, biometric data collection is a statutory requirement

D.

Once their personal information has been shared with the project, data subjects are not limited in how they can exercise control over how it will be used

Full Access
Question # 15

Effective 2013, HIPAA Omnibus rule applies to which of the following?

A.

Covered Entities only

B.

Business Associates only

C.

Covered Entities & Business Associates

D.

Federal Health Bodies only

Full Access
Question # 16

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

For exporting EU branch employees’ data to Asian Countries for processing, which of the following instruments could be used for legal data transfer?

A.

Customized contracts mandating ISO 27001 certification by the data processor

B.

Standard Contractual Clauses

C.

Binding Corporate Rules

D.

Safe Harbor

Full Access
Go to page: