Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

DCPP-01 DSCI certified Privacy Professional (DCPP) Questions and Answers

Questions 4

Which among the following can be classified as the most important purpose for enactment of data protection/ privacy regulations across the globe?

Options:

A.

Protect the constitution

B.

Penalize the organizations and impose fines for failure to protect privacy

C.

Ensure peace in the society

D.

Protect individual rights

Buy Now
Questions 5

Which of the following laid foundation for the development of OECD privacy principles for the promotion of free international trade and trans border data flows?

Options:

A.

Fair information Privacy Practices of US, 1974

B.

EU Data Protection Directive

C.

Safe Harbor Framework

D.

WTO’s Free Trade Agreement

Buy Now
Questions 6

Which of the following privacy principle deals with informed consent of the data subject before sharing the personal information (of the data subject) to third parties for processing?

Options:

A.

Collection limitation

B.

Purpose limitation

C.

Disclosure of information

D.

Accountability

Buy Now
Questions 7

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

For the outsourced work of its customers’ data processing, in order to initiate data transfer to another organizations outside EU, which is the most appropriate among the following?

Options:

A.

The vendor (data importer) in the third country, and not the exporter is responsible to put in place suitable model contractual clauses, and hence the exporter does not need to take any action.

B.

Since the data is processed by the vendor outside the EU, the EU directive does not apply and hence there are no legal concerns

C.

The data exporter needs to initiate model contractual clauses after obtaining approvals from data protection commissioner and have the vendor be a signatory on the same as data importer

D.

The data importer need to notify about the transfer to data protection commissioner in the destination country and exporter need to similarly notify in the EU country of origin

Buy Now
Questions 8

Select the element(s) of APEC cross border privacy rules system from the following list:

i. self-assessment

ii. compliance review

iii. recognition/acceptance by APEC members

iv. dispute resolution and enforcement

Please select correct option:

Options:

A.

i, ii and iii

B.

ii, iii, and iv

C.

i, iii and iv

D.

i, ii, iii and iv

Buy Now
Questions 9

XYZ is a successful startup that acquired a respectable size & scale of operations in last 3 years, handling business process services for small & medium scale enterprises, largely in US & Europe. They are at the stage of closing a deal with a new banking client and working out the details of privacy related obligations in contract. Ensuring effective enforcement of which of the below listed privacy principles is client’s accountability, even after outsourcing its loan approval process to XYZ?

I. Notice

II. Choice and Consent

III. Collection Limitation

IV. Use Limitation

V. Access and Correction

VI. Security

VII. Disclosure to third Party

Please select the correct set of principles from below listed options:

Options:

A.

None of the above, since they are outsourcing the work to XYZ who will carry the liability going forward

B.

All except V and VI

C.

All except III

D.

All of the above listed privacy principles

Buy Now
Questions 10

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

For exporting EU branch employees’ data to Asian Countries for processing, which of the following instruments could be used for legal data transfer?

Options:

A.

Customized contracts mandating ISO 27001 certification by the data processor

B.

Standard Contractual Clauses

C.

Binding Corporate Rules

D.

Safe Harbor

Buy Now
Questions 11

Please select the incorrect statement in context of “Online Privacy”:

Options:

A.

A person’s act of ‘Selective disclosure” (of themselves) in an online environment

B.

A person’s concern over usage of information that were collected during an online activity

C.

A person’s control over collection of information during an online activity

D.

A person’s concern on the software licensing agreement they sign with any organization

Buy Now
Questions 12

Which of the following could be considered as triggers for updating privacy policy?

Options:

A.

Regulatory changes

B.

Privacy breach

C.

Change in service provider for an established business process

D.

Recruitment of more employees

Buy Now
Questions 13

Which of the following factor is least likely to be considered while implementing or augmenting data security solution for privacy protection:

Options:

A.

Security controls deployment at the database level

B.

Information security infrastructure up-gradation in the organization

C.

Classification of data type and its usage by various functions in the organization

D.

Training and awareness program for third party organizations

Buy Now
Questions 14

According to the EU, which of the following steps is not relevant when transferring data from an EU member to a third country that does not meet EU standards?

Options:

A.

Obtaining approval by the Data Protection Authority or informing it

B.

Aligning data protection legislation across geographies

C.

Sizing up the security measures employed by the importing organization to account for the sensitivity of the data being transferred

D.

A model contract is signed

Buy Now
Questions 15

A company collects personal information about its employees and requests them to provide accurate information in order to avail benefits such as life insurance and medical insurance. Employees of the company have raised concerns about use of their personal information. Due to the concerns, the company has decided to create a privacy policy. What all should the company include in its privacy policy to address the raised concerns?

Options:

A.

The purpose of collection of personal data

B.

The principle of presumed consent for data disclosure to avail benefits

C.

Information about how personal information is processed and used, specifically

D.

Contact details of Law Enforcement Agencies (LEA) to whom information is disclosed

Buy Now
Questions 16

Health insurance firm based in the US uses BPM services provided by an Indian company. It was found that one of the employees of the Indian company exported customer data of the insurance company to another US-based insurance company. Under which of the below ground, the company and its executives in India were also subjected to legal action ?

Options:

A.

These actions were not avoided by using data loss prevention tools.

B.

No reasonable security practices were implemented to protect data.

C.

Employees of the company were allowed to view sensitive personal information.

D.

Background checks were not conducted on the individuals.

Buy Now
Questions 17

A government agency collecting biometrics of citizens can deny sharing such information with Law Enforcement Agencies (LEAs) on which of the following basis?

Options:

A.

The purpose of collecting the biometrics is different than what LEAs intent to use it for

B.

The consent of data subjects has not been taken

C.

Government agencies would share the biometrics with LEAs on one condition if LEA properly notify the citizens

D.

None of the above, as government agencies would never deny any LEA for sharing such information for the purpose of mass surveillance

Buy Now
Questions 18

In relation to "Online Privacy" please pick the incorrect statement:

Options:

A.

Online disclosure of "selective" information by a person that is publicly available

B.

The process of obtaining information online that a person can control

C.

People's concerns over the license agreements they sign with any company

D.

People's concern over the way their personal information is used during online activities

Buy Now
Exam Code: DCPP-01
Exam Name: DSCI certified Privacy Professional (DCPP)
Last Update: Nov 23, 2024
Questions: 122

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99