Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the DSCI DCPP DCPP-01 Questions and answers with ValidTests

Exam DCPP-01 All Questions
Exam DCPP-01 Premium Access

View all detail and faqs for the DCPP-01 exam

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

For exporting EU branch employees’ data to Asian Countries for processing, which of the following instruments could be used for legal data transfer?

Options:

A.

Customized contracts mandating ISO 27001 certification by the data processor

B.

Standard Contractual Clauses

C.

Binding Corporate Rules

D.

Safe Harbor

Questions # 2:

XYZ & Co., an Indian hospital specialized in dealing with cancer treatment has organized a free health checkup camp for women in a specific district, after seeking due permission from competent authorities. During the camp the hospital staffs will be feeding the medical records of these women into the computer connected to hospital network system. Does the said hospital need to notify its privacy policy to the women attending the camp and seek their consent regarding the collection and processing of such information?

Options:

A.

No, since it is a free checkup camp for their welfare

B.

Yes, in the any language as per the wishes of said hospital

C.

No, since the law does not require the same in this case

D.

Yes, in the language such women would understand

Questions # 3:

With reference to APEC privacy framework, when personal information is to be transferred to another person or organization, whether domestically or internationally, “the ______________ should obtain the consent of the individual and exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with APEC information privacy principles”.

Options:

A.

Personal Information Owner

B.

Personal Information Controller

C.

Personal Information Processor

D.

Personal Information Auditor

Questions # 4:

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

Which of the following are not mandatory pre-requisite before transferring sensitive personal data to its Asian branches?

Options:

A.

Notifying the data subject

B.

Conducting risk assessment for the processing involved

C.

Determining adequacy status of the country

D.

Self-certifying to Safe Harbor practices and reporting to Federal Trade Commission

Questions # 5:

Please select the incorrect statement in context of “Online Privacy”:

Options:

A.

A person’s act of ‘Selective disclosure” (of themselves) in an online environment

B.

A person’s concern over usage of information that were collected during an online activity

C.

A person’s control over collection of information during an online activity

D.

A person’s concern on the software licensing agreement they sign with any organization

Questions # 6:

APEC privacy framework envisages common principles such as Notice, Collection limitation, Use Limitation, Access and Correction, Security/Safeguards, and Accountability. But it differs from the EU Data Protection Directive in which of the below aspect?

Options:

A.

APEC privacy framework does not deal with the usage of personal information

B.

APEC privacy framework does not mandate the binding treaties or directives for member countries

C.

APEC privacy framework does not have a provision for co-operation between privacy enforcement agencies of members

D.

APEC privacy framework does not deal with e-commerce

Questions # 7:

Which of the following provides the legal basis for an Adjudicating Officer in every Indian state & union territory, with the powers of a civil court, to hear complaints and order compensation to the affected individuals?

Options:

A.

Indian Civil Code

B.

Indian Criminal Procedure Code

C.

Telecom Regulatory Authority of India (TRAI) Act

D.

Information Technology Act, 2000 & Information Technology (Amendment) Act, 2008

Questions # 8:

Effective 2013, HIPAA Omnibus rule applies to which of the following?

Options:

A.

Covered Entities only

B.

Business Associates only

C.

Covered Entities & Business Associates

D.

Federal Health Bodies only

Questions # 9:

After the rules were notified under section 43A of the IT (Amendment) Act, 2008, a clarification was issued by the government which exempted the service providers, which get access to/processes Sensitive Personal Data or information (SPDI) under contractual agreement with a legal entity located within or outside India. Which privacy principle provisions notified under Sec 43A were exempted for the service providers?

Options:

A.

Consent

B.

Privacy policy (which is published)

C.

Access and Correction

D.

Disclosure of information

Questions # 10:

‘Challenging Compliance’ as a privacy principle is covered in which of the following data protection/ privacy act?

Options:

A.

Federal Data Protection Act, Germany

B.

UK Data Protection Act

C.

PIPEDA

D.

Singapore Data Protection Act

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions