DSCI DCPP-01 DSCI certified Privacy Professional Online Training
DSCI DCPP-01 Online Training
The questions for DCPP-01 were last updated at Nov 23,2024.
- Exam Code: DCPP-01
- Exam Name: DSCI certified Privacy Professional
- Certification Provider: DSCI
- Latest update: Nov 23,2024
Which among the following is the Canadian privacy law?
- A . COPPA
- B . PIPEDA
- C . HIPAA
- D . IT Act of Canada
ABC company is a large US based IT Company that provides a range of services to its clients. The company had developed a cloud based application providing end-to-end services for the medical industry.
The application had three modules for:
– Patients
– Hospitals and Doctors
– Insurance and Pharmaceutical companies
Each of the modules was designed to be integrated with others depending on user’s choice. For example, a patient could choose to share his/her medical history with his/her doctor (for medical advice) as well as insurance companies (for claims).
The application requires that all registered users of the application read and acknowledge the privacy policy. Additionally, users are required to identify the purpose for which they are providing any personal data in any of the modules. For example, a patient providing his/her medical history and current symptoms can select ‘Medical Advice’ as the purpose for the data being provided.
Few months ago, company launched new services in the applications namely, Business Analytics, Group Consultations, Insurance Policy purchase, and Medical Trials Management. The new services used all existing data collected over the years from users. The Company’s clients/users are based only in three geographical locations – United States, European Union and India. Additionally, to facilitate better performance of its application, the company established one datacenter each in US, Germany and India for its operations. Each of the datacenter provides the following: -US Datacenter – Storage of data for US based users only -Germany Datacenter – Storage of data for EU based users only -India Datacenter – Storage of data for India based users and alternate site for US and Germany Datacenters (used as part of global load balancing) -Services of a cloud service provider are leveraged in US as a Disaster Recovery (DR) site for Indian Datacenter
Recently, the company’s Application Support Desk has started receiving user complaints related to unsolicited communications.
These complaints have warranted a review of company’s privacy policies as well as practices.
The use of all user data for business analytics would be in direct conflict with which of the following privacy principles?
- A . Access and Correction
- B . Collection Limitation
- C . Data Quality
- D . Use Limitation
If an entity operates a website designed for kids or a website that targets general audience but collects information from individuals known to be under age of 13 years, the entity must comply with requirements in the US.
- A . Child online protection Act, 1998
- B . Gramm-Leach-Bliley Act, 1999
- C . Personal Information Protection and Electronic Documents Act (PIPEDA)
- D . Sarbanes-Oxley Act, 2000
As per GDPR, the adequacy decision is taken the European Commission based on its findings and assessment of privacy laws of the third country, territory, sector, etc. The ____________ is required to provide the Commission with an opinion for the assessment of the adequacy of the level of protection in a third country or international organization, including for the assessment whether a third country, a territory or one or more specified sectors within that third country, or an international organization.
- A . European Data Protection Board
- B . Article 29 Working Party
- C . Lead Supervisory Authority
- D . Convention 108 Council
As per Article 33 of GDPR, in case of a personal data breach, the data controller has to inform the supervisory authority within ___________ of becoming aware of the breach.
- A . 48 hours
- B . 14 days
- C . 72 hours
- D . 24 hours
Which of the following wasn’t prescribed as a privacy principle under the OECD Privacy Guidelines, 1980?
- A . Openness
- B . Data minimization
- C . Security Safeguard
- D . Purpose Specification
As per Article 6 of General Data Protection Regulation, 2016, which of the following is not a lawful ground of processing personal data?
- A . Performance of Contract
- B . Legal Obligation
- C . Legitimate Interest
- D . Consent
- E . Vital Interest
- F . All of them are lawful grounds of processing personal data
“As per Indian laws, any information that is freely available or accessible in public domain cannot be regarded as sensitive personal data or information.”
Please state if this statement is True or False.
- A . True
- B . False
Which of the following laws does not have a mandatory personal data breach notification requirement?
- A . General Data Protection Regulation, 2016
- B . Information Technology (Amendment) Act, 2008
- C . Japanese Act on the Protection of Personal Information
- D . UK Data Protection Act, 2018
The Information Technology (Reasonable Security Practices And Procedures and Sensitive Data or Information) Rules, 2011 incorporate which of the following privacy concepts and principles:
i. Collection Limitation
ii. Accountability
iii. Right to be forgotten
iv. Purpose Limitation
v. Access and correction
- A . i, ii, iii and iv
- B . I, ii, iv and v
- C . I, iii, iv and v
- D . All the above