Vendor: DSCI
Exam Code: DCPLA
Exam Name: DSCI Certified Privacy Lead Assessor
Date: Jan 10, 2023
File Size: 97 KB

Question 1
__________ calls for inclusion of data protection from the onset of the designing of systems.
  1. Agile Model
  2. Privacy by Design
  3. Logical Design
  4. Safeguarding Approach
Correct answer: B
Question 2
Which of the following are classified as Sensitive Personal Data or Information under Section 43A of ITAA, 2008? (Choose all that apply.)
  1. Password
  2. Financial information
  3. Sexual orientation
  4. Caste and religious beliefs
  5. Biometric information
  6. Medical records and history
Correct answer: BCEF
Question 3
Entities should collect personal information from user that is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. This Privacy Principle is called:
  1. Collection Limitation
  2. Use Limitation
  3. Accountability
  4. Storage Limitation
Correct answer: A
Question 4
The method of personal data usage in which the users must explicitly decide not to participate.
  1. Opt-In
  2. Opt-out
  3. Data mining
  4. Data matching
Correct answer: B
Question 5
An entity shall retain personal data only as long as may be reasonably necessary to satisfy the purpose for which it is processed; or with respect to an established retention period. This privacy principle is known as?
  1. Collection Limitation
  2. Use Limitation
  3. Security safeguards
  4. Storage Limitation
Correct answer: D
Question 6
What are the Nine Privacy Principles as described in DSCI Privacy Framework (DPF)?
I) Use Limitation
II) Accountability
III) Data Quality
IV) Notice
V) Preventing Harm
VI) Choice & Consent
VII) Access and Correction
VIII) Data Minimization
IX) Openness
X) Disclosure to Third Parties
XI) Right to be Forgotten
XII) Collection limitation
XIII) Security
  1. I, II, III, IV, V, VI, VII, VIII, IX
  2. I, II, IV, V, VI, VII, IX, X, XII, XIII
  3. I, II, III, IV, V, VI, VII, VIII, XII
  4. I, II, III, IV, VII, VIII, IX, X, XI
Correct answer: B
Question 7
The concept of data adequacy is based on the principle of _________.
  1. Adequate compliance
  2. Dissimilarity of legislations
  3. Essential equivalence
  4. Essential assessment
Correct answer: C
Question 8
What is a Data Controller?
  1. Entity that collects personal data
  2. Entity that stores personal data
  3. Entity that determines the purpose and means for data processing
  4. Entity that shares personal data with third parties
Correct answer: C
Question 9
What is a Data Subject? (Choose all that apply.)
  1. An individual who provides his/her data/information for availing any service
  2. An individual who processes the data/information of individuals for providing necessary services
  3. An individual whose data/information is processed
  4. A company providing PI of its employees for processing
  5. An individual who collects data from illegitimate sources
Correct answer: AC
Question 10
Your district council releases an interactive of map of orange trees in the district which shows that the locality in which your house is located has the highest concentration of orange trees. Does the council map contain your personal
  1. Yes  your ownership of the property is a matter of public record.
  2. No  Orange trees are not a person and so it can't have personal information.
  3. It depends  on the context of other information associated with the map.
  4. None of the above.
Correct answer: C

