Rashmi recently started working as a customer care representative for a bank. After receiving a customer complaint over the phone, she wrote an email to send to grievance department in the bank. The email included customer's full name, bank account number, residential address, email address and contact number. She picked 2-3 resources/employees from the intranet site of the bank, which belonged to the grievance department and sent the email. Please select the most ideal scenario from a privacy point of view?
-
A
Rashmi should have included some of the customer information in the email and send to grievance team.
-
B
Rashmi did the right thing by sharing all customer details to parties identified from company intranet.
-
C
Rashmi should have ascertained who in the grievance team is/are authorized to handle the complaint request and only then should have sent the customer details to the concerned person(s).
-
D
Reveal answer details
Close answer details
The primary concern from privacy governance perspective for a leading bank is that the personnel working in non-production environment are not always security cleared to operate with the customers' Personal Identifiable Information (PII) used in the production environment. This practice represents a security vulnerability where data can be copied by unauthorized personnel and security measures associated with standard production level controls can be easily bypassed. What technology solutions can be implemented by the organization to overcome this situation:
-
A
Data classification tools can be used to strengthen security of sensitive data.
-
B
Use of tool to mask the sensitive data.
-
C
Define policy for segregation of duties.
-
D
Reveal answer details
Close answer details
When an individual has choice to decide on who else can have access to their personal information, it is called
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which among the following would not be characteristic of a good privacy notice?
-
A
-
B
-
C
Comprehensive ?explaining all the possible scenarios and processing details making the notice lengthy
-
D
Reveal answer details
Close answer details
In the history of human evolution, erection of walls and fences around one's living spaces is interpreted as arrival of which type of privacy consciousness?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Complete the sentence: The Gramm-Leach-Bliley Act (GLBA) of US regulates the privacy practices adopted by financial institutions, requiring them to provide adequate security of the customer records. It lays various obligations on the financial institutions but allows such financial institutions to share the non-public information of customers (after properly notifying their consumers in a manner mentioned in the Act) with
-
A
Its affiliates only after obtaining explicit consent from the consumers
-
B
Its affiliates without need for obtaining explicit consent from the consumers for sharing their data
-
C
Its affiliates after disclosure in initial and annual GLBA privacy notices
-
D
Its affiliates after obtaining explicit permission of Federal Trade Commission
Reveal answer details
Close answer details
Company A collects and stores information from people X & Y on behalf of company B. Which of the following statements are true?
-
A
A is the data controller since it collects data directly from X & Y
-
B
B is the data controller while A is the sub processor as B has outsourced the data collection and processing to A
-
C
B is the data controller that uses A as data processor to collect and process data of data subjects X and Y
-
D
Both A & B are data controllers since both need to maintain highest principles of data protection
Reveal answer details
Close answer details
The Information Technology (Reasonable Security Practices And Procedures and Sensitive Data or Information) Rules, 2011, provide the consumer with which of the following rights?
-
A
Right to Access and Correction
-
B
-
C
Right to Data Portability
-
D
Right to restrict processing
-
E
Reveal answer details
Close answer details
What is not a best practice for maintaining privacy while sharing any personal information on social networking?
-
A
Share it among a closed group
-
B
-
C
Classify it private/secret while sharing
-
D
Make it public to increase transparency
Reveal answer details
Close answer details
Question 10
Single choice
Which one of the following is considered as the first step of evolution in the formation of today's concept of privacy?
-
A
Fundamental civil liberty
-
B
Universal declaration of human rights
-
C
-
D
Reveal answer details
Close answer details
Question 11
Single choice
Anonymity networks and platforms for Privacy Preferences Project (P3P) are generally _________.
-
A
Privacy-enhancing tools and technologies to mask data
-
B
Web based privacy-enhancing technologies
-
C
Network based privacy-enhancing technologies
-
D
Both "Privacy-enhancing tools and technologies to mask data" and "Web based privacy-enhancing technologies"
Reveal answer details
Close answer details
Question 12
Single choice
A government agency collecting biometrics of citizens can deny sharing such information with Law Enforcement Agencies (LEAs) on which of the following basis?
-
A
The purpose of collecting the biometrics is different than what LEAs intent to use it for
-
B
The consent of data subjects has not been taken
-
C
Government agencies would share the biometrics with LEAs on one condition if LEA properly notify the citizens
-
D
None of the above, as government agencies would never deny any LEA for sharing such information for the purpose of mass surveillance
Reveal answer details
Close answer details
Question 13
Single choice
From the following list, identify the technology aspects that are specially designed for upholding the privacy: i. Data minimization ii. Intrusion prevention system iii. Data scrambling iv. Data loss prevention v. Data portability vi. Data obfuscation vii. Data encryption viii. Data mirroring Please select the correct set of aspects from below options:
-
A
Only i., iii., vii. and viii
-
B
Only i., ii., iii., vii. and viii
-
C
Only i., ii., vi. and vii
-
D
Only ii., v., vi., vii. and viii
Reveal answer details
Close answer details
Question 14
Single choice
In India, who among the following would be the authorized legal entities to monitor and intercept communication of individuals?
-
A
"Intermediaries" as defined under the IT (Amendment) Act, 2008
-
B
Telecom Service Providers
-
C
Intelligence and Law Enforcement Agencies
-
D
Directorate of Revenue Intelligence (DRI)
Reveal answer details
Close answer details
Question 15
Single choice
Data Protection officer is reviewing the organization's existing privacy policy. Which of the following would be the most critical factor for the review process? i. Policy definition ii. Policy enforcement iii. IT infrastructure setup iv. Physical infrastructure setup
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
Which of the following aspects of personal information lifecycle management should the privacy function in an organization be concerned with i. Policy definition ii. Policy enforcement iii. IT infrastructure setup iv. Physical infrastructure setup Please select the correct option:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
A newly appointed Data Protection officer is reviewing the organization's existing privacy policy. Which of the following would be the most critical factor for the review process?
-
A
Awareness of the business units about the privacy policy
-
B
Changes in the legal/regulatory regime
-
C
Privacy policies of industry peers
-
D
Foreseeable challenges in the effective implementation of the policy
Reveal answer details
Close answer details
Question 18
Single choice
_______________ calls for inclusion of data protection from the onset of the designing of systems.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 19
Single choice
Which of the following best defines a `Data Subject'?
-
A
One who provides his/her personal information for availing any service
-
B
One who processes the data/information of individuals for providing necessary services
-
C
Corporate entity whose confidential information is shared with business partners
Reveal answer details
Close answer details
Question 20
Single choice
Which of the following could be considered as triggers for updating privacy policy?
-
A
-
B
-
C
Change in service provider for an established business process
-
D
Recruitment of more employees
Reveal answer details
Close answer details
Question 21
Single choice
What are the roles an organization can play from privacy perspective? i. Data Controller - determines the means and purpose of processing of data which is collected from its end customers ii. Data Controller - determines the means and purpose of processing of data which is collected from its employees iii. Data Sub-Processor - processes personal data on behalf of data processor iv. Joint Controller - determines the means and purpose of data processing along with other data controller Please select correct option:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Single choice
In the context of DSCI Privacy Framework (DPF? , what does PPP stand for?
-
A
Public Private Partnership
-
B
Privacy Policy and Processes
-
C
Personal Privacy and Processes
-
D
Private Policy and Procedures
Reveal answer details
Close answer details
Question 23
Single choice
For negligence in implementing and maintaining the reasonable security practices and procedures for protecting Sensitive Personal Data or Information (SPDI) as mentioned in Section 43A and associated rules under IT (Amendment) Act, 2008, a corporate entity may be liable to pay compensation of up to___________
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Single choice
As per Article 33 of GDPR, in case of a personal data breach, the data controller has to inform the supervisory authority within ___________ of becoming aware of the breach.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
What does PHI stand for, as per HIPAA/ HITECH?
-
A
Personal healthcare information
-
B
Public health information
-
C
Protected health information
-
D
Personal health information
Reveal answer details
Close answer details
|