Exam Details

  • Exam Code
    :DCPP-01
  • Exam Name
    :DSCI certified Privacy Professional (DCPP)
  • Certification
    :DSCI Certifications
  • Vendor
    :DSCI
  • Total Questions
    :162 Q&As
  • Last Updated
    :May 05, 2025

DSCI DSCI Certifications DCPP-01 Questions & Answers

  • Question 121:

    "As per Indian laws, any information that is freely available or accessible in public domain cannot be regarded as sensitive personal data or information."

    Please state if this statement is True or False.

    A. True

    B. False

  • Question 122:

    Which of the following laws does not have a mandatory personal data breach notification requirement?

    A. General Data Protection Regulation, 2016

    B. Information Technology (Amendment) Act, 2008

    C. Japanese Act on the Protection of Personal Information

    D. UK Data Protection Act, 2018

  • Question 123:

    The Information Technology (Reasonable Security Practices And Procedures and Sensitive Data or Information) Rules, 2011 incorporate which of the following privacy concepts and principles:

    i. Collection Limitation

    ii. Accountability

    iii. Right to be forgotten

    iv.

    Purpose Limitation

    v.

    Access and correction

    A.

    i, ii, iii and iv

    B.

    I, ii, iv and v

    C.

    I, iii, iv and v

    D.

    All the above

  • Question 124:

    With reference to APEC privacy framework, which of the following statements are true?

    A. The APEC Privacy Framework is intended to promote a flexible approach to information privacy protection across APEC members, while at the same time avoiding the creation of needless barriers to information flows.

    B. The APEC framework is detailed and prescribes stringent controls that need to be implemented for trans-border data flows to initiate.

    C. Companies can be certified by attested third parties for compliance to requirements mentioned under APEC Privacy Framework.

    D. Governments which are part of the APEC, authorize data transfer as per APEC privacy framework.

  • Question 125:

    While transferring personal data from an EU member nation to a third country which is not deemed adequate as per EU's assessment, which of the following step is not relevant?

    A. Signing of model contractual clauses

    B. Notifying or taking approval from the Data Protection Authority

    C. Assessing the appropriateness of safeguards and measures adopted by the importing organization commensurate to the sensitivity of data being transferred

    D. Harmonizing data protection legislations between the two geographies

  • Question 126:

    As per Article 33 of GDPR, in case of a personal data breach, the data controller has to inform the supervisory authority within ___________ of becoming aware of the breach.

    A. 48 hours

    B. 14 days

    C. 72 hours

    D. 24 hours

  • Question 127:

    Which of the following wasn't prescribed as a privacy principle under the OECD Privacy Guidelines, 1980?

    A. Openness

    B. Data minimization

    C. Security Safeguard

    D. Purpose Specification

  • Question 128:

    As per Article 6 of General Data Protection Regulation, 2016, which of the following is not a lawful ground of processing personal data?

    A. Performance of Contract

    B. Legal Obligation

    C. Legitimate Interest

    D. Consent

    E. Vital Interest

    F. All of them are lawful grounds of processing personal data

  • Question 129:

    If an entity operates a website designed for kids or a website that targets general audience but collects information from individuals known to be under age of 13 years, the entity must comply with requirements in the US.

    A. Child online protection Act, 1998

    B. Gramm-Leach-Bliley Act, 1999

    C. Personal Information Protection and Electronic Documents Act (PIPEDA)

    D. Sarbanes-Oxley Act, 2000

  • Question 130:

    As per GDPR, the adequacy decision is taken the European Commission based on its findings and assessment of privacy laws of the third country, territory, sector, etc. The ____________ is required to provide the Commission with an opinion for the assessment of the adequacy of the level of protection in a third country or international organization, including for the assessment whether a third country, a territory or one or more specified sectors within that third country, or an international organization.

    A. European Data Protection Board

    B. Article 29 Working Party

    C. Lead Supervisory Authority

    D. Convention 108 Council

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only DSCI exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your DCPP-01 exam preparations and DSCI certification application, do not hesitate to visit our Vcedump.com to find your solutions here.