Please select the incorrect statement in context of “Online Privacy”:
A. A person\\’s act of `Selective disclosure” (of themselves) in an online environment
B. A person\\’s concern over usage of information that were collected during an online activity
C. A person\\’s control over collection of information during an online activity
D. A person\\’s concern on the software licensing agreement they sign with any organization
Correct Answer: C

Effective 2013, HIPAA Omnibus rule applies to which of the following?
A. Covered Entities only
B. Business Associates only
C. Covered Entities and Business Associates
D. Federal Health Bodies only
Correct Answer: C
The final Omnibus Rule becomes effective on March 26, 2013. Covered entities and Business Associates Reference:

Indian constitution does not expressly provide for the “right to privacy” to its citizens. However, there were various
judicial pronouncements of the apex court which finally established the “right to privacy” as a fundamental right
subsumed under Article 21 of the constitution of India. Article 21 inter alia provides and protects the
A. Right to Life and Personal liberty
B. Right to Opportunity
C. Right to Freedom of Speech and Expression
D. Right to Equality before law
Correct Answer: A
Article 21 of the Constitution of India, 1950 provides that, “No person shall be deprived of his life or personal liberty
except according to procedure established by law.
Reference: https://www.google.com/search?q=article+21+of+indian+constitutionandrlz=1C1CHBF_enPK808PK808andoq=article+21+of+indiaandaqs=chrome.0.0j69i57j0l4.3344j0j7andsourceid=chromeandie=UTF-8

A multinational company with operations in several parts within EU and outside EU, involves international data transfer
of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization
has a works council. Most of the data transferred is personal, and some of the data that the organization collects is
sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.
Which of the following are not mandatory pre-requisite before transferring sensitive personal data to its Asian
A. Notifying the data subject
B. Conducting risk assessment for the processing involved
C. Determining adequacy status of the country
D. Self-certifying to Safe Harbor practices and reporting to Federal Trade Commission
Correct Answer: D

XYZ and Co., an Indian hospital specialized in dealing with cancer treatment has organized a free health checkup camp
for women in a specific district, after seeking due permission from competent authorities. During the camp the hospital
staffs will be feeding the medical records of these women into the computer connected to hospital network system.
Does the said hospital need to notify its privacy policy to the women attending the camp and seek their consent
regarding the collection and processing of such information?
A. No, since it is a free checkup camp for their welfare
B. Yes, in the any language as per the wishes of said hospital
C. No, since the law does not require the same in this case
D. Yes, in the language such women would understand
Correct Answer: B

With respect to privacy notice, what are the responsibilities of data controller?
A. Providing the notice before or during data collection
B. Identifying and communication the purposes for which data will be collected, used, and disclosed
C. Providing notice after the data collection
D. Providing notice at every instance of data processing
Correct Answer: B

In the history of human evolution, erection of walls and fences around one\\’s living spaces is interpreted as arrival of
which type of privacy consciousness?
A. Data privacy
B. Physical privacy
C. Organizational privacy
D. Communication privacy
Correct Answer: D

With reference to APEC privacy framework, when personal information is to be transferred to another person or
organization, whether domestically or internationally, “the ______________ should obtain the consent of the individual
and exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the
information consistently with APEC information privacy principles”.
A. Personal Information Owner
B. Personal Information Controller
C. Personal Information Processor
D. Personal Information Auditor
Correct Answer: B
Reference: https://iapp.org/news/a/gdpr-matchup-the-apec-privacy-framework-and-cross-border-privacy-rules/

Which of the following factor is least likely to be considered while implementing or augmenting data security solution for
privacy protection:
A. Security controls deployment at the database level
B. Information security infrastructure up-gradation in the organization
C. Classification of data type and its usage by various functions in the organization
D. Training and awareness program for third party organizations
Correct Answer: D

A privacy lead assessor assessing your company for DSCI\\’s privacy certification gets to know that your payroll process
has been outsourced to a third party service provider. So, he/she is reviewing your contract with that service provider to
ascertain which privacy related clauses are incorporated in the contract. What could be the possible reasons for
reviewing the contract?
A. Possible violation of `Collection Limitation\\’
B. Possible violation of `Use Limitation\\’
C. Risk of data subjects directly reaching to service provider
D. Data security controls in third party provider\\’s environment
Correct Answer: A

Which of the following statements are true about the privacy statement of an organization?
A. Content of the online privacy statement of an organization will depend upon the applicable laws, and may need to
address requirements across geographical boundaries and legal jurisdictions
B. As per privacy laws generally it is mandatory to mention the phone contact details of the owner of organization in the
online privacy statement where customers can reach out in case of a grievance or incident
C. Online privacy statement is an instrument to demonstrate to stakeholders how the organization gathers, uses,
discloses, and manages personal data
D. India\\’s Information Technology (Amendment) Act, 2008 does not require that privacy policy be published on the
Correct Answer: A
Reference: https://en.wikipedia.org/wiki/Privacy_policy

BS 10012 is a British standard used to establish ___________.
A. Personal information management system
B. Privacy technology architecture
C. Privacy reference architecture
D. Privacy by design framework
Correct Answer: A
Reference: https://www.itgovernance.co.uk/bs10012_pims

