Skip to content

DCPLA Practice Questions

Prepare for DCPLA with more than an answer.

148 questions in the full set9 sample questionsUpdated Aug 11, 2025
Exam fee
$150 USD
Level
Professional
Valid for
Does not expire (but ongoing professional development recommended)
Domains covered on the exam 8
  1. Data Privacy Concepts and Principles
  2. Indian Data Protection Regulatory Framework
  3. DSCI Privacy Framework (DPF)
  4. DSCI Assessment Framework Privacy (DAF-P)
  5. Approaches for Privacy Assessment
  6. Assessment of Organisational Competence in Privacy
  7. Privacy Principles Based Assessment
  8. DSCI Privacy Assessment Manual
  1. 1

    What are the Nine Privacy Principles as described in DSCI Privacy Framework (DPF©)?I: Use Limitation -II: Accountability -III: Data Quality -IV: Notice -V: Preventing Harm -VI: Choice & Consent -VII: Access and Correction -VIII: Data Minimization -IX: Openness -X: Disclosure to Third Parties -XI: Right to be Forgotten -XII: Collection limitation -XIII: Security - A.I, II, III, IV, V, VI, VII, VIII, IXB.I, II, IV, V, VI, VII, IX, X, XII, XIIIC.I, II, III, IV, V, VI, VII, VIII, XIID.I, II, III, IV, VII, VIII, IX, X, XI

    Show answer details

    Correct answer: B

  2. 2

    The concept of data adequacy is based on the principle of _________. A.Adequate complianceB.Dissimilarity of legislationsC.Essential equivalenceD.Essential assessment

    Show answer details

    Correct answer: C

  3. 3

    What is a Data Controller? A.Entity that collects personal dataB.Entity that stores personal dataC.Entity that determines the purpose and means for data processingD.Entity that shares personal data with third parties

    Show answer details

    Correct answer: C

  4. 4

    A lead assessor is reviewing the data flow diagram of a mobile banking application. The diagram shows that the user's precise geolocation data is sent to a third-party marketing analytics provider to 'personalize offers'. This specific data flow and purpose was not disclosed in the customer-facing privacy notice. This is a direct contravention of which core privacy principle, central to the DAF-P assessment?

    graph TD A[Mobile App on User Device] -- Geolocation Data --> B(Third-Party Marketing Analytics) A -- Transaction Data --> C{Bank's Core Processing System} C --> D[Bank's Internal Analytics]

    Show answer details

    Correct answer: C

    The principle of Transparency (often called Notice or Openness) requires organizations to be clear and open about their data processing activities. Sharing precise geolocation data with a third-party for marketing without disclosing this in the privacy notice is a direct violation of this principle. Users have not been informed about this specific use and disclosure of their personal information.

Create an account to continue.