Dsci Certified Privacy Professional Practice Questions
Prepare for DCPP-01 with more than an answer.
- Exam fee
- $250 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 3
- Privacy Fundamentals29.33%
- Privacy Principles and Regulations42.67%
- Privacy Technologies and Organization Ecosystem28%
- 1
From the below listed options, identify the new privacy principle that is being advocated in proposed EU General Data Protection Regulation? A.Right to be informed prior to sharing of dataB.Right to modify dataC.Right to be forgottenD.Right to object data collection and processing
Show answer details
Correct answer: C
- 2
Which of the following statements are true about the privacy statement of an organization? A.Content of the online privacy statement of an organization will depend upon the applicable laws, and may need to address requirements across geographical boundaries and legal jurisdictionsB.As per privacy laws generally it is mandatory to mention the phone contact details of the owner of organization in the online privacy statement where customers can reach out in case of a grievance or incidentC.Online privacy statement is an instrument to demonstrate to stakeholders how the organization gathers, uses, discloses, and manages personal dataD.India’s Information Technology (Amendment) Act, 2008 does not require that privacy policy be published on the website
Show answer details
Correct answer: A
- 3
With respect to ‘Data Minimization’ privacy principle, please select the correct statements from the following: A.Right to object by the data subject for minimizing the collection of personal informationB.Data controllers should limit the amount of data collected to what is directly relevant and necessary to accomplish a specified purposeC.Data controllers should retain the data only for as long as is necessary to fulfil the purpose for which it was collectedD.Process of analyzing and minimizing the collected data into useful information
Show answer details
Correct answer: A
- 4
A hospital is digitizing its patient records. The privacy architect needs to decide on a technology to protect patient data stored in the database, such that data analysts can run queries on trends and statistics without accessing individually identifiable health information. The chosen method must irreversibly prevent the re-identification of any single patient from the dataset. Which Privacy Enhancing Technology (PET) should be used?
graph TD A[Patient Records] --> B{Data Protection Process} B --> C[Protected Dataset] C --> D[Data Analysts] D --> E[Statistical Reports]Show answer details
Correct answer: C
The key requirement is to irreversibly prevent re-identification. This is the definition of anonymization. Techniques like pseudonymization and encryption are reversible (with the right key or mapping table) and thus the data remains personal data. Data masking obscures data but may not fully prevent re-identification. Anonymization, through methods like k-anonymity or l-diversity, aims to make it impossible to link data back to an individual.
