Concepts, Grounds and Principles of Processing
Accountability and Transparency
Rights of Data Subject
Transfer of Personal data outside India
Penalties
100

Which of the following is a form of processing?

A.) storage

B.) retrieval

C.) erasure

D.) all of the above

[Section 3(32)]

100

The Authority can determine that all or any of certain obligations shall apply only to significant data fiduciaries. Which of the following obligations are covered by this?

A.) record keeping and data audits

B.) appointment of data protection officer and conduct of data protection impact assessments

C.) privacy by design, transparency requirements and security safeguards

D.) all of the above

[Section 38(3)]

100

An individual can ask an organization to stop continuous disclosure of his data when which of the following conditions are satisfied:

A.) data was collected through valid consent of the individual and this consent has since been withdrawn.

B.) organization has processed the individual’s data without his/her consent.

C.) organization has disclosed the individual’s data to other organizations without obtaining the individual’s prior consent.

A – The right to be forgotten. 

[Section 27(1)(b)]

100

As per the data localization requirements, one copy of which of the following types of data should be stored within India?

A.) all personal data.

B.) only sensitive data.

C.) only critical data.

A

[Section 40(1)]

100

The servers of company “X” are hacked resulting in the names and PAN card numbers of 2000 people becoming compromised. The company fails to notify the Authority of the breach. Which of the following penalties will “X” be liable to incur?

A.) Fine up to INR 5 crore or 2% global turnover, whichever is higher.

B.) Fine up to INR 5 crore or 2% domestic Indian turnover, whichever is higher.

C.) Fine up to INR 5 crore.

D.) Fine up to 2% of domestic Indian turnover.

[Section 69(1)]

200

Which of the following is not a facet of the principle of accountability?

A.) Data fiduciary is responsible for complying with all obligations under the Bill in respect of any processing undertaken by it.

B.) Data fiduciary must be able to demonstrate that any processing undertaken is in compliance with the Bill.

C.) Data fiduciary must ensure that any organization processing data on its behalf is accountable for any data breaches that occur.

D.) a & b

[Section 11]

200

A company “X” exclusively engages and contracts with company “Y” for human resource management services. While rendering these services, “Y” decides to move the data from its own server to a third party server on its own accord. Was “Y” permitted to do so?

No – “Y” cannot engage another data processor without the prior permission of “X”. 

[Section 37]

200

An organization “X” buys a data set of consumers from an organization “Y” which includes the name and contact details of an individual “A”. Can “A” approach “X” and enquire if his/her data is being processed by “X”?

Yes. – The right to confirmation and access. 

[Section 26(1)]

200

“Critical” personal data includes which of the following categories of data?

A.) financial data.

B.) medical data.

C.) categories of data to be notified by the Government.

[Section 40(2)]

200

Company “X”, who is a significant fiduciary, fails to comply with a right to access and confirmation request from a data principal or offer an explanation for doing so. Which of the following liabilities will “X” be liable to incur?

A.) INR 5000 for each day of default up to a maximum of INR 10 lakh.

B.) INR 5000 for each day of default up to a maximum of INR 5 lakh.

C.) INR 3000 for each day of default up to a maximum of INR 10 lakh.

D.) INR 3000 for each day of default up to a maximum of INR 5 lakh.

[Section 70]

300

Apart from consent, there are various other specific grounds for processing personal data. Which of the following is not a valid ground for processing?

A.) Processing for prompt action in case of a medical emergency involving the data principal.

B.) Processing for purposes related to employment.

C.) Processing for prompt action in case of a financial emergency involving the data principal.  

D.) Processing in compliance with law or an order of a court or tribunal.

[Section 14, 15 &16]

300

A Data Protection Impact Assessment will not be required in which of the following situations?

A.) Processing involves risk of significant harm to data principals.

B.) Processing involves new technologies.

C.) Processing involves large scale processing and use of sensitive personal data.

D.) Processing involves storage of data in a foreign country.

[Section 33(1)]

300

An individual approaches the customer help desk of an online retailer along with adequate ID and orally requests them to provide a summary of his/her personal data being processed. Does the customer help desk provide him with the same?

No. – Requests must always be made in writing. 

[Section 28(1)]

300

India prescribes that cross border transfer of personal data to a country “A” is permissible. On this basis can a company transfer personal data from India to that country?

No, specific consent of the data principal for such transfer must also be obtained. 

[Section 41(d)]

300

A data principal has the right to seek compensation from data fiduciary or data processor if suffers any harm as a result of any violation of the Personal Data Protection Bill. Under which of the following circumstances can a data processor not incur liability?

A.) data processor has acted in a negligent manner.

B.) data processor has failed to notify affected data principals on the occurrence of a data breach.

C.) data processor acted contrary to the data fiduciary’s instructions.

D.) data processor has not incorporated adequate security safeguards.

[Section 75(1)]

400

Sensitive personal data can be processed on the basis of obtaining explicit consent from the data principal. Which of the following requirements need to be fulfilled for consent to be considered “explicit”?

A.) consent has to be informed

B.) consent has to be clear

C.) consent has to be specific

D.) all of the above.

[Section 18(2)]

400

True or False - when a data breach occurs, the data fiduciary must always inform all the affected data principals.

False – only as per directions of Authority. 

[Section 32(5)]

400

Which of the following rights can only be exercised only after approval by an Adjudicating Officer?

A.) Right to be forgotten.

B.) Right to data portability.

C.) Right to correction.

D.) right to confirmation and access.

[Section 27(2)]

400

The Central Government may exempt certain categories of personal data from data localization on the grounds of necessity or strategic interest. To which of the following categories of data does this not apply?

A.) Health data.

B.) Biometric data.

C.) Name.

D.) a & b.


[Section 40(4)]

400

What penalty is prescribed for a data fiduciary who fails to furnish any report, return or information to the Authority?

A.) a fine up to INR 5 crore or 2% of total global turnover.

B.) a fine up to INR 15 crore or 4% of total global turnover.

C.) a fine of INR 10000 for each day of default up to a maximum of INR 5 lakh.

D.) a fine of INR 5000 for each day of default up to a maximum of INR 10 lakh.

[Section 71]