Which of the following parameters should ideally be addressed by a privacy program of an organization? (Choose all that apply.)
Answer : A, C
Which of the following is outside the scope of an organization's privacy incident management plan?
Answer : B
A newly appointed Data Protection officer is reviewing the organization's existing privacy policy. Which of the following would be the most critical factor for the review process?
Answer : B
As a privacy lead assessor assessing the company for DSCI's privacy certification, you are assessing the adequacy of resources and skills in the organization, to address privacy related responsibilities.
Which DSCI Privacy Framework (DPF) practice area is relevant?
Answer : B
Privacy enhancing tools aim to allow users to take one or more of the following actions related to their personal data that is sent to, and used by online service providers, merchants or other users:
I) Increase control over their personal data
II) Choose whether to use services anonymously or not
III) Obtain informed consent about sharing their personal data
IV) Opt-out of behavioral advertising or any other use of data
Answer : C
Create an inventory of the specific contractual terms that explicitly mention the data protection requirements. This an imperative of which DPF practice area?
Answer : C
With respect to privacy monitoring and incident management process, which of the following should be a part of a standard incident handling process?
I) Incident identification and notification
II) Investigation and remediation
III) Root cause analysis
IV) User awareness training on how to report incidents
Answer : D