A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.
For the outsourced work of its customers’ data processing, in order to initiate data transfer to another organizations outside EU, which is the most appropriate among the following?
Under which of the following conditions can a company in India may transfer sensitive personal information (SPI) to any other company or a person in India, or located in any other country?
A country should allow its citizens to access specific information owned by the government in order to bring transparency in the government administration processes. This is the basis for formulation of which of the following rights in India?
Which among the following can be classified as the most important purpose for enactment of data protection/ privacy regulations across the globe?
Rising economic value of personal information has stressed the need for a comprehensive __________ legislation in India.
In India, who among the following would be the authorized legal entities to monitor and intercept communication of individuals?
Company A collects and stores information from people X & Y on behalf of company B. Which of the following statements are true?
Which type of data qualify as Sensitive Personal Data or Information under Section 43A of IT (Amendment) Act, 2008?
Which of the following laid foundation for the development of OECD privacy principles for the promotion of free international trade and trans border data flows?
Which of the following does not fall under the category of Personal Financial Information (PFI)?
Which of the following statements is true in respect of the India specific government projects such as Aadhaar, National Population Register (NPR), etc. that can have privacy implications?
Which of the following doesn’t contribute, or contributes the least, to the growing data privacy challenges in today’s digital age?
Which of the following statement about Personally Identifiable Information (PII) is true?
According to RTI Act, under which conditions can a government department refuse to release information?
The Qatar Concerning Privacy and Protection of Personal Data Act, 2016 addresses different types of personal data, including:
Who should be designated as a grievance officer in IT (Amendment) Act, 2008 to redress grievance(s) from information providers?
It is essential for an entity to comply with US requirements if it operates a website designed for kids or a website for general audiences that gathers information from individuals known to be under 13 years old. Which of the below regulations is applicable?
Which of the following does not fall under the category of Sensitive Personal Data or Information as defined in the Information Technology (Reasonable Security Practices and Procedures and Sensitive Data or Information) Rules, 2011?
From the below listed options, identify the new privacy principle that is being advocated in proposed EU General Data Protection Regulation?
Companies based in EU and willing to transfer data outside the EU/EEA, use model contracts as an instrument. Which of the following statements are true in reference to above statement?
‘Challenging Compliance’ as a privacy principle is covered in which of the following data protection/ privacy act?
XYZ & Co., an Indian hospital specialized in dealing with cancer treatment has organized a free health checkup camp for women in a specific district, after seeking due permission from competent authorities. During the camp the hospital staffs will be feeding the medical records of these women into the computer connected to hospital network system. Does the said hospital need to notify its privacy policy to the women attending the camp and seek their consent regarding the collection and processing of such information?
XYZ is a successful startup that acquired a respectable size & scale of operations in last 3 years, handling business process services for small & medium scale enterprises, largely in US & Europe. They are at the stage of closing a deal with a new banking client and working out the details of privacy related obligations in contract. Ensuring effective enforcement of which of the below listed privacy principles is client’s accountability, even after outsourcing its loan approval process to XYZ?
I. Notice
II. Choice and Consent
III. Collection Limitation
IV. Use Limitation
V. Access and Correction
VI. Security
VII. Disclosure to third Party
Please select the correct set of principles from below listed options:
Indian constitution does not expressly provide for the “right to privacy” to its citizens. However, there were various judicial pronouncements of the apex court which finally established the “right to privacy” as a fundamental right subsumed under Article 21 of the constitution of India. Article 21 inter alia provides and protects the __________________.
Which of the following privacy regulation advocates de-identification of personal information?
A financial organization may share nonpublic information about its customers in accordance with Gramm-Leach-Bliley Act of the US. Which one of the following is the requirement?
Which of the following are key contributors that would enhance the complexity in implementing security measures for protection personal information?
As part of the new EU General Data Protection Regulation, which of the following is being proposed?
In the wake of privacy-related concerns arising from various policies around the world, which of the following has not driven increased regulatory responses?
A privacy lead assessor assessing your company for DSCI’s privacy certification gets to know that your payroll process has been outsourced to a third party service provider. So, he/she is reviewing your contract with that service provider to ascertain which privacy related clauses are incorporated in the contract. What could be the possible reasons for reviewing the contract?
How does the APEC privacy framework differ from the EU Data Protection Directive in the following way?