Home›Learn›Module 2›Self-testModule 2 · Self-testThe core rules8 questions. Pick one answer for each, then mark yourself. Nothing leaves your browser.1. Under Section 4, a Data Fiduciary may process personal data for a lawful purpose on which grounds?Consent, or any purpose that benefits the businessConsent, or certain legitimate usesConsent only; there are no other groundsAny purpose mentioned in its terms of service2. A telemedicine app asks for consent to provide its service and to read the user's phone contact list. She agrees to both. What does Section 6(1) make of her consent?It is valid for both, because she gave a clear affirmative actionIt is invalid for both, because the request was bundledIt is limited to the telemedicine service, because the contact list is not necessary for that purposeIt is valid for both, provided the app later gives a notice3. A customer pays for an order and then withdraws her consent. Under Section 6(5), what may the online store do?Stop her placing new orders, but not stop processing needed to deliver the goods she already paid forCancel the paid order and refund her, because all processing must stop at onceIgnore the withdrawal until the order is delivered and the account closedTreat all past processing as unlawful and erase every record immediately4. Where must a Data Fiduciary's notice under Rule 3 stand?Inside the full privacy policy, so all terms are in one placeOnly in the terms of service accepted at sign-upIn a document filed with the Data Protection BoardOn its own: presented and understandable independently of any other information the Data Fiduciary makes available5. A woman messages a property broker for help finding a flat to rent, then tells him she no longer needs help. Under Section 7(a), what follows?He may keep sending her listings, because she provided the data voluntarilyHe must cease processing her personal data for that purposeHe needs her written consent to keep her data on fileHe must report the change to the Board6. Which of these is on Rule 6's minimum list of reasonable security safeguards?An annual external audit certificateStoring all personal data only on servers in IndiaKeeping logs and personal data for one year to detect, investigate and remediate unauthorised access, unless another law requires otherwiseAppointing a Data Protection Officer7. On becoming aware of a personal data breach, what does Rule 7(2) require the Data Fiduciary to send the Board without delay?A description of the breach, including its nature, extent, timing and location of occurrence and the likely impactA final forensic report naming the person who caused itNothing, unless more than a set number of Data Principals are affectedOnly a copy of the intimation sent to affected Data Principals8. Under Rule 8 and the Third Schedule, an e-commerce entity with not less than two crore registered users in India must erase a dormant user's data after...Thirty days from the last loginOne year from the date of each transactionThree years from when she last approached it or exercised her rights, or the commencement of the Rules, whichever is latestTen years from account closureAnswer all 8 questions to mark