Home›Learn›Module 4›Self-testModule 4 · Self-testSpecial cases7 questions. Pick one answer for each, then mark yourself. Nothing leaves your browser.1. Who decides that a Data Fiduciary is a Significant Data Fiduciary?The Central Government, by notification, after weighing the factors in Section 10(1)The Data Protection Board, on a complaint from a Data PrincipalThe Data Fiduciary itself, by a self-assessment of its data volumesThe sectoral regulator for that industry, such as a banking or insurance regulator2. Under Rule 13(1), how often must a Significant Data Fiduciary carry out a Data Protection Impact Assessment and an audit?Once, within six months of being notifiedOnce in every period of twelve months from the date of notificationEvery quarter, with a report to the Board each timeOnly when the Board directs one after a complaint3. Which of these is a condition for registration as a Consent Manager in Part A of the First Schedule?The applicant has at least one hundred employees based in IndiaThe applicant holds a licence from the Reserve Bank of IndiaThe applicant is a company incorporated in India with a net worth of not less than two crore rupeesThe applicant is a registered society or trust, not a company4. How does Section 16 deal with transfers of personal data outside India?All transfers are prohibited unless the destination is on a Government whitelistTransfers are allowed only to countries with a data protection law of their ownEvery transfer needs the prior approval of the Data Protection BoardThe Central Government may, by notification, restrict transfer to particular countries or territories5. Where the Section 17(1) exemption applies, which duties still bind the Data Fiduciary?Its overall responsibility for processing done by it or on its behalf, and the duty to take reasonable security safeguardsOnly the duty to give notice and take consentNone; the Act switches off completelyOnly the additional duties in relation to children6. Under Rule 16, processing for research, archiving or statistical purposes is outside the Act if it is carried on...With the prior approval of the Data Protection BoardIn accordance with the standards specified in the Second ScheduleBy a university or a Government research body onlyOn personal data that is anonymised within thirty days7. Rule 5 and the Second Schedule set standards for the State processing personal data in order to...Investigate and prosecute offencesConduct elections and maintain electoral rollsProvide or issue a subsidy, benefit, service, certificate, licence or permitAssess and collect taxesAnswer all 7 questions to mark