WorksheetsShieldUp2023: Assessment
Total questions: 25
Worksheet time: 13mins
What is considered personal information under the Data Privacy Act (DPA) of 2012?
Only sensitive information
Any information that identifies an individual
Corporate information only
Information stored in the cloud
Which of the following is an example of personal information?
Which of the following is an example of personal information?
Employee work schedule
Customer's email address
Publicly available business contact information
In data privacy, what does the principle of data minimization refer to?
Limiting the use of personal information to a specific purpose
Collecting only the necessary data for the intended purpose
Maximizing the amount of data collected for future use
Storing data indefinitely
Under the DPA, what rights do data subjects have regarding their personal information?
Right to unlimited access
Right to erasure
Right to sell their data
Right to modify company policies
If a customer requests access to their personal information, how should the company respond?
Ignore the request
Comply within 30 days
Request additional payment
Share information publicly
What is the importance of having a privacy policy on Edamama's platforms?
It is a legal requirement
It ensures faster website loading
It boosts sales
It is optional
Which of the following is a recommended practice for securing customer data?
Sharing passwords among employees
Regularly updating security software
Storing customer data in an unsecured database
Allowing public access to customer records
When is a Privacy Impact Assessment (PIA) typically conducted?
After a data breach
Before implementing a new system or process
Only for sensitive information
Every five years
What is the primary goal of a Privacy Impact Assessment?
To maximize data collection
To identify and mitigate privacy risks
To increase transparency
To promote data sharing
In the event of a data breach, what is the recommended first step?
Continue normal operations
Notify affected individuals and the National Privacy Commission (NPC)
Delete all affected data immediately
Conduct an internal investigation
What constitutes a data breach under the DPA?
Any unauthorized access to personal information
Only breaches involving financial data
Breaches that occur during office hours
Accidental sharing of public information
An employee accidentally sends an email containing customer information to the wrong recipient. What should be the immediate action taken?
Ignore the incident
Report to the immediate manager / privacy team
Delete the email without informing anyone
Wait for the customer to report the incident
A customer requests the deletion of their personal information, but the company is required to keep it for legal purposes. What should the company do?
Ignore the request
Delete the information immediately
Explain the legal requirements to the customer
Suspend the customer's account
During a system upgrade, a vulnerability is discovered that may expose customer data. What should the Tech team do?
Proceed with the upgrade and address the issue later
Inform the management about the vulnerability
Keep the information confidential to avoid panic
Downplay the severity of the vulnerability
One of the CS Team members receives a call from an individual claiming to be a customer and requests detailed information about their recent transactions. How should the CS member respond?
Provide the information as requested to assist the customer
Politely refuse and inform the customer about the company's privacy policies
Transfer the call to a supervisor without providing any information
Ask the customer to provide sensitive information to verify their identity
During a company training session, an employee mentions overhearing colleagues discussing confidential customer data in a public place. What should be done to address this situation?
Disregard the comment as it may not be accurate
Report the incident to the data protection officer or manager
Confront the colleagues publicly to clarify the situation
Wait for someone else to raise the concern
A vendor requests access to customer data for marketing purposes, but this was not part of the original agreement. How should you handle this request?
Share the data to strengthen the vendor relationship
Update the agreement to include data sharing and then proceed
Refuse the request and inform the vendor about the data privacy policy
Seek customer consent without informing them about the vendor's request
An employee notices a colleague accessing customer data for personal use. What action should the employee take?
Ignore the behavior as it doesn't directly affect them
Confront the colleague directly about the inappropriate use
Report the incident to the data protection officer or manager
Join the colleague in accessing customer data for personal use
A customer complains about receiving marketing emails despite unsubscribing multiple times. What should the CS team do to address this complaint?
Ignore the complaint as it might be a technical glitch
Explain the situation and apologize for the inconvenience
Request the customer to resubscribe and then unsubscribe again
Block the customer from future email communications
An employee receives an email with a link claiming to be a software update for a commonly used program. What should the employee do?
Click on the link to ensure the software is up to date
Forward the email to the IT department for verification
Ignore the email as it is likely spam
Share the link with colleagues to see if they received a similar email
A customer requests a copy of all the data the company holds about them. What is the appropriate response?
Ignore the request, as it is too time-consuming
Provide the information promptly without any verification
Request additional identification to ensure the data is shared with the right person
Decline the request, citing data security concerns
An Edamama executive insists on accessing customer data without proper authorization, citing urgency. What should employees do in this situation?
Comply with the executive's request to avoid conflict
Report the incident to the data protection officer or manager
Confront the executive directly about the unauthorized request
Share customer data with the executive but document the incident
A customer requests to know which third parties have received their personal data. How should the company respond?
Share the information freely to maintain transparency
Refuse the request, citing confidentiality agreements with third parties
Provide a general list without specific details to protect third-party relationships
Ask the customer to contact third parties directly for this information
A customer accidentally receives an email with another customer's personal details. What immediate steps should the customer service team take?
Ignore the incident, as it was accidental
Ask the customer to delete the email and forget about it
Report the incident to the data protection officer
Apologize to the customer and continue with regular operations
Edamama's Marketing team wants to implement a new analytics tool that tracks customer behavior on the website. What considerations should be taken regarding data privacy?
Implement the tool without informing customers to gather more data
Clearly communicate the implementation of the tool in the updated privacy policy
Implement the tool and inform customers afterward to avoid resistance
Ask customers individually for permission to track their behavior
