Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ShieldUp2023: Assessment

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

What is considered personal information under the Data Privacy Act (DPA) of 2012?

a)

Only sensitive information

b)

Any information that identifies an individual

c)

Corporate information only

d)

Information stored in the cloud

2.

Which of the following is an example of personal information?

a)

Which of the following is an example of personal information?

b)

Employee work schedule

c)

Customer's email address

d)

Publicly available business contact information

3.

  1. In data privacy, what does the principle of data minimization refer to?

a)

Limiting the use of personal information to a specific purpose

b)

Collecting only the necessary data for the intended purpose

c)

Maximizing the amount of data collected for future use

d)

Storing data indefinitely

4.

Under the DPA, what rights do data subjects have regarding their personal information?

a)

Right to unlimited access

b)

Right to erasure

c)

Right to sell their data

d)

Right to modify company policies

5.

If a customer requests access to their personal information, how should the company respond?

a)

Ignore the request

b)

Comply within 30 days

c)

Request additional payment

d)

Share information publicly

6.

What is the importance of having a privacy policy on Edamama's platforms?

a)

It is a legal requirement

b)

It ensures faster website loading

c)

It boosts sales

d)

It is optional

7.

Which of the following is a recommended practice for securing customer data?

a)

Sharing passwords among employees

b)

Regularly updating security software

c)

Storing customer data in an unsecured database

d)

Allowing public access to customer records

8.

When is a Privacy Impact Assessment (PIA) typically conducted?

a)

After a data breach

b)

Before implementing a new system or process

c)

Only for sensitive information

d)

Every five years

9.

What is the primary goal of a Privacy Impact Assessment?

a)

To maximize data collection

b)

To identify and mitigate privacy risks

c)

To increase transparency

d)

To promote data sharing

10.

In the event of a data breach, what is the recommended first step?

a)

Continue normal operations

b)

Notify affected individuals and the National Privacy Commission (NPC)

c)

Delete all affected data immediately

d)

Conduct an internal investigation

11.

What constitutes a data breach under the DPA?

a)

Any unauthorized access to personal information

b)

Only breaches involving financial data

c)

Breaches that occur during office hours

d)

Accidental sharing of public information

12.

An employee accidentally sends an email containing customer information to the wrong recipient. What should be the immediate action taken?

a)

Ignore the incident

b)

Report to the immediate manager / privacy team

c)

Delete the email without informing anyone

d)

Wait for the customer to report the incident

13.

A customer requests the deletion of their personal information, but the company is required to keep it for legal purposes. What should the company do?

a)

Ignore the request

b)

Delete the information immediately

c)

Explain the legal requirements to the customer

d)

Suspend the customer's account

14.

During a system upgrade, a vulnerability is discovered that may expose customer data. What should the Tech team do?

a)

Proceed with the upgrade and address the issue later

b)

Inform the management about the vulnerability

c)

Keep the information confidential to avoid panic

d)

Downplay the severity of the vulnerability

15.

One of the CS Team members receives a call from an individual claiming to be a customer and requests detailed information about their recent transactions. How should the CS member respond?

a)

Provide the information as requested to assist the customer

b)

Politely refuse and inform the customer about the company's privacy policies

c)

Transfer the call to a supervisor without providing any information

d)

Ask the customer to provide sensitive information to verify their identity

16.

During a company training session, an employee mentions overhearing colleagues discussing confidential customer data in a public place. What should be done to address this situation?

a)

Disregard the comment as it may not be accurate

b)

Report the incident to the data protection officer or manager

c)

Confront the colleagues publicly to clarify the situation

d)

Wait for someone else to raise the concern

17.

A vendor requests access to customer data for marketing purposes, but this was not part of the original agreement. How should you handle this request?

a)

Share the data to strengthen the vendor relationship

b)

Update the agreement to include data sharing and then proceed

c)

Refuse the request and inform the vendor about the data privacy policy

d)

Seek customer consent without informing them about the vendor's request

18.

An employee notices a colleague accessing customer data for personal use. What action should the employee take?

a)

Ignore the behavior as it doesn't directly affect them

b)

Confront the colleague directly about the inappropriate use

c)

Report the incident to the data protection officer or manager

d)

Join the colleague in accessing customer data for personal use

19.

A customer complains about receiving marketing emails despite unsubscribing multiple times. What should the CS team do to address this complaint?

a)

Ignore the complaint as it might be a technical glitch

b)

Explain the situation and apologize for the inconvenience

c)

Request the customer to resubscribe and then unsubscribe again

d)

Block the customer from future email communications

20.

An employee receives an email with a link claiming to be a software update for a commonly used program. What should the employee do?

a)

Click on the link to ensure the software is up to date

b)

Forward the email to the IT department for verification

c)

Ignore the email as it is likely spam

d)

Share the link with colleagues to see if they received a similar email

21.

A customer requests a copy of all the data the company holds about them. What is the appropriate response?

a)

Ignore the request, as it is too time-consuming

b)

Provide the information promptly without any verification

c)

Request additional identification to ensure the data is shared with the right person

d)

Decline the request, citing data security concerns

22.

An Edamama executive insists on accessing customer data without proper authorization, citing urgency. What should employees do in this situation?

a)

Comply with the executive's request to avoid conflict

b)

Report the incident to the data protection officer or manager

c)

Confront the executive directly about the unauthorized request

d)

Share customer data with the executive but document the incident

23.

A customer requests to know which third parties have received their personal data. How should the company respond?

a)

Share the information freely to maintain transparency

b)

Refuse the request, citing confidentiality agreements with third parties

c)

Provide a general list without specific details to protect third-party relationships

d)

Ask the customer to contact third parties directly for this information

24.

A customer accidentally receives an email with another customer's personal details. What immediate steps should the customer service team take?

a)

Ignore the incident, as it was accidental

b)

Ask the customer to delete the email and forget about it

c)

Report the incident to the data protection officer

d)

Apologize to the customer and continue with regular operations

25.

Edamama's Marketing team wants to implement a new analytics tool that tracks customer behavior on the website. What considerations should be taken regarding data privacy?

a)

Implement the tool without informing customers to gather more data

b)

Clearly communicate the implementation of the tool in the updated privacy policy

c)

Implement the tool and inform customers afterward to avoid resistance

d)

Ask customers individually for permission to track their behavior