Under the DSCI Privacy Framework and consistent with global definitions (including GDPR and APEC), a “Data Controller” is the entity that determines the purposes and means of processing personal data. For its own employees, an organization inherently controls how their personal data is collected, used, and stored — making it the data controller by default. This is not necessarily the case for clients or supervisory authorities, whose data processing may be governed by different contractual or legal terms.
==============
Question 2
Which of the following is not an objective of POR?
Options:
A.
Create an inventory of business processes, enterprise and operational functions, client relationships that deal with personal information
B.
Identify all the activities, functions and operations that can be attributed to the privacy initiatives of an organization
C.
Evaluate the role of corporate function in legal compliance management, its relations with IT, and security functions. Evaluate the role of legal function in compliance matters
D.
Establish a privacy function to address the activities, functions and operations that are required to manage the privacy initiatives
Answer:
A
Explanation:
The “Privacy Organization and Relationship (POR)” practice area is aimed at building the organizational structure for privacy. It includes:
Establishing the privacy function and governance (D)
Identifying responsibilities and stakeholders (B)
Coordinating between legal, IT, and security functions (C)
Option A relates more to the “Visibility over Personal Information (VPI)” practice area, where data inventories and mapping of processes are core objectives. Hence, it is not aligned with POR.
==============
Question 3
Which of the following statements is true with respect to organization’s privacy training and awareness program?
Options:
A.
It should define roles and responsibilities of personnel in privacy function
B.
It should cover employees of service provider dealing with personal information
C.
It should necessarily cover officials from Law Enforcement Agencies that request lawful access to personal information
D.
None of the above
Answer:
B
Explanation:
The DSCI Privacy Framework emphasizes that a privacy training and awareness program should:
Be role-based and targeted towards those who directly handle or have access to personal information
Include not just internal employees but also extend to third-party vendors and service providers who process personal information on behalf of the organization (B)
Officials from Law Enforcement Agencies (LEAs) are not part of an organization’s training scope; instead, interactions with LEAs are governed by legal access procedures, not internal training.