VALUATION EXAMINATION
MOCK TEST
DIGITAL PERSONAL DATA PROTECTION ACT, 2023
25 Multiple Choice Questions
Important exam note: IBBI’s syllabus specifically places the DPDP Act and Rules within Professional/Business Ethics and Standards, carrying 3% weight in the Land & Building syllabus. The statutory questions above also reflect important provisions concerning consent, Data Fiduciary responsibility, retention, children, Significant Data Fiduciaries, Data Principal rights, exemptions, the Data Protection Board and penalties.
For the Rules portion, particular attention should be paid to Rule 6 (security safeguards), Rule 7 (personal data breach notification), Rule 8 (retention), Rule 14 (Data Principal rights), Rule 15 (transfer outside India), and the First Schedule concerning Consent Managers.
Official reference: IBBI – Valuation Examination syllabus w.e.f. 21 August 2026 | MeitY – Digital Personal Data Protection Rules, 2025
QUESTION NO.-1 :
What is the principal objective of the Digital Personal Data Protection Act, 2023?
OPTION 1 : To regulate only government databases
OPTION 2 : To provide for processing of digital personal data in a manner that recognises the right of individuals to protect their personal data while permitting lawful processing
OPTION 3 : To regulate only cyber-crimes committed through computers
OPTION 4 : To regulate valuation of digital assets
CORRECT ANSWER : OPTION 2
EXPLANATION:
The DPDP Act, 2023 establishes a framework for processing digital personal data while recognising the individual’s right to protect personal data and the need to process such data for lawful purposes. For a registered valuer, this is particularly relevant because valuation assignments may involve personal information contained in financial statements, title records, employee records, loan documents, customer databases and other records.
QUESTION NO.-2 :
Under the DPDP Act, 2023, a person to whom the personal data relates is known as:
OPTION 1 : Data Processor
OPTION 2 : Data Fiduciary
OPTION 3 : Data Principal
OPTION 4 : Data Auditor
CORRECT ANSWER : OPTION 3
EXPLANATION:
The individual to whom the personal data relates is called the Data Principal. The entity determining the purpose and means of processing is generally the Data Fiduciary, while a person processing personal data on behalf of the Data Fiduciary is a Data Processor.
QUESTION NO.-3 :
A registered valuer receives personal data from a company for preparing a valuation report and processes that data on behalf of the company. In such circumstances, the valuer may ordinarily be regarded as:
OPTION 1 : Data Principal
OPTION 2 : Data Processor, depending upon the contractual and factual arrangement
OPTION 3 : Consent Manager automatically
OPTION 4 : Data Protection Board
CORRECT ANSWER : OPTION 2
EXPLANATION:
The classification depends on the actual role performed. Where the valuer processes personal data on behalf of the client/Data Fiduciary, the valuer may function as a Data Processor. The DPDP Act specifically permits a Data Fiduciary to engage a Data Processor for processing personal data on its behalf under a valid contract. Section 8 also places responsibility on the Data Fiduciary for processing undertaken by it or on its behalf by a Data Processor.
QUESTION NO.-4 :
Which of the following is a fundamental obligation of a Data Fiduciary under Section 8 of the DPDP Act?
OPTION 1 : To publish all personal data on its website
OPTION 2 : To implement appropriate technical and organisational measures
OPTION 3 : To permanently retain all personal data
OPTION 4 : To disclose personal data to every valuer
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 8 requires a Data Fiduciary to implement appropriate technical and organisational measures for effective compliance with the Act and Rules. It must also take reasonable security safeguards to prevent personal data breaches.
QUESTION NO.-5 :
A valuation professional is provided with personal data by a client. The valuation report does not require disclosure of an individual’s mobile number, Aadhaar-related information or personal email address. What is the most appropriate professional approach?
OPTION 1 : Include all such information in the valuation report
OPTION 2 : Publish the information because it was supplied by the client
OPTION 3 : Use and disclose only information necessary and appropriate for the legitimate valuation purpose, subject to applicable law and instructions
OPTION 4 : Sell the information to another valuer
CORRECT ANSWER : OPTION 3
EXPLANATION:
A valuer’s professional obligations include confidentiality and appropriate information management. Personal information should not be unnecessarily reproduced or disclosed merely because it was received during an assignment. The DPDP framework reinforces responsible handling of personal data.
QUESTION NO.-6 :
Where consent is the basis for processing personal data, the Data Principal has the right to:
OPTION 1 : Withdraw consent at any time, subject to the Act
OPTION 2 : Withdraw consent only after ten years
OPTION 3 : Withdraw consent only with approval of the Data Protection Board
OPTION 4 : Never withdraw consent
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 6 provides that where consent is the basis of processing, the Data Principal may withdraw consent at any time. The ease of withdrawing consent should be comparable to the ease with which consent was given. Withdrawal does not retrospectively invalidate processing that was lawful before withdrawal.
QUESTION NO.-7 :
If a question arises in a proceeding regarding whether consent was validly obtained, who bears the obligation to prove that proper notice was given and consent was obtained?
OPTION 1 : Data Principal
OPTION 2 : Data Processor
OPTION 3 : Data Fiduciary
OPTION 4 : Data Protection Officer personally
CORRECT ANSWER : OPTION 3
EXPLANATION:
Section 6(10) places the evidentiary burden on the Data Fiduciary to prove that notice was given and consent was obtained in accordance with the Act and Rules.
QUESTION NO.-8 :
Under the DPDP Act, a Data Fiduciary may process personal data without consent in certain circumstances identified as:
OPTION 1 : Unlimited commercial uses
OPTION 2 : Certain legitimate uses
OPTION 3 : Automatic public disclosure
OPTION 4 : Unrestricted data trading
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 7 identifies specified legitimate uses where personal data may be processed without consent, subject to the statutory conditions. These include certain State functions, legal obligations, compliance with judgments/orders, medical emergencies, public health/disaster situations and specified employment-related purposes.
QUESTION NO.-9 :
Which of the following is specifically recognised as a legitimate use under Section 7 of the DPDP Act?
OPTION 1 : Selling personal data to competitors
OPTION 2 : Processing necessary for responding to a medical emergency involving a threat to life or immediate threat to health
OPTION 3 : Publishing personal data for entertainment
OPTION 4 : Sharing personal data with unknown third parties without purpose
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 7 includes processing necessary for responding to a medical emergency involving a threat to the life or an immediate threat to the health of the Data Principal or another individual.
QUESTION NO.-10 :
A Data Fiduciary engages a cloud service provider to process personal data on its behalf. Under Section 8, the Data Fiduciary:
OPTION 1 : Automatically ceases to have any responsibility
OPTION 2 : Remains responsible for compliance in respect of processing undertaken by it or on its behalf by the Data Processor
OPTION 3 : Can transfer all statutory responsibility to the cloud provider
OPTION 4 : Is prohibited from using a Data Processor
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 8(1) expressly provides that the Data Fiduciary remains responsible for compliance with the Act and Rules in respect of processing undertaken by it or on its behalf by a Data Processor. This is highly relevant where valuers use cloud storage, document-management systems or external IT service providers.
QUESTION NO.-11 :
When personal data processed by a Data Fiduciary is likely to be used to make a decision affecting the Data Principal, the Data Fiduciary must ensure:
OPTION 1 : Completeness, accuracy and consistency of such personal data
OPTION 2 : That the data is publicly available
OPTION 3 : That the data is never corrected
OPTION 4 : That the data is transferred outside India
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 8(3) requires the Data Fiduciary to ensure completeness, accuracy and consistency where personal data is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary.
QUESTION NO.-12 :
Under Section 8, what is the general position regarding retention of personal data after the specified purpose is no longer being served?
OPTION 1 : It must always be retained permanently
OPTION 2 : It should generally be erased unless retention is necessary under applicable law
OPTION 3 : It must be sold to another Data Fiduciary
OPTION 4 : It must automatically be published
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 8(7) provides for erasure of personal data when the specified purpose is no longer being served or when consent is withdrawn, unless retention is necessary for compliance with applicable law. The corresponding Data Processor must also be caused to erase the data, subject to the statutory exception.
QUESTION NO.-13 :
A registered valuer’s assignment has been completed. However, certain personal data must be retained because another applicable law requires retention for a specified period. Under the DPDP Act, the data:
OPTION 1 : Must necessarily be deleted immediately
OPTION 2 : May be retained where retention is necessary for compliance with applicable law
OPTION 3 : Must be published
OPTION 4 : Must be transferred to the Data Principal
CORRECT ANSWER : OPTION 2
EXPLANATION:
The erasure obligation is subject to the exception where retention is necessary for compliance with a law for the time being in force. Therefore, a valuer should not mechanically delete records where another applicable statutory or regulatory retention obligation exists.
QUESTION NO.-14 :
The DPDP Act prohibits a Data Fiduciary from undertaking certain processing of children’s personal data. Which of the following is expressly prohibited, subject to statutory exceptions?
OPTION 1 : All processing of children’s data
OPTION 2 : Tracking or behavioural monitoring of children or targeted advertising directed at children
OPTION 3 : Maintaining any lawful record concerning a child
OPTION 4 : Providing any service to children
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 9 generally prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exceptions. It also prohibits processing likely to cause a detrimental effect on the well-being of a child.
QUESTION NO.-15 :
For processing personal data of a child, the Data Fiduciary is generally required to obtain:
OPTION 1 : Verifiable consent of the parent or lawful guardian
OPTION 2 : Consent of any employee of the Data Fiduciary
OPTION 3 : Consent of an unrelated third party
OPTION 4 : No consent under any circumstance
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 9 requires verifiable consent of the parent of the child or lawful guardian, as applicable, before processing children’s personal data, subject to prescribed exemptions.
QUESTION NO.-16 :
Which of the following factors may be considered by the Central Government while notifying an entity or class of entities as a Significant Data Fiduciary?
OPTION 1 : Volume and sensitivity of personal data processed
OPTION 2 : Colour of the company’s logo
OPTION 3 : Number of branches alone
OPTION 4 : Age of the company’s website
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 10 identifies factors including the volume and sensitivity of personal data, risk to the rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State and public order.
QUESTION NO.-17 :
Which of the following is an additional obligation of a Significant Data Fiduciary?
OPTION 1 : Appointment of an independent data auditor
OPTION 2 : Abolition of all internal audits
OPTION 3 : Public disclosure of every customer’s personal data
OPTION 4 : Automatic transfer of all data outside India
CORRECT ANSWER : OPTION 1
EXPLANATION:
A Significant Data Fiduciary is required to appoint an independent data auditor and undertake measures including periodic Data Protection Impact Assessments and periodic audits. It must also appoint a Data Protection Officer meeting the statutory requirements.
QUESTION NO.-18 :
Under the DPDP Act, which of the following is a right of the Data Principal?
OPTION 1 : Right to obtain certain information regarding processing and sharing of personal data
OPTION 2 : Right to demand another person’s confidential data
OPTION 3 : Right to impose penalties directly on a Data Fiduciary
OPTION 4 : Right to inspect the Board’s confidential records without restriction
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 11 provides the right to obtain information such as a summary of personal data being processed and certain information concerning other Data Fiduciaries and Data Processors with whom the personal data has been shared, subject to statutory limitations.
QUESTION NO.-19 :
Before approaching the Data Protection Board for grievance redressal, a Data Principal is generally required to:
OPTION 1 : First exhaust the opportunity of grievance redressal with the relevant Data Fiduciary or Consent Manager
OPTION 2 : File a criminal complaint in every case
OPTION 3 : Obtain permission from a registered valuer
OPTION 4 : Approach the Supreme Court directly
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 13 provides a grievance redressal mechanism, and Section 13(3) states that the Data Principal shall exhaust the opportunity of redressing the grievance under that section before approaching the Board.
QUESTION NO.-20 :
A Data Principal may nominate another individual under the DPDP Act. The nominee may exercise the Data Principal’s rights in the event of:
OPTION 1 : Death or incapacity of the Data Principal
OPTION 2 : Change of mobile phone only
OPTION 3 : Change of address only
OPTION 4 : Completion of every valuation assignment
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 14 permits a Data Principal to nominate another individual who may exercise the Data Principal’s rights in the event of the Data Principal’s death or incapacity, in accordance with the Act and Rules.
QUESTION NO.-21 :
Which of the following is a duty of a Data Principal under Section 15?
OPTION 1 : To impersonate another person where convenient
OPTION 2 : To register false or frivolous grievances
OPTION 3 : To furnish only verifiably authentic information while exercising the right to correction or erasure
OPTION 4 : To disclose another person’s personal data
CORRECT ANSWER : OPTION 3
EXPLANATION:
The Data Principal has statutory duties, including compliance with applicable laws, not impersonating another person, not suppressing material information in specified identity/address documents, not filing false or frivolous grievances and furnishing verifiably authentic information when exercising rights of correction or erasure.
QUESTION NO.-22 :
Under the DPDP Rules, 2025, a personal data breach requires the Data Fiduciary to notify affected Data Principals:
OPTION 1 : Only after receiving a court order
OPTION 2 : Without delay, through the specified communication channels and with prescribed information
OPTION 3 : Only after five years
OPTION 4 : Only if the affected person is a government employee
CORRECT ANSWER : OPTION 2
EXPLANATION:
Rule 7 of the DPDP Rules, 2025 requires notification to each affected Data Principal without delay and specifies information concerning the breach, its nature and extent, consequences, mitigation measures and steps that the Data Principal can take to protect her interests. The Data Fiduciary must also intimate the Data Protection Board in the prescribed manner.
QUESTION NO.-23 :
Under Rule 6 of the DPDP Rules, 2025, reasonable security safeguards include measures such as:
OPTION 1 : Encryption, access controls, logging/monitoring and appropriate safeguards for continuity
OPTION 2 : Sharing passwords among employees
OPTION 3 : Keeping all personal data in an unsecured public folder
OPTION 4 : Disabling all security monitoring
CORRECT ANSWER : OPTION 1
EXPLANATION:
Rule 6 requires reasonable security safeguards and identifies measures including encryption, obfuscation or masking, virtual tokens, access controls, visibility of access through logs/monitoring/review, measures for continuity and appropriate contractual and organisational safeguards.
QUESTION NO.-24 :
Under the DPDP Rules, 2025, a Consent Manager is required to maintain records of consent-related activities. For how long must such records generally be maintained under the notified Rules?
OPTION 1 : At least 1 year
OPTION 2 : At least 3 years
OPTION 3 : At least 7 years
OPTION 4 : Only until consent is withdrawn
CORRECT ANSWER : OPTION 3
EXPLANATION:
The First Schedule to the DPDP Rules, 2025 requires a Consent Manager to maintain specified records, including consent records, notices and sharing of personal data, for at least seven years, or for a longer period as agreed or required by law.
QUESTION NO.-25 :
A registered valuer negligently leaves a client’s personal data accessible to unauthorised persons and this results in a personal data breach. Which statement is MOST appropriate under the DPDP framework?
OPTION 1 : Personal data protection is irrelevant to valuation professionals
OPTION 2 : Only the Data Principal can be held responsible for the breach
OPTION 3 : Depending upon the valuer’s legal role and the contractual arrangement, the valuer may have responsibilities as a Data Processor, while the Data Fiduciary remains responsible under Section 8 for processing undertaken on its behalf
OPTION 4 : A data breach automatically makes the valuation report invalid
CORRECT ANSWER: OPTION 3
EXPLANATION:
The DPDP framework does not make valuation professionals exempt merely because they are performing professional assignments. Where a valuer acts as a Data Processor, contractual and statutory responsibilities concerning personal data handling may arise. Section 8 makes the Data Fiduciary responsible for compliance concerning processing undertaken by it or on its behalf by a Data Processor. Reasonable security safeguards and breach-response procedures are therefore important components of professional information management.


