VALUATION EXAMINATION
VERY DIFFICULT CASE-STUDIES MOCK TEST
DIGITAL PERSONAL DATA PROTECTION ACT, 2023
25 Multiple Choice Questions
Below is a much harder, exam-oriented set designed to test application rather than memorisation. I have deliberately made the fact patterns resemble the kind of professional/ethical judgment questions that can arise for a registered valuer.
One important correction to the earlier set: the DPDP Act, 2023 and DPDP Rules, 2025 have a phased commencement. The notification dated 13 November 2025 brought some provisions into force immediately, while Sections 3–17 and several related provisions are scheduled to commence 18 months after publication. The IBBI syllabus, however, states that laws/rules referred to are to be taken as notified as on 30 June 2026.
Also, because the DPDP regime is newly introduced, these are case-law-style hypothetical cases, not fabricated reports of actual court judgments.
QUESTION NO.-1 :
A registered valuer, Mr. A, is appointed by a bank to value an industrial undertaking. The bank provides him with a digital database containing the names, mobile numbers, salaries, PAN-related information and bank-account details of 150 employees. Mr. A needs only employee designation and aggregate salary figures for his valuation analysis. He nevertheless downloads the complete database onto his personal laptop “for future reference”.
Which is the MOST appropriate conclusion?
OPTION 1 : Mr. A is entitled to retain the entire database because he is a professional adviser.
OPTION 2 : Since the bank supplied the information lawfully, all subsequent use by Mr. A is automatically lawful.
OPTION 3 : Retaining and processing unnecessary personal data creates a data-protection and professional-information-management concern; Mr. A should limit processing to what is necessary for the assignment and applicable legal obligations.
OPTION 4 : DPDP obligations apply only to the bank and never to a valuer.
CORRECT ANSWER : OPTION 3
EXPLANATION:
The critical issue is not merely whether the information was lawfully received, but whether its subsequent processing is appropriate for the specified purpose. A valuer should avoid collecting, copying or retaining personal data that is unnecessary for the valuation assignment. Where the valuer is acting as a Data Processor, the contractual and statutory framework governing processing must also be considered. The fact that information was supplied by a client does not create an unlimited licence to retain or use it.
QUESTION NO.-2 :
A company appoints a registered valuer to determine the value of a business. The company’s HR head sends the valuer an employee database. The engagement letter states that the valuer will process employee information “solely for the purpose of undertaking valuation analysis and preparing the valuation report.”
After completing the assignment, the valuer proposes to sell the database to another consultancy for market-research purposes.
Which statement is MOST correct?
OPTION 1 : The sale is permissible because the valuer originally received the data lawfully.
OPTION 2 : The sale is permissible because valuation professionals are presumed to have implied consent for commercial reuse.
OPTION 3 : The proposed secondary use is outside the stated valuation purpose and cannot be justified merely by the fact that the data was lawfully received.
OPTION 4 : The sale is permissible if the consultancy promises not to disclose the database further.
CORRECT ANSWER : OPTION 3
EXPLANATION:
A fundamental distinction must be made between lawful receipt and lawful subsequent processing. A purpose limitation problem arises when personal data collected/processed for a valuation assignment is subsequently monetised for an unrelated purpose. A contractual Data Processor should also follow the instructions and restrictions governing the processing arrangement.
QUESTION NO.-3 :
During a valuation of a hotel, the valuer receives guest records containing names, phone numbers and stay histories. The client asks the valuer to include a spreadsheet containing all individual guest records as an annexure to the valuation report because “it will demonstrate the strength of the customer base.”
The valuer argues that the client owns the hotel and therefore owns the customer data.
Which is the BEST answer?
OPTION 1 : Ownership of the hotel automatically means ownership of all rights in every guest’s personal data.
OPTION 2 : The information may be reproduced without restriction because it relates to the business being valued.
OPTION 3 : The valuer should distinguish business information from personal data and should not unnecessarily disclose identifiable guest information merely because it supports the valuation.
OPTION 4 : All customer information becomes public information once a valuation is commissioned.
CORRECT ANSWER : OPTION 3
EXPLANATION:
The fact that customer data is commercially valuable does not eliminate data-protection obligations. A valuation report should normally contain the information necessary to substantiate the valuation without unnecessarily exposing identifiable personal data. Aggregation, anonymisation or summarisation may be preferable where individual identification is not necessary.
QUESTION NO.-4 :
A bank provides a valuer with a loan account database. The database contains Aadhaar numbers of borrowers. The valuation assignment requires only outstanding loan amounts, security details and property addresses.
The valuer argues that because Aadhaar numbers are “important identification information”, they should be reproduced in the valuation report.
Which is the MOST appropriate conclusion?
OPTION 1 : The valuer must reproduce Aadhaar numbers because they establish borrower identity.
OPTION 2 : The valuer should ordinarily avoid reproducing unnecessary personal identifiers when they are not required for the valuation purpose.
OPTION 3 : Aadhaar numbers are automatically public information once supplied to a bank.
OPTION 4 : The valuer must publish the Aadhaar numbers to establish independence.
CORRECT ANSWER : OPTION 2
EXPLANATION:
The question tests data minimisation and professional confidentiality, rather than whether Aadhaar is a special category under the DPDP Act. If the valuation conclusion can be reached without reproducing the identifier, unnecessarily including it increases privacy and security risk without adding valuation utility.
QUESTION NO.-5 :
A registered valuer uses an external cloud-storage provider to store valuation working papers containing personal data. The client argues that because the cloud provider is a separate company, the valuer has transferred all DPDP responsibility to the cloud provider.
Which is the BEST response?
OPTION 1 : Correct; outsourcing completely eliminates responsibility.
OPTION 2 : Correct only if the cloud provider is located outside India.
OPTION 3 : Incorrect; the legal responsibilities depend upon the roles of the parties, contractual arrangements and applicable provisions, and a Data Fiduciary remains responsible under Section 8 for processing undertaken on its behalf by a Data Processor.
OPTION 4 : The use of cloud storage is prohibited by the DPDP Act.
CORRECT ANSWER : OPTION 3
EXPLANATION:
Section 8 is particularly important. A Data Fiduciary cannot simply avoid statutory responsibility by outsourcing processing. The Act expressly addresses processing undertaken by a Data Processor on behalf of a Data Fiduciary. For a valuer, contractual controls, access restrictions, security safeguards and appropriate vendor arrangements are therefore important.
QUESTION NO.-6 :
A valuation firm has an employee database. The firm originally obtained consent for a specific digital service. Later, it decides to use the same personal data for an unrelated commercial analytics project. The employee is told, “You already gave consent once.”
Which proposition is MOST defensible?
OPTION 1 : Consent is a perpetual licence for every future purpose.
OPTION 2 : A prior consent automatically covers all purposes that the Data Fiduciary subsequently chooses.
OPTION 3 : The validity and scope of processing must be assessed against the notice, purpose and legal basis for the particular processing; a blanket assumption that old consent covers unrelated purposes is inappropriate.
OPTION 4 : Consent can never be used for more than one processing activity.
CORRECT ANSWER : OPTION 3
EXPLANATION:
Consent must be linked to the processing described to the Data Principal. The notified Rules require notice to be clear, standalone and understandable, including an itemised description of personal data and purposes. A Data Fiduciary cannot safely treat every historical consent as an unrestricted permission for unrelated future processing.
QUESTION NO.-7 :
A Data Principal gives consent to a company through a digital interface. The “Accept” button is prominently displayed, but withdrawal of consent requires the person to submit a notarised physical application to the company’s head office.
Which is the strongest objection?
OPTION 1 : Withdrawal of consent is prohibited once digital consent is given.
OPTION 2 : Withdrawal must be made more difficult than giving consent to prevent frivolous withdrawals.
OPTION 3 : Where consent is the basis of processing, the mechanism for withdrawal should be as easy as, or comparable to, the manner in which consent was given.
OPTION 4 : Withdrawal requires approval of the Data Protection Board in every case.
CORRECT ANSWER : OPTION 3
EXPLANATION:
Section 6 embodies the principle that withdrawal should be as easy as giving consent. The notified Rules also require the notice to provide information concerning easy withdrawal mechanisms and exercise of rights. The deliberately burdensome withdrawal mechanism in the fact pattern is therefore problematic.
QUESTION NO.-8 :
A company claims that it obtained valid consent because its privacy notice was 47 pages long and contained every possible category of personal data that might conceivably be collected in the future.
Which is the BEST answer under the notified Rules?
OPTION 1 : A longer notice is automatically legally superior.
OPTION 2 : Length alone establishes informed consent.
OPTION 3 : The notice should be clear, standalone and understandable, using plain language and providing an itemised description of the personal data and purposes of processing.
OPTION 4 : Privacy notices are not relevant to consent.
CORRECT ANSWER : OPTION 3
EXPLANATION:
The Rules specifically emphasise a clear, standalone and understandable notice, including an itemised description of personal data and purposes. A lengthy document that obscures rather than communicates the relevant information is not necessarily a better notice.
QUESTION NO.-9 :
A valuation firm discovers that a junior employee accidentally emailed a spreadsheet containing personal data to the wrong recipient. The firm immediately deletes the email from its own sent folder and takes no further action, arguing that “the problem has been internally corrected.”
Which statement is MOST accurate?
OPTION 1 : Internal deletion automatically extinguishes all breach obligations.
OPTION 2 : A personal data breach can trigger prescribed notification obligations; merely deleting the sender’s copy does not necessarily resolve the incident.
OPTION 3 : A breach exists only if the recipient publishes the data online.
OPTION 4 : A breach exists only if financial loss is proved.
CORRECT ANSWER : OPTION 2
EXPLANATION:
The Rules prescribe a framework for notification of personal data breaches. The occurrence of a breach is not dependent upon proof that the recipient publicly published the information or that financial loss has already occurred. Appropriate incident response and notification requirements must be assessed according to the statutory framework.
QUESTION NO.-10 :
A Data Fiduciary suffers a breach involving 80,000 individuals. It informs the Data Protection Board but decides not to inform the affected Data Principals because “the Board has already been informed.”
Which is the MOST appropriate answer?
OPTION 1 : Correct; Board notification substitutes for individual notification.
OPTION 2 : Correct where the breach was accidental.
OPTION 3 : Incorrect; the prescribed framework separately addresses notification to affected Data Principals and intimation to the Board.
OPTION 4 : Correct if no individual has yet complained.
CORRECT ANSWER : OPTION 3
EXPLANATION:
The notified Rules provide separate requirements concerning breach communication to affected Data Principals and intimation to the Board. One should not assume that notifying the regulator automatically satisfies every communication obligation owed to affected individuals.
QUESTION NO.-11 :
A company retains valuation-related employee personal data indefinitely because “data may become useful someday.” No applicable law requires indefinite retention and the original purpose has ceased.
Which conclusion is MOST consistent with the statutory framework?
OPTION 1 : Indefinite retention is mandatory because historical data is commercially valuable.
OPTION 2 : Data must always be retained once collected.
OPTION 3 : Retention should be assessed against the specified purpose and applicable legal retention requirements; indefinite retention merely for possible future usefulness is problematic.
OPTION 4 : Retention is permitted only if the data is sold.
CORRECT ANSWER : OPTION 3
EXPLANATION:
Section 8 contains an erasure framework where the specified purpose is no longer being served, subject to retention necessary for compliance with law. A blanket policy of indefinite retention is inconsistent with responsible lifecycle management of personal data.
QUESTION NO.-12 :
A valuer’s report contains a table showing the salaries of 500 employees. The valuation model only uses the aggregate annual employee cost.
Which approach is the strongest?
OPTION 1 : Publish all 500 salaries because individual figures provide greater transparency.
OPTION 2 : Include the minimum information necessary to support the valuation conclusion, such as aggregate or appropriately anonymised information, where individual identities are unnecessary.
OPTION 3 : Delete the entire employee-cost analysis because employee information can never be used in valuation.
OPTION 4 : Publish employee names beside each salary to make the report more credible.
CORRECT ANSWER : OPTION 2
EXPLANATION:
This is a classic professional application of privacy-conscious information management. Personal data may be relevant to a valuation, but relevance does not necessarily require individual identification. Proper aggregation or anonymisation can preserve valuation utility while reducing privacy risk.
QUESTION NO.-13 :
A Data Fiduciary receives a request from a Data Principal for correction of personal data. The company refuses, saying, “Our internal system has never been wrong.”
Which is the MOST appropriate approach?
OPTION 1 : The company can refuse every correction request.
OPTION 2 : The statutory right to correction must be considered in accordance with the Act and Rules.
OPTION 3 : Correction can be made only by the Data Protection Board.
OPTION 4 : Only a registered valuer can decide whether personal data is accurate.
CORRECT ANSWER : OPTION 2
EXPLANATION:
The DPDP framework recognises the Data Principal’s right concerning correction and erasure, subject to the Act and Rules. A Data Fiduciary cannot create a blanket internal rule that defeats a statutory right merely by asserting that its system is infallible.
QUESTION NO.-14 :
A Data Principal asks a company to tell her which Data Processors have received her personal data. The company replies, “They are our vendors, and therefore you have no right to know anything about them.”
Which is the BEST answer?
OPTION 1 : The company is automatically correct because vendor information is always confidential.
OPTION 2 : The Data Principal’s statutory right to obtain prescribed information concerning sharing with Data Processors must be considered, subject to statutory limitations.
OPTION 3 : The Data Principal can demand every commercial contract with every vendor.
OPTION 4 : Only the Data Protection Board can request such information.
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 11 provides the Data Principal with specified information rights, including information concerning certain sharing with Data Processors/Data Fiduciaries, subject to the statutory framework. The right does not necessarily mean that every underlying commercial contract must be disclosed.
QUESTION NO.-15 :
A registered valuer is engaged by a resolution professional to value a company undergoing insolvency proceedings. The company’s records contain personal data. The valuer argues that because the assignment is connected with a statutory insolvency process, every item of personal data can automatically be published in the valuation report.
Which is the MOST accurate answer?
OPTION 1 : Statutory context automatically makes every item of personal data public.
OPTION 2 : A statutory or legal purpose may provide a lawful basis for particular processing, but it does not automatically justify unnecessary disclosure of every piece of personal data.
OPTION 3 : No personal data can ever be processed during insolvency.
OPTION 4 : Personal data becomes public once an insolvency professional is appointed.
CORRECT ANSWER : OPTION 2
EXPLANATION:
The existence of a statutory process must be distinguished from unrestricted disclosure. Particular processing may be supported by a legitimate use or other legal basis where applicable, but necessity, purpose, confidentiality and the specific legal requirements governing disclosure remain relevant.
QUESTION NO.-16 :
A company processes a large quantity of highly sensitive personal data and is notified as a Significant Data Fiduciary. Its management says that an internal compliance checklist prepared by its legal department is enough; therefore, an independent data audit is unnecessary.
Which is the BEST answer?
OPTION 1 : Correct because internal audits always replace independent audits.
OPTION 2 : Incorrect; Significant Data Fiduciaries have additional statutory obligations, including appointment of an independent data auditor and periodic assessment/audit requirements.
OPTION 3 : Correct if the company has more than 1,000 employees.
OPTION 4 : Correct if no Data Principal has complained.
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 10 imposes enhanced obligations on Significant Data Fiduciaries. These include appointment of a Data Protection Officer, appointment of an independent data auditor and periodic Data Protection Impact Assessments and audits, subject to the statutory framework.
QUESTION NO.-17 :
A company argues that it cannot possibly be a Significant Data Fiduciary because its turnover is modest. However, it processes an enormous volume of sensitive personal data and its processing creates significant risks to individuals.
Which is the MOST appropriate conclusion?
OPTION 1 : Turnover is the only factor relevant to Significant Data Fiduciary status.
OPTION 2 : Volume and sensitivity of personal data and risks to Data Principals are among the factors relevant to determining Significant Data Fiduciary status.
OPTION 3 : Only the number of employees matters.
OPTION 4 : Every company is automatically a Significant Data Fiduciary.
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 10 identifies several factors, including the volume and sensitivity of personal data processed, risks to the rights of Data Principals and potential impacts involving sovereignty, security and public order. Turnover alone does not determine the issue.
QUESTION NO.-18 :
A valuer is asked to process personal data of minors contained in customer records. The client says: “We have consent from the minors themselves, so no further issue arises.”
Which is the BEST answer?
OPTION 1 : Consent of the minor always satisfies the statutory requirement.
OPTION 2 : The special statutory framework concerning children’s personal data, including verifiable parental/lawful-guardian consent and restrictions on tracking/behavioural monitoring and targeted advertising, must be considered.
OPTION 3 : Children’s data is outside the DPDP Act.
OPTION 4 : Children’s data can never legally be processed.
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 9 establishes additional safeguards for children’s personal data. The Data Fiduciary is generally required to obtain verifiable consent of the parent/lawful guardian and is subject to restrictions concerning tracking or behavioural monitoring and targeted advertising directed at children, subject to prescribed exceptions.
QUESTION NO.-19 :
A Data Principal files a grievance against a Data Fiduciary directly before the Data Protection Board without first using the grievance-redressal mechanism provided by the Data Fiduciary.
The Data Principal argues that going directly to the Board is always permissible.
Which is MOST accurate?
OPTION 1 : The Data Principal must generally exhaust the opportunity for grievance redressal before approaching the Board, as provided by the Act.
OPTION 2 : The Data Protection Board can never hear an individual grievance.
OPTION 3 : The Data Principal must first approach a civil court.
OPTION 4 : The Data Principal must first approach a registered valuer.
CORRECT ANSWER : OPTION 1
EXPLANATION:
Section 13 establishes the grievance-redressal mechanism and provides that the Data Principal shall exhaust the opportunity for redressal under that mechanism before approaching the Board.
QUESTION NO.-20 :
A Data Principal dies after giving consent for processing. His nominated person asks the Data Fiduciary to recognise the nomination and exercise the Data Principal’s statutory rights.
Which proposition is MOST accurate?
OPTION 1 : Nomination has no legal relevance under the DPDP Act.
OPTION 2 : The Act permits a Data Principal to nominate another individual to exercise rights in the event of death or incapacity, subject to the Act and Rules.
OPTION 3 : Only a registered valuer may act as nominee.
OPTION 4 : Nomination is valid only for one year.
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 14 specifically provides for nomination by the Data Principal. The nominee may exercise the Data Principal’s rights in the event of death or incapacity in accordance with the statutory framework.
QUESTION NO.-21 :
A Data Principal deliberately files ten false complaints against a Data Fiduciary merely to harass it and later admits that none of the complaints was genuine.
Which statement is MOST accurate?
OPTION 1 : Filing complaints is an unrestricted fundamental right and can never have consequences.
OPTION 2 : The Data Principal has statutory duties, including not registering false or frivolous grievances.
OPTION 3 : Only the Data Fiduciary has statutory duties.
OPTION 4 : A Data Principal can file unlimited complaints without regard to statutory duties.
CORRECT ANSWER : OPTION 2
EXPLANATION:
Section 15 imposes duties on Data Principals, including the duty not to register a false or frivolous grievance or complaint. The DPDP framework therefore imposes responsibilities on both sides of the data relationship.
QUESTION NO.-22 :
A valuation firm receives personal data from a foreign group company. The data is transferred to an Indian valuer and then stored on a server in another country. The valuer says: “The DPDP Act has no relevance because the original data came from outside India.”
Which is the BEST answer?
OPTION 1 : The origin of the data automatically determines that the DPDP Act never applies.
OPTION 2 : Applicability must be determined under the territorial and processing provisions of the Act; the mere foreign origin of the data does not automatically answer the question.
OPTION 3 : All foreign data is automatically exempt.
OPTION 4 : Any foreign transfer is automatically illegal.
CORRECT ANSWER : OPTION 2
EXPLANATION:
The Act’s applicability depends upon the statutory conditions concerning digital personal data and processing, including the territorial framework. One must not substitute a simplistic “Indian data/foreign data” test for the statutory provisions. Cross-border storage may additionally raise issues under the applicable Rules and government restrictions.
QUESTION NO.-23 :
A Data Fiduciary suffers a cyber incident. The technical team concludes that because the stolen database was encrypted, no personal data breach occurred.
Which is the MOST legally defensible answer?
OPTION 1 : Encryption automatically means a breach can never occur.
OPTION 2 : The incident must be assessed under the statutory definition and breach framework; encryption may be an important security safeguard but does not automatically eliminate the need to assess whether a personal data breach occurred.
OPTION 3 : Every cyber incident is automatically a statutory breach without examination.
OPTION 4 : Only financial loss determines whether a breach occurred.
CORRECT ANSWER : OPTION 2
EXPLANATION:
The notified Rules expressly contemplate technical safeguards such as encryption, but the existence of safeguards does not permit an organisation to skip incident assessment. The facts, access obtained, nature of the data, consequences and applicable breach-notification requirements must be examined.
QUESTION NO.-24 :
A company argues that the DPDP Act cannot affect its valuation business because “the value of an asset is financial, whereas privacy is a legal issue.”
During due diligence for a business valuation, the valuer discovers that the company has systematically collected personal data without appropriate safeguards and has suffered repeated data breaches.
Which is the BEST professional conclusion?
OPTION 1 : Data-protection compliance can never have relevance to business valuation.
OPTION 2 : The issue may be relevant to the valuer’s assessment of business risks, liabilities, compliance exposure, reputation and other factors affecting the subject interest, depending on the assignment and valuation methodology.
OPTION 3 : The valuer must automatically reduce enterprise value by the maximum statutory penalty.
OPTION 4 : The valuer must ignore all legal risks because only tangible assets can be valued.
CORRECT ANSWER : OPTION 2
EXPLANATION:
This is the most valuation-oriented question in the set. The DPDP framework itself does not prescribe a valuation adjustment formula. However, material regulatory exposure, litigation risk, remediation costs, business interruption, reputational effects and contingent liabilities may potentially affect valuation depending on the asset, purpose, basis of value and applicable valuation methodology. The valuer must exercise professional judgement rather than automatically equating a statutory penalty with a valuation deduction.
QUESTION NO.-25 :
A bank appoints a registered valuer for a stressed-company valuation. The valuer receives employee and customer personal data. The engagement letter states that the valuer may process the data only for the assignment. The valuer’s IT system suffers a breach, exposing part of the database. The valuer immediately informs the bank but argues that the bank alone must notify the affected individuals because “the bank is the Data Fiduciary.”
Which is the MOST appropriate conclusion?
OPTION 1 : The valuer has no responsibility whatsoever because it is not the Data Fiduciary.
OPTION 2 : The bank’s status as Data Fiduciary automatically makes the valuer irrelevant to the breach.
OPTION 3 : The parties’ respective roles and obligations must be examined; a Data Fiduciary remains responsible under Section 8 for processing undertaken on its behalf by a Data Processor, while the Data Processor’s contractual and applicable statutory obligations concerning security and incident handling must also be considered.
OPTION 4 : The valuation report automatically becomes void because of the breach.
CORRECT ANSWER : OPTION 3
EXPLANATION:
This is the intended “highest difficulty” question. The correct analysis requires distinguishing Data Fiduciary responsibility from Data Processor responsibility rather than treating the two as interchangeable.
Where processing is undertaken on behalf of a Data Fiduciary, Section 8 preserves the Data Fiduciary’s responsibility for compliance in respect of such processing. At the same time, the Data Processor’s contractual obligations, security controls, incident-response duties and applicable provisions of the DPDP framework cannot simply be ignored.
The correct answer therefore avoids both extremes: the valuer is not automatically free from responsibility, but neither does the valuer necessarily become the statutory Data Fiduciary merely because it processed the information.


