1. Lawful Basis & Purpose Limitation advanced

    Data was collected to fulfil bookings. A team wants to use it to train a recommendation model. What determines whether that is permitted, and how is it enforced?

    2 min answer purpose-limitationlawful-basisconsentenforcement
  2. PCI-DSS Scoping advanced

    A commerce platform wants to reduce the systems in scope for payment card compliance. What architecture achieves that?

    2 min answer pcitokenisationscope-reductionsegmentation
  3. PCI-DSS Scoping advanced

    A merchant keeps card entry inside a provider-hosted iframe and believes its scope is minimal. Customer support uses a screen-sharing tool that can see and record the customer's browser during checkout, calls are recorded, and a session-replay script runs on every page for analytics. Review the arrangement.

    3 min answer pci-dssscopesession-replayscreen-sharing
  4. PCI-DSS Scoping advanced

    A payments platform wants to reduce the systems subject to card-data compliance. What actually reduces scope, and what does not?

    2 min answer razorpaypciscopetokenisation
  5. PCI-DSS Scoping advanced

    An e-commerce platform stores card numbers to support repeat purchases. How do you reduce PCI scope?

    2 min answer pcitokenisationscopepayments
  6. PCI-DSS Scoping intermediate

    An e-commerce site collects card details in its own form and posts them to a payment provider's API. What would you change and why?

    2 min answer stripepciscopesecurity
  7. PCI-DSS Scoping advanced

    Your first PCI assessment finds the whole estate in scope. How did that happen and how do you reduce it?

    2 min answer pcisegmentationcompliance
  8. Privacy by Design beginner Multiple choice

    A food-delivery app of Zomato's shape must refuse alcohol orders to under-18s. The sign-up form asks for a full date of birth and the team is about to store it on the user row alongside the address. What should the account record hold instead, and what does the full date of birth cost you later?

    3 min answer data-minimisationderived-attributesgdpr-article-25age-verification
  9. Privacy by Design advanced

    A privacy review finds that a customer's date of birth and partial bank details are visible in session-replay recordings for a subset of users, although the analytics vendor's configuration masks those fields. It affects roughly 3% of sessions, all on one flow. Where do you look, and what does the pattern tell you?

    3 min answer session-replaymaskingthird-party-scriptsdata-minimisation
  10. Privacy by Design advanced

    On 20 March 2023 a change to OpenAI's servers spiked Redis request cancellations, a redis-py bug returned another user's cached reply on a pooled connection, and chat titles plus payment details of roughly 1.2% of active ChatGPT Plus subscribers were exposed during a nine-hour window. Which design decision turned a client-library bug into a personal-data breach?

    3 min answer openaicacheconnection-poolbreach
  11. Privacy by Design intermediate

    Product wants to add a recommendation feature using browsing history. Legal asks for a data protection impact assessment. What does architecture need to supply?

    2 min answer privacydpiadesigncompliance
  12. Privacy by Design advanced

    What does privacy by design mean architecturally rather than as a policy statement, and which decisions must be made first?

    2 min answer jupiterprivacyminimisationdefaults