Time: 180 minutes. Suggested readiness benchmark: 70%. Answer from the Act and cite sections.
Part A: 30 Multiple-Choice Questions
1. Which provision is assigned to Orientation and Act Map?
A. Long title, arrangement of sections and s.1
B. s.26
C. ss.32-33
D. s.40
2. Which provision is assigned to Scope and Exemptions?
A. ss.2-3
B. s.27
C. s.34
D. ss.41-42
3. Which provision is assigned to The Regulator?
A. ss.4-7
B. s.28
C. ss.35-36
D. s.43
4. Which provision is assigned to Governance of the Commission?
A. ss.8-18
B. s.29 and s.65
C. s.37
D. ss.44-45 and s.65
5. Which provision is assigned to Finance, Audit and Review?
A. ss.19-23
B. s.30 and s.65
C. s.38
D. s.46
6. Which provision is assigned to Processing Principles?
A. s.24
B. s.31 and s.65
C. s.39
D. ss.47-48
7. Which provision is assigned to Lawful Bases?
A. s.25
B. ss.32-33
C. s.40
D. ss.49-53
8. Which provision is assigned to Consent?
A. s.26
B. s.34
C. ss.41-42
D. ss.54-59
9. Which provision is assigned to Transparency and Privacy Notices?
A. s.27
B. ss.35-36
C. s.43
D. ss.60-66
10. Which provision is assigned to Data Privacy Impact Assessment?
A. s.28
B. s.37
C. ss.44-45 and s.65
D. Whole Act
11. Which provision is assigned to Controller and Processor Obligations?
A. s.29 and s.65
B. s.38
C. s.46
D. Whole Act
12. Which provision is assigned to Sensitive Personal Data?
A. s.30 and s.65
B. s.39
C. ss.47-48
D. Long title, arrangement of sections and s.1
13. Which provision is assigned to Children and Persons Lacking Capacity?
A. s.31 and s.65
B. s.40
C. ss.49-53
D. ss.2-3
14. Which provision is assigned to Data Protection Officer Function?
A. ss.32-33
B. ss.41-42
C. ss.54-59
D. ss.4-7
15. Which provision is assigned to Data-Subject Rights I?
A. s.34
B. s.43
C. ss.60-66
D. ss.8-18
16. Which provision is assigned to Data-Subject Rights II?
A. ss.35-36
B. ss.44-45 and s.65
C. Whole Act
D. ss.19-23
17. Which provision is assigned to Automated Decision-Making?
A. s.37
B. s.46
C. Whole Act
D. s.24
18. Which provision is assigned to Data Portability?
A. s.38
B. ss.47-48
C. Long title, arrangement of sections and s.1
D. s.25
19. Which provision is assigned to Security, Integrity and Confidentiality?
A. s.39
B. ss.49-53
C. ss.2-3
D. s.26
20. Which provision is assigned to Personal Data Breaches?
A. s.40
B. ss.54-59
C. ss.4-7
D. s.27
21. Which provision is assigned to Cross-Border Transfers I?
A. ss.41-42
B. ss.60-66
C. ss.8-18
D. s.28
22. Which provision is assigned to Cross-Border Transfers II?
A. s.43
B. Whole Act
C. ss.19-23
D. s.29 and s.65
23. Which provision is assigned to Registration and Fees?
A. ss.44-45 and s.65
B. Whole Act
C. s.24
D. s.30 and s.65
24. Which provision is assigned to Complaints and Investigations?
A. s.46
B. Long title, arrangement of sections and s.1
C. s.25
D. s.31 and s.65
25. Which provision is assigned to Compliance and Enforcement Orders?
A. ss.47-48
B. ss.2-3
C. s.26
D. ss.32-33
26. Which provision is assigned to Offences, Remedies and Liability?
A. ss.49-53
B. ss.4-7
C. s.27
D. s.34
27. Which provision is assigned to Legal Proceedings and Enforcement Powers?
A. ss.54-59
B. ss.8-18
C. s.28
D. ss.35-36
28. Which provision is assigned to Miscellaneous and Interpretation?
A. ss.60-66
B. ss.19-23
C. s.29 and s.65
D. s.37
29. Which provision is assigned to The 90-Day Compliance Programme?
A. Whole Act
B. s.24
C. s.30 and s.65
D. s.38
30. Which provision is assigned to Final Assessment and Teaching Demonstration?
A. Whole Act
B. s.25
C. s.31 and s.65
D. s.39
Part B: 10 Short-Answer Questions
Explain the principal statutory rule and DPO evidence requirements for Processing Principles.
Explain the principal statutory rule and DPO evidence requirements for Consent.
Explain the principal statutory rule and DPO evidence requirements for Data Privacy Impact Assessment.
Explain the principal statutory rule and DPO evidence requirements for Sensitive Personal Data.
Explain the principal statutory rule and DPO evidence requirements for Data Protection Officer Function.
Explain the principal statutory rule and DPO evidence requirements for Data-Subject Rights II.
Explain the principal statutory rule and DPO evidence requirements for Data Portability.
Explain the principal statutory rule and DPO evidence requirements for Personal Data Breaches.
Explain the principal statutory rule and DPO evidence requirements for Cross-Border Transfers II.
Explain the principal statutory rule and DPO evidence requirements for Complaints and Investigations.
Part C: Five Scenario Questions
A online retail business begins a project involving staff or customer personal data. The project raises questions about lawfulness fairness transparency and purpose limitation. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under s.24, key risks and the compliance evidence that should be retained.
A public university begins a project involving staff or customer personal data. The project raises questions about high-risk screening and necessity and proportionality. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under s.28, key risks and the compliance evidence that should be retained.
A payment service provider begins a project involving staff or customer personal data. The project raises questions about designation by controllers of major importance and knowledge and position. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under ss.32-33, key risks and the compliance evidence that should be retained.
A specialist hospital begins a project involving staff or customer personal data. The project raises questions about qualifying automated processing and consent or contract basis. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under s.38, key risks and the compliance evidence that should be retained.
A Akwa Ibom State ministry begins a project involving staff or customer personal data. The project raises questions about informed consent and contract necessity. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under s.43, key risks and the compliance evidence that should be retained.
Part D: Two Practical Compliance Tasks
Prepare a breach assessment record and notification-decision workflow for a Nigerian payment service provider, using sections 39-40.
Prepare a 90-day privacy compliance programme for a Nigerian public university, identifying owners, evidence, milestones and management reporting.
Reveal the examination answer framework
Part A: the correct answer to each question is option A. Parts B-D should be marked for accurate section citation, complete legal test, factual application, risks, controls, evidence and a defensible conclusion.
Final Evaluation Record
| MCQ score | ____ / 30 |
|---|---|
| Short-answer score | ____ / 30 |
| Scenario score | ____ / 25 |
| Practical-task score | ____ / 15 |
| Overall score | ____% |
| Remaining gaps | ________________________________ |
| Readiness level | Developing / Competent / Ready |
| Targeted revision plan | ________________________________ |
