Question 1 Which concept is NOT an element of Cross Border Privacy Rules (CBPR)? AEnforcement by Accountability Agents. BSelf-assessment against CBPR Question:naire. CConsultation with Privacy Enforcement (PE) Authority. DDispute resolution via the Accountability Agent's compliance program. Reveal Answer Hide Answer Next Question Correct Answer: B. Self-assessment against CBPR Question:naire.
Question 2 All of the following are guidelines the PDPC gives about anonymised data EXCEPT? AAnonymised data is not personal data. BAny data that has been anonymised bears the same risks for re-identification. CData that has been anonymised satisfies the 'cease to retain' requirement of Section 25. DOrganizations should consider the risk of re-identification if it intends to publish or disclose anonymised data. Reveal Answer Hide Answer Next Question Correct Answer: C. Data that has been anonymised satisfies the 'cease to retain' requirement of Section 25. Explanation: https://www.pdpc.gov.sg/-/media/Files/PDPC/New_DPO_Connect/nov_15/pdf/Anonymisation.pdf
Question 3 Who is NOT potentially liable when an employee in a Singapore corporation or partnership breaches the PDPA? AA corporate officer. BThe employee. CThe employer. DA partner. Reveal Answer Hide Answer Next Question Correct Answer: A. A corporate officer.
Question 4 Besides the Personal Data Protection Act (PDPA), which of the following is a potential source of privacy protection for Singapore citizens? AConstitutional protections of personal information. BInternational agreements protecting privacy. CThe tort of invasion of privacy. DBreach of confidence law. Reveal Answer Hide Answer Next Question Correct Answer: A. Constitutional protections of personal information.
Question 5 Which was NOT listed as an individual right in the 1998 Fair Information Practice Principles (FIPPs)? ANotice. BChoice. CRight to erasure. DRight to data access. Reveal Answer Hide Answer Next Question Correct Answer: B. Choice.
Question 6 In the area of human rights, what separates Singapore from many other Asian countries? AIt is not a member of the Association of Southeast Asian Nations (ASEAN). BIt has not signed the International Covenant on Civil and Political Rights. CIt has not adopted the ASEAN Human Rights Declaration. DIt is not a member of the United Nations. Reveal Answer Hide Answer Next Question Correct Answer: B. It has not signed the International Covenant on Civil and Political Rights.
Question 7 In what case would a foreign company NOT be liable for breaches of Singapore's PDPA? AIf it has a physical office in Singapore. BIf it is storing information in Singapore. CIf it is collecting personal information in Singapore. DIf it collects information from Singaporeans living abroad. Reveal Answer Hide Answer Next Question Correct Answer: D. If it collects information from Singaporeans living abroad.
Question 8 Which of the following principles of the OECD guidelines and Council of European Convention principles does Singapore's PDPA incorporate? ADisclosures to third parties included in access requests. BAdditional protections for sensitive personal data. CThe ability to opt-out from direct marketing. DThe right of deletion of data on request. Reveal Answer Hide Answer Next Question Correct Answer: C. The ability to opt-out from direct marketing.
Question 9 Which jurisdiction was the first to consider IP addresses to be personal information? AIndia. BHong Kong. CThe United States. DThe European Union. Reveal Answer Hide Answer Next Question Correct Answer: D. The European Union.
Question 10 SCENARIO -- Please use the following to answer the next QUESTION:Dracarys Inc. is a large multinational company with headquarters in Seattle, Washington, U.S. ADracarys began as a small company making and selling women's clothing, but rapidly grew through its early innovative use of online platforms to sell its products. Dracarys is now one of the biggest names in the industry, and employs staff across the globe, and in Asia has employees located in both Singapore and Hong Kong. Due to recent management restructuring they have decided, on the advice of external consultants, to open an office in India in order to centralize its call center as well as its internal human resource functions for the Asia region. Dracarys would like to centralize the following human resource functions in India: 1. The recruitment process; 2. Employee assessment and records management; 3. Employee benefits administration, including health insurance. Dracarys will have employees on the ground in India managing the systems for the functions listed above. They have been presented with a variety of vendor options for these systems, and are currently assessing the suitability of these vendors for their needs. The CEO of Dracarys is concerned about the behavior of her employees, especially online. After having proprietary company information being shared with competitors by former employees, she is eager to put certain measures in place to ensure that the activities of her employees, while on Dracarys' premises or when using any of Dracarys' computers and networks are not detrimental to the business. Dracarys' external consultants are also advising the company on how to increase earnings. Dracary's management refuses to reduce production costs and compromise the quality of their garments, so the consultants suggested utilizing customer data to create targeted advertising and thus increase sales. What must Dracarys confirm about the vendor in India in order to centralize elements of its Human Resource function? AThat the vendor submits for approval from Dracarys a privacy notice explaining how personal data will be protected under the Indian Information Technology Act. BThat the vendor files requests for transfer of personal data out of India through the offices of the privacy commissioners of Hong Kong and Singapore. CThat the vendor is bound by legally enforceable obligations to provide the personal data a standard of protection that is at least comparable to the protection under the Singapore PDPA. DThat the vendor adheres to the same sector privacy rules followed by Dracarys headquarters based in Seattle regarding the transfer of personal data. Reveal Answer Hide Answer Next Question Correct Answer: A, A