IAPP CIPP-A Exam Practice Questions (P. 4)
- Full Access (93 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
Which of the following principles of the OECD guidelines and Council of European Convention principles does Singapore's PDPA incorporate?
- ADisclosures to third parties included in access requests.
- BAdditional protections for sensitive personal data.
- CThe ability to opt-out from direct marketing.
- DThe right of deletion of data on request.
Correct Answer:
C
C
send
light_mode
delete
Question #17
SCENARIO – Please use the following to answer the next question:
B-Star Limited is a Singapore based construction company with many foreign construction workers. B-Star's HR team maintains two databases. One (the "simple database") contains basic details from a standard in-processing form such as name, local address and mobile number. The other database (the "sensitive database") contains information collected by the HR Department as part of Annual Review Interviews. With the workers' cooperation, this database has expanded to include far-reaching sensitive information such as medical history, religious beliefs, ethnicity and educational levels of immediate family members. Carl left B-Star's employment yesterday, and has flown back home, rendering him unreachable. Today B-Star, without Carl's consent, wants to conduct research using Carl's medical records in the sensitive database.
Can B-Star legally conduct this research using Carl's medical data?
B-Star Limited is a Singapore based construction company with many foreign construction workers. B-Star's HR team maintains two databases. One (the "simple database") contains basic details from a standard in-processing form such as name, local address and mobile number. The other database (the "sensitive database") contains information collected by the HR Department as part of Annual Review Interviews. With the workers' cooperation, this database has expanded to include far-reaching sensitive information such as medical history, religious beliefs, ethnicity and educational levels of immediate family members. Carl left B-Star's employment yesterday, and has flown back home, rendering him unreachable. Today B-Star, without Carl's consent, wants to conduct research using Carl's medical records in the sensitive database.
Can B-Star legally conduct this research using Carl's medical data?
- AYes, because Carl gave his consent for his sensitive personal data to be collected during his employment.
- BNo, an organization is not allowed to use sensitive personal data without an individual's consent unless absolutely necessary.
- CNo, because the research is taking place after Carl has left B-Star's employment.
- DYes, if the research is deemed to be in the public interest.
Correct Answer:
B
B
send
light_mode
delete
Question #18
A Singapore employer can do all of the following without obtaining an employee's consent EXCEPT?
- AShare an employee's personal data with a company that provides financial planning.
- BDisclose personal health data to a public agency during a health crisis.
- CUse computer monitoring software on an employee's computers.
- DUse closed-circuit television surveillance in the workplace.
Correct Answer:
A
A
send
light_mode
delete
Question #19
Which control is NOT included in the requirements established by the Monetary Authority of Singapore (MAS) for financial institutions in order to deter money-laundering and financial aid to terrorism (AML/CFT)?
- AIdentifying and knowing customers.
- BSharing personal information with the PDPC.
- CConducting regular reviews of customer accounts.
- DMonitoring and reporting suspicious financial transactions.
Correct Answer:
A
A
send
light_mode
delete
Question #20
All of the following are guidelines the PDPC gives about anonymised data EXCEPT?
- AAnonymised data is not personal data.
- BAny data that has been anonymised bears the same risks for re-identification.
- CData that has been anonymised satisfies the "cease to retain" requirement of Section 25.
- DOrganizations should consider the risk of re-identification if it intends to publish or disclose anonymised data.
Correct Answer:
C
C
send
light_mode
delete
All Pages