chapter 4 Flashcards

1
Q

what is the PDPA

A

–> Is Singapore’s data privacy regulation
–> Governs the collection, use, disclosure and care of
personal data
–> Regulates telemarketing practices through the Do Not
Call registry

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

why do we need PDPA

A

–> Is designed to encourage business innovation, while
also guaranteeing that personal data protection

–> Aims to strengthen Singapore’s position as a trusted
hub for businesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

who does the PDPA apply to

A

–> Recognizes the right of individuals to protect their personal data

–> Recognizes the need for organisations to collect, use or
disclose personal data for legitimate and reasonable purposes

–> Does not apply to the public sector, which has separate
rules under the government

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

where is the PDPA applicable

A

Has extraterritorial effect.

–> It is applicable to organizations collecting, using or disclosing personal data in Singapore, regardless of the organization’s
physical presence or where it was incorporated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what is the cost of failing to comply with the PDPA

A

–> 10% of an organization’s annual turnover in Singapore,
or SGD 1 million, whichever is greater

–> Reputation damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

how many PDPA obligations are there

A

11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what are the 11 PDPA obligations

A

Accountability

Notification

Consent

Purpose limitation

Accuracy

Protection

Retention Limitation

transfer limitation

Access and correction

data breach notification

data portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what does accountability mean

A

Accountability helps organisations to strengthen trust and enhance competitiveness.

Organisations must take responsibility for the personal
data under their possession or control:
* Appoint a data protection officer
* Develop data protection policies
* Foster a data protection awareness and culture
* Implement measures to meet PDPA obligations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what are the pdpa obligations which come under the collection of personal data category

A

notification

consent

purpose limitation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what does notification mean ?

A

Notify individuals of the purposes for which the organisation is intending to collect, use or disclose their personal data

Important considerations for Notification include:
* Content of the notification
* Format of the notification
* When to notify

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what does consent mean ?

A

Personal data may be collected, used or
disclosed only after consent has been given
by the individual

Important considerations for obtaining Consent
include:
* Consent cannot be accepted, unless the individual
has been Notified of the purposes
* Allow the individual to withdraw consent
* Consent can be obtained in writing or verbally
Collection of Personal Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what does purpose limitation mean ?

A

Personal data may be collected, used or
disclosed ONLY for the purposes that is
reasonable to provide the organisation’s
product or service

Important considerations for Purpose Limitation
include:
* Collect, use and disclose personal data, that are
relevant for the purposes
* Ensure the purposes are reasonable for the product
or service provided

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

4 obligations under care for personal data

A

accuracy

protection

retention limitation

transfer limitation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what does accuracy mean ?

A

Organizations should ensure that the personal data collected is accurate and complete

Important considerations for Accuracy include:
* Reliability of the data
* Currency of the data
* Impact of the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what does protection mean ?

A

Organizations should put in place the required security measures to protect personal data to prevent unauthorized
access

Important considerations for Protection include:
* Well-trained personnel responsible for ensuring
information security
* Robust information security policies and procedures
* Breach response preparedness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what does retention limitation mean

A

Organizations should cease retention of personal data or dispose of it in a proper manner

Important considerations for Protection include:
* Review the need to hold personal data on a regular
basis
* Render personal data completely irretrievable or
inaccessible
* No means to associate the personal data with
particular individuals

17
Q

what does transfer limitation

A

Ensure that the standard of protection is
comparable to the PDPA when transferring
personal data to another country

Important consideration for Transfer Limitation:
* In transferring data overseas, the receiving
organisation is not subject to Singapore laws
* The Accountability Obligation requires that the
transferring organisation ensures that personal data
under its care continue to be protected to the same
standard as that established in PDPA

18
Q

what does accesss and correction mean ?

A

Individuals have the right to request for access to their personal data and for correction of their personal data

Organizations may not accede to an access request
where the provision of personal data is expected to:
* threaten the safety or physical or mental health of
an individual
* reveal personal data about another individual
* be contrary to the Singapore’s national interest

19
Q

what is data breach notificaiton

A

In the event of a data breach, that likely results in significant harm to individuals, or are of significant scale, PDPC and the
affected individuals need to be notified

Significance in Breach Notification include:
* Name or alias or full national identification number
* Financial/health information, not publicly disclosed
* Identification of vulnerable individuals
* Private key used to authenticate/sign an digital
document

20
Q

what is data portability

A

At the request of the individual, organisations
are required to transfer the individual’s data
to another environment

*As at March 2022, this Obligation is under review and
will take effect when it is later issued

21
Q

what are the 3 obligations that come under Individual’ autonomy over personal data

A

data portability

data breach notification

access and correction