DEFINITIONS UNDER THE PDPA Flashcards

1
Q

How is defined personal data under the PDPA?

A

Personal data is data - whether true or not - about an individual who can be identified from that data - or from that data and other information to which the organization has or is likely to have access. It contains provisions for certain personal data of deceased individuals for a specified period. Under PDPA - IP adresses may not be personal data but the more data points are collected - the more likely the IP address is personal data. However - cookies are considered personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Is Sensitive personal data defined under the PDPA and if so - how?

A

It is important to know that PDPA doesn’t have a distinct category called sensitive personal data although there is some personal data is considered more sensitive and require higher levels of protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What would be considered sensitive personal data under the PDPA?

A

Biometric data - Health data - Sex life or sexual orientation - Financial data - Minors data - NRIC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the PDPA regulate regarding NRIC numbers?

A

The collection - use - and disclosure of NRIC numbers and copies to minimize the risk of misuse and identity theft - including consent requirement - purpose limitation - and security safeguards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Are there data protection rules specifically for children under the PDPA ?

A

No. But children from 13 to 18 years old can consent if they have sufficient understanding to do so - however - children under 13 have to consent with their parents or legal tutor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Is pseudonymisation defined under the PDPA and if so - how?

A

Pseudonymisation isn’t defined by PDPA although considered to be a good practice. Regardless - pseudonymised data is still considered personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Is de-identification defined under the PDPA and if so - how?

A

-While not being defined by GDPR but joins concepts covered under pseudonymisation and anonymization - the PDPO and PDPA acknowledge de-identification as a process to remove direct identifiers but it’d remain personal data if it could be linked to an individual with additional information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is anonymization defined under the PDPA and if so - how?

A

It is the process of irreversibly removing personal identifiers from data so that the data subject is no longer identifiable by any means reasonable likely to be used. In all cases - anonymized data is not subject to the law.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the definition of Organization under the PDPA?

A

Any individual - company - association - body of persons - corporate or incorporated - whether or not formed or recognized under the law or Singapore - or resident - or having an office or a place of business - in Singapore.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the definition of Individual under the PDPA?

A

A natural person - whether living or deceased. For deceased individuals - only those who have been dead for 10 years of fewer are concerned by the PDPA and for their personal data - only disclosure and security obligations apply to organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the definition of Data Intermediary under the PDPA?

A

An organisation that processes personal data in behalf of another organisation but does not include an employee of that other organisation. They are only subject to the retention limitation and security obligations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the definition of Specified Message under the PDPA?

A

A message that offers to supply - advertise - or promote goods - services - land - interests in land - business or investment opportunities - or a supplier.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the definition of Survivorship under the PDPA?

A

The PDPA does not specify a survivorship period (retention duration) - but organizations must ensure that they have the necessary consent for the collection - use - and disclosure of personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the definition of Publicly Available under the PDPA?

A

Personal data that is made available to the public without restriction - such as data published in public registers or directories.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly