DPP Topic 4 - PDPA Flashcards

1
Q

Personal Data Protection Act (PDPA)

A

Singapore’s data privacy regulation that governs the collection, use, and disclosure of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Motivation for PDPA

A

Encourage business innovation while guaranteeing personal data protection and strengthen Singapore’s position as a trusted hub for businesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Extraterritorial effect of PDPA

A

Applicable to organizations collecting, using, or disclosing personal data in Singapore, regardless of the organization’s physical presence or where it was incorporated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Penalties for non-compliance

A

Up to 10% of an organization’s annual turnover in Singapore or SGD 1 million, whichever is greater, as well as reputation damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data Protection Obligations

A

11 obligations that organizations must comply with when undertaking activities relating to the collection, use, or disclosure of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

1) Accountability

A

Organizations must take responsibility for the personal data under their possession or control, appoint a data protection officer, develop policies, and implement measures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

2) Notification (Collection)

A

Notify individuals of the purposes for which the organization is intending to collect, use, or disclose their personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

3) Consent (Collection)

A

Personal data may be collected, used, or disclosed only after consent has been given by the individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

4) Purpose Limitation (Collection)

A

Personal data may be collected, used, or disclosed only for purposes that are reasonable to provide the organization’s product or service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

5) Accuracy (Care)

A

Organizations should ensure that the personal data collected is accurate and complete

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

6) Protection (Care)

A

Organizations should put in place the required security measures to protect personal data and prevent unauthorized access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

7) Retention Limitation (Care)

A

Organizations should cease retention of personal data or dispose of it in a proper manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

8) Transfer Limitation (Care)

A

Ensure that the standard of protection is comparable to the PDPA when transferring personal data to another country

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

9) Access and Correction (Autonomy)

A

Individuals have the right to request access to their personal data and for correction of their personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

10) Data Breach Notification (Autonomy)

A

In the event of a data breach that likely results in significant harm to individuals or is of significant scale, the PDPC and the affected individuals need to be notified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

11) Data Portability Obligation

A

At the request of the individual, organizations are required to transfer the individual’s data to another environment