PDPA Flashcards

1
Q

BS What is personal data?

A

Data, whether true or not, that an organisation has, that can narrow identification down to an individual. Business contact info (what can be found on name card/business website info doesn’t count)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

BS What counts as organisations?

A

natural persons, corporate bodies, associations etc, regardless of whether they are recognised/live in SG. Includes individuals when not acting in personal/domestic capacity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

BS What is not allowed for NRIC/FIN? What are 4 exceptions?

A

Collection, Use, Disclosure. (c/u/d)

1) required by law
2) healthcare
3) financial/real estate transactions
4) emergency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

BS What is the protection obligation [PDPA] of an organisation?

A

An organisation must make reasonable security arrangements to prevent unauthorised access to personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BS How is PDPA enforced? (2)

A

1) one makes a complaint to Personal Data Protection Commission (PDPC)
2) PDPC can: fine/warn offender or direct offender to act (e.g. training)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

BS What are organisations required to do when c/u/d-ing your personal data? (3)

A

1) notify you of reasonable & specific purposes
2) get your valid consent (actual/deemed), preferably by opt-in (not by failure to opt-out)
3) cannot require an individual to consent to c/u/d of their personal data as a condition of providing a [primary] service - beyond what is reasonably required to provide the product/service. also cannot use deceptive/misleading practices to do so

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

BS What does publicly available data refer to?

A

personal data that can be observed in public (by reasonably expected means)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

BS What data can be used without consent?

A

a
1) publicly available data
2) photos of you in location open to public with few restrictions
3) social media posts if privacy settings are: set to public, closed online group that public can join with minimal effort, not just your closed circle
4) profile photos on social media if set to public on public account
5) news activity by news organisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

BS When is consent required for photos with identifiable people in places not open to public?

A

When photo is not for personal/domestic use (e.g. internet newsletter, website)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

BS How to get consent for photos with identifiable people in places not open to public? (2)

A

1) get recorded consent, OR

2) consent may be deemed (if subject allows photo to be taken after given notice of purpose)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How to give notice for photos with identifiable people in places not open to public? (3)

A

1) state in invitation that photos will be taken, OR
2) obvious notice on premises, OR
3) photographer asks permission to take photo (for stated purpose) & you allow it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Flashcard 1: Jurisdiction
Which organisations must comply with the PDPA regarding personal data activities?

A

All organisations dealing with the collection, use, and disclosure of personal data in Singapore, including those based overseas handling data of people in Singapore.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are examples of personal data that identify someone uniquely?

A

Full name, NRIC or FIN, passport number, mobile number, facial image, and biometric data (voice, thumbprint, iris image, DNA profile).

Business contact info (e.g., from business cards) is NOT considered personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How is personal data defined under the PDPA?

A

Data about an identifiable individual from either the data itself or combined with other accessible information. Determining if data is personal depends on context.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When is it permissible to collect, use, or disclose NRIC/FIN?

A

Generally not allowed, except for legal requirements (e.g., mobile sign-ups), healthcare, financial/real estate transactions, and emergencies (e.g., COVID-19 contact tracing).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is considered an “organisation” under the PDPA?

A

Includes natural persons, corporate bodies, and associations, regardless of location, covering individuals when not acting in a personal or domestic capacity (e.g., freelance photographers).

16
Q

What actions can the PDPC take upon a PDPA complaint?

A

The PDPC can fine offenders, mandate corrective actions, issue warnings, and publish decided cases. Advisory Guidelines provide hypothetical examples.

17
Q

What is the Protection Obligation under PDPA?

A

Organisations must secure data to prevent unauthorized access. Example: PDPC fined IHiS and SingHealth S$1 million for a data breach.

18
Q

What happened in the NUS 2017 Freshmen Orientation Camp incident?

A

A Google Docs sheet with student data was widely shared without proper access control, violating the protection obligation. Result: Training requirement, not a fine.

19
Q

What are the two requirements when collecting, using, or disclosing personal data?

A

Notify individuals of reasonable, specific purposes and obtain valid consent (actual or deemed), preferably via opt-in. Exceptions: Public data and news.

20
Q

At a restaurant opening, if attendee data is collected without stating the purpose, what is the issue?

A

There was no notification of purpose, breaching PDPA requirements.

21
Q

What must be done when collecting, using, or disclosing personal data?

A

Notify individuals of specific purposes and secure valid consent, preferably opt-in. Exceptions: Public data and news.

22
Q

What makes a purpose “reasonably specific” for data use?

A

Specific purposes like offering discounts based on past purchases are acceptable, while vague statements are not.

23
Q

What is required for PDPA compliance when collecting personal data?

A

Notification of specific purposes and obtaining valid consent (actual or deemed), preferably by opt-in.

24
Q

Why is opt-in preferred over opt-out for obtaining consent?

A

Opt-in demonstrates clear consent, unlike opt-out, where inaction is deemed as consent.

25
Q

Under what conditions is opt-out consent acceptable post-2020 PDPA amendments?

A

If unlikely to harm individuals, with reasonable notification and response time provided.

26
Q

Does providing a mobile number for booking imply consent to receive relevant service updates?

A

Yes, for service-related updates (e.g., vehicle arrival). Not for unrelated promotions.

27
Q

When is consent for photography deemed at private events?

A

When notification states photo purposes or visible notices are displayed at the event.

28
Q

What are two practices that make consent invalid under PDPA?

A

Using deceptive practices or making consent conditional beyond necessary data collection for services.

29
Q

Is consent valid if a gym requires disclosure of data to third-party retailers?

A

No, disclosure for third-party marketing isn’t reasonably required for gym services.

30
Q

Can a gym require consent for data disclosure for entry into a prize draw?

A

Yes, as it’s beyond standard services and offers an optional incentive.

31
Q

When is personal data exempt from notification and consent requirements?

A

When data is publicly accessible in unrestricted public spaces, such as parks or malls.

32
Q

When is social media data considered “publicly available” under PDPA?

A

If privacy settings are public, groups are open, or content is accessible with minimal effort.

33
Q

Why are images of people in public spaces permissible for news under PDPA?

A

Licensed news organisations are exempt from notification/consent for news reporting.

34
Q
A