PDPA Flashcards

1
Q

Purpose of PDPA?

A

To govern collection, use, and disclosure of personal data
by organisations
in a manner which recognises
the individual’s right to protect personal data,
and the organisation’s need to collect, use, and disclose personal data, for purposes which a reasonable person would consider appropriate in the circumstances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who is exempted from Pts III - VI?

A
  • individual acting in personal or domestic capacity
  • employee acting in the course of employment with organisation
  • public agency or org acting on behalf of public agency
  • any other prescribed org or personal data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an “individual” under the PDPA?

A

Natural person whether dead or alive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data intermediary exemption?

A

Exempted from Pts III - VI

  • if the org is processing personal data on behalf of, and for purposes of, another org
  • pursuant to a contract evidenced / made in writing

EXCEPT FOR

  • s24 (protection of personal data)
  • s25 (retention of personal data)

Note: Org is still responsible for the personal data as if it were processing it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an “organisation” under the PDPA?

A
  • Individual
  • Company
  • Association
  • Body of persons incorporated / unincorporated
  • Whether or not formed / recognised in SG
  • Whether or not resident, has office, or has place of business in SG
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is “domestic” under the PDPA?

A

Relates to home or family

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What age of data is exempted from the PDPA?

A
  • Personal data in a >= 100yr record
  • Personal data about dead person,
    but if dead for <=10 years, still subject to s24 (protection of personal data)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is “business contact information” under the PDPA?

A

Exempted from Pts III - VI PDPA, unless BCI expressly referred to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What obligations on companies IRT policies and practices?

A

(1) Org must develop and implement policies and practices needed to comply with PDPA.
(2) Must communicate them to staff.
(3) Must develop process to receive and respond to complaints.
(3) Upon request, must make info on (1) and (3) available.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What obligations on companies IRT DPO?

A
  • Must designate one; can be external / internal.
  • DPO can delegate responsibilities.
  • DPO’s biz contract info must be available.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What happens if a data intermediary goes beyond its contract with the org, in processing data?

A

Will no longer be a data intermediary in respect of that processing, and will be subject to all the obligations of the PDPA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a “data intermediary”?

A

An org processing data on behalf of another org (but not an employee of that org).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is “processing”?

A

Carrying out operations IRT personal data, including:

(1) recording
(2) holding
(3) organisation, adaptation, alteration
(4) erasure, destruction
(5) retrieval
(6) transmission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What can the PDPC review IRT an org’s decision?

A

(1) Org refused / failed to give access to personal data.
(2) Amount of $ charged to access / correct personal data [not supposed to charge to correct].
(3) Org refused to correct personal data, or failed to do it within reasonable time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can appeal PDPC?

A

Can apply to PDPC within 28 days to reconsider decision / direction. But does not suspend it unless IRT financial penalty.

Can also appeal to Data Protection Appeal Panel within 28 days. But if you apply for PDPC reconsideration, this will be deemed withdrawn.

Then can appeal to HC:

(1) on point of law in decision / direction.
(2) amount of financial penalty.

Then can appeal to CA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Offences under the PDPA?

A

(1) Obstruction / impediment of PDPC or authorised officer.
(2) Dispose, alter, falsify, conceal, destroy records,
with intent to evade request to access / correct
or info about collection / use / disclosure