Personal Data Protection Act (PDPA) Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

What is personal data?

A

Data, whether true or not, that an organisation has, that can narrow identification down to an individual. Business contact info (what can be found on name card/business website info doesn’t count)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What counts as organisations?

A

natural persons, corporate bodies, associations etc, regardless of whether they are recognised/live in SG. Includes individuals when not acting in personal/domestic capacity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is not allowed for NRIC/FIN? What are 4 exceptions?

A

Collection, Use, Disclosure. (c/u/d)

1) required by law
2) healthcare
3) financial/real estate transactions
4) emergency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the protection obligation [PDPA] of an organisation?

A

An organisation must make reasonable security arrangements to prevent unauthorised access to personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How is PDPA enforced? (2)

A

1) one makes a complaint to Personal Data Protection Commission (PDPC)
2) PDPC can: fine/warn offender or direct offender to act (e.g. training)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are organisations required to do when c/u/d-ing your personal data? (3)

A

1) notify you of reasonable & specific purposes
2) get your valid consent (actual/deemed), preferably by opt-in (not by failure to opt-out)
3) cannot require an individual to consent to c/u/d of their personal data as a condition of providing a [primary] service - beyond what is reasonably required to provide the product/service. also cannot use deceptive/misleading practices to do so

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does publicly available data refer to?

A

personal data that can be observed in public (by reasonably expected means)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What data can be used without consent?

A

1) publicly available data
2) photos of you in location open to public with few restrictions
3) social media posts if privacy settings are: set to public, closed online group that public can join with minimal effort, not just your closed circle
4) profile photos on social media if set to public on public account
5) news activity by news organisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When is consent required for photos with identifiable people in places not open to public?

A

When photo is not for personal/domestic use (e.g. internet newsletter, website)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How to get consent for photos with identifiable people in places not open to public? (2)

A

1) get recorded consent, OR

2) consent may be deemed (if subject allows photo to be taken after given notice of purpose)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How to give notice for photos with identifiable people in places not open to public? (3)

A

1) state in invitation that photos will be taken, OR
2) obvious notice on premises, OR
3) photographer asks permission to take photo (for stated purpose) & you allow it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly