IAPP CIPP-A Practice Test - Questions Answers, Page 7
List of questions
Related questions
The "due diligence" exemption in Hong Kong's PDPO was meant to apply to?
Third-party data processors located in foreign countries.
Companies researching the viability of business mergers.
Service providers hosting customer information in the cloud.
Direct marketers acting in the best interest of their company.
What clarification did India make in a 2011 Press Note regarding their Sensitive Personal Data Rules?
That the rules apply to data subjects located outside of India.
That the rules apply to persons or companies collecting sensitive data within India.
That the data processor must provide notice to the data subject before data is processed.
That sensitive personal data or information includes passwords, financial information, medical records, and biometric information.
Which of the following topics was NOT addressed in India's Information Technology Act 2000 (IT Act)?
Digital signatures.
Censorship limitations.
Electronic transactions.
Cybersecurity procedures.
Which Hong Kong body has recommended legislation that provides for the right of civil action to be taken when private information is publicly disclosed?
Hong Kong's Court of Final Appeal.
Hong Kong Law Reform Commission.
Office of the Privacy Commissioner for Personal Data.
Standing Committee of the National People's Congress of the PRC.
Hong Kong's Personal Data (Privacy) Ordinance (PDPO) was primarily inspired by which of the following?
Asia's APEC Privacy Framework.
Macau's Personal Data Protection Act.
South Korea's Public Agency Data Protection Act.
Europe's Data Protection Directive (Directive 95/46/EC).
In which of the following cases would a Singaporean be prevented from accessing information about herself from an organization?
The information was collected in the previous 12 months.
The information is related to an individual's credit rating.
The cost of providing the information proved to be unreasonable.
Any personal information about others has been deleted from the document.
All of the following are guidelines the PDPC gives about anonymised data EXCEPT?
Anonymised data is not personal data.
Any data that has been anonymised bears the same risks for re-identification.
Data that has been anonymised satisfies the "cease to retain" requirement of Section 25.
Organizations should consider the risk of re-identification if it intends to publish or disclose anonymised data.
A Singapore employer can do all of the following without obtaining an employee's consent EXCEPT?
Share an employee's personal data with a company that provides financial planning.
Disclose personal health data to a public agency during a health crisis.
Use computer monitoring software on an employee's computers.
Use closed-circuit television surveillance in the workplace.
Which Indian institution is vested with powers under the Credit Information Companies (Regulation) Act of 2005?
The Reserve Bank of India.
The National Housing Bank.
The Oriental Bank of Commerce.
The Securities and Exchange Board of India.
All of the following are exempt from Section 43A of India's IT Rules 2011 EXCEPT?
Charitable groups.
Sole proprietorships.
Government agencies.
Religious organizations.
Question