Winter Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

CIPP-A Certified Information Privacy Professional/Asia (CIPP/A) Questions and Answers

Questions 4

In which of the following cases would a Singaporean be prevented from accessing information about herself from an organization?

Options:

A.

The information was collected in the previous 12 months.

B.

The information is related to an individual's credit rating.

C.

The cost of providing the information proved to be unreasonable.

D.

Any personal information about others has been deleted from the document.

Buy Now
Questions 5

In June 2011, the Hong Kong Privacy Commissioner determined that data subject consent is NOT valid if it is what?

Options:

A.

Provided by the data subject solely in verbal form.

B.

Used for a directly related but separate purpose.

C.

Bundled with other terms of the agreement.

D.

Intended for direct marketing purposes.

Buy Now
Questions 6

In the area of human rights, what separates Singapore from many other Asian countries?

Options:

A.

It is not a member of the Association of Southeast Asian Nations (ASEAN).

B.

It has not signed the International Covenant on Civil and Political Rights.

C.

It has not adopted the ASEAN Human Rights Declaration.

D.

It is not a member of the United Nations.

Buy Now
Questions 7

Which Indian institution is vested with powers under the Credit Information Companies (Regulation) Act of 2005?

Options:

A.

The Reserve Bank of India.

B.

The National Housing Bank.

C.

The Oriental Bank of Commerce.

D.

The Securities and Exchange Board of India.

Buy Now
Questions 8

SCENARIO – Please use the following to answer the next QUESTION:

Dracarys Inc. is a large multinational company with headquarters in Seattle, Washington, U.S.A. Dracarys began as a small company making and selling women's clothing, but rapidly grew through its early innovative use of online platforms to sell its products. Dracarys is now one of the biggest names in the industry, and employs staff across the globe, and in Asia has employees located in both Singapore and Hong Kong.

Due to recent management restructuring they have decided, on the advice of external consultants, to open an office in India in order to centralize its call center as well as its internal human resource functions for the Asia region. Dracarys would like to centralize the following human resource functions in India:

1.The recruitment process;

2.Employee assessment and records management;

3.Employee benefits administration, including health insurance.

Dracarys will have employees on the ground in India managing the systems for the functions listed above. They have been presented with a variety of vendor options for these systems, and are currently assessing the suitability of these vendors for their needs.

The CEO of Dracarys is concerned about the behavior of her employees, especially online. After having

proprietary company information being shared with competitors by former employees, she is eager to put certain measures in place to ensure that the activities of her employees, while on Dracarys' premises or when using any of Dracarys' computers and networks are not detrimental to the business.

Dracarys' external consultants are also advising the company on how to increase earnings. Dracary's management refuses to reduce production costs and compromise the quality of their garments, so the consultants suggested utilizing customer data to create targeted advertising and thus increase sales.

Which of the following guidelines does Dracarys NOT need to take into account when implementing monitoring and surveillance tools?

Options:

A.

The Indian Information Technology Act of 2000.

B.

The Hong Kong guide to monitoring personal data privacy at work.

C.

The Hong Kong Code of Practice on Human Resource Management.

D.

The Singapore advisory guidelines on the personal data protection act for selected topics (employment and CCTV).

Buy Now
Questions 9

In the Asia-Pacific Economic Cooperation (APEC) Privacy Framework, what exception is allowed to the Access and Correction principle?

Options:

A.

Paper-based records.

B.

Publicly-available information.

C.

Foreign intelligence.

D.

Unreasonable expense.

Buy Now
Questions 10

In which situation would a data intermediary based in Singapore be liable for breaches against the PDPA?

Options:

A.

When it fails to provide an individual access to his or her data.

B.

When it does not provide anonymous transactions with an individual.

C.

When it fails to inform an individual it is processing data from a controller.

D.

When it processes data contrary to the provisions established in the contract.

Buy Now
Questions 11

What term is defined by the European Commission to mean any data that relates to an identified or identifiable individual?

Options:

A.

Personally identifiable information.

B.

Sensitive information.

C.

Personal data.

D.

Identified data.

Buy Now
Questions 12

SCENARIO – Please use the following to answer the next QUESTION:

Bharat Medicals is an established retail chain selling medical goods, with a presence in a number of cities throughout India. Their strategic partnership with major hospitals in these cities helped them capture an impressive market share over the years. However, with lifestyle and demographic shifts in India, the company saw a huge opportunity in door-to-door delivery of essential medical products. The need for such a service was confirmed by an independent consumer survey the firm conducted recently.

The company has launched their e-commerce platform in three metro cities, and plans to expand to the rest of

the country in the future. Consumers need to register on the company website before they can make purchases. They are required to enter details such as name, age, address, telephone number, sex, date of birth and nationality – information that is stored on the company's servers. (Consumers also have the option of keeping their credit card number on file, so that it does not have to be entered every time they make payment.) If ordered items require a prescription, that authorization needs to be uploaded as well. The privacy notice explicitly requires that the consumer confirm that he or she is either the patient or has consent of the patient for uploading the health information. After creating a unique user ID and password, the consumer's registration will be confirmed through a text message sent to their listed mobile number.

To remain focused on their core business, Bharat outsourced the packaging, product dispatch and delivery activities to a third party firm, Maurya Logistics Ltd., with which it has a contractual agreement. It shares with Maurya Logistics the consumer name, address and other product-related details at the time of every purchase.

If consumers underwent medical treatment at one of the partner hospitals and consented to having their data transferred, their order requirement will be sent to their Bharat Medicals account directly, thereby doing away with the need to manually place an order for the medications.

Bharat Medicals takes regulatory compliance seriously; to ensure data privacy, it displays a privacy notice at the time of registration, and includes all the information that it collects. At this stage of their business, the company plans to store consumer information indefinitely, since the percentage of repeat customers and the frequency of orders per customer is still uncertain.

Which of the following is NOT true for Maurya Logistics?

Options:

A.

It must have a privacy policy on its website describing its data processing practices.

B.

It must obtain consent from Bharat Medicals consumers before processing their data.

C.

It must process Bharat Medicals' consumer data only according to agreed contractual terms.

D.

It must protect any unauthorized access any of Bharat Medicals consumer data that it obtained.

Buy Now
Questions 13

SCENARIO – Please use the following to answer the next QUESTION:

Singabank is a boutique bank in Singapore. After being notified during the hiring process, Singabank employees are subject to constant and thorough monitoring and tracking through CCTV cameras, computer monitoring software and keyboard loggers. Singabank does this to ensure its employees are complying with Singabank's data security policy. Bigbank is now considering acquiring Singabank's retail banking division. As part of its due diligence, Bigbank is seeking for Singabank to disclose to it all of its surveillance material on its employees, whether or not they are part of the retail banking division. Jimmy works in Singabank's investment banking division.

Assuming the monitoring was legal, can Singabank disclose Jimmy's personal data to Bigbank?

Options:

A.

No, because Jimmy is not in the division that Bigbank seeks to acquire.

B.

No, because the data was collected for the express purpose of complying with Singabank's privacy policies.

C.

Yes, if Singabank informs Jimmy of the disclosure of his personal data before it occurs.

D.

Yes, if Jimmy's personal data is necessary for Bigbank to determine whether to proceed with the acquisition.

Buy Now
Exam Code: CIPP-A
Exam Name: Certified Information Privacy Professional/Asia (CIPP/A)
Last Update: Nov 21, 2024
Questions: 90

PDF + Testing Engine

$64  $159.99

Testing Engine

$48  $119.99
buy now CIPP-A testing engine

PDF (Q&A)

$40  $99.99
buy now CIPP-A pdf