PassFish

CIPP-A practice questions — 10 free

Certified Information Privacy Professional/Asia · every answer carries the reasoning, and why each other option fails.
166 questions
18 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

A Singapore employer can do all of the following without obtaining an employee's consent EXCEPT?

Why A is correct

Singapore's PDPA lets an employer process employee data without consent where the processing is reasonable for managing or terminating the employment relationship. Workplace CCTV and computer-monitoring software fall within that evaluative/employment carve-out, and disclosing health data to a public agency during a health crisis is covered by the emergency and public-interest exceptions. Passing employee data to a third-party financial planning firm is none of these: it sits outside employment management and is a commercial disclosure, so the Consent Obligation applies in full.

Question 2 of 10

How are the scope of Singapore's Personal Data Protection Act and the scope of India's IT Rules similar?

Why A is correct

Both regimes reach beyond the controller. Singapore's PDPA defines a data intermediary and imposes the Protection and Retention Limitation obligations on it directly, while India's IT Rules 2011 place reasonable security practice requirements on any body corporate handling sensitive personal data, including one processing on another's behalf. Neither confines compliance duties to the controller alone, and neither turns on a military exemption or a purely domestic actor.

Question 3 of 10

In enforcement cases, what is Singapore's Personal Data Protection Commission (PDPC) obligated to do?

Why A is correct

The PDPA obliges the PDPC to make an appeal route available against its enforcement decisions, running to the Data Protection Appeal Committee and onward to the courts. Publishing decisions or naming organisations is a practice the Commission follows selectively rather than a statutory duty, and it does not intervene in private civil actions, which individuals bring under the separate right of action.

Question 4 of 10

Section 43A of India's IT Rules 2011 requires which of the following for a privacy policy?

Why A is correct

The IT Rules 2011 require the body corporate to have a privacy policy for handling sensitive personal data that is available and produced on request, so that a provider of information can obtain it. The Rules do not impose website publication, delivery by email or fax, or presentation at the moment of collection; those are requirements found in other regimes and are the usual distractors here.

Question 5 of 10

What personal information is considered sensitive in almost all countries with privacy laws?

Why B is correct

Health information is treated as sensitive in virtually every jurisdiction that recognises a sensitive category, from Article 9 GDPR to India's SPDI Rules, because disclosure exposes individuals to discrimination in employment, insurance and credit. Marital status and employment history are ordinary personal data, and criminal convictions are handled through separate regimes rather than being universally classed as sensitive.

Question 6 of 10

Which of the following is NOT a way that the Singapore government can monitor its citizens?

Why C is correct

There is no personal computer registration system in Singapore, so it cannot be a monitoring channel. The national identity card system ties biometric registration to everyday transactions, electronic road pricing records where and when a vehicle travels, and a national online health record service holds medical information, each of which does provide visibility.

Question 7 of 10

Which of the following is TRUE of a Significant Data Fiduciary under the Digital Personal Data Protection Act 2023?

Why A is correct

The Central Government designates a Significant Data Fiduciary, weighing the volume and sensitivity of the data, risks to Data Principals, and risks to sovereignty, electoral democracy and public order. Designation adds section 10 obligations, including an India-based DPO, an independent data auditor and prescribed periodic measures. It does not replace generally applicable contact and grievance mechanisms. No numerical threshold triggers status automatically and there is no self-assessment registration route.

Question 8 of 10

Which set of additional obligations attaches to a Significant Data Fiduciary under the Digital Personal Data Protection Act 2023?

Why C is correct

Designation as a Significant Data Fiduciary adds three duties: appoint a Data Protection Officer based in India and answerable to the board, carry out periodic data protection impact assessments, and undergo independent audits. It does not introduce data localisation, prior approval for transfers, or publication of a list of individuals served, which would itself be a disclosure.

Question 9 of 10

Which statement about the Data Protection Board of India is correct?

Why B is correct

The Board adjudicates contraventions and imposes penalties, while rule-making stays with the ministry. It does not legislate, it does not supervise credit information companies, which is the Reserve Bank's function, and it does not approve cross-border transfers, since transfer runs on a restriction list rather than case-by-case clearance.

Question 10 of 10

Which guidance instrument specifically governs the collection and use of identity card numbers in Hong Kong?

Why B is correct

The Code of Practice on Identity Card Number and Other Personal Identifiers governs when the HKID number may be collected, held and used, reflecting how widely that identifier circulates. The other instruments have different subjects: direct marketing, online collection practices, and the standard for erasure and anonymisation respectively.

These 10 are a sample

See the full bank