Certified Information Privacy Professional/Asia · every answer carries the reasoning, and why each
other option fails.
166 questions
18 chapters of notes
EN + ZH languages
Tap an option to see the answer, the reasoning, and why the other three fail.
Question 1 of 10
A Singapore employer can do all of the following without obtaining an employee's consent EXCEPT?
AShare an employee's personal data with a company that provides financial planning.
BDisclose personal health data to a public agency during a health crisis.Disclosing health data to a public agency during a health crisis falls within the PDPA consent exceptions for public interest or legal requirements, so separate consent is not required and this is not the EXCEPT.
CUse computer monitoring software on an employee's computers.Using computer monitoring software for workplace management generally falls within a reasonable exception related to employment management under the PDPA, so separate consent is not required.
DUse closed-circuit television surveillance in the workplace.Workplace CCTV surveillance, with appropriate notice, is a reasonable exception recognized in PDPC guidance for employer safety management, so separate consent is not required.
Why A is correct
Singapore's PDPA lets an employer process employee data without consent where the processing is reasonable for managing or terminating the employment relationship. Workplace CCTV and computer-monitoring software fall within that evaluative/employment carve-out, and disclosing health data to a public agency during a health crisis is covered by the emergency and public-interest exceptions. Passing employee data to a third-party financial planning firm is none of these: it sits outside employment management and is a commercial disclosure, so the Consent Obligation applies in full.
Question 2 of 10
How are the scope of Singapore's Personal Data Protection Act and the scope of India's IT Rules similar?
AThey apply to controllers and processors alike.
BThey allow exemptions for military personnel.Neither law provides a general exemption for military personnel, so that is not a shared feature of the two regimes.
CThey impose obligations on individuals acting in a domestic capacity.The regulated parties under these laws are not limited to individuals acting in a purely personal or domestic capacity, so this does not accurately describe their scope.
DThey only apply to the private sector.Neither the PDPA nor the IT Rules 2011 applies only to the private sector. The PDPA includes exceptions for certain public-sector activities, so this is not a common feature.
Why A is correct
Both regimes reach beyond the controller. Singapore's PDPA defines a data intermediary and imposes the Protection and Retention Limitation obligations on it directly, while India's IT Rules 2011 place reasonable security practice requirements on any body corporate handling sensitive personal data, including one processing on another's behalf. Neither confines compliance duties to the controller alone, and neither turns on a military exemption or a purely domestic actor.
Question 3 of 10
In enforcement cases, what is Singapore's Personal Data Protection Commission (PDPC) obligated to do?
AProvide the complainant with a way to appeal a decision.
BPublish the decisions it makes regarding complaints.The PDPC may selectively publish enforcement decisions that have precedential or educational value, but it is not required to publish every decision on complaints.
CPublish the name of an organization named in a complaint.The PDPC is not under a statutory duty to disclose the name of the organization in every complaint case; publication depends on the circumstances.
DIntervene in civil actions to provide assistance to complainants.As an administrative regulator, the PDPC is not legally required to intervene in civil actions or assist complainants in bringing them.
Why A is correct
The PDPA obliges the PDPC to make an appeal route available against its enforcement decisions, running to the Data Protection Appeal Committee and onward to the courts. Publishing decisions or naming organisations is a practice the Commission follows selectively rather than a statutory duty, and it does not intervene in private civil actions, which individuals bring under the separate right of action.
Question 4 of 10
Section 43A of India's IT Rules 2011 requires which of the following for a privacy policy?
AIt should be available and produced on request.
BIt should be published on the website of the body corporate.Although the Rules do require a privacy policy to be published on the body corporate’s website, that statement is incomplete because it omits the separate obligation to make it available on request.
CIt should be emailed or faxed to data providers by the body corporate.The IT Rules 2011 do not require the body corporate to proactively email or fax the privacy policy to every data provider. That option invents a form of obligation that the Rules do not impose.
DIt should be shown to the data provider at the time of data collection.The Rules do not require the full privacy policy to be shown to the data provider at the moment of collection. They require the policy to be available and produced on request, so this option overstates the timing requirement.
Why A is correct
The IT Rules 2011 require the body corporate to have a privacy policy for handling sensitive personal data that is available and produced on request, so that a provider of information can obtain it. The Rules do not impose website publication, delivery by email or fax, or presentation at the moment of collection; those are requirements found in other regimes and are the usual distractors here.
Question 5 of 10
What personal information is considered sensitive in almost all countries with privacy laws?
AMarital status.Marital status is usually treated as general personal data and is not, in most privacy regimes, classified as a sensitive category requiring special protection.
BHealth information.
CEmployment history.Employment history generally falls within ordinary personal data and is not commonly recognized across jurisdictions as a sensitive category.
DCriminal convictions.Criminal conviction data receives special treatment in some jurisdictions, such as under GDPR Article 10, but it is not uniformly classified as sensitive personal information in almost all countries with privacy laws. Health information is far more consistently treated as sensitive.
Why B is correct
Health information is treated as sensitive in virtually every jurisdiction that recognises a sensitive category, from Article 9 GDPR to India's SPDI Rules, because disclosure exposes individuals to discrimination in employment, insurance and credit. Marital status and employment history are ordinary personal data, and criminal convictions are handled through separate regimes rather than being universally classed as sensitive.
Question 6 of 10
Which of the following is NOT a way that the Singapore government can monitor its citizens?
AThrough the national identity card system.The NRIC system covers biometric data and is widely used for identity verification, making it a real monitoring channel closely linked to an individual's identity.
BThrough the electronic road pricing system.The electronic road pricing system records when and where vehicles pass, creating traceable travel data. It is an actual means of monitoring.
CThrough a personal computer registration system.
DThrough an online service that holds an individual’s medical records.An electronic health information service that holds an individual's medical records enables relevant bodies to access that person's health history, making it a real channel for retaining personal data traces.
Why C is correct
There is no personal computer registration system in Singapore, so it cannot be a monitoring channel. The national identity card system ties biometric registration to everyday transactions, electronic road pricing records where and when a vehicle travels, and a national online health record service holds medical information, each of which does provide visibility.
Question 7 of 10
Which of the following is TRUE of a Significant Data Fiduciary under the Digital Personal Data Protection Act 2023?
AThe Central Government designates it on factors including volume and sensitivity of data and risk, and additional obligations then attach
BThe designation replaces the Data Fiduciary’s contact-publication and grievance-redressal obligationsDesignation adds section 10 obligations; it does not replace the section 8(10) business-contact publication duty or the section 13 effective grievance-redressal mechanism. The Act does not require every Data Fiduciary to appoint a role uniformly titled grievance officer.
CAn entity becomes one automatically once it processes data about more than a fixed number of individualsThe law does not set an automatic numerical threshold for designation. Data volume is only one factor the government may consider; it is not a self-executing trigger.
DAn entity self-assesses against published criteria and registers with the Data Protection BoardThe DPDPA does not create a self-assessment and registration regime. This option imports a compliance model from elsewhere.
Why A is correct
The Central Government designates a Significant Data Fiduciary, weighing the volume and sensitivity of the data, risks to Data Principals, and risks to sovereignty, electoral democracy and public order. Designation adds section 10 obligations, including an India-based DPO, an independent data auditor and prescribed periodic measures. It does not replace generally applicable contact and grievance mechanisms. No numerical threshold triggers status automatically and there is no self-assessment registration route.
Question 8 of 10
Which set of additional obligations attaches to a Significant Data Fiduciary under the Digital Personal Data Protection Act 2023?
AMaintain a copy of all personal data within India at all timesThe DPDPA does not impose a general data localization storage requirement; that imports rules from other jurisdictions.
BPublish an annual transparency report listing all Data Principals servedThere is no obligation to publish a list of Data Principals served; doing so would itself create a disclosure risk.
CAppoint a Data Protection Officer based in India, conduct periodic data protection impact assessments, and undergo independent audits
DObtain government approval before each cross-border transferCross-border transfers are governed by a restriction list, not case-by-case approval.
Why C is correct
Designation as a Significant Data Fiduciary adds three duties: appoint a Data Protection Officer based in India and answerable to the board, carry out periodic data protection impact assessments, and undergo independent audits. It does not introduce data localisation, prior approval for transfers, or publication of a list of individuals served, which would itself be a disclosure.
Question 9 of 10
Which statement about the Data Protection Board of India is correct?
AIt supervises credit information companiesCredit information companies are regulated by the Reserve Bank of India under separate legislation.
BIt adjudicates contraventions and imposes penalties, while rule-making sits with the ministry
CIt makes the rules under the DPDP Act and adjudicates contraventionsRule-making power sits with the ministry; the Board does not also serve as the rule-maker.
DIt approves cross-border transfers case by caseCross-border transfers are not subject to transaction-by-transaction approval; only countries restricted by government notification are off limits.
Why B is correct
The Board adjudicates contraventions and imposes penalties, while rule-making stays with the ministry. It does not legislate, it does not supervise credit information companies, which is the Reserve Bank's function, and it does not approve cross-border transfers, since transfer runs on a restriction list rather than case-by-case clearance.
Question 10 of 10
Which guidance instrument specifically governs the collection and use of identity card numbers in Hong Kong?
AThe New Guidance on Direct MarketingThe New Guidance on Direct Marketing addresses direct marketing.
BThe Code of Practice on Identity Card Number and Other Personal Identifiers
CThe Internet Data GuidanceThe Internet Data Guidance concerns the online collection of personal data.
DThe Guidance on Personal Data Erasure and AnonymisationThe Guidance on Personal Data Erasure and Anonymisation explains when data falls outside the Ordinance after erasure or anonymisation.
Why B is correct
The Code of Practice on Identity Card Number and Other Personal Identifiers governs when the HKID number may be collected, held and used, reflecting how widely that identifier circulates. The other instruments have different subjects: direct marketing, online collection practices, and the standard for erasure and anonymisation respectively.
These 10 are a sample
✓166 questions, each with the full reasoning
✓Every wrong option explained, not just the right one
✓18 chapters of syllabus notes, written from a cold start
✓Full-length mock exam with per-domain scoring
✓Printable PDF included — one purchase, no renewal