Skip to main content

CIPP-A Real Exam Questions

Certified Information Privacy Professional/Asia (CIPP/A)

93 questions available · Page 1 of 10

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

All of the following are exempt from Section 43A of India's IT Rules 2011 EXCEPT?

  1. A

    Charitable groups.

  2. B

    Sole proprietorships.

  3. C

    Government agencies.

  4. D

    Religious organizations.

Show answer and explanation

Correct answer: C

Question 2 Single choice

Under India's IT Rules 2011, data subjects have the right to correct inaccuracies in personal information collected about them only if?

  1. A

    They are also the providers of the information.

  2. B

    They confirm their consent to maintain the information.

  3. C

    They are able to prove the legitimacy of the corrections.

  4. D

    They request the corrections within a specified amount of time.

Show answer and explanation

Correct answer: A

Question 3 Single choice

SCENARIO - Please use the following to answer the next question:

Fitness For Everyone ("FFE") is a gym on Hong Kong Island that is affiliated with a network of gyms throughout Southeast Asia. When prospective members of the gym stop in, call in or submit an inquiry online, they are invited for a free trial session. At first, the gym asks prospective clients only for basic information: a full name, contact number, age and their Hong Kong ID number, so that FFE's senior trainer Kelvin can reach them to arrange their first appointment.

One day, a potential customer named Stephen took a tour of the gym with Kelvin and then decided to join FFE for six months. Kelvin pulled out a registration form and explained FFE's policies, placing a circle next to the part that read "FEE and affiliated third parties" may market new products and services using the contact information provided on the form to Stephen "for the duration of his membership." Stephen asked if he could opt-out of the marketing communications. Kelvin shrugged and said that it was a standard part of the contract and that most gyms have it, but that even so Kelvin's manager wanted the item circled on all forms. Stephen agreed, signed the registration form at the bottom of the page, and provided his credit card details for a monthly gym fee. He also exchanged instant messenger/cell details with Kelvin so that they could communicate about personal training sessions scheduled to start the following week.

After attending the gym consistently for six months, Stephen's employer transferred him to another part of the Island, so he did not renew his FFE membership.

One year later, Stephen started to receive numerous text messages each day from unknown numbers, most marketing gym or weight loss products.

Suspecting that FFE shared his information widely, he contacted his old FFE branch and asked reception if they still had his information on file. They did, but offered to delete it if he wished. He was told FFE's process to purge his information from all the affiliated systems might take 8 to 12 weeks. FFE also informed him that Kelvin was no longer employed by FFE and had recently started working for a competitor. FFE believed that Kelvin may have shared the mobile contact details of his clients with the new gym, and apologized for this inconvenience.

Which of the following practices would likely violate Hong Kong's Data Protection Principle 1 regarding data collection?

  1. A

    FFE's collection of full name from prospective clients.

  2. B

    FFE affiliates' receipt of Stephen's contact information.

  3. C

    FFE's collection of age and HKID from prospective clients.

  4. D

    FFE's collection of Stephen's messenger cell details through Kelvin.

Show answer and explanation

Correct answer: D

Question 4 Single choice

In enforcement cases, what is Singapore's Personal Data Protection Commission (PDPC) obligated to do?

  1. A

    Publish the decisions it makes regarding complaints.

  2. B

    Provide the complainant with a way to appeal a decision.

  3. C

    Publish the name of an organization named in a complaint.

  4. D

    Intervene in civil actions to provide assistance to complainants.

Show answer and explanation

Correct answer: B

Question 5 Single choice

In the area of human rights, what separates Singapore from many other Asian countries?

  1. A

    It is not a member of the Association of Southeast Asian Nations (ASEAN).

  2. B

    It has not signed the International Covenant on Civil and Political Rights.

  3. C

    It has not adopted the ASEAN Human Rights Declaration.

  4. D

    It is not a member of the United Nations.

Show answer and explanation

Correct answer: B

Question 6 Single choice

In addition to adhering to the data export principle of section 43A of India's IT Act 2000, data exporters in India must also follow principles of?

  1. A

    Privity of contract.

  2. B

    Disclosure limitation.

  3. C

    Mandatory registration.

  4. D

    Third party assessment.

Show answer and explanation

Correct answer: C

Question 7 Single choice

In which situation would a data intermediary based in Singapore be liable for breaches against the PDPA?

  1. A

    When it fails to provide an individual access to his or her data.

  2. B

    When it does not provide anonymous transactions with an individual.

  3. C

    When it fails to inform an individual it is processing data from a controller.

  4. D

    When it processes data contrary to the provisions established in the contract.

Show answer and explanation

Correct answer: D

Question 8 Single choice

In India's IT Rules 2011, which is included in the definition of "sensitive personal data"?

  1. A

    Tax records.

  2. B

    IP addresses.

  3. C

    Next of kin.

  4. D

    Sexual Orientation.

Show answer and explanation

Correct answer: D

Question 9 Single choice

Section 43A was amended by India's IT Rules 2011 to include?

  1. A

    A definition of what constitutes reasonable security practices.

  2. B

    A requirement for the creation of a data protection authority.

  3. C

    A list of cases in which privacy policies are not necessary.

  4. D

    A clarification regarding the role of non-automated data.

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which personal data element is NOT considered a special category of data under the General Data Protection Regulation (GDPR)?

  1. A

    Physical or mental health data.

  2. B

    Financial information.

  3. C

    Race or ethnic origin.

  4. D

    Political opinions.

Show answer and explanation

Correct answer: B

Explanation

The personal data element that is NOT considered a special category of data under the General Data Protection Regulation (GDPR) is B. Financial information.

The GDPR identifies "special categories" of personal data that require additional protection due to their sensitive nature. These categories include physical or mental health data, race or ethnic origin, and political opinions, among others. However, financial information is not classified as a special category of data under the GDPR. Nonetheless, it is still subject to the GDPR's general principles and protections for personal data.