All of the following are exempt from Section 43A of India's IT Rules 2011 EXCEPT?
Show answer and explanation
Correct answer: C
CIPP-A Real Exam Questions
93 questions available · Page 1 of 10
Updated Exam DumpsVerified AnswersPass Guarantee
All of the following are exempt from Section 43A of India's IT Rules 2011 EXCEPT?
Correct answer: C
Under India's IT Rules 2011, data subjects have the right to correct inaccuracies in personal information collected about them only if?
Correct answer: A
SCENARIO - Please use the following to answer the next question:
Fitness For Everyone ("FFE") is a gym on Hong Kong Island that is affiliated with a network of gyms throughout Southeast Asia. When prospective members of the gym stop in, call in or submit an inquiry online, they are invited for a free trial session. At first, the gym asks prospective clients only for basic information: a full name, contact number, age and their Hong Kong ID number, so that FFE's senior trainer Kelvin can reach them to arrange their first appointment.
One day, a potential customer named Stephen took a tour of the gym with Kelvin and then decided to join FFE for six months. Kelvin pulled out a registration form and explained FFE's policies, placing a circle next to the part that read "FEE and affiliated third parties" may market new products and services using the contact information provided on the form to Stephen "for the duration of his membership." Stephen asked if he could opt-out of the marketing communications. Kelvin shrugged and said that it was a standard part of the contract and that most gyms have it, but that even so Kelvin's manager wanted the item circled on all forms. Stephen agreed, signed the registration form at the bottom of the page, and provided his credit card details for a monthly gym fee. He also exchanged instant messenger/cell details with Kelvin so that they could communicate about personal training sessions scheduled to start the following week.
After attending the gym consistently for six months, Stephen's employer transferred him to another part of the Island, so he did not renew his FFE membership.
One year later, Stephen started to receive numerous text messages each day from unknown numbers, most marketing gym or weight loss products.
Suspecting that FFE shared his information widely, he contacted his old FFE branch and asked reception if they still had his information on file. They did, but offered to delete it if he wished. He was told FFE's process to purge his information from all the affiliated systems might take 8 to 12 weeks. FFE also informed him that Kelvin was no longer employed by FFE and had recently started working for a competitor. FFE believed that Kelvin may have shared the mobile contact details of his clients with the new gym, and apologized for this inconvenience.
Which of the following practices would likely violate Hong Kong's Data Protection Principle 1 regarding data collection?
Correct answer: D
In enforcement cases, what is Singapore's Personal Data Protection Commission (PDPC) obligated to do?
Correct answer: B
In the area of human rights, what separates Singapore from many other Asian countries?
Correct answer: B
In addition to adhering to the data export principle of section 43A of India's IT Act 2000, data exporters in India must also follow principles of?
Correct answer: C
In which situation would a data intermediary based in Singapore be liable for breaches against the PDPA?
Correct answer: D
In India's IT Rules 2011, which is included in the definition of "sensitive personal data"?
Correct answer: D
Section 43A was amended by India's IT Rules 2011 to include?
Correct answer: A
Which personal data element is NOT considered a special category of data under the General Data Protection Regulation (GDPR)?
Correct answer: B
The personal data element that is NOT considered a special category of data under the General Data Protection Regulation (GDPR) is B. Financial information.
The GDPR identifies "special categories" of personal data that require additional protection due to their sensitive nature. These categories include physical or mental health data, race or ethnic origin, and political opinions, among others. However, financial information is not classified as a special category of data under the GDPR. Nonetheless, it is still subject to the GDPR's general principles and protections for personal data.