PDPC · Singapore

PDPA Study Map

DPO Exam Revision
Tap a node to study · drag to pan · scroll / + − to zoom

Readable outline — open in a web browser (Safari/Chrome) for the interactive map.

PDPA Personal Data Protection Act

Nine topic clusters drawn from your notes. Compliance is treated as a continuous cycle — not a one-time checklist.

Tap a branch below to start, or explore from the map.

PDPA Regime The big picture

Singapore's data-protection regime is primarily governed by the Personal Data Protection Act (PDPA), which sets a baseline standard of protection across the economy.

Its core aim is to balance individuals' right to protect their data with organisations' need to use data for legitimate, reasonable purposes. Explore the five facets below.

Core Concepts Foundations

The PDPA balances individuals' right to protect their data against organisations' need to use data for legitimate, reasonable purposes.

Three overarching concepts

  • Consent — generally obtain knowledge & consent before handling data (unless an exception applies).
  • Purpose — inform individuals of the specific reasons for collection, use or disclosure.
  • Reasonableness — only handle data for purposes a reasonable person would find appropriate.

4 Objectives Regime goals

  1. Strengthen consumer trust through organisational accountability — boosting protection to support trust and active participation in the digital economy.
  2. Ensure effective enforcement — robust mechanisms (voluntary statutory undertakings, higher financial-penalty caps) to drive compliance.
  3. Enhance consumer autonomy — give individuals greater control of their data, supported by frameworks like Data Portability.
  4. Support data use for innovation — let organisations confidently harness data for legitimate purposes (with the requisite safeguards & accountability) to improve products and services.

Scope & Exclusions Application

Applies broadly to any individual, company, association or body (formed in Singapore or not) handling personal data. Covers electronic and physical data, whether true or false.

Key exclusions

  • Individuals acting in a personal/domestic capacity.
  • Employees acting in the course of employment.
  • Business Contact Information (BCI) — corporate email, business title, business phone.
  • Public agencies — governed by separate public-sector rules.

Key dates & rules

  • The Data Protection (DP) provisions came into operation on 2 July 2014.
  • For deceased individuals, the disclosure & protection provisions still apply for 10 years after death.

Two Pillars DP & DNC

1. Data Protection (DP) Provisions

The bulk of the regime — the 11 Key Obligations (POPCON ExTRAS ADD) governing collection, care of data, and individual autonomy. Accountability underpins them: a proactive, risk-based approach, not a checklist.

2. Do Not Call (DNC) Provisions

Apply to marketing messages (voice, SMS, fax) to Singapore numbers. Organisations must check the DNC Registry before sending, identify the sender, and are barred from dictionary attacks / address-harvesting software. A registry check is valid for up to 21 days before the message is sent.

Enforcement & Penalties PDPC

Enforced by the Personal Data Protection Commission (PDPC). Options range from advisory notices to accepting voluntary undertakings for remediation.

Severe breaches

For egregious or high-impact breaches, the PDPC can investigate and impose financial penalties of up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.

Operationalizing In practice

Every organisation must appoint at least one Data Protection Officer (DPO).

To demonstrate accountability, organisations are encouraged to use these frameworks & tools — tap to jump:

DPMP & DPIA each have their own full branch; PATO lives under Tools & Roles.

Data Breach Respond & notify

Handle a breach with the C.A.R.E. response model. Notification rules live under the Report step.

  • C — Contain: act swiftly to stop further compromise; limit damage.
  • A — Assess: circumstances, ease of identifying individuals, and whether it is legally notifiable.
  • R — Report: notify the PDPC and/or affected individuals if thresholds are met.
  • E — Evaluate: review the response to improve recovery & prevention.

Contain C

Act swiftly to prevent further compromise and implement mitigating actions to limit damage.

Assess A

Evaluate the circumstances, the ease of identifying individuals from compromised data, and whether the breach is legally notifiable.

Report R

Fulfil the duty to notify the PDPC and, where required, affected individuals, once a breach is assessed as notifiable.

Scale vs harm

  • ≥ 500 affected individuals → "significant scale" → notify the PDPC.
  • Notify an affected individual only if the breach results, or is likely to result, in significant harm.
  • ≥ 500 but no significant harm → you do not notify individuals.

Timing

  • Assess a suspected breach within 30 days to decide if it is notifiable.
  • Notify the PDPC within 3 calendar days of deciding it is notifiable.
  • Notify affected individuals as soon as practicable — at the same time as, or after, the PDPC.

Significant Harm Threshold

Generally met when a full name / alias / full NRIC is compromised together with sensitive data:

  • Financial info (wages, salary, income from sale of goods/property).
  • Medical, health, or life-insurance records.
  • Account identifiers paired with passwords, security codes, biometric data, or access codes.

3 Exceptions No need to notify

Even if the harm threshold is met, individual notification is not required if:

  • Remedial action — taken immediately, making significant harm unlikely.
  • Technological protection — data was encrypted to a reasonable standard.
  • Law enforcement / PDPC — agency prohibits notice, or PDPC waives it.

Evaluate E

Review the overall response so recovery and future prevention strategies can be improved.

DPIA Impact assessment

A process & tool to identify, assess and address personal-data risks based on an organisation's functions, needs and processes.

Why conduct one

  • Identifies high risks to individuals' data-protection rights.
  • Checks compliance with the PDPA and best practice.
  • Builds safeguards before a system/process goes live.

When

  • New IT systems / business processes, or major changes to existing ones.
  • Organisational restructuring affecting departments that handle personal data.
  • When relying on certain exceptions — legitimate interests or deemed consent by notification — since the adverse effects on individuals must be assessed and mitigated.

1 · Assess Need Phase 1

Determine if a new/changed system or process involves personal data. Check for new data collection, disclosure to new third parties, or a new/unconsented purpose.

2 · Plan Phase 2

Form the DPIA project team (PM, DPO, steering committee, departmental reps). Define scope, the risk framework & methodology, stakeholders, and timeline.

3 · Identify PD Flows Phase 3

Map how data moves via a Data Inventory Map or Data Flow Diagram. Review documents, contracts, specs; consult departments / on-site inspection.

4 · Assess Risks Phase 4

Check compliance against obligations (consent, notification, purpose limitation) using a checklist. Rate & rank risks by impact and likelihood.

5 · Action Plan Phase 5

Propose technical & organisational measures to treat risks. Assign action owners and set an implementation timeline.

6 · Implement & Monitor Phase 6

Document into a DPIA report (DPO reviews, senior management approves). Owners execute; the DPO monitors results to ensure risks are managed.

DPMP Management programme

A framework to build a robust data-protection infrastructure and demonstrate accountability. A continuous four-step cycle: Governance & Risk → Policy & Practices → Processes → Review.

Governance & Risk Step 1

Establish a governance structure with leadership to define values and identify data-protection risks.

Risk Fundamentals Threat · Vulnerability · Risk

Three core concepts in risk management, and how they connect.

In short: a threat exploits a vulnerability, which creates a risk.

Threat — something with the potential to cause harm. It can be technical (malware, spyware) or human (a disgruntled former employee, or careless staff who leave confidential documents in a coffee shop).

Vulnerability — a specific weakness, gap, or shortcoming in a system or process that a threat can exploit. Examples: an inadequate firewall, unpatched software, or weak internal policies (e.g. allowing staff to take physical documents out of the office).

Risk — the potential for loss, harm, or negative effect on an organisation or individual. Assessed by combining the likelihood of an incident with its expected impact (Risk ≈ Likelihood × Impact).

How they connect: a threat has the potential to do harm by exploiting a vulnerability (a weakness), which creates a risk (the potential for loss, compliance failure, or negative impact).

Policy & Practices Step 2

Develop data-protection policies and clearly designate roles and responsibilities.

Processes Step 3

Design SOPs that operationalise policies into daily business functions.

Review Step 4

Regularly review and update policies & processes; conduct audits to stay current.

11 Obligations Lifecycle loop

Mapped as a continuous lifecycle. Accountability sits at the top as the overarching principle.

POPCON ExTRAS ADD Memory aid

An acronym checklist a company runs through whenever it collects, uses or stores personal data.

POPCON — basics & collection

  • Personal data — is this actually personal data?
  • Organisation — are we acting as an organisation?
  • Purpose — reasonable business purpose? (Purpose Limitation)
  • Consent — did we get permission? (Consent)
  • Open & Accountable — policies + a DPO in place? (Accountability)
  • Notified — did we tell them why, before collecting? (Notification)

ExTRAS — taking care of the data

  • Exceptions — a valid exception if no consent? (e.g. emergency)
  • Transferred — sent overseas with comparable protection? (Transfer Limitation)
  • Retained — kept only as long as needed, then destroyed? (Retention Limitation)
  • Accurate — is the data correct & up to date? (Accuracy)
  • Secured — proper security against leaks/hackers? (Protection)

ADD — individual rights & emergencies

  • Access & Correction — can they view/fix their data? (Access & Correction)
  • Data Breach — can we notify authorities & people if hacked? (Data Breach Notification)
  • Data Porting — can we transmit data to another provider? (Data Portability)

Collection Group

Three obligations govern how data is collected:

  • Notification — before/at collection, use or disclosure, inform the individual of the specific purpose(s).
  • Consent — obtain valid consent before handling data, unless an exception applies; consent isn't valid unless the purpose was notified first.
  • Purpose Limitation — only handle data for purposes a reasonable person would consider appropriate; don't collect excessively beyond what's reasonable for the product/service.

An organisation can rely on four valid types of consent — explore each below.

1 · Express Consent Consent type

The most straightforward and safest form of consent.

The individual actively agrees to the collection, use or disclosure of their data — e.g. physically signing a form or ticking a checkbox online.

2 · Deemed — Conduct Consent type

Inferred from the individual's actions rather than explicitly given. Applies when someone voluntarily provides their data, fully knowing and understanding the purpose.

Example: giving your home address to a restaurant specifically so they can deliver your food order.

3 · Deemed — Contractual Necessity Consent type

Also inferred, but specifically in the context of a contract. Applies when an individual provides data to enter a contract and processing/sharing it is reasonably necessary to perform or fulfil that contract.

The individual is deemed to consent to

  • The original organisation disclosing data to a third party.
  • The third party collecting and using it.
  • The third party further disclosing it to others to fulfil the contract.

Examples

  • Service delivery (restaurant): ordering via an app — name, address & phone passed to a third-party delivery provider, as that's necessary to deliver the food.
  • Employment: providing your NRIC and bank details to secure an employment contract.

4 · Deemed — Notification Consent type

The organisation clearly notifies the individual of a new purpose for using their data and gives a reasonable period to opt out. If they don't opt out in time, they are deemed to have consented.

Pre-condition

The organisation must first conduct a risk assessment to ensure the new purpose is low risk and won't negatively impact the customer.

Care Group

Four obligations govern caring for data once held:

  • Accuracy — make reasonable effort to keep data accurate & complete, especially if used for a decision affecting the individual or disclosed to another organisation.
  • Protection — make reasonable security arrangements (physical, administrative, technical) against unauthorised access, use, disclosure, loss, etc.
  • Retention — don't keep data indefinitely; dispose of or anonymise once the purpose is served and no legal/business need remains.
  • Transfer Limitation — overseas recipients must be bound (contracts/binding corporate rules) to a comparable standard of protection.

Transfer Limitation — purpose

To ensure personal data transferred outside Singapore is protected to a standard comparable to the PDPA.

It protects individuals' data rights even when their data crosses international borders.

Protection — administrative safeguards

Management controls, training, and policy-driven procedures — e.g. developing and communicating clear data-protection policies to all staff.

Key term — Vulnerability

A specific weakness or gap that can be exploited — an internal flaw in a system or process that gives threats an opening to cause harm. Safeguards exist to close these.

Key term — Pseudonymisation

Replacing identifying data with artificial identifiers or aliases. It reduces the linkability of a data set while still allowing re-identification if the key is available — so it is not full anonymisation.

Key term — Anonymisation

Removing identifying information from a dataset so the remaining data can no longer identify any particular individual. This lets an organisation securely retain and reuse what used to be personal data for other purposes — e.g. trend analysis or statistical market research — without identifying the people involved.

Anonymisation is a valid way to comply with the Retention Limitation Obligation: when data is no longer needed for business or legal purposes, the organisation must either securely destroy it or “remove the means by which the personal data can be associated with particular individuals” (i.e. anonymise it).

Techniques — textual / database data:

  • Suppression — remove an entire record or attribute (e.g. a whole column).
  • Character masking — hide parts of a string with symbols like * or x.
  • Pseudonymisation — replace identifiers with made-up values or references.
  • Generalisation / Recoding — reduce precision (exact age → age range; exact address → region).
  • Swapping / Shuffling — rearrange values so they no longer match the original records.
  • Aggregation — summarise into broad values rather than individual lists.

Physical documents: redact (black out) names, or alter precise dates and locations. Audio / video: blur faces in photos or CCTV, and electronically disguise audio.

Re-identification risk & the Motivated Intruder Test. As computing power and public data grow, anonymised data can sometimes be combined with other information to re-identify someone. To test robustness, organisations run a “Motivated Intruder Test” — checking whether a reasonably competent person, using standard investigative techniques and public resources (internet, social media), could work out an individual’s identity from the anonymised dataset.

Key term — C-I-A parameters

Three industry principles used to determine risk levels and assess impact if data or systems are compromised:

  • Confidentiality — risk from unauthorised/inappropriate disclosure; access must be restricted.
  • Integrity — risk to data quality/corruption; data must stay accurate, complete, unaltered.
  • Availability — risk of data not being available to intended users when needed.

Autonomy Group

Three obligations protect the individual's ongoing rights:

  • Access & Correction — on request, provide access to their data and how it was used/disclosed in the past year; process requests to correct errors.
  • Data Breach Notification — assess a breach within 30 days; if notifiable (≥500 people or likely significant harm), notify the PDPC and, in some cases, affected individuals.
  • Data Portability — on request, transmit a copy of the individual's electronic data to another organisation in a machine-readable format, so consumers can switch providers.

Data Portability — limitation

The obligation only applies to data categories that have been 'white-listed' by regulations.

To provide certainty, it is limited to specific white-listed data categories prescribed by regulations — not to all personal data.

Accountability Overarching

The fundamental principle sitting above the whole cycle.

What it means

A risk-based approach to identifying, monitoring, and responding to personal-data risks in order to demonstrate compliance.

It is about being proactive and systematic in managing data risks — showing that the organisation takes responsibility, rather than reacting only after something goes wrong.

DPO vs the organisation

Appointing a Data Protection Officer (DPO) is a requirement — but the accountability for adherence to the Act rests with the organisation as a whole, not the DPO alone.

3PIE Consent exceptions

A mnemonic for the scenarios where an organisation may collect, use or disclose personal data without consent. Three groups of three: 3 P's · 3 I's · 3 E's.

Pair it with POPCON ExTRAS ADD (the 11 obligations) when revising.

Note

Business Contact Information (BCI) is usually grouped with the P's — the PDPA data-protection rules don't apply to it.

3 P's Public & payment

  • Public agency
  • Payment / debt collection
  • Publicly available data

Plus BCI — Business Contact Information (PDPA rules don't apply).

3 I's Interests

  • Legitimate Interest
  • Business Improvement
  • National Interest

Legitimate Interests — mandatory requirement

To rely on this exception, an organisation must conduct an assessment to determine whether its legitimate interests outweigh any adverse effect on the individual.

This is a balancing test and risk assessment — it ensures the organisation's interests do not unfairly harm the individual.

In short, the framework requires balancing the business need against the potential impact on individuals.

3 E's Operational

  • Emergency
  • Employment
  • Evaluation

Scope of 'Evaluation'

The Evaluation exception applies to activities like determining suitability for employment, promotion, or awarding scholarships.

Loyalty programs do not qualify — they usually operate under express consent and count as marketing / business activities, not 'evaluation' in the legal sense.

Tools & Roles Supporting

Self-assessment, accountability and data-mapping instruments referenced across your notes.

PATO Self-assessment

A digital self-assessment tool by the PDPC.

  • Identifies gaps in PDPA compliance from your inputs.
  • Directs you to resources — guidelines, guides, best practices — to close those gaps.

RACI Roles matrix

The RACI Matrix is a tool used to clearly define roles and responsibilities within an organisation's team.

  • Responsible — does the task.
  • Accountable — ultimate ownership.
  • Consult — asked for input/advice.
  • Informed — kept up to date.

DIM Data map

Documents how data flows through a process — from collection to secure destruction.

Pros

  • Easy to develop & maintain.
  • No specialised software needed.
  • No limits on info recorded.
  • Good for extensive, complex flows.

Cons

  • No visual representation (unlike a DFD).
  • Limited at showing interconnectivity across systems.

Mock Questions Self-test

All 63 practice questions with options, grouped by topic. Tap any card to reveal the correct answer.

DPIA Quiz DPIA — mock questions

Q1. What is a DPIA?
A An assessment to assess the impact of data protection risks to the organisation only
B A tool to handle data breach
C An assessment to gauge the effectiveness of your DPMP
D A tool for identifying, assessing and addressing personal data protection risk based on an organisations functions, needs and processes.
Q2. What is the scope of a DPIA? What areas could an organisation conduct a DPIA on?
A DPIA should only be conducted on an organisation's IT system(s), including public facing websites, cloud storage platforms, customer relationship management (CRM) systems
B DPIA can be conducted on an organisation's IT system(s), including public facing websites, cloud storage platforms, customer relationship management (CRM) systems and on its processes
C DPIA can be conducted on the processes of an organisation.
D DPIA can be conducted on the network of an organisation's IT system(s)
Q3. What are the steps of a DPIA?
A The steps are plan the DPIA, identify the personal data and personal data flow, identify and assess data protection risks, create an action plan, implement the action plan and monitor its results.
B The steps are assess the need for a DPIA, plan the DPIA, identify the personal data and personal data flow, identify and assess data protection risks, create an action plan, implement the action plan and monitor its results.
C The steps are assess the need for a DPIA, identify the personal data and personal data flow, identify and assess data protection risks, plan the DPIA, create an action plan, implement the action plan and monitor its results.
D The steps are create an action plan, assess the need for a DPIA, plan the DPIA, identify the personal data and personal data flow, identify and assess data protection risks, implement the action plan and monitor its results.
Q4. What are not key tasks of a DPIA?
A Identify the risks to personal data
B Identify the personal data flows and purposes for these processes thru the IT systems
C Address personal data risks by policies and SOPs
D Assess need for DPIA
This is a DPMP task, not specific to a single DPIA.
Q5. Who should be involved in a DPIA?
A Project Manager
B DPO
C DPIA steering committee
D All of the answers
Q6. When planning the DPIA, what needs to be considered?
A All of the answers
B Estimate time required
C Obtain input from all stakeholders involved
D Define the risk assessment framework and methodology
Q7. When does a DPIA need to be conducted?
A Designing a new corporate website
B Implementing a new IT system or a process for a receptionist collecting personal data from visitors
C Creating a new procurement process for raw materials
D Auditing the effectiveness of the DPMP
Q8. What are some questions to consider when deciding if a DPIA is required?
A Is an existing IT system or process that the organisation is reviewing for collecting, using, disclosing and storing personal data
B Is an existing IT system or process that the organisation is substantially redesigning for collecting, using, disclosing and storing personal data
C Is a new IT system or process that the organisation is introducing, developing or implementing a new process for collecting, using, disclosing and storing personal data
D All of the answers
Q9. What needs to be considered to identify and assess risks when conducting a DPIA?
A Create a DPMP checklist
B Provide notification to individuals on how their personal data is handled
C Understand the purposes for which personal data is collected , used, disclosed, stored
D Implement controls to mitigate the risks
Q10. What happens when risks are identified and assessed during a DPIA?
A Provide contact point for queries regarding DPIA, report to senior management and document implementation plan
B Provide contact point for queries regarding DPIA, provide report for implementation, action owners for implementation outcomes.
C Report to senior management, provide mechanism for implementation, indicate action owners for implementation outcomes.
D Provide contact point for queries regarding DPIA, mechanism for implementation, action owners for implementation outcomes.
Q11. What are the considerations when implementing the action plan from a DPIA?
A If and when there is a change in risks associated with the collection, use, disclosure and/or storage of personal data in an IT system or a process that has been the subject of a DPIA, conduct a secondary DPIA
B The leader of the DPIA Project Team should document the entire DPIA process (that is, how the DPIA was scoped, planned and carried out, its findings, and the proposed action plan) into a DPIA report.
C The DPO should monitor the outcomes of the action plan to ensure that identified personal data protection risks are addressed as planned and that the organisation continues to manage risks to personal data responsibly
D All of the answers
Q12. How does an organisation monitor the implementation of DPIA?
A Monitor legislative changes
B Monitor technology or security developments
C Monitor how the processing is conducted
D All of the answers

Data Breach Quiz Data breach — mock questions

Q13. What is the first thing an organisation needs to do in a data breach?
A Report to PDPC
B Contain the breach
C Notify individuals
D Assess the risks and impact of the breach to the orgnisation and individuals
Q14. What are the first questions to ask when investigating a data breach?
A How did the breach happen
B How much to factor for the penalties
C How to answer the stakeholders
D Who is responsible for the breach
Q15. Upon containment of the data breach, what are the secondary considerations when investigating a data breach?
A Where did the personal data protection breach take place?
B How was the personal data protection breach detected and by whom?
C What was the cause of the personal data protection breach?
D How and when was the personal data protection breach escalated to the organisations Breach Response and Team and to the organisations senior management?
Q16. How does an organisation assess risks and impact of a data breach for individuals whose personal data has been exposed?
A How many individual's personal data was exposed?
B Who, by category, are these individuals?
C What types of personal data were involved, in particular, how sensitive is the personal data that was involved and the corresponding potential harm caused by the disclosure of such personal data?
D All of the answers
Q17. What are risks and impact of data breach for an organisation?
A What did not prevent the personal data protection breach from happening?
B When did the personal data protection beach occur and was it a one-off incident and, if not, how often has it occurred?
C Will compromised personal data affect transactions with any third parties?
D All of the answers
Q18. What is not necessary for an organisation in a post breach evaluation?
A Operational and policy issues
B Resource-related issues
C Stockholders related issues
D Employee-related issues

DPO & Accountability Quiz DPO & accountability — mock questions

Q19. What does a DPO do?
A Liaise with the stakeholders on data protection matters, if necessary
B Foster logical decision making a culture among employees and communicate personal data protection policies to stakeholders
C Alert management to any risks that might arise with regard to personal data and
D Manage personal security-related queries and complaints
Option D wrongly says "personal security" instead of data protection.
Q20. What is accountability?
A It is a way of assessing risks
B It is a way of mitigating risks
C It is a way of demonstrating compliance
D It is a way of developing DPMP
Q21. What is the benefit of Data Protection by Design?
A Identify data protection issues early
B Increase awareness of data protection across the organisation
C Meet the data protection obligations under the PDPA
D All of the answers
Q31. What are some things an organisation do to demonstrate compliance to PDPA?
A Keep up with the latest developments in data protection
B Designate a DPO
C Get educated on data protection
D Form a PDPA project team

DPMP Quiz DPMP — mock questions

Q22. What does a DPMP do for an organisation?
A To help organisations develop, manage and maintain a robust data protection infrastructure
B To enhance the organisations public image and reputation which could provide businesses with a competitive edge
C To help foster a culture of data protection within the organisation
D All of the answers
Q23. What are the steps of a DPMP?
A Assess, Protect, Sustain
B Governance and Risks, Policy and Practices, Processes, Review
C Policy, SOPs, Controls
D Administration, Physical, technical controls
Q24. Who are the stakeholders of an organisation?
A Customers, public, investors, media
B Regulators, associations, third parties
C Employees, associates
D All of the answers
Q25. The following are characteristics of a management sponsor except
A Is driver of DPMP.
B Has authority to staff and allocate financial resources.
C Is involved in all data protection related risk management activities
D Able to emphasise to staff that DPMP is high priority and oversees the DPMP project team.
Daily risk management is handled by the DPO/team.
Q29. Data Classification is based on the following except for
A Levels of data classification to adopt
B Deciding who should secure each level of data classification
C Parameters for each level of data classification for ease of classification
D Access rights to the relevant data that should be granted to staff
Q30. The first step in developing a DPMP is
A Build a data inventory map
B Identify potential data protection risks
C Decide on data classification
D Assign PDPA project team members roles and responsibilities
Q32. Which are the following are common mistakes organisations when complying with the PDPA?
A Insufficient data protection measures
B IT infrastructure that is known to be vulnerable to online threats but action is not taken to remedy those vulnerabilities
C Disjointed practices and processes within the organisation,
D All of the answers
Q60. What is a process that should be in the DPMP checklist?
A Personal data protection policy
B Personal data protection notice
C Maker checker process or a buddy system
D Information security policy
Q61. What needs to be monitored when revising and review your DPMP?
A The organisation's external environment (i.e. changes in legislation)
B The organisation's internal environment (i.e. such as new business projects that deal with personal data) on an ongoing basis
C Feedback from internal staff so that they may raise the alert about gaps or risks in personal data protection policies or processes
D All of the answers
Q62. What are ways to validate your DPMP?
A Reviewed by a external third party
B Certify their personal data protection policies and practices / SOPs
C Monitor complaints the organisation receives to highlight possible gaps in policies and processes or flaws in the way policies and processes are communicated.
D All of the answers
Q63. The following are areas to audit your DPMP except for
A To assess the process of the organisation's financials
B For compliance with the PDPA
C To gauge staff awareness of the organisation's personal data protection policies and practices / SOPs
D To gauge the adequacy of the organisation's training and education activities

Risk & Controls Quiz Risk & controls — mock questions

Q26. What is risk?
A An identified security gap in a system
B The likelihood of an event, incident or attack
C A compliance gap regarding the PDPA
D All of the answers
Q27. What is a threat?
A Policy of letting employees bring confidential files out of the office
B Failing to terminate the log-in credentials of employees immediately after they leave the organisation
C Failing to apply update patches to software
D Malware and spyware
Q28. What is a vulnerability?
A Former employees who deliberately seek to do harm to an organisation are also threats
B Remove paper documents from the office and accidentally leave them in a coffee shop or on a bus
C Disgruntled employees.
D Inadequate firewall
Q33. How should an organisation rate risk?
A Rate the impact to stock of organisation
B Rate the effectiveness of the DPMP
C Rate the likelihood of risk happening and impact of risk to business
D Rate incidents that are escalated to senior management
Q34. What are main purpose of reporting risks to senior management?
A Senior management support for the organisations data protection efforts
B Obtain right level of priority and resources for data protection eff orts
C Clear visibility of the current state of the organisation's compliance with the PDPA and the data protection risks highlighted
D So that senior management remains responsible for compliance of PDPA
Q35. The following are common ways an organisation respond to risks with the exception of ?
A Risk reduction
B Risk retention
C Risk treatment
D Risk Avoidance
The four ways are reduction, retention, avoidance, and sharing.
Q36. What are 3 controls used when treating risks?
A Administrative, Physical, Technical controls
B Policiy, Physical, People Controls
C Preventive, Detective, Corrective controls
D Info Security, Physical, Access controls
Q37. What are examples of technical controls?
A Anti-virus programs
B Data loss prevention (DLP) tools
C Penetration tests
D All of the answers

Obligations & SOPs Quiz Obligations, vendors & SOPs — mock questions

Q38. What are not examples of considerations when developing SOPs to mitigate risks related to retention Obligation
A Make sure there are appropriate / secure disposal procedures
B Make sure staff collect only what is reasonable to fulfill its intended purpose(s)
C Develop retention schedules / policies for personal data
D Make sure staff follow procedures for implementing the retention schedules / policies
This pertains to Collection/Purpose Limitation, not Retention.
Q39. What are examples of SOPs for complying with consent, notification and purpose limitation obligations?
A Make sure there are appropriate / secure disposal procedures
B Make sure staff collect only what is reasonable to fulfill its intended purpose(s)
C Develop retention schedules / policies for personal data
D Make sure staff follow procedures for implementing the retention schedules / policies
Q40. What does an organisation need to do in relation to transfer limitation obligation within a corporate group?
A Ensure staff are trained in data protection before their first day
B Maintain a personal data inventory map, personal data flow diagram,
C Use binding corporate rules
D Communicate policies to all relevant staff
Q41. What are ways for an organisation to manage risks related to data intermediary?
A Conduct appropriate due diligence
B Ensure written contract between an organisation and its data intermediary have strong PDPA protection for the organisation
C Ensure reasonable security arrangements made to protect personal data and that CUDS of personal data is compliant with PDPA
D All of the answers
Q42. What are not checks an organisation could conduct that would determine if the potential vendor could comply with your organisation's requirement to complying to PDPA?
A Conduct a risk assessment on vendors risk posture
B Enquire about what personal data employees of the potential vendor can access remotely
C Understand potential vendors security policies and the security of its IT network including by requesting an independent auditors report and/or requesting penetration tests and/or vulnerability assessments of its IT systems
D Check the background of directors' of the data intermediary
Q43. What is an exception to the terms of the processing contract between the organistaion and its data intermediary?
A Provide organisation with audit rights
B Require the data intermediary to indemnify the organisation for any breach due to data intermediary
C Set up disposal procedures for sata intermediary when contract terminates
D Provide organisation with information of the personal data of employees of data intermediary
Q44. What are some considerations for data sharing?
A Individuals do not need to provide consent
B Specify how the personal data will be shared
C Once contract with data intermediary is signed, employees of data intermediary may have access to the data
D If individuals have consented, no notification is necessary
Q45. What are considerations related to data protection when deciding between a bespoke or tailor made IT solution?
A For bespoke-ensure IT service provider takes into account data moving through system when designing the service and ensure that security requirements are spelled out in the contract
B For ready made solutions - ensure that contract spells out security requirements
C For ready made solutions-ensure IT service provider takes into account data moving through system when designing the service and ensure that security requirements are spelled out in the contract
D For ready-made solutions-it is the responsibility of the service provider to ensure that features and limitations be understood by the organisation
Q46. When setting up a website, what should an organisation require of the vendor with regards to PDPA?
A Host the website so that it is accessible on the internet
B Perform administrative tasks, such as managing user accounts
C The contract should state clearly the responsibilities of the IT vendor with respect to the PDPA
D Maintain the website by updating the design, layout, graphics and programming when required
Q47. The following are not considerations when deciding on security measures to manage personal data in electronic medium
A Type of personal data held by the organisation
B Risk and impact to the individual should such personal data be accessed and used by unauthorised persons
C Form of the personal data (that is, physical or electronic) in the organisations possession or under its control
D None of the answers
Meaning A, B and C are all valid considerations.
Q48. Risks in cloud computing can be addressed by the following
A Ensure accounts are shared
B Use encryption only for data at rest
C Use anonymisation to ensure there is no unauthorised access
D Understand what will happen to personal data it has stored in the cloud if organisation decides to withdraw from the service
Q49. What does anonymisation refers to?
A Anonymisation is a systematic framework to help organisations establish a robust data protection infrastructure.
B Anonymisation involves identifying, assessing and addressing personal data protection risk based on an organisations functions, needs and processes.
C Anonymisation is a way of demonstrating compliance
D Anonymisation refers to the process of removing identifying information, such that the remaining data does not identify and particular individual.
Q50. What are not examples of anonymisation techniques?
A Data shuffling
B Data analytics
C Data suppression
D Aggregation
Q51. What is meant by a motivated intruder test?
A It is a general test for assessing the risks of re-identifi cation and the robustness of anonymisation.
B It is a general test for assessing the personal data inventory risks of organisation
C It is a general test for assessing the motivation of the intruder
D It is a general test for assessing the impact and risks of a data breach
Q52. What are some ways to carry out a motivated intruder test?
A Doing a web search to discover whether a combination of birth date and postcode data can be used to reveal a particular individuals identity
B Searching the archives of newspapers to see whether it is possible to associate a victims name with crime map data
C Using social networking to see if it is possible to link anonymised data to a users profile
D All of the answers
Q53. What is a destruction process for physical medium?
A Degaussing
B Reformatting
C Recycling
D Pulping
Q54. What is a way to manage risks to data in transit or accidental disclosure?
A Ensure that staff are trained to spot any mismatched data after sorting has been carried out
B Pulping
C Ensure that individuals are notified on documents being sent
D Ensure that there is consent from individuals to send their personal data to other recipients

Policies & Statements Quiz Policies & statements — mock questions

Q55. Which are the four steps of a policy lifecycle?
A Drafting, reviewing, revising / getting management approval / communicating to staff
B Drafting, reviewing, revising / getting stockholders approval / communicating to stakeholders / training and enforcing the policy
C Drafting, reviewing, revising / getting management approval / communicating to stakeholders / training and enforcing the policy
D Getting management approval / communicating to stakeholders / training and enforcing the policy
Q56. What is an acceptable use policy?
A Policy that sets out the rules governing the circumstances under which an employee can connect a device owned by them to the organisations IT network
B Policy that is an internal statement for users of personal data, defining the handling of personal data usage
C Policy that sets out constraints and practices that an employee must agree to for access to an organisations IT network and/or for access to the Internet via the organisations IT network
D Policy that allows the appropriate level of access control and protection measures to be developed and implemented.
Q57. What is included in a BYOD policy?
A Sets out the rules governing the circumstances under which an employee can connect a device owned by them to the organisation's IT network,
B Sets the degree to which the organisation will support the device
C Sets the extent to which the organisation may monitor that device, including the employees own personal information on it and wipe the device clean of all data if it is lost or stolen
D All of the answers
Q58. What needs to be included in an external data protection statement?
A It needs to describe how stakeholders can contact the organisations Data Protection Officer (DPO) to make a general query or complaint for example, how the organisation has processed personal data about them
B It needs to describe the rights of the individual in connection with that personal data (such as the right to withdraw consent and the right to access the personal data the organisation holds about them), which also reflects what is in the personal data protection policy about how an individual exercises these rights
C It needs to reflect what is in the personal data protection policy about how the organisation collects, uses, discloses and stores personal data
D All of the answers
Q59. When should the data protection policy be reviewed?
A When there are legislative changes and updates to the PDPA and other related legislation
B After the organisation suffers a personal data breach or other major incident and
C Whenever business circumstances change, including when the organisation introduces a new product or services that involves it in collecting, using, disclosing and storing personal data and/or is involved in selling part of itsbusiness, acquiring a new business or merging with another organisation
D All of the answers

EXTRAS Extra notes

Extra exam facts gathered in one place, so you don't have to hunt through each branch. Tap a topic below.

Scope & Deceased Bonus

100-year record rule

The PDPA applies to personal data in a record that has been in existence for less than 100 years.

Deceased individuals

Limited protection applies: only the Disclosure and Protection (Safeguarding) obligations, for up to 10 years after the date of death.

Reasonable person test

The objective standard throughout the PDPA: data purposes must be ones a reasonable person would consider appropriate in the circumstances.

Innovation Exceptions Bonus

Four purposes where data may be collected, used or disclosed without consent:

  • Business Improvement — improving products, services, customer profiling.
  • Research — early-stage / exploratory / broader R&D.
  • Legitimate Interests — e.g. fraud prevention, security, detecting misuse.
  • Contractual Performance — processing necessary to perform a contract with the individual.

Innovation criteria checklist

For Research / Business Improvement, all must hold:

  • Necessary to use data in identifiable form?
  • Impractical to seek consent?
  • For Research: clear public benefit?
  • Assurance results will not negatively affect individuals?

Legitimate interests & group sharing

Conduct a risk assessment so the legitimate interest outweighs adverse effects, and notify individuals you rely on it. Data may be shared within a group of companies for business improvement if they are bound by contract to safeguard it and the individuals are existing or prospective customers.

Deemed consent by notification

An opt-out framework: notify the individual of the purpose and give a reasonable period to opt out.

Data Portability extras Bonus

  • Includes: user-provided data and transactional data (e.g. booking history) in electronic form.
  • Excludes: derived data (created via business rules/analytics) and paper records.
  • Conditions: the receiving organisation must have a presence in Singapore, and the data must fall under white-listed categories prescribed by regulations.

DNC extras Bonus

Registry mechanics

  • 21-day rule: check the DNC Registry within 21 days before sending a marketing message.
  • Consent override: with clear, unambiguous consent in evidential form, you need not check the registry.
  • Identification: messages must show the org's ID & contact; calls must show the originating number.
  • Business numbers may be registered on the DNC registry to opt out.

Channel scope

Covered: voice calls, SMS, MMS, faxes. Excluded: email and IM (e.g. Telegram) — still governed by the DP provisions.

Prohibited acts

  • Dictionary attacks — generating numbers via automated sequences.
  • Address-harvesting software — scraping numbers.

5 Roles of a DPO Bonus

  • Compliance — ensure policies meet PDPA requirements.
  • Culture — foster awareness and train employees.
  • Query Management — handle complaints and access requests.
  • Risk Alerting — inform management of data risks.
  • PDPC Liaison — primary contact for the Commission.

DPMP & DPbD Bonus

Step 3 (Processes) implements Data Protection by Design (DPbD): consider data protection from the earliest design stage and throughout the operational lifecycle — not bolted on later.

Accountability Myths Bonus

  • “Compliance is just the DPO's job.” → Data protection must be in the culture; every employee is responsible for the data they handle.
  • “SMEs are exempt.” → The PDPA applies to all organisations, regardless of size or revenue.
  • “VWOs / non-profits are exempt.” → The Act is sector-neutral; any entity collecting personal data must comply.
  • “A lawyer-drafted policy is enough.” → Accountability needs policies translated into real processes (DPMP) that staff follow.
  • “I can keep data as long as I want.”Retention Limitation: destroy or anonymise once the purpose is met or legal/business needs expire.
Breach & response Assessment & mapping Governance & framework Roles & tools