BCP - Basic Insurance Concepts and Principles Singapore Data Protection and Hygiene Questions and Answers — Questions and Answers
Question 1: A financial adviser representative stores digital copies of clients' application forms, which include NRIC numbers and health declarations, on a personal, unencrypted laptop. If this laptop is stolen, which primary obligation under Singapore's Personal Data Protection Act (PDPA) has been breached?
- The Consent Obligation, as clients did not consent to storage on a personal device.
- The Accuracy Obligation, as the data may become outdated.
- The Protection Obligation, as reasonable security arrangements were not made. (Correct answer)
- The Retention Limitation Obligation, as the data should have been deleted immediately.
Correct answer: The Protection Obligation, as reasonable security arrangements were not made.
The PDPA's Protection Obligation requires organisations to make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, or similar risks. Storing sensitive personal data on an unencrypted personal device fails this standard and constitutes a breach if the device is lost or stolen, leading to unauthorised access.
Question 2: To comply with the accountability principle under Singapore's Personal Data Protection Act (PDPA), what must every insurance agency, regardless of its size, do?
- Appoint at least one individual as a Data Protection Officer (DPO). (Correct answer)
- Encrypt all email communications with clients using military-grade encryption.
- Conduct a third-party data security audit every financial year.
- Register all their data processing activities with the Personal Data Protection Commission (PDPC).
Correct answer: Appoint at least one individual as a Data Protection Officer (DPO).
The PDPA's Accountability Obligation requires an organisation to designate at least one individual as a Data Protection Officer (DPO) to be responsible for ensuring compliance with the Act. While the other options are good data hygiene practices, the appointment of a DPO is a mandatory, foundational requirement for all organisations.
Question 3: An insurance company obtains a list of phone numbers from a third-party vendor to market a new retirement plan. To comply with the Do Not Call (DNC) provisions of the PDPA, which action is mandatory before making unsolicited telemarketing calls?
- Assume consent is given as the numbers were purchased from a reputable vendor.
- Check the numbers against the national DNC Registry and only call those not listed. (Correct answer)
- Call the numbers but provide an option to opt-out during the first 30 seconds of the call.
- Send a preliminary SMS to each number to request consent for a call.
Correct answer: Check the numbers against the national DNC Registry and only call those not listed.
The PDPA generally prohibits sending unsolicited marketing messages to Singapore telephone numbers listed in the Do Not Call (DNC) Registry. Organisations must check their call lists against the relevant DNC Register(s) before conducting telemarketing campaigns, unless they have received clear and unambiguous consent from the individual to be contacted.
Question 4: Mr. Tan provides his personal data to an insurance agent for the sole purpose of obtaining a quotation for a car insurance policy. A week later, the agent adds Mr. Tan's email to a monthly newsletter mailing list for investment-linked products. Which PDPA obligation has the agent most likely breached?
- The Access Obligation.
- The Correction Obligation.
- The Purpose Limitation Obligation. (Correct answer)
- The Data Portability Obligation.
Correct answer: The Purpose Limitation Obligation.
The Purpose Limitation Obligation dictates that personal data can only be collected, used, or disclosed for purposes that a reasonable person would consider appropriate and for which the individual has given consent. Using the data for a new, unrelated purpose (marketing investment products) without fresh consent is a breach of this obligation.
Question 5: An insurer in Singapore discovers a cyber-attack has resulted in the unauthorised access of the NRIC numbers and policy details of 1,200 clients. According to the PDPA's mandatory data breach notification requirements, what is the insurer's primary obligation?
- Offer complimentary credit monitoring to all affected individuals before notifying any authorities.
- Immediately publish a notice of the breach on their corporate website without delay.
- Notify only the Monetary Authority of Singapore (MAS) within 72 hours.
- Notify the affected individuals and the Personal Data Protection Commission (PDPC). (Correct answer)
Correct answer: Notify the affected individuals and the Personal Data Protection Commission (PDPC).
The PDPA requires organisations to notify the Personal Data Protection Commission (PDPC) and the affected individuals of a notifiable data breach. A breach is considered notifiable if it results in (or is likely to result in) significant harm to individuals, or is of a significant scale (affecting 500 or more individuals). As this breach affects more than 500 people, both the PDPC and the individuals must be notified.
Question 6: A client's life insurance policy with ABC Insurer lapsed five years ago. Under the PDPA's Retention Limitation Obligation, when should ABC Insurer cease to retain the client's personal data?
- Immediately upon the policy lapsing to minimise data risk.
- Only after receiving a written request for deletion from the former client.
- Exactly seven years after the policy lapse date, to align with general accounting practices.
- When retention no longer serves the original purpose and is not necessary for legal or business purposes. (Correct answer)
Correct answer: When retention no longer serves the original purpose and is not necessary for legal or business purposes.
The Retention Limitation Obligation states that organisations must cease to retain personal data when it is no longer necessary for the legal or business purposes for which it was collected. There is no single fixed timeline; it depends on factors like potential future claims, regulatory record-keeping requirements, and other legal obligations that may require retention for a certain period even after a policy has ended.
A financial adviser representative stores digital copies of clients' application forms, which include NRIC numbers and health declarations, on a personal, unencrypted laptop.
If this laptop is stolen, which primary obligation under Singapore's Personal Data Protection Act (PDPA) has been breached?