CIPP-A Sample Questions

CIPP-A Sample Questions & Answers

Singapore's PDPA, Hong Kong's PDPO, and India's DPDPA each carry an equal, heavy share, built on modern privacy principles and how adequacy works globally, and the common threads and data-subject rights running across all three frameworks.

Launch the full CIPP-A simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    III. Hong Kong Privacy Laws and Practices · Data Transfer/Export, Ordinance Section 33

    True or False: Under Hong Kong's PDPO, Section 33, which governs cross-border transfers of personal data, is fully implemented and enforced, requiring organizations to obtain consent or ensure whitelist adequacy before any transfer.

    Show answer & explanation

    Correct answer: B

    As of early 2025, Section 33 of the PDPO has not yet come into effect. While it is part of the ordinance, its implementation has been deferred. Therefore, organizations in Hong Kong currently rely on other measures like contractual clauses and consent to ensure protection for cross-border data transfers, rather than the specific mechanisms outlined in Section 33.

  2. Question 2Beginner

    I. Privacy Fundamentals · Modern Privacy Principles

    The Asia Pacific Economic Cooperation (APEC) Privacy Framework is a foundational set of principles for the region. Which of the following is a key objective of the APEC Cross-Border Privacy Rules (CBPR) system built upon this framework?

    Show answer & explanation

    Correct answer: C

    The APEC CBPR system is a voluntary, accountability-based system. Its goal is not to create a single law but to build trust in cross-border data flows by allowing companies to be certified by an 'Accountability Agent' as compliant with the APEC Privacy Framework. This certification helps bridge differences between national privacy laws and facilitates data transfers between participating APEC economies.

  3. Question 3IntermediateSelect 2

    II. Singapore Privacy Laws and Practices · Data breach notification obligation

    A hospital in Singapore uses a third-party vendor to transcribe patient medical records. The vendor's employee inadvertently emails a batch of records to the wrong recipient. The hospital's DPO is assessing the situation. Which of the following factors would require the hospital to notify the PDPC of this data breach? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    Under Singapore's PDPA, data breach notification to the PDPC is mandatory if (1) the breach is likely to result in significant harm to an individual, OR (2) the breach affects 500 or more individuals. The source of the breach (vendor error) or the type of data (health information) are factors in assessing harm, but the notification triggers are the 'significant harm' threshold and the 'scale' threshold (500 individuals).

  4. Question 4Intermediate

    III. Hong Kong Privacy Laws and Practices · Six Data Protection Principles (DPPs)

    During a compliance audit of a company in Hong Kong, it is found that customer service call recordings containing personal data are kept indefinitely 'for quality assurance'. Which Data Protection Principle (DPP) under the PDPO is most directly violated by this practice?

    Show answer & explanation

    Correct answer: B

    DPP2 explicitly states that personal data should not be kept for longer than is necessary to fulfill the purpose for which it was collected. Keeping recordings indefinitely without a clear, time-bound justification directly contravenes the duration of retention aspect of this principle. While other DPPs might be relevant, the core violation here is the lack of a retention policy.

  5. Question 5Intermediate

    IV. India Privacy Law and Practices · Digital Personal Data Protection Act 2023 (DPDPA)

    Under India's DPDPA, a 'Data Fiduciary' that processes a high volume of personal data and undertakes processing that carries a risk of harm to Data Principals may be classified as a 'Significant Data Fiduciary' (SDF). What is a primary additional obligation imposed specifically on an SDF?

    Show answer & explanation

    Correct answer: B

    The DPDPA imposes additional compliance burdens on organizations designated as Significant Data Fiduciaries. Key among these are the mandatory appointment of a Data Protection Officer (DPO) who must be based in India, and the requirement to undertake periodic Data Protection Impact Assessments (DPIAs) to evaluate and mitigate risks associated with their data processing activities.

  6. Question 6Beginner

    II. Singapore Privacy Laws and Practices · Accountability and openness

    A financial services firm in Singapore is updating its privacy policy. The firm wants to ensure compliance with the PDPA's Openness Obligation. What is the most crucial element the firm must make available to its customers?

    Show answer & explanation

    Correct answer: C

    The Openness Obligation under Singapore's PDPA requires organizations to develop and implement policies and practices to meet their obligations and to make information about these policies and practices publicly available. A key, explicit requirement is to provide the business contact information of a person (the DPO) who can answer questions about the organization's data protection practices.

  7. Question 7Intermediate

    I. Privacy Fundamentals · Modern Privacy Principles

    The OECD 'Guidelines Governing the Protection of Privacy and Trans-border Data Flows of Personal Data' (1980) introduced several foundational privacy principles. The 'Individual Participation Principle' grants individuals which fundamental right?

    Show answer & explanation

    Correct answer: C

    The OECD's Individual Participation Principle is the precursor to modern access and correction rights. It establishes that individuals should have the right to: (a) obtain confirmation about data relating to them; (b) have that data communicated to them within a reasonable time and in an intelligible form; (c) be given reasons if a request is denied and be able to challenge the denial; and (d) challenge the data's accuracy and have it erased, rectified, completed, or amended if the challenge is successful.

  8. Question 8Intermediate

    III. Hong Kong Privacy Laws and Practices · Major Exemptions

    A journalist in Hong Kong obtains personal data about a public official's financial dealings as part of an investigation into corruption. The official sues the journalist's newspaper for violating the PDPO. Which exemption is the newspaper MOST likely to rely on in its defense?

    Show answer & explanation

    Correct answer: B

    The PDPO provides a specific exemption for journalism and news media activities. This exemption applies if the use of the personal data is for publication or broadcast, the data user has reasonable grounds to believe that publishing or broadcasting is in the public interest, and the use is compatible with the professional activities of journalism. This is the most direct and applicable defense in this scenario.

  9. Question 9Intermediate

    IV. India Privacy Law and Practices · Right of grievance redressal

    An e-commerce company in India is designing its grievance redressal process to comply with the DPDPA and its associated rules. According to the Act, what is the initial step a Data Principal must take before they can approach the Data Protection Board with a complaint?

    Show answer & explanation

    Correct answer: C

    The DPDPA establishes a tiered approach to dispute resolution. Before a Data Principal can escalate a complaint to the Data Protection Board, they must first attempt to resolve the issue directly with the Data Fiduciary through its established grievance redressal mechanism. This 'exhaustion of remedies' is a prerequisite for approaching the Board.

  10. Question 10Advanced

    III. Hong Kong Privacy Laws and Practices · Six Data Protection Principles (DPPs)

    Case Study

    A Hong Kong-based luxury retailer, 'Elegance HK,' operates a popular customer loyalty program. To join, customers provide their name, mobile number, and email address. The sign-up form includes a pre-ticked checkbox that says, "By signing up, you agree to receive marketing updates from Elegance HK and our partners." The company regularly shares its customer list with affiliated lifestyle brands for cross-promotion.

    Recently, Elegance HK received a complaint from a customer who claims they never consented to receive marketing from third parties. The company's privacy officer reviews the process and finds that the opt-out link in marketing emails is often broken, and requests to be removed from the list take several weeks to process. The Privacy Commissioner for Personal Data (PCPD) has launched an investigation.

    Which Data Protection Principles (DPPs) has Elegance HK most likely breached?

    Show answer & explanation

    Correct answer: C

    Elegance HK has likely breached DPP1 and DPP3. The use of a pre-ticked checkbox for consent is an unfair means of collection (breaching DPP1), as consent for direct marketing must be explicit. Sharing the data with third-party partners without clear, specific consent for that disclosure is a breach of DPP3, which limits the use of personal data to the purposes for which it was collected or a directly related purpose, unless voluntary and explicit consent is obtained.

Ready for the real thing?

The full CIPP-A simulator has every exam-style question, timed mode, and instant scoring.

Go to the CIPP-A simulator →