Home›Learn›Module 6›Self-testModule 6 · Self-testIn your business8 questions. Pick one answer for each, then mark yourself. Nothing leaves your browser.1. Your clinic keeps patient records on paper and later scans them into a practice management system. Does the Act apply to those records?No; the Act covers only data collected onlineOnly if the clinic has more than fifty patientsYes; Section 3 applies to personal data collected in non-digital form and digitised subsequentlyOnly if the records are shared with a third party2. Under Rule 3, a notice must be...A link to the full privacy policy, which may contain the detailsApproved by the Data Protection Board before useSigned by the Data Principal before any processingPresented and understandable independently of any other information, with an itemised description of the personal data and the specified purposes3. A customer withdraws consent. Under Section 6, what must the Data Fiduciary do?Within a reasonable time, cease processing and cause its Data Processors to cease, unless the processing is otherwise required or authorised by lawNothing, because consent once given cannot be withdrawnDelete all records immediately, including invoices required by tax lawCharge a withdrawal fee to cover administrative costs4. A customer hands over her phone number and asks for a payment receipt by SMS. Which ground covers sending the receipt?It needs a separate written consent formSection 7, as a legitimate use: she voluntarily provided the personal data for that specified purpose and has not objectedIt is prohibited unless the business is a bankIt is outside the Act because a receipt is not personal data5. Where must a Data Fiduciary publish the contact of the person who answers questions about processing?Only in its filings with the Registrar of CompaniesOnly in the privacy notice shown at sign-upProminently on its website or app, and in every response to a rights requestOnly on request by the Data Protection Board6. A Data Principal is unhappy with how her request was handled. Under Section 13, what must she do before approaching the Board?File a civil suitObtain a lawyer's opinionWait one year from the date of the requestExhaust the grievance redressal route the Data Fiduciary provides7. Under Rule 7, how quickly must a Data Fiduciary give the Board the detailed information about a personal data breach?Within seventy-two hours of becoming aware of it, or a longer period the Board allows on a written requestWithin twenty-four hours, with no extensionWithin thirty days of the end of the quarterOnly if more than one thousand Data Principals are affected8. Under Rule 10, before processing a child's personal data a Data Fiduciary must...Register the child with the Data Protection BoardObtain verifiable consent of the parent and check, with due diligence, that the person identifying as the parent is an identifiable adultAccept a tick-box confirmation that the user is over eighteenObtain the school's written approvalAnswer all 8 questions to mark