01 — Practice solutions
These are independently written explanations, not an official marking scheme.
01A
Answer: the programmer fails to act with integrity by disclosing entrusted customer details to a friend, breaching confidentiality and trust. The unauthorised disclosure raises a Protection issue: the organisation should have reasonable arrangements restricting customer data to authorised recipients. Consent/permitted-purpose issues can also be relevant if explained with appropriate qualification.
Avoid: saying that the list is automatically public because it contains names, or naming the CMA without establishing an access-related fact. The stated problem is unauthorised disclosure; do not invent how the list was obtained.
Reasoning
The act is disclosure to someone outside the authorised access arrangement. The question asks for one professional principle and one PDPA issue, so repeating “privacy” twice does not explain the two perspectives.
01B
Answer: monitoring can detect security incidents so staff can respond. Secret monitoring prevents students from knowing how they are observed, undermining privacy and trust. Clearly explain what is collected, its purpose and who can access it, while limiting monitoring to the justified need.
Why: the change directly addresses lack of awareness and excessive intrusion. Simply buying faster monitoring software would not address that concern. Transparency alone does not establish compliance with every applicable legal requirement.
Reasoning
Three outputs are required: a benefit, an ethical concern and a change addressing that concern. A proposed change should connect to the concern you selected.
01C
Possible answer: the customer’s contact number is personal data because it can identify the customer, including when linked to their name in the company’s records.
Analyse (h): “state two actions” asks what the company must do. Two distinct actions are more useful than an extended general definition of PDPA.
Possible answer: inform customers that their contact details are collected and used to manage their bookings; obtain the required consent for the stated collection/use/disclosure purposes.
Why these fit: the first is Notification and the second Consent. “Ensure privacy” is not a specific action. “Notify them of collection” and “tell them why details are used” may overlap rather than supply two clearly distinct obligations. Other well-supported actions can be defensible; this is not an exhaustive official marking scheme.
Reasoning
Choose an actual attribute from the question, then explain why it identifies a person. A contact number is a strong choice because it relates to an identifiable customer; you can explicitly link it with the customer’s name in the booking record.
01D
(i) Accountability; (ii) Access & Correction; (iii) Transfer Limitation; (iv) Data Breach Notification; (v) Retention Limitation.
For (iv), Protection concerns reasonable safeguards; once a breach has occurred, the organisation must also assess it and make notifications when the relevant criteria are met. Restoring security does not answer whether reporting is required.
01E
| Case | Law and scenario link |
|---|---|
| (i) | CMA: knowingly unauthorised account access and modification of stored work. |
| (ii) | POFMA may apply: a false statement of fact is communicated online in Singapore. Directions require the public-interest condition; personal preference or criticism is not automatically a false factual statement. |
| (iii) | POHA: identifying disclosure with the stated intent to frighten and encourage threats makes harassment/doxxing relevant. |
| (iv) | PDPA — Notification: explain the purposes of collecting, using or disclosing the personal data. |
Do not infer that every other law or obligation is breached. One scenario may engage more than one law when its facts support this.
01F
Sensors reveal wear early, enabling planned maintenance that reduces downtime and lost production. Installing sensors and retraining staff create costs. Train affected workers to interpret alerts and maintain the system, helping them move into the changed roles. The recommendation addresses a specific impact rather than assuming all automation causes unemployment.