POHA → Protects people from harassment
POFMA → Protects society from fake news
PDPA → Protects personal data/privacy
CMA → Protects computers and systems

LawFull NameMain PurposeWhat It Protects
Protection from Harassment Act (POHA)Protection from Harassment ActPrevent harassment, bullying, threats, and stalkingPeople’s safety, dignity, and emotional well-being
Protection from Online Falsehoods and Manipulation Act (POFMA)Protection from Online Falsehoods and Manipulation ActStop false information spreading onlinePublic interest, public trust, security, and social harmony
Personal Data Protection Act 2012 (Singapore) (PDPA)Personal Data Protection ActRegulate collection and use of personal dataIndividuals’ personal data and privacy
Computer Misuse Act (CMA)Computer Misuse ActPrevent cybercrime and unauthorised accessComputer systems, networks, and digital data

PDPA

To govern the collection, use, and disclosure of personal data by organisations in a manner that recognises both:

  • the right of individuals; and
  • the need of organisations to collect, use, or disclose personal data for purposes that a reasonable person would consider appropriate in the circumstances.

Full name
NRIC, FIN or passport number
Photograph or video image of an individual
Mobile telephone number
Personal email address
Thumbprint
DNA profile
Name and residential address
Name and residential telephone number

*Do not cover business information (ie Name, business number, business address, business email)

!

  1. Consent Obligation
    Organisations must get consent before collecting, using, or disclosing personal data.
  2. Purpose Limitation Obligation
    Personal data can only be used for purposes that were informed to the individual and are reasonable.
  3. Notification Obligation
    Organisations must notify individuals about why their data is being collected, used, or disclosed.
  4. Access Obligation
    Individuals can request access to their personal data and information on how it has been used or disclosed.
  5. Correction Obligation
    Individuals can request corrections to inaccurate or incomplete personal data.
  6. Accuracy Obligation
    Organisations must make reasonable efforts to ensure personal data is accurate and complete.
  7. Protection Obligation
    Organisations must protect personal data from unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks.
  8. Retention Limitation Obligation
    Personal data should not be kept longer than necessary.
  9. Transfer Limitation Obligation
    Organisations transferring personal data overseas must ensure comparable protection standards.
  10. Data Breach Notification Obligation
    Organisations must assess data breaches and notify affected individuals and/or the Personal Data Protection Commission (PDPC) when required.
  11. Accountability Obligation
    Organisations must develop policies and practices to meet PDPA requirements and make information about these policies available.

POFMA

The purpose of Protection from Online Falsehoods and Manipulation Act (POFMA) is to prevent the spread of false information online that may harm the public interest.

CMA

The purpose of the Computer Misuse Act (CMA) is to prevent and punish unauthorised access, misuse, or attacks on computer systems and data. It protects computers, networks, and users from cybercrimes such as hacking, malware attacks, and data theft.

POHA

The purpose of the Protection from Harassment Act (POHA) is to protect people from harassment, bullying, threats, stalking, and abusive behaviour, including online harassment. It also provides legal action against individuals who cause alarm, distress, or fear to others.

2 items under this folder.