POHA → Protects people from harassment
POFMA → Protects society from fake news
PDPA → Protects personal data/privacy
CMA → Protects computers and systems
| Law | Full Name | Main Purpose | What It Protects |
|---|---|---|---|
| Protection from Harassment Act (POHA) | Protection from Harassment Act | Prevent harassment, bullying, threats, and stalking | People’s safety, dignity, and emotional well-being |
| Protection from Online Falsehoods and Manipulation Act (POFMA) | Protection from Online Falsehoods and Manipulation Act | Stop false information spreading online | Public interest, public trust, security, and social harmony |
| Personal Data Protection Act 2012 (Singapore) (PDPA) | Personal Data Protection Act | Regulate collection and use of personal data | Individuals’ personal data and privacy |
| Computer Misuse Act (CMA) | Computer Misuse Act | Prevent cybercrime and unauthorised access | Computer systems, networks, and digital data |
PDPA
To govern the collection, use, and disclosure of personal data by organisations in a manner that recognises both:
- the right of individuals; and
- the need of organisations to collect, use, or disclose personal data for purposes that a reasonable person would consider appropriate in the circumstances.
Full name
NRIC, FIN or passport number
Photograph or video image of an individual
Mobile telephone number
Personal email address
Thumbprint
DNA profile
Name and residential address
Name and residential telephone number
*Do not cover business information (ie Name, business number, business address, business email)
!
- Consent Obligation
Organisations must get consent before collecting, using, or disclosing personal data. - Purpose Limitation Obligation
Personal data can only be used for purposes that were informed to the individual and are reasonable. - Notification Obligation
Organisations must notify individuals about why their data is being collected, used, or disclosed. - Access Obligation
Individuals can request access to their personal data and information on how it has been used or disclosed. - Correction Obligation
Individuals can request corrections to inaccurate or incomplete personal data. - Accuracy Obligation
Organisations must make reasonable efforts to ensure personal data is accurate and complete. - Protection Obligation
Organisations must protect personal data from unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks. - Retention Limitation Obligation
Personal data should not be kept longer than necessary. - Transfer Limitation Obligation
Organisations transferring personal data overseas must ensure comparable protection standards. - Data Breach Notification Obligation
Organisations must assess data breaches and notify affected individuals and/or the Personal Data Protection Commission (PDPC) when required. - Accountability Obligation
Organisations must develop policies and practices to meet PDPA requirements and make information about these policies available.
POFMA
The purpose of Protection from Online Falsehoods and Manipulation Act (POFMA) is to prevent the spread of false information online that may harm the public interest.
CMA
The purpose of the Computer Misuse Act (CMA) is to prevent and punish unauthorised access, misuse, or attacks on computer systems and data. It protects computers, networks, and users from cybercrimes such as hacking, malware attacks, and data theft.
POHA
The purpose of the Protection from Harassment Act (POHA) is to protect people from harassment, bullying, threats, stalking, and abusive behaviour, including online harassment. It also provides legal action against individuals who cause alarm, distress, or fear to others.