PDPA
PDPA

Purpose of PDPA
Govern the Collection, Use and **Disclosure **of Personal Data by organisations
in a manner that recognizes
both the right of individuals and the** need of organisations** to collect, use or disclose personal data
for **purposes **that a reasonable person would consider appropriate in the circumstances
**Scope of personal data **
Full name
NRIC/Fin/passport number
Photograph of video image
Mobile telephone number
Personal email address
Thumbprint
DNA profile
Name and residential address
Name and residential phone number
Data protection provisions do not cover Business Contact Information (BCI), if such information is not provided solely for personal purposes
Obligations of PDPA (11)
- Consent Obligation
- Only collect, use or disclose personal data when an individual has given consent
- Allow individuals to withdraw consent, with reasonable notice, and inform them of likely consequences of withdrawal. Upon withdrawal, and depending on withdrawal request,, you must cease to collect, use or disclose personal data
- Purpose Limitation Obligation
- An organisation may collect, use or disclose personal data about an individual for the purposes that a reasonable person would consider appropriate in the circumstances and for which the individual has given consent.
- An organisation may not, as a condition of providing a product or service, require the individual to consent to the collection, use or disclosure of his or her personal data beyond what is reasonable to provide that product or service.
- **Notification Obligation **
- Notify individuals of the purposes for which your organisation is intending to collect, use or disclose their personal data on or before such collection, use or disclosure of personal data.
- Access and Correction Obligation
- Upon request, the personal data of an individual and information about the ways in which his or her personal data may have been used or disclosed in the past year should be provided.
- Organisations are also required to correct any error or omission in an individual’s personal data upon his or her request.
- Accuracy Obligation
- Make reasonable effort to ensure that personal data collected by or on behalf of your organisation is accurate and complete, if it is likely to be used to make a decision that affects the individual, or if it is likely to be disclosed to another organisation.
- Protection Obligation
- Make security arrangements to protect the personal data that your organisation possesses or controls to prevent unauthorised access, collection, use, disclosure or similar risks.
- Retention Limitation Obligation
- Cease retention of personal data or remove the means by which the personal data can be associated with particular individuals when it is no longer necessary for any business or legal purpose.
- Transfer Limitation Obligation
- Transfer personal data to another country only according to the requirements prescribed under the regulations, to ensure that the standard of protection provided to the personal data so transferred will be comparable to the protection under the PDPA, unless exempted by the PDPC.
- ** Accountability Obligation**
- Make information about your data protection policies, practices and complaints process available on request.
- Designate one or more individuals as a Data Protection Officer to ensure that your organisation complies with the PDPA, including the implementation of personal data protection policies within your organisation. The business contact information of at least one of such individuals should also be made available to the public.
- Compliance with the PDPA remains the responsibility of the organisation.
- Data Breach Notification Obligation
- In the event of a data breach, organizations must take steps to assess if it is notifiable. If the data breach likely results in significant harm to individuals, and/or are of significant scale, organizations are required to notify the PDPC and the affected individuals as soon as practicable.
- ** Data Portability Obligation**
- At the request of the individual, organizations are required to transmit the individual’s data that is in the organization’s possession or under its control, to another organization in a commonly used machine-readable format.
https://document.grail.moe/1954c396fcdc4678b1ce74b72e9d88c3.pdf