PDPA

PDPA

Purpose of PDPA

Govern the Collection, Use and **Disclosure **of Personal Data by organisations

in a manner that recognizes

both the right of individuals and the** need of organisations** to collect, use or disclose personal data

for **purposes **that a reasonable person would consider appropriate in the circumstances

**Scope of personal data **

Full name

NRIC/Fin/passport number

Photograph of video image

Mobile telephone number

Personal email address

Thumbprint

DNA profile

Name and residential address

Name and residential phone number

Data protection provisions do not cover Business Contact Information (BCI), if such information is not provided solely for personal purposes

Obligations of PDPA (11)

  1. Consent Obligation
  2. Only collect, use or disclose personal data when an individual has given consent
  3. Allow individuals to withdraw consent, with reasonable notice, and inform them of likely consequences of withdrawal. Upon withdrawal, and depending on withdrawal request,, you must cease to collect, use or disclose personal data
  4. Purpose Limitation Obligation
  5. An organisation may collect, use or disclose personal data about an individual for the purposes that a reasonable person would consider appropriate in the circumstances and for which the individual has given consent.
  6. An organisation may not, as a condition of providing a product or service, require the individual to consent to the collection, use or disclosure of his or her personal data beyond what is reasonable to provide that product or service.
  7. **Notification Obligation **
  8. Notify individuals of the purposes for which your organisation is intending to collect, use or disclose their personal data on or before such collection, use or disclosure of personal data.
  9. Access and Correction Obligation
  10. Upon request, the personal data of an individual and information about the ways in which his or her personal data may have been used or disclosed in the past year should be provided.
  11. Organisations are also required to correct any error or omission in an individual’s personal data upon his or her request.
  12. Accuracy Obligation
  13. Make reasonable effort to ensure that personal data collected by or on behalf of your organisation is accurate and complete, if it is likely to be used to make a decision that affects the individual, or if it is likely to be disclosed to another organisation.
  14. Protection Obligation
  15. Make security arrangements to protect the personal data that your organisation possesses or controls to prevent unauthorised access, collection, use, disclosure or similar risks.
  16. Retention Limitation Obligation
  17. Cease retention of personal data or remove the means by which the personal data can be associated with particular individuals when it is no longer necessary for any business or legal purpose.
  18. Transfer Limitation Obligation
  19. Transfer personal data to another country only according to the requirements prescribed under the regulations, to ensure that the standard of protection provided to the personal data so transferred will be comparable to the protection under the PDPA, unless exempted by the PDPC.
  20. ** Accountability Obligation**
  21. Make information about your data protection policies, practices and complaints process available on request.
  22. Designate one or more individuals as a Data Protection Officer to ensure that your organisation complies with the PDPA, including the implementation of personal data protection policies within your organisation. The business contact information of at least one of such individuals should also be made available to the public.
  23. Compliance with the PDPA remains the responsibility of the organisation.
  24. Data Breach Notification Obligation
  25. In the event of a data breach, organizations must take steps to assess if it is notifiable. If the data breach likely results in significant harm to individuals, and/or are of significant scale, organizations are required to notify the PDPC and the affected individuals as soon as practicable.
  26. ** Data Portability Obligation**
  27. At the request of the individual, organizations are required to transmit the individual’s data that is in the organization’s possession or under its control, to another organization in a commonly used machine-readable format.

https://document.grail.moe/1954c396fcdc4678b1ce74b72e9d88c3.pdf