Data Privacy and PDPA

Data Privacy

  • **Requirement **for **data **to be **accessed **by or **disclosed **to authorised persons only
  • Important as unauthorised people should not have **access **to **data **they are not supposed to have
  • Purpose
    • Consumer
      • Give more control over personal data
      • Allow **access **and **correction **of personal data
      • Reduces unsolicited telemarketing messages received
    • Business
      • Builds consumer confidence
      • Facilitates cross-border transfer
      • Enhances efficiency, **branding **and competitiveness

Personal Data Protection Act (PDPA)

Purpose of PDPA

  • To **govern **the collection, **use **and **disclosure **of personal data by organisations
  • In a manner that **recognises both **
    • The right of individuals
    • The need of organisations to collect, **use **or disclose personal data
  • For the purposes that a reasonable person would consider appropriate in the circumstances

Definitions

  • **Collection: Actions **through which an organisation obtains personal data
  • **Use: Actions **through which an organisation employs personal data
  • **Disclosure: Actions **through which an organisation discloses, transfers or makes available personal data to any other organisation
  • Personal Data: **Data **about an **individual **who can be identified from it
  • **Purpose: Objectives **or **Reasons **(NOT activities)
    • Organisations must specify objectives relating to personal data

Scope of Personal Data

Full namePersonal email address
NRIC, FIN or passport numberThumbprint
Photograph or video image of an individualDNA profile and biometrics
Mobile telephone numberResidential address

Obligations of PDPA

  • Remember CN | PA | PRATA | DD
  1. Consent Obligation: Collect, use, or disclose personal data only with consent. Allow individuals to withdraw consent and stop usage accordingly.
  2. Notification Obligation: Inform individuals of data collection purposes before collecting, using, or disclosing their data
  3. Purpose Limitation: Use data only for reasonable, consented purposes. Don’t ask for more data than needed to provide a product or service.
  4. Access and Correction: Provide individuals access to their personal data and correct errors upon request
  5. Protection Obligation: Secure personal data to prevent unauthorised access, use, or disclosure
  6. Retention Limitation: Stop retaining data when it’s no longer needed for business or legal purposes
  7. Accuracy Obligation: Ensure data is accurate and complete if used for decisions or shared externally
  8. Transfer Limitation: Transfer data overseas only if the receiving country ensures comparable data protection standards
  9. Accountability Obligation: Appoint a Data Protection Officer (DPO) and make data protection policies available to the public
  10. Data Breach Notification: Notify the PDPC and affected individuals if a data breach could cause significant harm or affect many people
  11. Data Portability: Upon request, transfer personal data to another organization in a machine-readable format