Data Privacy and PDPA
Data Privacy
- **Requirement **for **data **to be **accessed **by or **disclosed **to authorised persons only
- Important as unauthorised people should not have **access **to **data **they are not supposed to have
- Purpose
- Consumer
- Give more control over personal data
- Allow **access **and **correction **of personal data
- Reduces unsolicited telemarketing messages received
- Business
- Builds consumer confidence
- Facilitates cross-border transfer
- Enhances efficiency, **branding **and competitiveness
Personal Data Protection Act (PDPA)
Purpose of PDPA
- To **govern **the collection, **use **and **disclosure **of personal data by organisations
- In a manner that **recognises both **
- The right of individuals
- The need of organisations to collect, **use **or disclose personal data
- For the purposes that a reasonable person would consider appropriate in the circumstances
Definitions
- **Collection: Actions **through which an organisation obtains personal data
- **Use: Actions **through which an organisation employs personal data
- **Disclosure: Actions **through which an organisation discloses, transfers or makes available personal data to any other organisation
- Personal Data: **Data **about an **individual **who can be identified from it
- **Purpose: Objectives **or **Reasons **(NOT activities)
- Organisations must specify objectives relating to personal data
Scope of Personal Data
| Full name | Personal email address |
|---|
| NRIC, FIN or passport number | Thumbprint |
| Photograph or video image of an individual | DNA profile and biometrics |
| Mobile telephone number | Residential address |
Obligations of PDPA
- Remember CN | PA | PRATA | DD
- Consent Obligation: Collect, use, or disclose personal data only with consent. Allow individuals to withdraw consent and stop usage accordingly.
- Notification Obligation: Inform individuals of data collection purposes before collecting, using, or disclosing their data
- Purpose Limitation: Use data only for reasonable, consented purposes. Don’t ask for more data than needed to provide a product or service.
- Access and Correction: Provide individuals access to their personal data and correct errors upon request
- Protection Obligation: Secure personal data to prevent unauthorised access, use, or disclosure
- Retention Limitation: Stop retaining data when it’s no longer needed for business or legal purposes
- Accuracy Obligation: Ensure data is accurate and complete if used for decisions or shared externally
- Transfer Limitation: Transfer data overseas only if the receiving country ensures comparable data protection standards
- Accountability Obligation: Appoint a Data Protection Officer (DPO) and make data protection policies available to the public
- Data Breach Notification: Notify the PDPC and affected individuals if a data breach could cause significant harm or affect many people
- Data Portability: Upon request, transfer personal data to another organization in a machine-readable format