When an offence under the Personal Data Protection Act 2012 (PDPA) is committed by a body corporate, and is proved to have been committed with the consent or involvement of the officer or is due to his neglect, the officer and the body corporate shall be guilty of the offence and shall be liable to be proceeded against and punished accordingly. This would also apply in cases where the affairs of the body corporate are managed by its members.
Any act done or conduct engaged in by an employee in the course of his or her employment shall be treated as if it were done or engaged in by his employer as well as by him, whether or not it was with his employer’s knowledge or approval. In defence, the employer may prove that it took steps to prevent the employee from doing the act or engaging in the misconduct at hand.
Section 50(1) of the PDPA provides that the PDPC may, upon complaint or of its own motion, conduct an investigation to determine whether an organisation is compliant with the PDPA.
When a case is submitted to the PDPC, it will conduct a preliminary investigation to assess if a Do Not Call Registry penalty (“DNC Registry penalty”) offence may have been committed. If, during the preliminary investigation, the PDPC determines that a Do Not Call Registry Penalty may have been committed, the PDPC may contact the organisation to furnish documents or information.
Where the PDPC has reasonable grounds for suspecting that an offence under the Do Not Call Registry Penalty has been committed, it may require any organisation to produce specified documents or to provide specified information, by written notice.
The PDPC is not limited to approaching an organisation suspected of infringement and/or the organisation’s officers. For example, the PDPC may approach third parties such as outsourced telemarketers, associated business agents and other affiliates. When requiring an organisation to produce a document, the PDPC may:
The PDPC may also specify, in the notice:
If the information is not in recorded form, the PDPC may require that the information be compiled and produced to the PDPC. For example, an organisation may be asked to provide documents or information relating to several complaints of unsolicited phone calls or text messages over a considerable period.
The written notice may be addressed to individuals or organisations. If a written notice is addressed to an organisation, the appropriate person to respond is the person who is authorised by the organisation to respond on the organisation’s behalf. If a written notice is addressed to an individual, that individual must respond, and it is not acceptable for another person to respond on that individual’s behalf unless there are reasonable grounds to do so.
The PDPC has powers enabling it to enter premises and to gain access to information, documents and equipment or articles relevant to an investigation.
When entering any premises for inspection, the PDPC’s inspector or person assisting the inspector will identify himself by producing his Authorisation Card and evidence of his authority to enter the premises.
Please contact the PDPC’s main line at 6377 3131 (during office hours) if you require verification of an officer’s identity.
The PDPC may enter into any premises without a warrant by giving the occupier of the premises at least 2 working days’ written notice of the intended entry, and indicating the subject matter and purpose of the investigation. The PDPC may also enter into any premises without a warrant and without notice if the inspector has reasonable grounds for suspecting that the premises are, or have been, occupied by an organization that he is investigating in relation to a contravention of the PDPA. The PDPC may exercise this power if the inspector has taken reasonably practicable steps to give notice to the organization but has not been able to do so.
The PDPC is not limited to entering the premises of an organization suspected or infringement but may enter any premises. This includes premises of associated business partners or customers of an organization.
Also read: Top 25 Data Protection Statistics That You Must Be Informed
The PDPC may apply to a District Court for a warrant authorising an inspector or officer of the PDPC named in the warrant (“named officer”) and other persons assisting the inspector or authorised in writing by the PDPC (“accompanying officers”) to enter and search any premises.
Accompanying officers may include persons such as computer technicians or forensic experts, who may carry out specific tasks under the supervision of the named officer.
The named officer and any other accompanying officers entering premises under a warrant may take with them such equipment as they deem necessary. This may include equipment that used to enter the premises using reasonable force (for example, equipment for breaking locks) as well as equipment used to facilitate a search (for example, computer equipment).
The warrant may authorise a named officer and any other accompanying officers to:
If the PDPC exercises its powers to effect entry into the occupier’s premises, the occupier of the premises may request to consult its legal advisor. The investigating officer, authorised person, inspector or person required by the inspector may allow this request if he thinks that the time taken for the occupier’s legal adviser to arrive at the premises is reasonable.
The exercise of the right to consult a legal advisor must not delay or impede the inspection. The investigating officer, authorised person, inspector or person required by the inspector may not wait for an external legal adviser to arrive, if the occupier has an in-house legal advisor present on the premises, or if the occupier was given prior notice of the intended entry.
It is an offence under section 51(3)(b) and (c) of the PDPA to:
An organisation or person that commits an offence under section 51(3)(b) or (c) of the PDPA is liable to:
Any organisation that breaches the Do Not Call Registry Penalty provisions in the PDPA is liable to a fine of up to $10,000 per offence.
In appropriate cases, the PDPC may compound the offence for a sum of up to $1,000. Whether composition is offered and the amount of composition will be decided by the PDPC based on the facts of each case.
Also read: 12 brief explanation about the benefits of data protection for business success