The Personal Data Protection Act 2012 (PDPA) governs the collection, use and disclosure of personal data. The PDPA for companies was passed by Parliament in October 2012 and came into force in 4 stages between January 2013 and July 2014.
The PDPA recognizes both:
Personal data means:
Examples of personal data that can, on its own, identify an individual include:
Note that the PDPA also protects, to a limited extent, the personal data of individuals who have been dead for less than 10 years. For such personal data, only the provisions relating to the disclosure and protection of personal data will apply.
The PDPA for companies does not apply to the following categories of personal data:
The PDPA for companies imposes obligations on organisations in respect of the collection, use and disclosure of personal data in Singapore.
The following persons, however, do not have to comply with these obligations:
Employees acting in the course of their employment with an organisation will have to adhere to their organisation’s policies for ensuring the organisation’s compliance with the PDPA for companies. However, they themselves cannot be held personally liable for actions resulting in their organisation breaching the PDPA for companies.
Additionally, organisations which are data intermediaries are partially excluded from these obligations.
The PDPA for companies defines “data intermediary” as an organisation that processes personal data on behalf of another organisation. However, this definition does not include employees of the organisation (for which the data is being processed).
The 9 main obligations under the PDPA for companies are:
1. Consent Obligation: your business can only collect, use and/or disclose the personal data of individuals who have consented to such collection, use and/or disclosure.
2. Purpose Limitation Obligation: your business can only collect, use and/or disclose personal data of individuals for the purpose(s) for which consent have been given by these individuals.
3. Notification Obligation: your business must inform individuals of the purpose(s) for which their personal data is being collected, used and/or disclosed.
4. Access and Correction Obligation: your business is obliged to provide information to individuals, upon request and as soon as reasonably possible, on:
Your business must also correct errors or omissions in the personal data that is in its possession upon request, unless it is reasonable to not make the correction.
5. Accuracy Obligation: your business must make a reasonable effort to ensure that the personal data collected by the business is accurate and complete, if the personal data is likely to be:
6. Protection Obligation: your business must put in place reasonable security measures to protect the personal data in its possession or control. This is to prevent risks such as the unauthorised access, collection, use and/or disclosure of such data.
7. Retention Limitation Obligation: your business should retain the personal data for only as long as is necessary for business or legal purposes.
8. Transfer Limitation Obligation: if your business is transferring the personal data overseas, such as storing the data in the cloud, ensure that the transfer meets the PDPA’s data protection requirements. This is to ensure that the data being transferred is offered a comparable level of data protection as is provided by the PDPA for companies.
9. Openness Obligation: your business must implement the necessary policies and procedures to fulfil its PDPA for companies obligation. It must make information about such policies and procedures publicly available.
To what extent can your business collect individuals’ personal data?
Pursuant to the Purpose Limitation Obligation (see above), your business may collect, use or disclose personal data about an individual:
The particular circumstances need to be taken into account in determining whether the purpose of such collection, use or disclosure of personal data is reasonable.
For example, a purpose that is illegal or would harm the individual concerned is unlikely to be considered appropriate by a reasonable person.
Also read: Top 25 Data Protection Statistics That You Must Be Informed
If your business regularly collects personal data, it is important to keep track of:
1. Implementing Data Protection Policies
In order for your business to be in compliance with the Protection Obligation, it is critical to implement personal data protection policies and communicate such policies to your employees.
For example, your business could implement physical and technical data protection measures.
Physical measures include providing personal data access only to authorised personnel and ensuring that physical records (such as printed documents containing employees’ NRIC numbers and home addresses) are held in a secured location. For example, a locked filing cabinet.
Technical measures range from installing anti-virus software on computer systems to maintaining a strong password for electronic files containing personal data.
2. Utilising Tools to Assess Your Business’ Compliance with the PDPA
The PDPA Assessment Toolkit available on the Personal Data Protection Commission’s (PDPC) webpage may be helpful in identifying the areas in which your business is not PDPA for companies compliant.
It provides a guided questionnaire on your business’ personal data protection and policies. It can therefore serve as a handy checklist of your business’ compliance with the PDPA obligations.
3. Appointing a Data Protection Officer (DPO)
It is also compulsory under the PDPA for companies to appoint one or more Data Protection Officer(s) (DPO) to supervise your business’ collection, usage and disclosure of personal data. The DPO is accordingly responsible for ensuring that your business complies with the PDPA.
Your DPO is also required to review and update your business’ PDPA for companies policies and processes in line with the latest regulatory developments.
This is to ensure that your business remains PDPA for companies compliant in light of changes to the relevant data protection rules.
Finally, your business’ DPO will serve as a point of contact for individuals to get in touch with your business for PDPA-related matters.
Read our other article for more information on appointing a Data Protection Officer.
Your business is accountable for its PDPA compliance in various ways.
For example, individuals may request for access to their personal data held by your business (see the Access and Correction Obligation above). They may also submit a complaint to the PDPC which will investigate your business’ conduct and compliance with the PDPA for companies.
If it is found that your business is not PDPA-compliant, the PDPC may:
In April 2016, the Business Times reported that 11 companies, including Challenger Technologies and K Box Entertainment Group (K Box), had been fined for breaching data protection obligations under the PDPA.
K Box, in particular, was fined $50,000 for failing to implement adequate security measures to protect the personal data of its members.
To prevent thefts and leaks of personal data, and monetary penalties as a result, it is important to have a clear understanding of the business’ PDPA obligations.
Also read: How Being Data Protection Trained Can Help With Job Retention