Personal Data Protection Act, commonly known as PDPA is a general data protection law in Singapore that specifies mandatory requirements for personal data protection and handling. The Personal Data Protection Commission (PDPC) is the regulatory body that ensures PDPA compliance in Singapore.
The objective of PDPA is framing policies and procedures for collecting, using and disclosing personal data and empowering individuals for more effective and better control of their data. Organisations are mandated for establishing reasonable purposes when collecting, using and disclosing personal data.
Personal data is defined as information about an individual which helps in identifying that individual and accessing other information about the individual.
An act to govern and administer personal data collection, usage and disclosure by organisations is known as PDPA in Singapore. It functions as a baseline standard for personal data protection and supports sector-specific regulatory frameworks including Banking and Insurance Acts.
Singapore PDPA compliance needs organisations to comply with specific requirements for collection, use, disclosure and care of personal data in Singapore.
In today’s world, huge amounts of personal data are collected, used and even transferred to third-party organisations daily for a variety of reasons and are growing exponentially as the processing and analysis of large amounts of personal data becomes possible with sophisticated technology and computing power.
However, the usage of large personal data poses concerns to individuals and authorities about their data usage and disclosure. The concerns about personal data are driving data protection regimes for framing appropriate policies for the governance of personal data.
The PDPA also focuses on promoting Singapore’s competitiveness as a trusted business hub to foreign investors, authorities and consumers by enacting mandatory PDPA compliance in Singapore.
The PDPA recognises both the need to protect individuals’ data and the need of organisations to collect, use or disclose personal data for legitimate and reasonable purposes.
Singapore PDPA compliance is also necessary to safeguard sensitive personal data from any misuse and fraudulent act.
Personal data stored both in electronic and non-electronic formats comes under the purview of PDPA with the following exemptions applied.
Individuals acting on a personal or domestic capacity
Individuals acting as employees with an organisation
Public agencies about the collection, use or disclosure of personal data
Business contact information including individual’s name, position, title, business telephone number, business address, business email, business fax number and any similar information
Different types of data protection obligations apply to business organisations specifying regulatory requirements for PDPA compliance in Singapore when they perform activities relating to the collection, use or disclosure of personal data.
The chronological order of events that took place about personal data protection and Singapore PDPA compliance are as under
Once sector-specific legislation and regulatory frameworks are critically reviewed, a reference standard for personal data protection is usually drawn across the entire economy by the PDPC for documenting PDPA.
Singapore PDPA compliance becomes mandatory for organizations including compliance with common and industry/sector-specific regulations while handling personal data within their reach.
The below-mentioned aspects are the prime considerations of the PDPA while putting into force
There are nine obligations for organisations dealing with personal data specified under PDPA and include the following
Purpose Limitation Obligation
Access and Correction Obligation
Retention Limitation Obligation
Transfer Limitation Obligation
Singapore Personal Data Protection Commission (PDPC) in its endeavour to make the compliance obligations more comprehensive, issued a 10 step PDPA checklist for Singapore PDPA compliance. The steps are
- 1. Employing a Data Protection Officer to liaise with PDPC on data protection measures
- 3. Allowing corrections of personal data provided under section 22 (4) of the PDPA as appropriate
- 5. Responding to individuals' queries on personal data
- 7. Protecting personal data when transferring to foreign countries
- 9. Checking the Do Not Call (DNC) if organizations are involved in telemarketing
- 2. Notifying Purposes of data collection and seeking the consent of individuals before collection of personal data
- 4. Securing personal data by establishing data security policies and employee training
- 6. Deleting personal data no longer required
- 8. Effectively Managing service providers handling personal data
- 10. Ensuring company-wide PDPA awareness and communicating personal data protection policies, procedures and processes
Businesses demonstrating PDPA compliance in Singapore are treated with more respect and enjoy enhanced customer loyalty.
It also creates a more trusting environment amongst employees, customers and other stakeholders.
Singapore PDPA compliance can help businesses improve overseas market share and avoid regulatory penalties imposed by authorities.