DPP Topic 4 - PDPA Flashcards
Personal Data Protection Act (PDPA)
Singapore’s data privacy regulation that governs the collection, use, and disclosure of personal data
Motivation for PDPA
Encourage business innovation while guaranteeing personal data protection and strengthen Singapore’s position as a trusted hub for businesses
Extraterritorial effect of PDPA
Applicable to organizations collecting, using, or disclosing personal data in Singapore, regardless of the organization’s physical presence or where it was incorporated
Penalties for non-compliance
Up to 10% of an organization’s annual turnover in Singapore or SGD 1 million, whichever is greater, as well as reputation damage
Data Protection Obligations
11 obligations that organizations must comply with when undertaking activities relating to the collection, use, or disclosure of personal data
1) Accountability
Organizations must take responsibility for the personal data under their possession or control, appoint a data protection officer, develop policies, and implement measures
2) Notification (Collection)
Notify individuals of the purposes for which the organization is intending to collect, use, or disclose their personal data
3) Consent (Collection)
Personal data may be collected, used, or disclosed only after consent has been given by the individual
4) Purpose Limitation (Collection)
Personal data may be collected, used, or disclosed only for purposes that are reasonable to provide the organization’s product or service
5) Accuracy (Care)
Organizations should ensure that the personal data collected is accurate and complete
6) Protection (Care)
Organizations should put in place the required security measures to protect personal data and prevent unauthorized access
7) Retention Limitation (Care)
Organizations should cease retention of personal data or dispose of it in a proper manner
8) Transfer Limitation (Care)
Ensure that the standard of protection is comparable to the PDPA when transferring personal data to another country
9) Access and Correction (Autonomy)
Individuals have the right to request access to their personal data and for correction of their personal data
10) Data Breach Notification (Autonomy)
In the event of a data breach that likely results in significant harm to individuals or is of significant scale, the PDPC and the affected individuals need to be notified