Personal Data Protection Act (PDPA) Flashcards
What is personal data?
Data, whether true or not, that an organisation has, that can narrow identification down to an individual. Business contact info (what can be found on name card/business website info doesn’t count)
What counts as organisations?
natural persons, corporate bodies, associations etc, regardless of whether they are recognised/live in SG. Includes individuals when not acting in personal/domestic capacity.
What is not allowed for NRIC/FIN? What are 4 exceptions?
Collection, Use, Disclosure. (c/u/d)
1) required by law
2) healthcare
3) financial/real estate transactions
4) emergency
What is the protection obligation [PDPA] of an organisation?
An organisation must make reasonable security arrangements to prevent unauthorised access to personal data
How is PDPA enforced? (2)
1) one makes a complaint to Personal Data Protection Commission (PDPC)
2) PDPC can: fine/warn offender or direct offender to act (e.g. training)
What are organisations required to do when c/u/d-ing your personal data? (3)
1) notify you of reasonable & specific purposes
2) get your valid consent (actual/deemed), preferably by opt-in (not by failure to opt-out)
3) cannot require an individual to consent to c/u/d of their personal data as a condition of providing a [primary] service - beyond what is reasonably required to provide the product/service. also cannot use deceptive/misleading practices to do so
What does publicly available data refer to?
personal data that can be observed in public (by reasonably expected means)
What data can be used without consent?
1) publicly available data
2) photos of you in location open to public with few restrictions
3) social media posts if privacy settings are: set to public, closed online group that public can join with minimal effort, not just your closed circle
4) profile photos on social media if set to public on public account
5) news activity by news organisation
When is consent required for photos with identifiable people in places not open to public?
When photo is not for personal/domestic use (e.g. internet newsletter, website)
How to get consent for photos with identifiable people in places not open to public? (2)
1) get recorded consent, OR
2) consent may be deemed (if subject allows photo to be taken after given notice of purpose)
How to give notice for photos with identifiable people in places not open to public? (3)
1) state in invitation that photos will be taken, OR
2) obvious notice on premises, OR
3) photographer asks permission to take photo (for stated purpose) & you allow it