Singapore’s Personal Data Protection Act (PDPA), Compliance

Singapore’s Personal Data Protection Act (PDPA),  Compliance

Singapore’s Personal Data Protection Act or PDPA for short is a data protection law that was passed in Singapore in 2012. The PDPA was passed with the goal of creating a baseline standard for the protection of personal data and information within the country of Singapore. What’s more, the PDPA also complements other regulatory and legislative frameworks within the country, such as Singapore’s Banking and Insurance Acts. In contrast to many other privacy laws around the world, such as the California Privacy Rights Act or CCPA and the EU’s General Data Protection Regulation of GDPR, the PDPA also established a National Do Not Call or DNC, allowing Singaporean citizens to opt-out of receiving unwanted calls and telemarketing messages from businesses and organizations.

What is the scope of the PDPA?

The PDPA applies to all businesses entities and organizations within Singapore that collect, use, or disclose the personal information of Singaporean citizens. Furthermore, the PDPA also applies to businesses and organizations that are not physically located within Singapore but nevertheless collect, use, or disclose the personal information of Singaporean citizens. Moreover, the PDPA also applies to cross-border transfers of personal information, in instances where the personal data of a Singaporean citizen is transferred to another country or overseas location. Despite all of this, there are certain businesses and organizations that are exempted from the jurisdiction of the PDPA. These businesses and organizations are as follows:

Data intermediaries within Singapore are also exempt from the scope and jurisdiction of the PDPA, provided that such intermediaries are processing the personal data of Singaporean citizens on behalf of and for the purposes of another business or organization, that is pursuant to a contract that is made in writing or otherwise evidenced, and as such only have obligations to the PDPA in relation to the following:

What are the requirements of businesses and organizations under the PDPA?

The PDPA sets forth various principles in regards to how businesses and organizations should go about the practice of engaging in data protection obligations. These principles include:

What are the penalties for violating the PDPA?

In addition to establishing specific requirements or principles that organizations and businesses must adhere to at all times, the PDPA also established the Personal Data Protection Commission or PDPC for the purposes of enforcing the law. As such, penalties that can be imposed against businesses or organizations found to be in violation of PDPA on the part of the PDPC include the following:

As countries around the world continue to pass legislation related to protecting the data privacy rights of their citizens, Singapore joins one of the many nations to pass a comprehensive data privacy law in the past decade. Compared to many U.S. state privacy laws such as the Virginia Consumer Data Protection Act or VCDPA, as well as international privacy regulations such as the EU’s General Data Protection Regulation or GDPR, the PDPA has considerable scope and applicability within the country of Singapore. As the PDPA allows the PDPC to obtain a warrant to enter the premises of businesses or organizations that are found to be noncompliant, Singaporean citizens are afforded a level of data protection that few other countries offer. As such, citizens of Singapore can have the peace of mind that their personal data privacy rights are being upheld to the utmost degree of fortitude.

Related Reads