PDPA
Personal Data Protection Act 2012 (PDPA)
- Regulator
- Personal Data Protection Commission (PDPC)
- Who it applies to
- Every private sector organisation in Singapore that collects, uses or discloses personal data.
- If you fall short
- Up to 10% of annual turnover in Singapore for organisations with turnover above SGD 10 million, otherwise up to SGD 1 million.
- What it asks of you
- Consent, purpose limitation and notification for collection, use and disclosure
- Access, correction, accuracy, protection, retention limitation and transfer limitation obligations
- Appoint a Data Protection Officer and make their business contact information available
- Assess a suspected breach within 30 days, and notify the PDPC within three calendar days of deciding it is notifiable
- Keep the Do Not Call Registry rules for marketing messages