The PDPA is intended to be aligned with international standards on data protection.
7 At the same time, however, it presents a “light touch” regime which establishes
a “minimum data protection standard”.
8 In the event of a conflict, other laws shall
prevail over the PDPA.
9
Other key statutes which affect personal data are also discussed in this report:
• Computer Misuse Act (“CMA”)
10 ;
• Criminal Procedure Code (“CPC”)
11 ;
• Cybersecurity Act
12 ;
• Electronic Transactions Act (“ETA”)
13 ;
• Protection from Harassment Act (“POHA”)
14 ;
• Protection from Online Falsehoods and Manipulation Act 2019 (“POFMA”)
15 ;
• Public Sector (Governance) Act 2018 (“PS(G)A”)
16 ;
• Spam Control Act (“SCA”)
17 ; and
• Telecommunications Act.
18
2 General Data Protection Framework
2.1 Overview
The PDPA governs the collection, use and disclosure of personal data, in any form,
by organisations, in a manner that balances the “right of individuals to protect their
personal data” with the “need of organisations to collect, use or disclose personal
data for purposes that a reasonable person would consider appropriate in the
circumstances”.
19
7 Singapore Parliamentary Debates, Official Report (15 October 2012) vol 89. See also Chesterman
(2018), para 2.47.
8 Chik (2013), p. 558 (discussing PDPA s 4(6)).
9 Chik (2013), p. 558 (discussing PDPA s 4(6)).
10 Cap 50A, 2007 Rev Ed.
11 Cap 68, 2012 Rev Ed.
12 No 9 of 2018.
13 Cap 88, 2011 Rev Ed.
14 Cap 256A, 2015 Rev Ed.
15 No 18 of 2019.
16 No 5 of 2018.
17 Cap 311A, 2008 Rev Ed.
18 Cap 323, 2000 Rev Ed.
19 PDPA s 3. There is no specific right of privacy in Singapore, although the usual common law
protections for privacy apply, e.g. the law of confidence and defamation. See Chan and Lee (2016).
Certain privacy-related rights also exist under other legislation such as the Protection from
Harassment Act (Cap 256A, 2015 Rev Ed) and the Copyright Act (Cap 63, 2006 Rev Ed). See
Goh and Aw (2018).
310
E.-I. Ong
7 At the same time, however, it presents a “light touch” regime which establishes
a “minimum data protection standard”.
8 In the event of a conflict, other laws shall
prevail over the PDPA.
9
Other key statutes which affect personal data are also discussed in this report:
• Computer Misuse Act (“CMA”)
10 ;
• Criminal Procedure Code (“CPC”)
11 ;
• Cybersecurity Act
12 ;
• Electronic Transactions Act (“ETA”)
13 ;
• Protection from Harassment Act (“POHA”)
14 ;
• Protection from Online Falsehoods and Manipulation Act 2019 (“POFMA”)
15 ;
• Public Sector (Governance) Act 2018 (“PS(G)A”)
16 ;
• Spam Control Act (“SCA”)
17 ; and
• Telecommunications Act.
18
2 General Data Protection Framework
2.1 Overview
The PDPA governs the collection, use and disclosure of personal data, in any form,
by organisations, in a manner that balances the “right of individuals to protect their
personal data” with the “need of organisations to collect, use or disclose personal
data for purposes that a reasonable person would consider appropriate in the
circumstances”.
19
7 Singapore Parliamentary Debates, Official Report (15 October 2012) vol 89. See also Chesterman
(2018), para 2.47.
8 Chik (2013), p. 558 (discussing PDPA s 4(6)).
9 Chik (2013), p. 558 (discussing PDPA s 4(6)).
10 Cap 50A, 2007 Rev Ed.
11 Cap 68, 2012 Rev Ed.
12 No 9 of 2018.
13 Cap 88, 2011 Rev Ed.
14 Cap 256A, 2015 Rev Ed.
15 No 18 of 2019.
16 No 5 of 2018.
17 Cap 311A, 2008 Rev Ed.
18 Cap 323, 2000 Rev Ed.
19 PDPA s 3. There is no specific right of privacy in Singapore, although the usual common law
protections for privacy apply, e.g. the law of confidence and defamation. See Chan and Lee (2016).
Certain privacy-related rights also exist under other legislation such as the Protection from
Harassment Act (Cap 256A, 2015 Rev Ed) and the Copyright Act (Cap 63, 2006 Rev Ed). See
Goh and Aw (2018).
310
E.-I. Ong
