The PDPA covers all personal data, whether in electronic or other form.
20
“Personal data” means “data (whether true or not) about an individual who can be
identified (a) from that data; or (b) that data and other information to which the
organisation has or is likely to have access”.
21 However, the PDPA does not apply
to: personal data about an individual in a record that has existed for at least
100 years
22 ; data about a deceased individual
23
; business contact information
24 ;
and anonymised data.
25
The PDPA focuses on organisations. An “organisation” is broadly defined, and
includes any “individual, company, association or body of persons” whether or not
formed under Singapore law, or resident, or having a place of business in Singapore.
26 The PDPA generally excludes: individuals acting in a personal or domestic
capacity; public agencies (including the Singapore Government and governmental
organisations)
27 ; and employees acting in the course of their employment.
28 Some
exceptions also apply for data intermediaries, which are organisations, which process personal data on behalf of other organisations.
29
2.2 Obligations
Organisations Under the PDPA, there are ten general categories of data protection,
each an “Obligation” on an organisation:
• Consent: No collection, use, or disclosure of personal data about an individual
without that individual’s consent as obtained through specified procedures (see
Sect. 2.2.1).
30
20 PDPC Advisory Guidelines on Key Concepts paras 5.2, 5.30.
21 PDPA s 2(1).
22 PDPA s 4(4)(a).
23 PDPA s 4(4)(b). The individual must have been deceased for more than 10 years.
24 PDPA s 4(5).
25 PDPC Advisory Guidelines on Key Concepts para 5.3; Advisory Guidelines for Selected Topics
chapter 3.
26 PDPA s 2(1).
27 The Singapore Government and governmental organisations (and employees thereof) are
prohibited from disclosing confidential information obtained in the course of their work by,
among others, the Statutory Bodies and Government Companies (Protection of Secrecy) Act
(Cap 319, 2004 Rev Ed) and the Official Secrets Act (Cap 213, 2012 Rev Ed). See also discussion
on the Public Sector (Governance) Act 2018.
28 PDPA s 4(1)(b).
29 PDPA s 2(1). Data intermediaries are discussed elsewhere in this report.
30 PDPA ss 13–16.
Singapore Report: Data Protection in the Internet
311
Précédent

- 313/540

Suivant