2.2.3 Access
An organisation shall provide, on an individual’s request: personal data about the
individual in the organisation’s possession or control; and information about the
ways in which such data has or may have been used or disclosed by the organisation
within a year before the date of the request.
84 An organisation can charge reasonable
fees for access.
85
Exceptions Access shall not be provided if provision of that data or information
could reasonably be expected to: threaten the safety or physical or mental health of
another individual; cause immediate or grave harm to the safety or physical or
mental health of another individual; reveal personal data about another individual;
reveal the identity of an individual who has provided personal data about another
individual and the former does not consent to disclosure of his/her identity; or be
contrary to the national interest.
86 An organisation shall also not inform an individual that it has disclosed personal data to a law enforcement agency, if such disclosure
was made without that individual’s consent (as allowed under the Fourth Schedule of
the PDPA or other law).
87
Access is also not required regarding, e.g. opinion data kept solely for an
evaluative purpose; school examinations; personal data subject to legal privilege;
personal data collected, used or disclosed without consent for the purposes of an
investigation in progress; “confidential commercial information” that could, in the
opinion of a reasonable person, harm the organisation’s competitive position; and
repetitious requests “that would unreasonably interfere with the operations of an
organisation”.
88
However, access shall be given to an individual’s personal data and information if
such data or information can be stripped of the abovementioned prohibited data and
information.
89
2.2.4 Correction
An individual may request an organisation to correct an error or omission in his/her
personal data in the possession or control of the organisation.
90 Unless the organisation is “satisfied on reasonable grounds” that a correction should not be made
(in which case it shall annotate the personal data with the correction that was
84 PDPA s 21(1).
85 Personal Data Protection Regulations 2014 (S 362 of 2014) s 7(1). See also PDPC Advisory
Guidelines on Key Concepts para 15.19.
86 PDPA s 21(3).
87 PDPA s 21(4).
88 PDPA Fifth Schedule s 1.
89 PDPA s 21(5).
90 PDPA s 22(1).
Singapore Report: Data Protection in the Internet
317
An organisation shall provide, on an individual’s request: personal data about the
individual in the organisation’s possession or control; and information about the
ways in which such data has or may have been used or disclosed by the organisation
within a year before the date of the request.
84 An organisation can charge reasonable
fees for access.
85
Exceptions Access shall not be provided if provision of that data or information
could reasonably be expected to: threaten the safety or physical or mental health of
another individual; cause immediate or grave harm to the safety or physical or
mental health of another individual; reveal personal data about another individual;
reveal the identity of an individual who has provided personal data about another
individual and the former does not consent to disclosure of his/her identity; or be
contrary to the national interest.
86 An organisation shall also not inform an individual that it has disclosed personal data to a law enforcement agency, if such disclosure
was made without that individual’s consent (as allowed under the Fourth Schedule of
the PDPA or other law).
87
Access is also not required regarding, e.g. opinion data kept solely for an
evaluative purpose; school examinations; personal data subject to legal privilege;
personal data collected, used or disclosed without consent for the purposes of an
investigation in progress; “confidential commercial information” that could, in the
opinion of a reasonable person, harm the organisation’s competitive position; and
repetitious requests “that would unreasonably interfere with the operations of an
organisation”.
88
However, access shall be given to an individual’s personal data and information if
such data or information can be stripped of the abovementioned prohibited data and
information.
89
2.2.4 Correction
An individual may request an organisation to correct an error or omission in his/her
personal data in the possession or control of the organisation.
90 Unless the organisation is “satisfied on reasonable grounds” that a correction should not be made
(in which case it shall annotate the personal data with the correction that was
84 PDPA s 21(1).
85 Personal Data Protection Regulations 2014 (S 362 of 2014) s 7(1). See also PDPC Advisory
Guidelines on Key Concepts para 15.19.
86 PDPA s 21(3).
87 PDPA s 21(4).
88 PDPA Fifth Schedule s 1.
89 PDPA s 21(5).
90 PDPA s 22(1).
Singapore Report: Data Protection in the Internet
317
