2.2.6 Accountability
This obligation, previously called the “Openness” obligation, was recently amended
to incorporate the concept of “Accountability”. This refers to how an organisation
discharges its responsibility for personal data which it has collected or obtained for
processing, or which it has control over. Accountability requires organisations to not
only take measures to meet their PDPA obligations, but also to demonstrate that they
can meet their obligations when required. These measures include appointing a data
protection officer, developing and implementing appropriate data protection policies
and practices, and making information about such policies and practices available.
102 This also signals a shift from a compliance-based approach to an accountability-based approach in managing personal data.
103
2.3 Supervising Authority
The PDPA is administered and enforced by the Commission. The Commission is
overseen by the Info-communications Media Development Authority (“IMDA”),
and the IMDA in turn comes under the Ministry of Communications and
Information.
104
The Commission may conduct investigations regarding alleged non-compliance
of the PDPA,
105 including requiring documents and information, inspecting premises,
106 and imposing certain remedies and sanctions.
107 The Commission shall
also: promote awareness of data protection in Singapore; provide advisory services
(including to the Singapore Government) regarding data protection; conduct
research and educational activities regarding data protection; and manage technical
co-operation regarding data protection with foreign, international, and governmental
authorities.
108
102 PDPC Advisory Guidelines on Key Concepts para 20.1.
103 PDPC Guide to Accountability under the PDPA.
104 MCI (2019) Agencies. https://www.mci.gov.sg/agencies. Accessed 30 August 2019.
105 PDPA s 50.
106 PDPA Ninth Schedule.
107 PDPA s 29. See also Sect. 3.10.
108 PDPA s 6.
Singapore Report: Data Protection in the Internet
319
This obligation, previously called the “Openness” obligation, was recently amended
to incorporate the concept of “Accountability”. This refers to how an organisation
discharges its responsibility for personal data which it has collected or obtained for
processing, or which it has control over. Accountability requires organisations to not
only take measures to meet their PDPA obligations, but also to demonstrate that they
can meet their obligations when required. These measures include appointing a data
protection officer, developing and implementing appropriate data protection policies
and practices, and making information about such policies and practices available.
102 This also signals a shift from a compliance-based approach to an accountability-based approach in managing personal data.
103
2.3 Supervising Authority
The PDPA is administered and enforced by the Commission. The Commission is
overseen by the Info-communications Media Development Authority (“IMDA”),
and the IMDA in turn comes under the Ministry of Communications and
Information.
104
The Commission may conduct investigations regarding alleged non-compliance
of the PDPA,
105 including requiring documents and information, inspecting premises,
106 and imposing certain remedies and sanctions.
107 The Commission shall
also: promote awareness of data protection in Singapore; provide advisory services
(including to the Singapore Government) regarding data protection; conduct
research and educational activities regarding data protection; and manage technical
co-operation regarding data protection with foreign, international, and governmental
authorities.
108
102 PDPC Advisory Guidelines on Key Concepts para 20.1.
103 PDPC Guide to Accountability under the PDPA.
104 MCI (2019) Agencies. https://www.mci.gov.sg/agencies. Accessed 30 August 2019.
105 PDPA s 50.
106 PDPA Ninth Schedule.
107 PDPA s 29. See also Sect. 3.10.
108 PDPA s 6.
Singapore Report: Data Protection in the Internet
319
