also act based on what a reasonable person would consider appropriate in the
circumstances.
204
Organisations must still ensure that their employees’ data is “properly protected,
accurate and stored only for the period that it is needed”.
205 Organisations must also
allow the employee to access
206 and correct
207 his/her personal data, as well as
withdraw consent.
208 Two important exceptions to an employer’s Access Obligation
are if: the data is solely for evaluative purposes
209 ; and disclosing the data would
reveal confidential commercial information that could, in the opinion of a reasonable
person, harm the organisation’s competitive position.
210 There is also no need to
correct personal data kept solely for evaluative purposes.
211
CCTVs The PDPA encompasses the use of CCTVs (at a workplace or otherwise),
i.e. individuals must be informed of the purposes for which their personal data
(obtained through the CCTV) will be collected, use or disclosed.
212 Additionally,
notices should be placed “so as to enable individuals [including employees] to have
sufficient awareness that CCTVs have been deployed for a particular purpose”, e.g.
at the entry to a building.
213 However, the exact location of the CCTV need not be
revealed.
214 Concerning an access request for CCTV records, such access shall be
provided unless an exception applies, e.g. if the records may reveal personal data
about another individual.
215 (However, access can be given if the organisation masks
the personal data of other individuals.
216 ) A reasonable processing fee can also be
charged.
217 The organisation may also reject access requests which are “frivolous or
vexatious”, or if the burden of providing access would be unreasonable to the
organisation or disproportionate to the individual’s interests.
218
Employee Usage of Personal Data There is no specific legislation or case law on
this point. However, in My Digital Lock Pte Ltd,
219 the complainant and respondent
were engaged in a legal dispute. Respondent’s director “A” posted screenshots of the
204 PDPC Advisory Guidelines for Selected Topics para 5.26.
205 PDPA ss 23–25; Protecting the Personal Data of Job Applicants and Employees p. 3.
206 PDPA s 21.
207 PDPA s 22.
208 PDPA s 16(1). See also Sect. 2.2.1.
209 PDPA Fifth Schedule s 1(a).
210 PDPA Fifth Schedule s 1(g).
211 PDPA Sixth Schedule s 1(a).
212 PDPC Advisory Guidelines for Selected Topics para 4.34.
213 PDPC Advisory Guidelines for Selected Topics para 4.36.
214 PDPC Advisory Guidelines for Selected Topics para 4.38.
215 PDPC Advisory Guidelines for Selected Topics paras 4.42–4.43 (discussing PDPA s 21(3)(c)).
216 PDPC Advisory Guidelines for Selected Topics para 4.43(c).
217 PDPR s 7; PDPC Advisory Guidelines for Selected Topics para 4.46.
218 PDPA s 21(2) read with Fifth Schedule ss 1( j )(ii), (v).
219 [2016] SGPDPC 20.
Singapore Report: Data Protection in the Internet
329
Précédent

- 331/540

Suivant