conduct investigations under the ETA,
285 and compound any offences under the
act.
286
3.8 Data Protection and Digital Forensics
The PDPA provides exceptions from the various Obligations due to criminal
investigations
287 :
• Collection without consent is allowed if it “is necessary for any investigation or
proceedings, if it is reasonable to expect that seeking the consent of the individual
would compromise the availability or the accuracy of the personal data;”
288
• Use and disclosure without consent is allowed if such use or disclosure “is
necessary for any investigation or proceedings”
289 or disclosed to an officer of
a law enforcement agency
290 ;
• Access is not required for: “a document related to a prosecution if all proceedings
related to the prosecution have not been completed”; personal data “subject to
legal privilege”; or personal data collected, used or disclosed without consent for
an investigation (pursuant to the consent exceptions in Second, Third and Fourth
Schedules regarding investigations) if “the investigation and associated proceedings and appeals have not been completed”
291 ; additionally, an organisation shall
not inform an individual that it has disclosed personal data to a law enforcement
agency, if such disclosure was made without that individual’s consent (pursuant
to the Fourth Schedule or other law)
292 ; and
• Correction is not required for a document related to a prosecution “if all proceedings related to the prosecution have not been completed”.
293
More generally, pursuant to an investigation the police may access and inspect
computers (including computer networks), as well as decrypt data on computers and
networks.
294 See Sect. 3.2 for recent amendments to the Criminal Procedure Code,
the CMA, and the Cybersecurity Act.
285 ETA s 24.
286 ETA s 36(1).
287 PDPA s 2(1).
288 PDPA Second Schedule s 1(e).
289 PDPA Third Schedule s 1(e), Fourth Schedule s 1( f ).
290 PDPA Fourth Schedule s 1(n).
291 PDPA Fifth Schedule ss 1(e), ( f ), (h).
292 PDPA s 21(4).
293 PDPA Sixth Schedule s 1(e).
294 CPC ss 39–40, read with CMA s 2(1).
Singapore Report: Data Protection in the Internet
337
Précédent

- 339/540

Suivant