3.9 Data Protection and Electronic Surveillance for Security
and Defence Purposes
A number of statutes discuss the electronic processing of personal data for security
and national defence purposes.
First, under the PDPA, an organisation shall not provide an individual with
his/her personal data (or information about the ways in which the data has or may
have been used or disclosed by the organisation) if the provision of that data or other
information could reasonably be expected to “be contrary to the national interest”.
295
Additionally, consent is not required for the collection, use or disclosure of personal
data where such collection, use or disclosure is in the national interest.
296 National
interest includes “national defence, national security, public security, the maintenance of essential services and the conduct of international affairs”.
297
Second, the CMA applies to any unauthorised use of computers and related
materials, including any data contained therein, whether the offender or computer
or data is in Singapore or not, for any offence which “causes, or creates a significant
risk of, serious harm in Singapore”.
298
“[S]erious harm in Singapore” involves:
• “a disruption of, or a serious diminution of public confidence in, the provision of
any essential service”;
• “a disruption of, or a serious diminution of public confidence in, the performance
of any duty or function of, or the exercise of any power by” the Singapore
government or any Singapore governmental agency; or
• “damage to the national security, defence or foreign relations of Singapore”.
299
An example would be giving the public access to confidential documents belonging to a Singapore governmental ministry.
300
The Cybersecurity Act also empowers the minister to “authorise or direct any
person or organisation” to “take such measures or comply with such requirements as
may be necessary to prevent, detect or counter any threat to a computer or computer
service” for the “purposes of preventing, detecting or countering any serious and
imminent threat to (a) the provision of any essential service; or (b) the national
security, defence, foreign relations, economy, public health, public safety or public
order of Singapore”.
301 This may include the powers to access computers granted
295 PDPA s 21(3)(e).
296 PDPA Second Schedule s 1(d), Third Schedule s 1(d), Fourth Schedule s 1(e).
297 PDPA s 2(1).
298 CMA s 11.
299 CMA s 11(4).
300 CMA s 11.
301 Cybersecurity Act s 23(1).
338
E.-I. Ong
and Defence Purposes
A number of statutes discuss the electronic processing of personal data for security
and national defence purposes.
First, under the PDPA, an organisation shall not provide an individual with
his/her personal data (or information about the ways in which the data has or may
have been used or disclosed by the organisation) if the provision of that data or other
information could reasonably be expected to “be contrary to the national interest”.
295
Additionally, consent is not required for the collection, use or disclosure of personal
data where such collection, use or disclosure is in the national interest.
296 National
interest includes “national defence, national security, public security, the maintenance of essential services and the conduct of international affairs”.
297
Second, the CMA applies to any unauthorised use of computers and related
materials, including any data contained therein, whether the offender or computer
or data is in Singapore or not, for any offence which “causes, or creates a significant
risk of, serious harm in Singapore”.
298
“[S]erious harm in Singapore” involves:
• “a disruption of, or a serious diminution of public confidence in, the provision of
any essential service”;
• “a disruption of, or a serious diminution of public confidence in, the performance
of any duty or function of, or the exercise of any power by” the Singapore
government or any Singapore governmental agency; or
• “damage to the national security, defence or foreign relations of Singapore”.
299
An example would be giving the public access to confidential documents belonging to a Singapore governmental ministry.
300
The Cybersecurity Act also empowers the minister to “authorise or direct any
person or organisation” to “take such measures or comply with such requirements as
may be necessary to prevent, detect or counter any threat to a computer or computer
service” for the “purposes of preventing, detecting or countering any serious and
imminent threat to (a) the provision of any essential service; or (b) the national
security, defence, foreign relations, economy, public health, public safety or public
order of Singapore”.
301 This may include the powers to access computers granted
295 PDPA s 21(3)(e).
296 PDPA Second Schedule s 1(d), Third Schedule s 1(d), Fourth Schedule s 1(e).
297 PDPA s 2(1).
298 CMA s 11.
299 CMA s 11(4).
300 CMA s 11.
301 Cybersecurity Act s 23(1).
338
E.-I. Ong
