Protection from Harassment (Amendment) Bill
Anyone who publishes the identity information of a person in contravention of those
provisions can be fined up to $5,000 SGD and/or jailed for up to 6 months.
358
4 Private International Law Rules
4.1 Territorial Scope; Foreign Entities
The PDPA applies to all organisations carrying out activities involving personal data
in Singapore.
359 Any organisation that collects personal data overseas and brings it
into Singapore is also subject to the PDPA from the time it seeks to collect the
personal data (if such collection occurs in Singapore) or brings such data into
Singapore.
360 Similarly, electronic data processing by entities seated outside Singapore is still considered under the PDPA, so long as the personal data is located in
Singapore. Indeed, the definition of “organisation” includes companies formed
under non-Singapore laws and/or resident outside Singapore.
361
It should be noted that a data intermediary has no obligation under the PDPA save
for the Protection Obligation and the Retention Obligation
362 (but these Obligations
may also apply to data intermediaries who are overseas
363 ). Instead, an organisation
that uses a data intermediary shall have the same obligation in respect of personal
data processed on its behalf by a data intermediary as if the data were processed by
the organisation itself.
364
Regarding personal data implicated in computer-related crimes: under the CMA,
Singapore claims extra-territorial jurisdiction over any person or any data which
causes or creates a significant risk of serious harm in Singapore.
365 (See Sect. 3.9 for
the definition of “serious harm”.) Under the Criminal Procedure Code, investigators
can also inspect and search, in and from Singapore, any data stored on or available to
a computer implicated in the investigation, regardless of whether the computer is
358 No 11/2019 s 13. See Sect. 3.7.1.
359 PDPC Advisory Guidelines on Key Concepts para 11.1.
360 PDPC Advisory Guidelines on Key Concepts para 11.2. See also Lim (2018), para 8.9: “[t]he
reach of the PDPA [was] explicitly extended to those organisations that may not have any presence
in Singapore, or which may not even be recognised under the law of Singapore”.
361 PDPA s 2(1).
362 PDPA s 4(2). See, e.g., K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Challenger
Technologies Limited [2016] SGPDPC 06.
363 Greenleaf (2018), para 8.55.
364 PDPA s 4(3). Indeed, it has been said that “Singapore has enacted a form of vicarious liability on
Singaporean data controllers for overseas processing”. Greenleaf (2018), para 8.55.
365 CMA s 11.
344
E.-I. Ong
Anyone who publishes the identity information of a person in contravention of those
provisions can be fined up to $5,000 SGD and/or jailed for up to 6 months.
358
4 Private International Law Rules
4.1 Territorial Scope; Foreign Entities
The PDPA applies to all organisations carrying out activities involving personal data
in Singapore.
359 Any organisation that collects personal data overseas and brings it
into Singapore is also subject to the PDPA from the time it seeks to collect the
personal data (if such collection occurs in Singapore) or brings such data into
Singapore.
360 Similarly, electronic data processing by entities seated outside Singapore is still considered under the PDPA, so long as the personal data is located in
Singapore. Indeed, the definition of “organisation” includes companies formed
under non-Singapore laws and/or resident outside Singapore.
361
It should be noted that a data intermediary has no obligation under the PDPA save
for the Protection Obligation and the Retention Obligation
362 (but these Obligations
may also apply to data intermediaries who are overseas
363 ). Instead, an organisation
that uses a data intermediary shall have the same obligation in respect of personal
data processed on its behalf by a data intermediary as if the data were processed by
the organisation itself.
364
Regarding personal data implicated in computer-related crimes: under the CMA,
Singapore claims extra-territorial jurisdiction over any person or any data which
causes or creates a significant risk of serious harm in Singapore.
365 (See Sect. 3.9 for
the definition of “serious harm”.) Under the Criminal Procedure Code, investigators
can also inspect and search, in and from Singapore, any data stored on or available to
a computer implicated in the investigation, regardless of whether the computer is
358 No 11/2019 s 13. See Sect. 3.7.1.
359 PDPC Advisory Guidelines on Key Concepts para 11.1.
360 PDPC Advisory Guidelines on Key Concepts para 11.2. See also Lim (2018), para 8.9: “[t]he
reach of the PDPA [was] explicitly extended to those organisations that may not have any presence
in Singapore, or which may not even be recognised under the law of Singapore”.
361 PDPA s 2(1).
362 PDPA s 4(2). See, e.g., K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Challenger
Technologies Limited [2016] SGPDPC 06.
363 Greenleaf (2018), para 8.55.
364 PDPA s 4(3). Indeed, it has been said that “Singapore has enacted a form of vicarious liability on
Singaporean data controllers for overseas processing”. Greenleaf (2018), para 8.55.
365 CMA s 11.
344
E.-I. Ong
