inside or outside Singapore (thus this could include web-based email accounts and
web storage accounts).
366
For the Cybersecurity Act, a computer/computer system has to be located wholly
or partly in Singapore to be considered a CII.
367 The PS(G)A does not discuss this
issue; however it covers generally data “under the control” of an agency.
368
4.2 Transfer of Personal Data to Foreign Jurisdictions
No personal data shall be transferred outside Singapore unless the recipient of that
data must, under legally enforceable obligations, provide the transferred data with a
standard of protection that is at least comparable to the protection afforded under the
PDPA.
369
“Legally enforceable obligations” includes obligations imposed on the
recipient under: any law; the use of contractual arrangements; and/or binding
corporate rules (for intra-corporate transfers only).
370
The above requirement is also satisfied if, among others: the individual concerned
consents to the data transfer; the transfer is necessary for the performance of a
contract between the individual and the organisation; the transfer is necessary for a
use or disclosure in certain situations where consent is not required under the PDPA;
the data is merely in transit through Singapore; or the data is publicly available in
Singapore.
371 Additionally, exemptions may be granted.
372
Certain cross-border agreements may also have implications for foreign transfers
of personal data.
373
366 CPC s 39(1).
367 Cybersecurity Act s 7(1)(b).
368 PS(G)A s 6(1).
369 PDPA s 26(1); PDPR s 9(1).
370 PDPR s 10; PDPC Advisory Guidelines on Key Concepts para 19.2.
371 PDPR s 9(3).
372 PDPA s 26(2). There are also specific requirements for certain sectors. For instance, a specific
data protection regime applies to cross-border transfers of data in the banking industry, as enforced
by MAS. Chia (2018), p. 321.
373 For instance, Singapore has free-trade agreements which include provisions relating to data
protection. However, these provisions (if they exist) are generally not specific enough to override
the restrictions on cross-border data transfers in the national laws of the parties to these agreements
Chia (2018), p. 324. More recently in March 2018, Singapore joined the APEC Cross-Border
Privacy Rules (“CBPR”) system. This is a framework for the exchange of personal data among
participating APEC economies. The Commission is working on a scheme for organisations to be
certified under this system, and will likely provide guidance in due course on the operation of the
CBPR system in the context of the PDPA’s requirements for cross-border transfers of personal data
Alfred and Goh (2018) paras 12.42–12.44.
Singapore Report: Data Protection in the Internet
345
Précédent

- 347/540

Suivant