{"id":2798,"date":"2022-11-22T16:47:00","date_gmt":"2022-11-22T16:47:00","guid":{"rendered":"https:\/\/lawpilots.com\/?p=2798"},"modified":"2023-03-31T09:16:18","modified_gmt":"2023-03-31T09:16:18","slug":"pdpa-southeast-asia","status":"publish","type":"post","link":"https:\/\/lawpilots.com\/en\/blog\/data-protection\/pdpa-southeast-asia\/","title":{"rendered":"What is the data privacy law PDPA in Singapore?"},"content":{"rendered":"\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\" style=\"margin-bottom:1.75em;\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"wp-block-paragraph\">The year 2020 brought some important developments to the world of&nbsp;data&nbsp;protection&nbsp;legislation. Most notably, the&nbsp;<a href=\"https:\/\/lawpilots.com\/en\/blog\/data-protection\/ccpa-requirements\/\" data-type=\"URL\" data-id=\"https:\/\/lawpilots.com\/en\/blog\/data-protection\/ccpa-requirements\/\">California Consumer&nbsp;Privacy&nbsp;Act (CCPA)<\/a> came into force in the US in January. The Court of Justice of the&nbsp;European&nbsp;Union (CJEU) effectively put an end to the free flow of&nbsp;data&nbsp;between the US and the EU, ruling in&nbsp;<a href=\"https:\/\/lawpilots.com\/en\/blog\/data-protection\/schremsii-gdpr\/\" data-type=\"URL\" data-id=\"https:\/\/lawpilots.com\/en\/blog\/data-protection\/schremsii-gdpr\/\">Schrems II<\/a>&nbsp;that the&nbsp;European&nbsp;Commission\u2019s adequacy decision regarding the EU-US&nbsp;Privacy&nbsp;Shield was invalid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Southeast Asia also&nbsp;modified&nbsp;its&nbsp;Personal&nbsp;Data&nbsp;Protection&nbsp;Act (PDPA), introducing, among other things, mandatory&nbsp;data&nbsp;breach&nbsp;notifications, an expansion of the notional&nbsp;consent&nbsp;framework, exceptions to&nbsp;consent&nbsp;for legitimate interests and higher penalties for non-compliance. These changes will be applied in practice in 2021. The first amendments to the&nbsp;PDPA&nbsp;already came into force in Singapore in February and in&nbsp;Thailand&nbsp;it has been in force since June 1, 2021.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lawpilots.com\/wp-content\/uploads\/2021\/09\/Design-ohne-Titel-5-1024x1024.png\" alt=\"\" class=\"wp-image-20200\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Who needs to comply with PDPA?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The new and&nbsp;modified&nbsp;data&nbsp;protection&nbsp;regime applies to countries including Malaysia, Singapore,&nbsp;Thailand, Korea, Vietnam and India. It is designed to help limit the misuse of&nbsp;personal&nbsp;data&nbsp;and maintain&nbsp;individuals\u2019 trust in&nbsp;companies and&nbsp;organizations&nbsp;that manage their&nbsp;data. In this way, Southeast Asia would like to appear more trustworthy to international businesses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The&nbsp;Personal&nbsp;Data&nbsp;Protection&nbsp;Act (PDPA) addresses both the&nbsp;protection&nbsp;of&nbsp;individuals\u2019&nbsp;personal&nbsp;data&nbsp;and the&nbsp;collection&nbsp;of&nbsp;personal&nbsp;data&nbsp;by&nbsp;organizations&nbsp;that gather, use or disclose it for legitimate&nbsp;purposes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What data is PDPA?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Under the terms of the PDPA, personal data is any data concerning a person by which they can be identified, for example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Full name&nbsp;<\/li>\n\n\n\n<li>NRIC or passport number&nbsp;<\/li>\n\n\n\n<li>Photograph or video image of a person&nbsp;<\/li>\n\n\n\n<li>Mobile telephone number&nbsp;<\/li>\n\n\n\n<li>Personal email address&nbsp;<\/li>\n\n\n\n<li>Thumbprint&nbsp;<\/li>\n\n\n\n<li>Residential address&nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Is PDPA mandatory?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Compliance&nbsp;with the&nbsp;PDPA&nbsp;is mandatory for companies. Companies have to&nbsp; let customers know why their&nbsp;personal&nbsp;information is being requested and obtain their permission to use it up front by notifying them.&nbsp;Organizations&nbsp;must not compel&nbsp;individuals&nbsp;to&nbsp;consent&nbsp;to the&nbsp;collection, use or&nbsp;disclosure&nbsp;of&nbsp;personal&nbsp;information beyond what is appropriate to&nbsp;provide&nbsp;a product or service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Customers can&nbsp;request&nbsp;that an&nbsp;organization&nbsp;stops collecting, using or disclosing&nbsp;their&nbsp;personal&nbsp;information. The&nbsp;organization&nbsp;must then inform them of the likely consequences of the withdrawal of permission before complying with the&nbsp;request. However, the&nbsp;organization&nbsp;is under no obligation to delete or destroy the&nbsp;personal&nbsp;information and may retain it as long as necessary for&nbsp;business&nbsp;or&nbsp;legal&nbsp;reasons. In addition, customers can&nbsp;request&nbsp;to see the&nbsp;personal&nbsp;information that has been&nbsp;collected&nbsp;about them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If customers do not receive&nbsp;notifications or companies&nbsp;breach&nbsp;the terms of the&nbsp;PDPA&nbsp;they will be&nbsp;subject&nbsp;to penalties. The penalty for a violation of the principles set forth in the&nbsp;PDPA&nbsp;could be a fine of up to US$1 million and\/or imprisonment for a term not exceeding two years. One of the highest fines imposed by the Personal Data Protection Commission (PDPC) to date was against IT vendor Learnaholic that totalled US$60,000. Many of these fines were for cyber&nbsp;security&nbsp;violations that resulted in the unauthorized&nbsp;access&nbsp;and&nbsp;disclosure&nbsp;of&nbsp;personal&nbsp;data.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lawpilots.com\/wp-content\/uploads\/2021\/08\/4-3-1024x576.jpg\" alt=\"What is considered personaldata in Singapore?\" class=\"wp-image-20041\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What is considered personal data in Singapore?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The&nbsp;Personal&nbsp;Data&nbsp;Protection&nbsp;Act also provides Singapore with a basic standard for the&nbsp;protection&nbsp;of&nbsp;personal&nbsp;data. It supplements&nbsp;legal&nbsp;and administrative provisions such as the Banking Act and the Insurance Act.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Singapore&nbsp;PDPA&nbsp;applies to all&nbsp;electronic&nbsp;and non-electronic&nbsp;communications involving the&nbsp;collection,&nbsp;processing&nbsp;or&nbsp;transfer&nbsp;of&nbsp;data&nbsp;within Singapore, irrespective of whether the company in question has an actual physical presence in Singapore. The&nbsp;PDPA&nbsp;empowers&nbsp;individuals&nbsp;to protect,&nbsp;access&nbsp;and correct their own&nbsp;data.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Organizations that collect, process or disclose this type of personal data must comply with the following requirements in Singapore:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>They must obtain the&nbsp;consent&nbsp;of the&nbsp;data&nbsp;subject.<\/li>\n\n\n\n<li>They must collect the&nbsp;data&nbsp;for an appropriate&nbsp;purpose.<\/li>\n\n\n\n<li>They must inform the&nbsp;data&nbsp;subject&nbsp;of the reason for collecting the&nbsp;data.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Singapore and Malaysia also require that&nbsp;data&nbsp;not be&nbsp;transferred to countries with a lower level of&nbsp;protection&nbsp;for&nbsp;personal&nbsp;data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, the Singapore&nbsp;PDPA&nbsp;contains various regulations on the&nbsp;collection, use,&nbsp;disclosure&nbsp;and maintenance of&nbsp;personal&nbsp;data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also seeks to establish a national Do Not Call (DNC) registry in Singapore, on which&nbsp;individuals&nbsp;can register their telephone numbers to stop receiving unsolicited telemarketing calls from companies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Southeast Asia\u2019s\u00a0economy\u00a0is growing rapidly. Likewise, the digitalization of the population is increasing, which is why new regulations and\u00a0standards\u00a0are being established. If your company has economic ties to Southeast Asia, it is very important that you and your employees are familiar with the current regulations regarding\u00a0personal\u00a0data\u00a0in the region.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sources<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ismail, Noriswadi. Selected Issues Regarding the Malaysian Personal Data Protection Act (PDPA) 2010. International Data Privacy Law 2.2 (2012): 105-112.<\/li>\n\n\n\n<li>Cavey, Stephen (2020). <a href=\"https:\/\/www.groundlabs.com\/blog\/PDPA-in-malaysia-singapore-korea-vietnam-and-india\/\" target=\"_blank\" data-type=\"URL\" data-id=\"https:\/\/www.groundlabs.com\/blog\/PDPA-in-malaysia-singapore-korea-vietnam-and-india\/\" rel=\"noreferrer noopener nofollow\">PDPA: In Malaysia, Singapore, Korea, Vietnam, and India<\/a>. <\/li>\n\n\n\n<li>Malaysia (2021). <a href=\"https:\/\/www.malaysia.gov.my\/portal\/content\/654\" data-type=\"URL\" data-id=\"https:\/\/www.malaysia.gov.my\/portal\/content\/654\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Personal Data Protection Act<\/a>. <\/li>\n\n\n\n<li>Pdpc (2021). <a href=\"https:\/\/www.pdpc.gov.sg\/Overview-of-PDPA\/The-Legislation\/Personal-Data-Protection-Act\" target=\"_blank\" data-type=\"URL\" data-id=\"https:\/\/www.pdpc.gov.sg\/Overview-of-PDPA\/The-Legislation\/Personal-Data-Protection-Act\" rel=\"noreferrer noopener nofollow\">A PDPA Overview<\/a>.<\/li>\n\n\n\n<li>Pdpc (2021). <a href=\"https:\/\/www.pdpc.gov.sg\/-\/media\/Files\/PDPC\/PDF-Files\/Resource-for-Individuals\/what-you-need-to-know-about-PDPA-v1-0.pdf?la=en\" target=\"_blank\" data-type=\"URL\" data-id=\"https:\/\/www.pdpc.gov.sg\/-\/media\/Files\/PDPC\/PDF-Files\/Resource-for-Individuals\/what-you-need-to-know-about-PDPA-v1-0.pdf?la=en\" rel=\"noreferrer noopener nofollow\">What You Should Know About the Personal Data Protection Act<\/a>. <\/li>\n\n\n\n<li>Wong YongQuan, Benjamin. Data Privacy Law in Singapore: the Personal Data Protection Act 2012. International Data Privacy Law 7.4 (2017).<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\"><section id=\"table-of-content\" class=\"mb-3\">\n    <div class=\"container\">\n        <div class=\"row\">\n            <div class=\"col-12 pe-lg-0\">\n                                <div class=\"bg-light-blue-25 rounded-4 p-2\">\n                    <p class=\"mb-2 h2\">Inhaltsangabe<\/p>\n                    <ul id=\"table-holder\">\n                      \t\t\t\t\t\t\t\t<li><a href='#ueberschrift0'>Who needs to comply with PDPA?<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href='#ueberschrift1'>What data is PDPA?<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href='#ueberschrift2'>Is PDPA mandatory?<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href='#ueberschrift3'>What is considered personal data in Singapore?<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t                    <\/ul>\n                <\/div>\n                                    <div class=\"newsletter-block bg-blue-100 rounded-4 p-2 mt-2\">\n                                                                                            <\/div>\n                            <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<script type=\"text\/javascript\">\n\n    if (jQuery(\"#table-of-content\").length && jQuery(\"#table-of-content\").parents().hasClass('wp-block-column')) {\n        jQuery(\"#table-of-content\").parent().addClass(\"order-first order-lg-2\");\n        jQuery(\"#table-of-content\").parents().siblings('.wp-block-column').children('h2').each(function (index, item) {\n            item.id = \"ueberschrift\" + index;\n\/\/                 jQuery(\"#table-holder\").append(\"<li><a href='#ueberschrift\" + index + \"'>\" + item.innerText + \"<\/a><\/li>\");\n        });\n    }\n\n    let anchorSelector = 'a[href^=\"#\"]';\n\n    let anchorList =\n        document.querySelectorAll(anchorSelector);\n\n    anchorList.forEach(link => {\n        link.onclick = function (e) {\n\n            e.preventDefault();\n\n            let destination =\n                document.querySelector(this.hash);\n\n            const y = destination.getBoundingClientRect().top + window.pageYOffset - 150;\n\n            window.scrollTo({top: y, behavior: 'smooth'});\n\n        }\n    });\n\n<\/script>\n<style>\n    .newsletter-block .newsletter-link {\n        font-size: 16px;\n        text-decoration: none;\n    }\n\n    .newsletter-block .newsletter-text {\n        font-size: 16px;\n        line-height: 24px;\n    }\n\n    #table-of-content #table-holder a {\n        font-size: 16px;\n        line-height: 24px;\n    }\n\n    .single-blog #table-of-content {\n        position: static;\n        top: 0;\n        height: 100%;\n    }\n\n    .single-blog #table-of-content .container,\n    .single-blog #table-of-content .row,\n    .single-blog #table-of-content .row > div {\n        height: 100%;\n    }\n\n    .single-blog #table-of-content .newsletter-block {\n        position: sticky;\n        top: 140px;\n    }\n\n    \/*@media screen and (max-width: 991px) {\n        .single-blog #table-of-content .newsletter-block {\n            position: static;\n            top: 110px;\n        }\n    }*\/\n\n    @media screen and (max-width: 781px) {\n        .single-blog #table-of-content .newsletter-block {\n            position: static;\n            top: 0;\n        }\n    }\n<\/style><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The year 2020 brought some important developments to the world of&nbsp;data&nbsp;protection&nbsp;legislation. Most notably, the&nbsp;California Consumer&nbsp;Privacy&nbsp;Act (CCPA) &#8230;<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[88],"tags":[],"class_list":["post-2798","post","type-post","status-publish","format-standard","hentry","category-data-protection"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/posts\/2798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/comments?post=2798"}],"version-history":[{"count":5,"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/posts\/2798\/revisions"}],"predecessor-version":[{"id":16242,"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/posts\/2798\/revisions\/16242"}],"wp:attachment":[{"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/media?parent=2798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/categories?post=2798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawpilots.com\/en\/wp-json\/wp\/v2\/tags?post=2798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}