PDPA
PDPA Section 3
- Governs collection, use and disclosure of personal data by organisations
- PDPA could be thought of as balancing 1) rights of individuals to protect their personal data, and 2) needs of organisations
- There are no proprietary rights over personal data conferred, with usual laws applying.
PDPA Section 2(1): Interpretation
Personal data is defined as:
- Data about an identifiable individual
- Includes factual information and opinions
- Does not depend on whether the data is “true”
- Does not include various exclusions, such as business contact information.
“personal data” means data, whether true or not, about an individual who can be identified —
| (a) | from that data; or |
| (b) | from that data and other information to which the organisation has or is likely to have access; |
Individual:
- Natural person, living or deceased
Organisation:
- Includes (non-exhaustively) any individual, company, association or body of persons regardless of where formed, recognised, resident or having an office/place of business.
- Excludes individuals acting in a personal or domestic capacity or as an employee
- Excludes public agencies (covered under a separate framework/law)
Data intermediaries:
- Known as ‘data processors’ in other jurisdictions
- Organisations that processes personal data on behalf of another organisation
- Fewer obligations under the PDPA: only s 24, 25, 26C(3)(a) and 26E and Part 6B apply.
Data controllers (DCs)
- Not a defined term in the PDPA
- Refers to the organisation on whose behalf a DI is processing personal data
- Controls the purposes and sometimes the manner of processing
- Responsible for personal data processed on its behalf by the DI
Collection, use and disclosure
- Not defined in the PDPA
- Overlaps with the defined term “processing:
PDPA Section 4(6): PDPA does not affect any authority, right, privilege or immunity conferred or obligation or limitation imposed, by or under the law (in event of inconsistency, provisions of other written law prevails)
- Note: performance of a contractual obligation is not an excuse to contract out of the PDPA.

Obligations of Organisations
[COLLECTION]
Purpose Limitation
- Reasonable, appropriate, lawful, legitimate, relevant
- Data minimisation is part of Purpose Limitation
Consent Obligation (Legal Bases for Processing)
- One of several legal bases under which organisations may collect, use and disclose personal data
- Consent and general deemed consent
- Deemed consent by contractual necessity
- Legal obligations/authority under written law
- Vital interests of individuals
- Public matters
- Legitimate interests of organisations
- Business assess transactions
- Business improvement purposes and research
Notification Obligation
[USE/STORAGE/CARE]
- Data Minimisation (Purpose Limitation)
- Accuracy
- Security requirements
- Protection
- Data Breach Notification
- Offence against misuse of personal data
- Transfer limitation
- Retention limitation
[Disclosure]
- How should disclosed personal data be protected?
- Requirements for outsourcing (use of data intermediaries)
- Transfer Limitation
[Disposal/Deletion]
- Retention Limitation
Leave a Reply