This website supports IPv6

You are here:Home > News
Text Size:[L M S]
Personal Data Protection Act (PDPA) Came into Effect in January 2013

Introduction

Personal Data Protection Act (PDPA) was passed in Parliament in 15 October 2012 and came into effect in January 2013.

The Act will change the collection, use and disclosure of personal data by organization in a manner that balances the right of individuals to protect their personal data with an organization’s need for such data. As a result, banks will no longer be allowed to disclose customer information in connection with the promotion of financial products and services.

Scope of PDPA

The PDPA only covers “personal data” which means data, whether true or not, about an individual who can be identified or identifiable. Individual refers to a natural person, whether living or deceased. The Act covers all forms of personal data, whether electronic or non-electronic.

The PDPA is intended to operate concurrently with existing sector specific standards (i.e. Banking Act) and is not intended to change any of these standards. In the event that there is any inconsistency, the sector specific standards shall prevail. However, if there are issues which are not addressed by the sector specific standards, PDPA shall be the point of reference.

Main Elements of PDPA

1. Consent: Consent is required before collecting, using and disclosing personal data of individuals.

2. Purpose: Purpose of data should be reasonably scoped and notified to the individual concerned(*1).

3. Access & Correction: Individuals can request access to and correct their personal data.

4. Accuracy: All personal data should be accurate and complete.

5. Retention: All personal data should not be retained if it is no longer needed for legal or business purposes.

6. Transfer: All personal data should not be transferred outside Singapore unless there is a comparable standard of protection.

7. Openness: The Bank needs to appoint a Data Protection Officer and make available its policies and procedures to the public.

8. Screening: The Bank needs to check against the Do-Not-Call (DNC) registry(*2) before sending marketing messages unless consent has been obtained.

 

Implications to the Banks in Singapore

The Bank shall need to:

1. Review application forms (e.g. account opening forms etc) and facility agreements (e.g. letter of offer etc) to include the consent clause.

2. Obtain consent from all customers (opt-out does not constitute consent).

3. Set up a system which can track all consent (including withdrawal).

4. Establish processes to facilitate access and correction requests within 30 days or less.

5. Establish sound security arrangements (according to the Risk Management Guidelines issued by the MAS) to prevent unauthorized access, copying, modification etc of the data

6. Review the existing data retention policy and establish processes that destroy/erase all forms of records of personal data that is no longer needed.

7. Review all existing outsourcing arrangements (according to the MAS Guidelines to Outsourcing) to ensure no information is transferred to anywhere outside Singapore which does not have a comparable standard of protection.

8. Include policies and procedures of the Bank’s PDPA in all publicly-available sources such as the Branch’s website etc.

9. Appoint a Data Protection Officer (DPO) and establish the DPO’s roles and responsibilities which include addressing all queries from the Personal Data Protection Commission and the public when the need arises.

10. Establish processes and set up a system to screen contact list against DNC register (to be updated with the internal calling lists every 30 days) every month.

 

During this transition period, the Personal Data Protection Commmission (PDPC) will undertake educational and outreach activities to aid organisations’ understanding and compliance with the Act. The national DNC registry is expected to be ready for public registration by early 2014. Currently, the associations of relevant industries are still developing guidelines for banks and other organisations to ensure smooth transition when the DNC registry and the actual data protection rules come into place in early-2014 and mid-2014 respectively.

Further information on the PDPA can be found on the following official website:

http://www.pdpc.gov.sg/personal-data-protection-act/overview

 

-----------------

*1 Banks are only required to inform customers that information is being obtained for the purpose of customer due diligence as required by MAS. No consent is required unless the information collected will be used for purpose other than what is set out in Notice 626. Banks need to be mindful not to collect information beyond what is actually required.

*2 DNC registry is comprised of 3 separate registers – telephone calls, text messages and faxes. Messages sent to individuals’ email addresses or home addresses would not be included.