Personal Data Protection Act 2012
   HOME

TheInfoList



OR:

The Personal Data Protection Act 2012 ("PDPA") sets out the law on
data protection Data protection may refer to: * Information privacy, also known as data privacy * Data security {{Authority control ...
in
Singapore Singapore, officially the Republic of Singapore, is an island country and city-state in Southeast Asia. The country's territory comprises one main island, 63 satellite islands and islets, and one outlying islet. It is about one degree ...
. The PDPA regulates the processing of personal data in the private sector.


Overview

The PDPA establishes a general data protection regime, originally comprising nine data protection obligations which are imposed on organisations: the Consent Obligation, the Purpose Limitation Obligation, the Notification Obligation, the Access and Correction Obligation, the Accuracy Obligation, the Protection Obligation, the Retention Limitation Obligation, the Transfer Limitation Obligation and the Openness Obligation (now referred to as the Accountability Obligation). Major amendments to the PDPA were proposed and passed in 2020. Among other changes, a tenth data protection obligation was added, namely, the Data Breach Notification Obligation. The PDPA also governs telemarketing in Singapore. It establishes the Do Not Call Registers, on which telephone numbers may be registered. There are three Do Not Call Registers: (i) the No Fax Message Register; (ii) the No Text Message Register; and (iii) the No Voice Call Register. Generally, if a telephone number is listed on a Do Not Call Register (e.g. the No Text Message Register), then it is not permitted to send a marketing message of the relevant kind to that telephone number.


Personal Data Protection Commission

The PDPA establishes the Personal Data Protection Commission (PDPC) as the regulatory authority governing data protection in Singapore. The PDPC enforces the PDPA and publishes advisory guidelines on the interpretation of the PDPA. To date, the PDPC has enforced the PDPA against a number of organisations. Notable enforcement cases include
SingHealth Singapore Health Services, commonly known as SingHealth, is the largest group of healthcare institutions in Singapore. Established in 2000, the group consists of four public hospitals, two community hospitals, five national specialty centres a ...
, which was implicated in the 2018 SingHealth data breach.


Management


References


External links


Official text of the Act
{{Privacy 2012 in law 2012 in Singapore Singaporean legislation Privacy legislation Data laws of Asia