PDPA basics every employee should know

You will be able to name the main obligations under the Personal Data Protection Act and what each means day to day.

Daniel runs the front desk and operations at a physiotherapy clinic in Toa Payoh. Last month a patient asked him why the clinic had sent her a promotion for a sister clinic's pilates classes. She'd given her number to book an appointment, not to receive marketing. Daniel wasn't sure whether she had a point. She did, and the law that says so is the Personal Data Protection Act.

The PDPA is Singapore's main data protection law for private organisations. You don't need to be a lawyer to work with it, but you do need to know what it asks of the company you work for, because at work you're the person the company acts through. This lesson covers the obligations that come up most often, in plain words. The next three lessons apply them to AI.

What counts as personal data

Under the Act, personal data is data about an individual who can be identified from that data, or from that data combined with other information the organisation has or is likely to have access to.

The second half of that definition matters. A name and a phone number obviously identify someone. But "the 34-year-old patient with the knee injury who comes on Tuesday mornings" may identify her too, if the clinic's booking system can match the details. Removing the name doesn't automatically make a record anonymous.

The Act carves out some things. Business contact information, such as a work email given out for business purposes, is excluded from most of the obligations. The PDPC's website explains the exclusions, and it's worth reading them once before you rely on one.

Consent, purpose and notification

These three work together, and they're what Daniel's patient was getting at.

Consent means an organisation generally needs a person's agreement before it collects, uses or discloses their personal data. The Act also sets out situations where consent can be deemed, and exceptions where it isn't needed, such as some uses for the organisation's legitimate interests. Those exceptions have conditions, and someone in your company should be the one deciding they apply.

Notification means telling people the purposes for which their data will be collected, used or disclosed, at or before the time of collection.

Purpose limitation means using the data only for purposes a reasonable person would consider appropriate in the circumstances, and that the person was told about.

Put together: the patient was told her number was for appointments. Using it to market another business's classes was a new purpose she hadn't been told about or agreed to. Daniel's clinic now asks a separate question on the intake form about marketing.

Protection and transfer

The protection obligation says an organisation must make reasonable security arrangements to protect personal data in its possession or under its control. That covers locked cabinets and passwords, and it covers the tools staff use. Sending data to a service provider doesn't end the obligation. The organisation is expected to choose providers carefully and set out in a contract how they must handle the data.

The transfer limitation obligation applies when personal data is sent outside Singapore. The organisation must make sure the data gets a standard of protection comparable to the PDPA's. Many AI services process data on servers in other countries, which is why this one comes up so often in module 2.

There are other obligations too: letting people access and correct their data, keeping it accurate, not keeping it longer than needed, and notifying the PDPC and affected people about certain data breaches. The PDPC's website lists them all with guidance on each.

Accountability: the company answers for what you do

The accountability obligation requires an organisation to take responsibility for personal data in its care. In practice that means having data protection policies, making them available, training staff, and appointing at least one person to be responsible for compliance, usually called the data protection officer.

This is why your individual choices at work aren't only your own business. If you paste customer details into a tool the company hasn't approved, the company is the one answerable to the PDPC and to the customer, even though it didn't know. That's also why a good employer would much rather hear about a mistake early than discover it later.

It also tells you who to ask. Every organisation covered by the Act should have someone in the data protection officer role, and their business contact details should be available to the public. If you've never known who that is at your workplace, find out. It's the person you'll name in your checklist in lesson 2.4, Run a PDPA check on three work uses of AI.

The details of the Act, its exceptions and the PDPC's guidance change from time to time, so check the PDPC website for the current version rather than relying on any summary, this one included.

Daniel's own examples would start with the patient who got the pilates promotion. Yours will probably be just as ordinary, and that's the useful thing to notice: the Act shapes normal working days, not only the data breaches that make the news.

Write one sentence in plain words for each of four PDPA obligations, with an example from your own job.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).