熱門推薦罰單破解實戰交通警察名師 25 年經驗,親授警察臨檢、檢舉魔人、科技執法、車禍糾紛的執法邏輯看課程介紹
購物車我的課程我的書籤免費註冊

Personal Data Protection Act 2012 PART 3 — GENERAL RULES WITH RESPECT TO PROTECTION OF AND ACCOUNTABILITY FOR PERSONAL DATA

s 11–s 122 provisions

Compliance with Act

s 11

11.—(1) In meeting its responsibilities under this Act, an organisation must consider what a reasonable person would consider appropriate in the circumstances.(2) An organisation is responsible for personal data in its possession or under its control. (3) An organisation must designate one or more individuals to be responsible for ensuring that the organisation complies with this Act. (4) An individual designated under subsection (3) may delegate to another individual the responsibility conferred by that designation. (5) An organisation must make available to the public the business contact information of at least one of the individuals designated under subsection (3) or delegated under subsection (4). (5A) Without limiting subsection (5), an organisation is deemed to have satisfied that subsection if the organisation makes available the business contact information of any individual mentioned in subsection (3) in any prescribed manner.[40/2020] (6) The designation of an individual by an organisation under subsection (3) does not relieve the organisation of any of its obligations under this Act. —(1) In meeting its responsibilities under this Act, an organisation must consider what a reasonable person would consider appropriate in the circumstances. (2) An organisation is responsible for personal data in its possession or under its control. (3) An organisation must designate one or more individuals to be responsible for ensuring that the organisation complies with this Act. (4) An individual designated under subsection (3) may delegate to another individual the responsibility conferred by that designation. (5) An organisation must make available to the public the business contact information of at least one of the individuals designated under subsection (3) or delegated under subsection (4). (5A) Without limiting subsection (5), an organisation is deemed to have satisfied that subsection if the organisation makes available the business contact information of any individual mentioned in subsection (3) in any prescribed manner.[40/2020] (6) The designation of an individual by an organisation under subsection (3) does not relieve the organisation of any of its obligations under this Act.

Policies and practices

s 12

12. An organisation must —(a) develop and implement policies and practices that are necessary for the organisation to meet the obligations of the organisation under this Act; (b) develop a process to receive and respond to complaints that may arise with respect to the application of this Act; (c) communicate to its staff information about the organisation’s policies and practices mentioned in paragraph (a); and (d) make information available on request about —(i) the policies and practices mentioned in paragraph (a); and (ii) the complaint process mentioned in paragraph (b).

Back to Personal Data Protection Act 2012 — full text

Provisions on this page are reproduced verbatim from official open data. See the attribution line.

Source: Singapore Statutes Online (Attorney-General's Chambers), © Government of Singapore.