熱門推薦罰單破解實戰交通警察名師 25 年經驗,親授警察臨檢、檢舉魔人、科技執法、車禍糾紛的執法邏輯看課程介紹
購物車我的課程我的書籤免費註冊

Personal Data Protection Act 2012 PART 6 — CARE OF PERSONAL DATA

s 23–s 264 provisions

Accuracy of personal data

s 23

23. An organisation must make a reasonable effort to ensure that personal data collected by or on behalf of the organisation is accurate and complete, if the personal data —(a) is likely to be used by the organisation to make a decision that affects the individual to whom the personal data relates; or (b) is likely to be disclosed by the organisation to another organisation.

Protection of personal data

s 24

24. An organisation must protect personal data in its possession or under its control by making reasonable security arrangements to prevent —(a) unauthorised access, collection, use, disclosure, copying, modification or disposal, or similar risks; and (b) the loss of any storage medium or device on which personal data is stored.[40/2020]

Retention of personal data

s 25

25. An organisation must cease to retain its documents containing personal data, or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that —(a) the purpose for which that personal data was collected is no longer being served by retention of the personal data; and (b) retention is no longer necessary for legal or business purposes.

Transfer of personal data outside Singapore

s 26

26.—(1) An organisation must not transfer any personal data to a country or territory outside Singapore except in accordance with requirements prescribed under this Act to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under this Act.(2) The Commission may, on the application of any organisation, by written notice exempt the organisation from any requirement prescribed pursuant to subsection (1) in respect of any transfer of personal data by that organisation. (3) An exemption under subsection (2) —(a) may be granted subject to such conditions as the Commission may specify in writing; and (b) need not be published in the Gazette and may be revoked at any time by the Commission. (4) The Commission may at any time add to, vary or revoke any condition imposed under this section. —(1) An organisation must not transfer any personal data to a country or territory outside Singapore except in accordance with requirements prescribed under this Act to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under this Act. (2) The Commission may, on the application of any organisation, by written notice exempt the organisation from any requirement prescribed pursuant to subsection (1) in respect of any transfer of personal data by that organisation. (3) An exemption under subsection (2) —(a) may be granted subject to such conditions as the Commission may specify in writing; and (b) need not be published in the Gazette and may be revoked at any time by the Commission. (4) The Commission may at any time add to, vary or revoke any condition imposed under this section.

Back to Personal Data Protection Act 2012 — full text

Provisions on this page are reproduced verbatim from official open data. See the attribution line.

Source: Singapore Statutes Online (Attorney-General's Chambers), © Government of Singapore.