Feeds

Singapore lures big biz with mega data protection regime

Citizens may get protection from telesales pests too...

Beginner's guide to SSL certificates

Singapore based data protection law specialist Rosemary Lee of Pinsent Masons, the law firm behind Out-Law.com, said the Personal Data Protection Bill (74-page/387KB PDF) being proposed by Singapore's government would establish a single data protection regime for the nation for the first time.

The draft legislation sets out rules for the collection, processing and storage of all personal data, whether in electronic or non-electronic form.

Companies based outside of Singapore would be required to observe the rules if they were collecting or processing personal data with a 'Singapore link'. Generally the information would be said to have that link if it is "located" in Singapore at the time it is collected, used or disclosed or if it is collected, used or disclosed in relation to a person based in the country. The scope of the legislation would therefore cover overseas organisations engaged in data collection activities online and collection of personal data from a person in Singapore.

The Bill includes provisions setting out individuals' right to access their personal data.

The Bill makes a distinction between 'data controllers' and 'data intermediaries' and places different responsibilities on those kind of organisations. The distinction means that whilst organisations in control of personal data would have to adhere to all of the draft provisions, the intermediaries concerned only with processing data on others' behalf would only have to comply with the various requirements around the safeguarding of that data.

Those safeguards include making "reasonable effort" to ensure personal data is kept accurately and "making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal or similar risks".

Because of the distinction, the task of obtaining consent from individuals - which is generally required in order for personal data processing to be legitimate under the terms of the Bill - would be the exclusive responsibility of data controllers and not those merely processing the information.

The reasons given for the distinction include the lack of effective control that organisations in the role of data processors may have over data in their possession; the potential competitive disadvantage that local hosting or cloud providers may be subject to without such a distinction; and having such a distinction is consistent with EU standards as well as internationally-accepted business practices, according to Singapore's Ministry of Information, Communications and the Arts (MICA) consultation paper on the new Bill.

Under the planned reforms a new Data Protection Commission would be set up and would have the power to issue fines to organisations of up to SIN$50,000 (about £25,000) for "wilfully" breaching the terms of the Bill in relation to the collection, use and disclosure of personal data. Individuals can be fined up to SIN$5,000 (about £2,500).

Individuals can be jailed and fined up to SIN$10,000 (about £5,000) if they either obstruct the Commission "in the performance of [its] duties or powers" or if the person "knowingly or recklessly makes a false statement to the Commission, or knowingly misleads or attempts to mislead the Commission, in the course of the performance of the duties or powers of the Commission". For the same offences organisations can be fined up to SIN$100,000 (about £50,000).

Plans have also been outlined to establish a 'do not call registry' in Singapore. The registry would allow Singapore citizens to opt out of receiving "specified messages" from marketers. Organisations would be required to check the registry within 30 days of sending messages and receive confirmation that the number is not listed before making the call. Companies that do not follow the protocol and send messages without authorisation can be fined up to SIN$10,000 (about £5,000).

"The Personal Data Protection Bill has been eagerly awaited and much anticipated in Singapore," Rosemary Lee said. "This is an important move which brings us on par with the more established data protection regimes already in place in the region, such as Australia, Hong Kong.”

“As a relatively late adopter of data protection laws, Singapore has sought to adopt a more comprehensive data protection regime using the data protection laws of key jurisdictions such as the EU, the UK, Hong Kong, Canada and New Zealand for reference," Lee said. "Adopting a comprehensive data protection regime will definitely help to reinforce Singapore’s position as a trusted hub for businesses, by creating a conducive environment for the fast growing global data processing and data management industries (such as cloud computing) in Singapore."

MICA published the Bill on Monday and has opened a consultation in a bid to obtain feedback from industry.

MICA intends to put the draft legislation to Parliament in the third quarter of 2012. If the Bill is passed the Personal Data Protection Act would be enacted but would not actually come into force for 18 months. This has been arranged to allow organisations sufficient time to put in place the necessary measures to comply with the Act.

Plans to reform the data protection regime in the EU were outlined in January. The plans have been criticised as "unworkable" by UK business body the Confederation of British Industry.

Copyright © 2012, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

Choosing a cloud hosting partner with confidence

More from The Register

next story
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Yes, yes, Steve Jobs. Look what I'VE done for you lately – Tim Cook
New iPhone biz baron points to Apple's (his) greatest successes
Lords take revenge on REVENGE PORN publishers
Jilted Johns and Jennies with busy fingers face two years inside
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.