PDPASG-1 | Accountability, Records, DPO Appointment, and Training | 43 |
PDPASG-2 | Notification, Consent, Purpose Limitation, and Lawful Basis | 42 |
PDPASG-3 | Access, Correction, Data Portability, and Individual Rights | 25 |
PDPASG-4 | Children's Data, DPIA, and Privacy by Design | 71 |
PDPASG-5 | Protection, Accuracy, and Security of Personal Data | 89 |
PDPASG-6 | Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight | 27 |
PDPASG-7 | Retention Limitation, Do Not Call, Compliance, Complaints | 22 |
PDPASG-8 | Data Breach Notification, Incident Response, and Enforcement | 58 |
1-3 | Short title, interpretation and purpose | 0 |
11 | Reasonable-person standard, responsibility for personal data and designation of a data protection officer | 0 |
12 | Policies, complaints process, staff communication and information on request | 0 |
13-14 | Consent required, and what counts as consent | 0 |
15 | Deemed consent by conduct and by contractual necessity | 0 |
15A | Deemed consent by notification | 0 |
16 | Withdrawal of consent | 0 |
17 | Collection, use and disclosure without consent: the First and Second Schedule exceptions | 0 |
18 | Purpose limitation | 0 |
19 | Personal data collected before the appointed day | 0 |
20 | Notification of purposes | 0 |
21 | Access to personal data | 0 |
22 | Correction of personal data | 0 |
22A | Preservation of personal data after an access refusal | 0 |
23 | Accuracy of personal data | 0 |
24 | Protection of personal data | 0 |
25 | Retention limitation | 0 |
26 | Transfer of personal data outside Singapore | 0 |
26A-26B | Data breaches and notifiable data breaches | 0 |
26C | Duty to assess a data breach, and the data intermediary's duty to notify the organisation | 0 |
26D | Duty to notify the Commission within 3 calendar days and affected individuals | 0 |
27-35 | Enforcement of the data protection provisions: mediation, review, directions, undertakings, private action, the Appeal Panel | 0 |
36-42 | The Do Not Call Registry | 0 |
4 | Application of the Act | 0 |
43 | Do Not Call: duty to check the register before sending specified messages | 0 |
44-45 | Do Not Call: sender identification, contact information and calling line identity | 0 |
48G-48L | Review, directions, financial penalties and other enforcement | 0 |
5-10 | The Personal Data Protection Commission | 0 |
6B | Part 6B: data portability (enacted 2020, not in force) | 0 |
9A | Part 9A: dictionary attacks and address-harvesting software | 0 |
9B | Part 9B: offences affecting personal data and anonymised information | 0 |
REGS | Regulations and PDPC advisory guidelines | 0 |