[HEADER — replace with your organisation’s letterhead, if used]
Personal Data Protection Policy
[COMPANY NAME]
Appointing at least one Data Protection Officer is mandatory, and the officer’s business contact information must be made available to the public. Data breach notification has been mandatory since 2021. A policy that describes principles without naming an officer, without a breach procedure and without a retention schedule addresses none of the three things most likely to be asked about.
| Item | Detail |
|---|
| Organisation | [COMPANY NAME], UEN [UEN] |
| Data Protection Officer | [NAME], [DESIGNATION] |
| DPO contact — published | [EMAIL], [PHONE], [POSTAL ADDRESS] |
| Deputy or alternate DPO | [NAME], [EMAIL] |
| Approved by | [NAME], [DESIGNATION], on [DATE] |
| Effective from | [DATE] |
| Applies to | All employees, contractors and anyone handling personal data for the Company |
| Review | Annually, and on any material change to processing |
1. Scope
1.1This policy applies to all personal data the Company collects, uses, discloses or cares for, whether about customers, employees, job applicants, suppliers, visitors or any other individual.
1.2"Personal data" means data about an individual who can be identified from that data, or from that data and other information the Company has or is likely to have access to, whether or not the data is true.
1.3This policy applies to data in any form, including electronic records, paper records, images, recordings and data held by third parties on the Company’s behalf.
2. The Obligations
| Obligation | What it requires of us |
|---|
| Consent | Collect, use or disclose personal data only with consent, or where an exception applies. Consent must be given voluntarily and cannot be a condition of a service beyond what is reasonable |
| Purpose limitation | Only for purposes a reasonable person would consider appropriate, and that have been notified |
| Notification | Inform the individual of the purposes before or at collection |
| Access | On request, provide the personal data held and information on how it has been used or disclosed |
| Correction | On request, correct an error or omission, and send the correction to organisations the data was disclosed to |
| Accuracy | Make reasonable effort to ensure data is accurate and complete where it will be used to make a decision affecting the individual or disclosed |
| Protection | Make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal |
| Retention limitation | Cease to retain data when the purpose has ended and retention is no longer necessary for legal or business purposes |
| Transfer limitation | Transfer outside Singapore only where the recipient is bound by a comparable standard of protection |
| Accountability | Appoint a Data Protection Officer, publish their contact, implement policies and practices, and be able to demonstrate compliance |
| Data breach notification | Assess and, where the threshold is met, notify the Commission and affected individuals |
| Data portability | Where in force, transmit specified data to another organisation at the individual’s request |