Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Deemed Consent PDPA: How Do Businesses Comply?

Deemed Consent PDPA
PDPA came into force, businesses are now required to obtain their customers’ deemed consent PDPA before collecting, using, and/or disclosing their personal data.

Deemed Consent PDPA: How Do Businesses Comply?

Since the Personal Data Protection Act (PDPA) came into force, businesses are now required to obtain their customers’ deemed consent PDPA before collecting, using and/or disclosing their personal data.

This article will summarise the main requirements in order for your business to remain compliant with this obligation.

What is Personal Data?

Personal data means any information about a customer that is likely to allow you to identify that customer. If your business wants to collect, use and/or disclose such information, you need your customers’ deemed consent PDPA to do so.

Have your customers given Deemed Consent PDPA for a specific purpose?

The safest way is to ask for it by having the customer sign or otherwise acknowledge a notice giving you deemed consent PDPA to collect, use and/or disclose their data for a particular purpose.

If you routinely collect data from customers via an online or physical form, it should contain a notice stating that by submitting the form, the customer deemed consent PDPA to the collection, use and/or disclosure of his personal data for whatever specific purpose the completion of the form has.

The deemed consent PDPA given is limited to the collection, use and/or disclosure of the personal data only for the purposes stated in the notice.

Can I use the customer’s deemed consent PDPA for other purposes not specified in the notice?

The deemed consent PDPA given is limited to the collection, use and/or disclosure of the personal data only for the purposes stated in the notice.

Also read: 7 Client Data Protection Tips to Keep Customers Safe

Can I, in the notice, refuse to sell a product/service if customers do not provide their personal data or give Deemed Consent PDPA for additional purposes?

You cannot insist that customers provide you with their personal data and allow you to collect, use or disclose it for any purpose other than as necessary to provide them with the product or service they are purchasing.

Nor can you refuse to provide the product or service to customers if they do not give their deemed consent PDPA for such additional uses.

For example, if your business is an online hat shop selling hats for home delivery, you can insist that your customers provide you with their delivery address, and refuse to sell them a hat if they don’t, but only for the purpose of processing their payment and delivering the hat to their address.

You cannot insist that they also provide their email address and telephone number so that you can contact them with hat-related promotional information and refuse to sell them a hat if they withhold their consent for the use of their personal data in this way.

The implications of this law on your online form is that you can include a line saying, for example:

“By clicking SUBMIT, you agree to our collection, use and/or disclosure of your personal data to the extent necessary to process your order and provide you with this product.”

However, if you want to be able to send promotional material to your customers, you have to include a tickbox which they can choose to select or deselect, to give their consent for the collection, use or disclosure of their personal data in this way.

If your business wants to collect, use and/or disclose such information, you need your customers’ deemed consent PDPA to do so.

Do We Always have to Obtain Our Customer’s Consent?

No, but it’s safer if you do.

However, under section 15 of the PDPA, a customer who has voluntarily provided his personal data for a particular purpose in circumstances where it was reasonable for him to do so will be deemed to have consented to its collection, use or disclosure for that purpose.

If your business relies heavily on the collection, use or disclosure of personal data in a context where it may be impracticable for you to obtain consent from each and every customer to do so, you should speak to a lawyer with expertise in privacy or data protection law.

There is a long list of very specific exceptions that may apply to the way your business collects, uses or discloses data, but you should be sure that you can legally justify your business practices by references to the PDPA before deciding not to obtain consent from your customers.

Can Customer Consent be Withdrawn?

Yes. You cannot obtain an irrevocable consent from a customer.

A customer can write to you at any time to indicate that he no longer wishes you to collect, use or disclose his personal data. If he does, you should write back to explain what consequences will ensue if you comply with his request.

If he confirms his instruction, you should then delete his personal data and ensure that any other companies who were taking instructions from you with respect to his data do the same. A common automated example of this is a customer unsubscribing from an email newsletter mailing list.

How Should We Draft a Notice for Consent?

The Personal Data Protection Commission (PDPC) has a handy template for drafting a notice for consent.

What Happens If We Do Not Comply with the PDPA Requirements for Consent?

If you don’t comply with the legal requirements discussed in this article, your business could face a fine of up to S$1 million.

The PDPC may also order you to delete data, provide it to a third-party, or stop you from using the data.

In short, it is easier to take a few simple steps to ensure compliance with the law than risk running afoul of it.

Also read: 12 brief explanation about the benefits of data protection for business success

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us