Singapore’s Personal Data Protection Commission Publishes Consultation Paper
Time 3 Minute Read
Categories: International

On February 5, 2013, Singapore’s new data protection agency, the Personal Data Protection Commission, published its first consultation paper (the “Paper”) articulating proposals for a data protection regulation. The Paper outlines the Commission’s positions on three key issues: (1) requests for access and correction; (2) transfer of personal data outside of Singapore; and (3) individuals who may act for others under the Personal Data Protection Act (“PDPA”). The PDPA was passed by the Singapore Parliament in October 2012 and became law in January 2013.

Access and Correction

The Paper outlines the rights of individuals and the responsibilities of organizations with respect to access and correction. It notes that the PDPA allows organizations to charge a reasonable fee for individual access to information and discusses the parameters for such fees, but stops short of establishing a maximum charge. The Commission seeks comments on the manner in which individuals might make access requests and how organizations might respond to such requests.

Transfer of Personal Data Outside of Singapore

The PDPA allows data to be transferred outside of Singapore only if the receiving organization can protect the data in a manner that is comparable to what is required in Singapore. The Paper suggests this may be accomplished through use of a legally binding instrument such as binding corporate rules or contractual clauses, provided the legal instrument implements obligations that address purpose, use, disclosure, accuracy, protection and retention. The Commission requests comments on both the means for assuring protection for data transferred outside Singapore and possible requirements for the binding legal instruments.

Individuals Who May Act for Others

The PDPA allows authorized individuals to act on behalf of others to exercise personal data protection rights. The Paper suggests that minors who are 18 – 21 years old be able to act on their own behalf, and minors who are 14 – 18 years old be able to act on their own behalf if they understand the consequences of exercising their rights. Commenters are asked to provide thoughts on whether there should be a minimum age requirement.

The Paper also discusses acting on behalf of a deceased person, indicating that if the deceased individual did not appoint a personal representative, the individual’s closest relative should be able to act on his or her behalf. The Paper suggests a ranking order for relatives in that scenario.

Comments on the Paper are due by March 19, 2013, and may be emailed to pdpc_consultation@pdpc.gov.sg.

You May Also Be Interested In

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On January 30, 2026, the Cybersecurity Administration of China released a Q&A document on policies and regulations for the security management of cross-border data transfers. 

Time 1 Minute Read

On January 26, 2026, the Brazilian data protection authority (“ANPD”) announced that Brazil and the European Union agreed to mutually recognize the adequacy of each other’s data protection networks.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page