| No. |
Proposed amendments |
| 1. |
Amendments to existing definitions
- The term “data user” to be replaced with “data controller”.
- The definition of “inspection officer” to be expanded to include the Deputy Commissioner and Assistant Commissioner, and employees engaged under section 51 of the PDPA, to provide greater flexibility in appointments and to strengthen enforcement.
- The definition of “standard”1 to be amended by replacing “minimum requirements by the Commissioner” with “measures determined by the Commissioner”. This is to emphasise that the standards constitute binding rules rather than merely minimum requirements. The amendment further supports a shift towards a more outcome-based approach, providing organisations with greater flexibility in achieving data protection objectives.
|
| 2. |
Introduction of new definitions
- “business contact information” – an individual’s name, position name or title, business telephone number, business address, business email address or business fax number and any other similar information about the individual, not provided by the individual solely for his or her personal purposes.
- “personal data protection notice” – notice in writing that the data controller is required to provide to data subject in compliance with section 7 of the PDPA (Notice & Choice Principle).
|
| 3. |
Further guidance on compliance with the Personal Data Protection Principles
- Clearer guidance on procedures to be provided for obtaining valid consent, issuing notices to data subjects, and introducing consent verification mechanisms.
- Requiring data controllers to display the business contact information of the appointed Data Protection Officer or another individual responsible for handling matters related to the personal data processing through the personal data protection notice or other channels.
- Extending the obligation to develop and implement a security policy to data processors, which shall also include procedures for managing data breaches.
- Providing the minimum contractual clauses that must be included in agreements with data processors.
|
| 4. |
Provisions on penalties
- Broadening the scope of penalties by amending “subregulation 3(1)” to “subregulation 3” to cover all breaches of the General Principle under the said subregulation.
- Introducing a new provision that places direct liability on data processors, in line with the amendments to the PDPA which require data processors to also comply with the Security Principle.
|
| 5. |
Enhanced inspection powers
- Clarifying the scope of information that may be requested during inspections by expressly including “documents, records or other information relating to personal data processing”.
- Reinforcing the inspection obligations imposed on data processors, especially regarding the security policies that they are now required to develop and implement.
|