Personal Data Protection Department issues Public Consultation Paper on Proposed Amendments to the Personal Data Protection Regulations 2013

The Personal Data Protection Department (“JPDP”) issued its Public Consultation Paper No. 4/2025 (“PCP”) to gather feedback from the public on the proposed amendments to the Personal Data Protection Regulations 2013 (“PDP Regulations”).
 
The proposed amendments aim to align the PDP Regulations with recent amendments to the Personal Data Protection Act 2010 (“PDPA”) and to better address evolving personal data protection needs.
 
No. Proposed amendments
1. Amendments to existing definitions
  • The term “data user” to be replaced with “data controller”. 
  • The definition of “inspection officer” to be expanded to include the Deputy Commissioner and Assistant Commissioner, and employees engaged under section 51 of the PDPA, to provide greater flexibility in appointments and to strengthen enforcement. 
  • The definition of “standard1 to be amended by replacing “minimum requirements by the Commissioner” with “measures determined by the Commissioner”. This is to emphasise that the standards constitute binding rules rather than merely minimum requirements. The amendment further supports a shift towards a more outcome-based approach, providing organisations with greater flexibility in achieving data protection objectives. 
2. Introduction of new definitions
  • business contact information” – an individual’s name, position name or title, business telephone number, business address, business email address or business fax number and any other similar information about the individual, not provided by the individual solely for his or her personal purposes. 
  • personal data protection notice” – notice in writing that the data controller is required to provide to data subject in compliance with section 7 of the PDPA (Notice & Choice Principle). 
3. Further guidance on compliance with the Personal Data Protection Principles
  • Clearer guidance on procedures to be provided for obtaining valid consent, issuing notices to data subjects, and introducing consent verification mechanisms. 
  • Requiring data controllers to display the business contact information of the appointed Data Protection Officer or another individual responsible for handling matters related to the personal data processing through the personal data protection notice or other channels. 
  • Extending the obligation to develop and implement a security policy to data processors, which shall also include procedures for managing data breaches. 
  • Providing the minimum contractual clauses that must be included in agreements with data processors. 
4. Provisions on penalties
  • Broadening the scope of penalties by amending “subregulation 3(1)” to “subregulation 3” to cover all breaches of the General Principle under the said subregulation. 
  • Introducing a new provision that places direct liability on data processors, in line with the amendments to the PDPA which require data processors to also comply with the Security Principle. 
5. Enhanced inspection powers
  • Clarifying the scope of information that may be requested during inspections by expressly including “documents, records or other information relating to personal data processing”. 
  • Reinforcing the inspection obligations imposed on data processors, especially regarding the security policies that they are now required to develop and implement. 
 
Interested parties and members of the public may submit their views and feedback on the PCP to JPDP by 8 September 2025 via this link.
 
Alert by Jillian Chia (Head/Partner), Natalie Lim (Partner), and Charmayne Ong (Partner) of the Personal Data Protection Practice of Skrine.
 
 
 

1 Existing definition of “standard” – “minimum requirement issued by the Commissioner, that provides, for common and repeated use, rules, guidelines or characteristics for activities or their results, aimed at the achievement of the optimum degree of order in a given context.”

This article/alert contains general information only. It does not constitute legal advice nor an expression of legal opinion and should not be relied upon as such. For further information, kindly contact skrine@skrine.com.