9/18/2019 Singapore | Global Network Initiative However, section 4(1)(c) of the PDPA states the restrictions on use, collection and disclosure of personal data does not impose any obligation on a public agency or organisation if acting as such. This would include the government, its ministries or state, tribunal or statutory bodies. Furthermore, the collection, use or disclosure of personal data without consent is permitted if necessary in the national interest or for any investigation or proceedings, (and if in relation to collection, such collection without consent is limited to if it is reasonable to expect that seeking the consent of the individual would compromise the availability or the accuracy of the personal data). These appear as some of the exceptions under the Second, Third and Fourth Schedules of the PDPA. Under the Fourth Schedule of the PDPA, disclosure without consent of an individual is also permitted if, requested in writing as, necessary for the functions of an officer of a law enforcement agency. As such, the provisions of the PDPA cannot generally be relied on to avoid obligations to disclose personal data to government authorities. (b) RETENTION OF DATA Telco Operators who hold a Service Based Operator (“SBO”) or Facility Based Operator (“FBO”) licenses regulated by the IMDA and who provide certain services are required – under the applicable license conditions – to keep a register of their subscriber details including their name, address, date of birth and nationality. In the case of FBO License holders this covers subscribers of IP telephony services; as far as SBO license holders are concerned the relevant services include IP telephony services, satellite mobile telephone and data services, mobile virtual network operations, and voice and data services which mask call line identity. In either case the relevant license holder will also be required to keep subscribers’ call detail records for a period of at least 12 months. The PDPA also sets out a retention obligation which states when an organisation has to cease to retain personal data of individuals or remove the means by which the personal data can be associated with particular individuals (section 25 PDPA). This must occur as soon as it reasonably practical after the purpose for collecting that data has become obsolete. As each organisation is different, the PDPA does not specify a fixed duration of time for which an organisation can legitimately retain personal data. The PDPC explain, in their Advisory Guidelines on Key Concepts in the PDPA (“the PDPA https://clfr.globalnetworkinitiative.org/country/singapore/ 6/13

Select target paragraph3