9/18/2019
Singapore | Global Network Initiative
However, section 4(1)(c) of the PDPA states the restrictions on use, collection
and disclosure of personal data does not impose any obligation on a public
agency or organisation if acting as such. This would include the government,
its ministries or state, tribunal or statutory bodies.
Furthermore, the collection, use or disclosure of personal data without consent
is permitted if necessary in the national interest or for any investigation or
proceedings, (and if in relation to collection, such collection without consent is
limited to if it is reasonable to expect that seeking the consent of the individual
would compromise the availability or the accuracy of the personal data). These
appear as some of the exceptions under the Second, Third and Fourth
Schedules of the PDPA. Under the Fourth Schedule of the PDPA, disclosure
without consent of an individual is also permitted if, requested in writing as,
necessary for the functions of an officer of a law enforcement agency. As such,
the provisions of the PDPA cannot generally be relied on to avoid obligations to
disclose personal data to government authorities.
(b) RETENTION OF DATA
Telco Operators who hold a Service Based Operator (“SBO”) or Facility Based
Operator (“FBO”) licenses regulated by the IMDA and who provide certain
services are required – under the applicable license conditions – to keep a
register of their subscriber details including their name, address, date of birth
and nationality. In the case of FBO License holders this covers subscribers of IP
telephony services; as far as SBO license holders are concerned the relevant
services include IP telephony services, satellite mobile telephone and data
services, mobile virtual network operations, and voice and data services which
mask call line identity. In either case the relevant license holder will also be
required to keep subscribers’ call detail records for a period of at least 12
months.
The PDPA also sets out a retention obligation which states when an
organisation has to cease to retain personal data of individuals or remove the
means by which the personal data can be associated with particular
individuals (section 25 PDPA). This must occur as soon as it reasonably
practical after the purpose for collecting that data has become obsolete.
As each organisation is different, the PDPA does not specify a fixed duration of
time for which an organisation can legitimately retain personal data. The PDPC
explain, in their Advisory Guidelines on Key Concepts in the PDPA (“the PDPA
https://clfr.globalnetworkinitiative.org/country/singapore/
6/13