首先你需搞清楚什么样的data才是被包括在这项条例。。通常,这类data是与个人身份有关的data, 如NRIC,电话号码,地址等。再来就是个人/商业财产与交易内容。。
What kind of data is covered?
Three conditions must be fulfilled in order for any data to be considered as ‘personal data’ within the ambit of the PDP Act.
Firstly, the data must be in respect of commercial transactions. ‘Commercial transactions’ is defined under the PDP Act as transactions of a commercial nature, whether contractual or not, and includes any matter relating to the supply or exchange of goods or services, agency, investments, financing, banking and insurance.
Secondly, such information must:
(i) be processed by means of equipment operating automatically in response to instructions given for that purpose; (ii) be recorded with the intention that it should be processed by such equipment; or (iii) be recorded as part of, or with the intention that it should form a part of a relevant filing system.
Thirdly, the information must relate directly or indirectly to a data subject who is identifiable from the information or other information in the possession of the data user.
The definition of ‘personal data’ appears to be sufficiently wide to cover the usual types of personal information collected in day to day transactions i.e. name, address, telephone number, email address, banking details and identification card numbers. Such data are also generally collected in most commercial transactions such as when purchasing items off the internet, subscribing for telecommunications services or registering to be a member of a website. Therefore upon the implementation of the PDP Act the use, processing and disclosure of such personal data will be regulated.
The PDP Act does not apply to information processed for the purpose of a credit reporting business carried on by a credit reporting agency under the Credit Reporting Agencies Act 2010 as the processing of such information has been specifically excluded from the definition of personal data under the PDP Act. |