July 12, 2018
What You Need To Know About Data Protection Officers
Did you know that the recent Personal Data Protection Act (PDPA) 2017 annual industry survey findings have highlighted that there are still a significant number of organisations who are not sufficiently aware of their responsibilities under the PDPA[1]? In light of these results, the watchdog has been reaching out to increase awareness and compliance with the PDPA.
The Role of a Data Protection Officer (DPO)
To ensure that organisations in Singapore are on the correct path, it is mandatory under the PDPA to appoint a Data Protection Officer (DPO)[2]. The DPO oversees an organisation’s data protection responsibilities and ensures compliance with the PDPA. Organisations are free to decide (according to their size and needs), whether the DPO function should be a dedicated responsibility or an additional function within an existing role in the organisation.
The DPO’s responsibilities include:
Practicing Good Data Protection Habits
Good data protection habits should be practiced by everyone, not just the DPO. Human Resource (HR) employees within an organisation are often targets of criminals as they are the keepers of personal data. HR employees should be diligent and store physical data correctly and securely. This can be done by storing confidential physical documents in a lockable cabinet that is only accessible authorised persons.
A reporter form Yahoo News Singapore last year wrote about the wealth of confidential information available to the public through carelessly disposed of paper documents[5]. Sensitive information such as NRIC numbers, work permits and photocopies of passports can be easily mined with dire consequences such as identity theft. Organisations can reduce the risk of a physical data breach by implementing simple security policies such as:
Having a DPO and practicing good data protection habits work hand in hand in reducing the risk of data breaches. Fostering a good data protection culture also reaps the benefits of enhanced trust and goodwill with existing and potential customers.
Start Protecting Your Business
To learn more about how Shred-it can protect your documents and hard drives, please contact us for a free quote and security risk assessment.
[1]PDPC. 2017. 2017 Industry Survey on the Personal Data Protection Act (PDPA). [ONLINE] Available at: https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Resource-for-General/Industry-Survey-2017.pdf. [Accessed 9 February 2018]
[2]PDPC. 2017. Data Protection Officers. [ONLINE] Available at: https://www.pdpc.gov.sg/Organisations/Data-Protection-Officers. [Accessed 9 February 2018]
[3]PDPC. 2017. Data Protection Officers. [ONLINE] Available at: https://www.pdpc.gov.sg/Organisations/Data-Protection-Officers. [Accessed 9 February 2018]
[4]Singapore Legal Advice. 2017. Appointing a Data Protection Officer For Your Business: All You Need to Know. [ONLINE] Available at: https://singaporelegaladvice.com/law-articles/data-protection-officer. [Accessed 14 February 2018]
[5]Yahoo News Singapore. 2017. Careless disposal of paper documents can have serious consequences: experts. [ONLINE] Available at: https://sg.news.yahoo.com/careless-disposal-paper-documents-can-serious-consequences-experts-084457678.html. [Accessed 14 February 2018]