Does the PDPA apply to foreign companies?
Yes. It applies to organisations that collect, use or disclose personal data in Singapore, wherever they are incorporated.
Is a Data Protection Officer mandatory for small companies?
Yes. Every organisation must designate at least one person responsible for PDPA compliance and make their business contact information available.
When must a data breach be reported?
Once you assess that a breach is notifiable, because it is likely to cause significant harm or affects 500 or more individuals, you must notify the PDPC within 3 calendar days.
How does the PDPA treat AI systems?
The PDPC’s advisory guidelines explain how personal data can be used to develop and deploy AI recommendation and decision systems, including consent, exceptions and transparency to users.
Is this legal advice?
No. Stratgik is a technology firm. We implement the processes and controls in your systems and work alongside your lawyers for legal opinions.
Are prices fixed?
Yes, for organisations with one website or app and up to five systems holding personal data. Larger scope is quoted in writing first. GST is added where applicable.