dotlah! dotlah!
  • Cities
  • Technology
  • Business
  • Politics
  • Society
  • Science
  • About
Social Links
  • zedreviews.com
  • citi.io
  • aster.cloud
  • liwaiwai.com
  • guzz.co.uk
  • atinatin.com
0 Likes
0 Followers
0 Subscribers
dotlah!
  • Cities
  • Technology
  • Business
  • Politics
  • Society
  • Science
  • About
  • Technology

Mastering The ‘Must-Dos’ Of Data Protection

  • November 3, 2021
Total
0
Shares
0
0
0

With online experiences full of ads and sponsored posts vying for our attention, businesses are turning to data analytics to gain an edge and win the attention of consumers. Spanning both physical and virtual business decisions, data has become the world’s most valuable resource—more so than oil. Each tap, swipe and purchase allows companies to collect data that can help improve business. But how can we be sure that our data is kept safe?

In 2012, Singapore put into place the Personal Data Protection Act (PDPA) to regulate the collection, use and disclosure of personal data. Earlier this year, the amended PDPA took effect, addressing the Republic’s evolving digital economy needs and providing guidelines for both consumers and businesses in better protecting personal data.

To help businesses stay accountable and updated with the changes, the Personal Data Protection Commission (PDPC) refreshed the content of two existing guides on data protection to align with the amendments to the PDPA and support businesses in implementing personal data protection policies and processes.

The first guide aims to help organisations develop or improve practices in accountability through the implementation of a Data Protection Management Programme (DPMP), while the other provides an introductory outline on how to address specific personal data protection risks through conducting a Data Protection Impact Assessment (DPIA) for their systems and processes.

DPMP screenshot 1
The four steps of the Guide to Developing A Data Protection Management Programme cover different facets of data protection for a robust system.

Setting up a culture of accountability

Accountability is an overarching principle in the PDPA. To demonstrate accountability, organisations must develop policies, inform and communicate to staff about these policies and appoint a data protection officer (DPO) who ensures that the implemented policies are in compliance with the PDPA. The DPMP encompasses these strategies and guides organisations as they seek to effectively protect data through a four-step framework that they can tailor-fit to better suit their unique contexts.

The first of four steps, ‘Governance and Risk Assessment’, emphasises how management can champion personal data protection.

While personal data may be shared between departments and teams when required, the organisational policies will ensure that all customer data is used in compliance with the PDPA. Additionally, a culture of accountability can trickle down from leaders to staff through company-wide training or regular risk assessments to identify risks like new initiatives or policies that might not comply with PDPA.

In the ‘Policy and Practices’ step, businesses will be asked to consider some general questions to guide their policy implementation. By putting in place clear practices, organisations will also be able to clearly communicate these policies to internal stakeholders like staff and external parties like vendors and customers.

DPMP screenshot 2
The DPMP takes businesses through the steps of deciding whether or not they should implement policies depending on who such policies apply to.

To help organisations design policies, the DPMP guides the organisation through questions such as the data types to be protected and the appropriate level of protection. This section also includes detailed examples, with a proposed situation and recommendations so that companies are aware of the different facets they might need to consider.

Continuous security improvement

The work of securing data does not, however, stop at the creation of new practices and policies. In the ‘Processes’ section, risks identified in the previous section form the basis of checklists and data inventories. It also suggests other mechanisms to safely collect and store data and make data breach reporting easier.

To help establish a clear process for handling data breaches, the guide conveniently provides a handy acronym: CARE, which represents Containing the breach, Assessing the risk, Reporting the incident and Evaluating the response and recovery to prevent future breaches.

DPMP Screenshot 3
The acronym CARE is used to help companies recall the step-by-step approach needed to manage potential data breaches.

The last step, ‘Maintenance’, encourages businesses to regularly review their data protection policies and processes. Instead of only reviewing policies when there is a breach, the PDPC recommends regular audits, reviews and revisions.

All in all, understanding how each step applies in the business context could go a long way towards actively helping organisations protect against data breaches and other risks. With the DPMP guide, organisations can establish robust personal data protection infrastructure with ease. For a more comprehensive guide on managing data breaches, the PDPC also has a Guide on Managing and Notifying Data Breaches Under the PDPA with more detailed information.

You can never be too secure

The PDPC’s DPIA guide goes hand in hand with the DPMP manual by providing businesses with a simple, six-step process for auditing data protection policies and determining risks.

Before beginning, businesses must assess the initial need for a DPIA. Next, the company should plan a DPIA by identifying parameters like scope, frameworks, parties involved and timeline. After developing a plan, map out the flow of relevant personal data involved in the project or policy to be audited. To fully illustrate the point, the guide offers an example of a website administrator who led a DPIA by consulting various departments about how they will access, use and store the collected data from a project.

DPIA Screenshot 1
The Data Life Cycle maps out the six phases involved in a DPIA.

Data protection risks should then be identified by comparing the project against PDPA requirements, and other specific analyses of potential gaps, especially so if there are new changes, be it strategic, operational or relating to their business structure. Finally, businesses can use the insights gathered to develop and implement an action plan and later evaluate the outcome.

Ultimately, there is no one-size-fits-all solution for every company but if businesses follow both the DPMP and DPIA as well as tailor data protection plans to their unique needs, they can be assured of PDPA compliance—while consumers can be assured that their personal data is kept safe.


To find out more about the PDPC and personal data accountability, click here. Meanwhile, view and download the two comprehensive guides through these links:

  • Data Protection Management Programme (DPMP) guide
  • Data Protection Impact Assessment (DPIA) guide

 

 

By Izo Lopez
Source IMDA

Total
0
Shares
Share
Tweet
Share
Share
Related Topics
  • Data Protection
  • IMDA
  • PDPA
  • PDPC
  • Personal Data Protection Act
  • Personal Data Protection Commission
dotlah.com

Previous Article
  • Cities
  • Lah!

9.6km Of New Cycling Paths In Taman Jurong And Tampines

  • November 3, 2021
View Post
Next Article
  • Lah!
  • Technology

Why Biomanufacturing 4.0 Is A Game-Changer

  • November 3, 2021
View Post
You May Also Like
View Post
  • People
  • Technology

This is what the new frontier of AI-powered financial inclusion looks like

  • dotlah.com
  • January 2, 2026
View Post
  • Artificial Intelligence
  • Technology

How AI can accelerate the energy transition, rather than compete with it

  • dotlah.com
  • November 19, 2025
View Post
  • Gears
  • Technology

Apple Vision Pro upgraded with the powerful M5 chip and comfortable Dual Knit Band

  • Dean Marc
  • October 15, 2025
View Post
  • Gears
  • Technology

Meet Samsung Galaxy Tab S11 Series: Packing Everything You Expect From a Premium Tablet

  • Dean Marc
  • September 4, 2025
View Post
  • Technology

Malaysia’s ‘ASEAN Shenzhen’ needs some significant legal reform to take off — here’s how

  • dotlah.com
  • August 25, 2025
View Post
  • Gears
  • Technology

Samsung Electronics Debuts Odyssey G7 Monitors, Showcasing Top Games on Its Displays at Gamescom 2025

  • Dean Marc
  • August 20, 2025
View Post
  • Artificial Intelligence
  • Technology

Thoughts on America’s AI Action Plan

  • Dean Marc
  • July 24, 2025
View Post
  • Technology

ESWIN Computing launches the EBC77 Series Single Board Computer with Ubuntu

  • dotlah.com
  • July 17, 2025


Trending
  • 1
    • Cities
    • Climate Change
    • People
    • Politics
    The World’s Top Cities Face Stiff Competition, Here’s Why
    • February 6, 2020
  • 2
    • Science
    • Technology
    One-Hour Antibody Test Tracks Neutralising Antibodies Of COVID-19
    • May 19, 2020
  • 3
    • Technology
    Total, ETH Zurich Join Forces To Convert CO2 And Hydrogen Into Methanol
    • August 16, 2019
  • city-london-andres-garcia-y_m-ivYJd94-unsplash 4
    • Cities
    • People
    5 Advantages Cities Have Over Rural Living
    • September 23, 2021
  • 5
    • Technology
    Singapore Renews MOU On Cybersecurity Cooperation With Australia
    • March 24, 2020
  • turkey-syria-earthquake 6
    • Features
    • People
    • World Events
    Where You Can Donate To Help Turkey & Syria Earthquake Victims
    • February 11, 2023
  • 7
    • Cities
    • Lah!
    Sembcorp Opens Singapore’s First Solar-Powered EV Charging Hub
    • July 20, 2021
  • living-room-outsite-co-R-LK3sqLiBw-unsplash 8
    • Cities
    Useful Tips To Help You Properly Maintain Your Home
    • November 16, 2021
  • 9
    • Cities
    Coronavirus Hasn’t Killed The City. Here’s Why
    • September 16, 2020
  • 10
    • Lah!
    • Technology
    Leveraging AI For Better Hiring Practices
    • January 19, 2021
  • 11
    • People
    • Science
    • Technology
    Nobel prize in physics awarded for work unveiling the secrets of electrons
    • October 4, 2023
  • 12
    • Cities
    DBS And ComfortDelgro Taxi Announce Strategic Payments Partnership
    • June 27, 2020
Trending
  • 1
    New research may help scientists predict when a humid heat wave will break
    • January 6, 2026
  • 2
    This is what the new frontier of AI-powered financial inclusion looks like
    • January 2, 2026
  • 3
    How bus stops and bike lanes can make or break your festive city trip
    • December 29, 2025
  • 4
    Skills development is critical to bridging the global digital talent gap
    • December 22, 2025
  • Tech Not To Miss 5
    Zed Approves | 12 Cool Tech You’ll Regret Missing
    • December 21, 2025
  • zedreviews-12-gaming-holiday-deals-202512 6
    Zed Approves | 12 Gaming Upgrades You Actually Need This Holiday Season
    • December 17, 2025
  • zedreviews-amazon-uk-50-christmas-deals 7
    Zed Approves | The Amazon 50+ Holiday Gift Deals Worth Buying – UK Edition
    • December 14, 2025
  • Watches 8
    Zed Approves | 12 Watch Gifts for the Holiday Season
    • December 14, 2025
  • 6 Bags You Might Be Missing for Your Next Trip 9
    Zed Approves | 6 Bags You Might Be Missing for Your Next Trip
    • December 2, 2025
  • Zed Approves | 48 Highly Rated Black Friday Deals in 2025 10
    Zed Approves | 48 Highly Rated Black Friday Deals in 2025
    • November 28, 2025
Social Links
dotlah! dotlah!
  • Cities
  • Technology
  • Business
  • Politics
  • Society
  • Science
  • About
Connecting Dots Across Asia's Tech and Urban Landscape

Input your search keywords and press Enter.