For Singaporean companies, a GDPR policy title might be "General Data Protection Policy (GDPR) & Personal Data Protection Act (PDPA) Compliance," describing how they protect EU and local data, covering consent, data use, security, and rights (access, deletion), with a core description emphasizing lawful processing, transparency, accountability, and data subject rights, often referencing both GDPR's stricter rules (explicit consent, broader scope) and the local PDPA (Singapore's primary law) for a unified approach, especially for those handling data for EU residents
For Singaporean companies, a GDPR policy title might be "General Data Protection Policy (GDPR) & Personal Data Protection Act (PDPA) Compliance," describing how they protect EU and local data, covering consent, data use, security, and rights (access, deletion), with a core description emphasizing lawful processing, transparency, accountability, and data subject rights, often referencing both GDPR's stricter rules (explicit consent, broader scope) and the local PDPA (Singapore's primary law) for a unified approach, especially for those handling data for EU residents
Policy Version: v1.0
Explains that the policy covers data processing under both the EU's GDPR (if offering goods/services to EU residents) and Singapore's PDPA (for all individuals in Singapore).
Details rights like access, correction, withdrawal of consent, and objection to processing (especially for direct marketing)
Emphasizes obtaining explicit, informed consent for data collection, usage, and disclosure.
States data is processed for specified, explicit, and legitimate purposes, citing GDPR's higher standards where applicable.
Commits to reasonable security measures and accountability for data handling, including mandatory breach notifications.
Addresses restrictions on transferring data outside Singapore or the EU.
Mentions retaining data only as long as necessary.