1) Overview
1.1) Purpose
The purpose of this policy is to set out New POS Network(S) Pte Ltd's (“the Company”) procedures on protection of personal data of individuals in the Company’s custody. It contains important information about how and why the Company collects, uses and discloses personal data of individuals. This policy takes into consideration the Personal Data Protection Act 2012 (“PDPA”) and all applicable PDPA advisory guidelines.
2) Personal Data Protection Act 2012
2.1) The PDPA establishes a data protection law in Singapore that comprises various rules governing the collection, use, disclosure, access to, correction and care of individuals’ personal data by organisations. It recognises both the rights of individuals to protect their personal data, including rights of access and correction, and the needs of organisations to collect, use or disclose personal data for legitimate and reasonable purposes.
2.2) The PDPA contains 2 main sets of provisions, covering data protection (effective 2 July 2014) and a Do Not Call (“DNC”) Registry (effective 2 January 2014).
2.3) The DNC provisions generally prohibit organisations from sending certain marketing messages (in the form of voice calls, text or fax messages) to individuals with Singapore telephone numbers registered with the DNC Registry.
2.4) The Company intends to comply with all applicable provisions covering data protection by implementing certain procedures as set out in this policy.
3) Definitions
3.1) Personal Data
Personal data refers to data, whether true or not, about an individual who can be identified from that data; or from that data and other information to which the organisation has or is likely to have access to.
This includes unique identifiers (e.g. NRIC number, passport number, fingerprint); as well as any set of data (e.g. name, age, address, telephone number, occupation, etc) which when taken together would be able to identify the individual.
3.2) Data Protection Officer
Data Protection Officer (“DPO”) means an individual designated by the organisation under Section 11(3) of the Personal Data Protection Act 2012 (“Act”) who is responsible for ensuring that the organisation complies with this Act or an individual to whom the responsibility of the data protection officer has been delegated under section 11(4) of the Act.
4) The Company’s Personal Data Inventory
4.1) The Company has the following personal data in its custody:
Employees: The Company collects personal data of its employees including but not limited to name, address, telephone numbers, e-mail address, NRIC number, passport number, FIN (Foreign Identification Number), date and place of birth, nationality, gender, resume, education background, employment history etc. in connection with the employees’ employment or job applications with the Company.
Customers - Individuals: The Company has in custody personal data of individuals who (i) have made online purchases via any of the platforms operated by the Company; and/or (ii) have consented to companies (“Transferring Companies”) to send them marketing messages, where such Transferring Companies contract with the Company as an outsourced service provider to send marketing messages to such individuals. Such personal data include but are not limited to name, address, mobile and telephone numbers, e-mail address, NRIC number, passport number, FIN, date and place of birth, nationality, gender, education background, etc.
Customers - Copies of identity papers of directors and/or authorised signatories of our corporate clients: The Company is required to comply with all applicable anti-money laundering and countering financing of terrorism (“AML/CFT”) laws, rules and regulations. Under the Company’s AML/CFT Policy, it is required to collect KYC documents relating to its corporate customers. Such KYC documents may include copies of identity papers such as NRICs or passports of directors and/or authorised signatories of corporate customers. For the purpose of meeting the AML/CFT requirements, the Company will collect, use and disclose such information without the corporate customers’ consent as allowed by the regulations.
4.2) It is important to note that the PDPA does not apply to business contact information. Business contact information refers to an individual’s name, position name or title, business telephone number, business address, business electronic mail address or business fax number and any other similar information about the individual, not provided by him or her solely for his or her personal purposes. The Company is not required to obtain consent before collecting, using or disclosing any business contact information or comply with any other obligations in the Data Protection Provisions in relation to business contact information.
5) Collection of Personal Data
5.1) Generally, the Company collects personal data from the following sources:
Employees: The personal data that we collect and process on our employees is sourced from (a) information provided by employees and/or relevant third parties in the course of a potential employee applying for a position with us; and (b) information provided by employees, relevant third party information sources, or information otherwise generated upon a potential employee being hired and in the course of employment with the Company.
Customers: The Company collects customers’ personal data from (a) personal data provided by the customers through their relationship with us, for example information provided in application forms, survey and feedback forms and/or agreements entered into with us, and when using our products or services; through verbal and written communications with us; from an analysis of customers’ transactions and payments; and through the Company’s mailbox; and (b) personal data from third party sources connected with customers, including any relevant third parties connected with the customers or any other sources which the customer has consented to or where lawfully permitted.
5.2) Unless permitted under the PDPA or any other laws, regulations and guidelines, the Company shall not collect personal data without the consent of the individual.
6) Purposes for the Collection, Use and Disclosure of Personal Data
6.1) Generally, the Company collects, uses and discloses personal data for the following purposes:
Employees: The Company may collect, process, use, and retain employees’ (including potential employees) personal data for legitimate activities, including but not limited to assessing suitability for the job, verifying information and conducting reference checks, conducting background checks, general administrative and record keeping purposes, headcount and payroll planning, workforce development, training and certification, performance management, approving and monitoring employee benefits and entitlements, posting employee photographs on the intranet and email directory, maintaining emergency contact details, audit, risk management and security and compliance purposes, internal investigations and legal proceedings, and purposes as required by regulators and laws.
Customers: The Company may collect, use and disclose customers’ personal data for purposes including but not limited to confirming and verifying identity, assessing applications or inquiries for products and services, processing transactions, managing our business and customer relationships, notifying customers about benefits and changes to product and service features, responding to enquiries and complaints, updating, consolidating and improving the accuracy of records, producing anonymised or aggregated data, conducting research for analytical or statistical assessments, facilitating audit, risk management and compliance, assessing financial and insurance risks, conducting AML/CFT checks for risk detection and prevention, and providing information to relevant regulatory authorities and for any other purpose required or permitted by laws, regulations and guidelines.
6.2) The Company may rely on the Legitimate Interests exception to collect, use and disclose personal data without consent for purposes such as prevention of misuse of services, evaluative purposes, investigations or proceedings, recovery or payment of debt, detecting or preventing illegal activities (e.g. fraud, money laundering) or threats to physical safety and security, IT and network security and other purposes as permitted under the PDPA.
7) Withdrawal of Consent
Customers may at any time withdraw any consent given or deemed to have been given in respect of the collection, use or disclosure of their personal data. Upon receipt of such request and after processing, the Company will cease (and cause any data intermediaries and agents to cease) collecting, using or disclosing the personal data, except to the extent required or authorised under the PDPA or other written law. If consent is withdrawn by a customer, the Company may no longer be able to provide the requested products or services and the relationship with the customer may have to be terminated.
8) Protection of Personal Data
8.1) The Company places great importance on ensuring the security of the personal data in its custody against risks of unauthorised access, collection, use, disclosure, copying, modification, disposal or destruction. The Company has implemented security measures which include computer safeguards and password-protected files to enhance the security of such personal data. Employees’ hardcopy personal files are maintained by the HR Department under lock and key. The Company will regularly review and implement appropriate security measures when processing and retaining personal data.
8.2) Employees of the Company are required to handle personal data securely and with strict confidentiality, failing which they may be subject to disciplinary action.
8.3) The Company will impose compliance with data confidentiality requirements on its agents, third party service providers, consultants and professional advisors in working relationships and agreements with them.
9) Access to Personal Data
9.1) A customer may make a request to access his/her personal data which is in the Company’s possession or control. The customer must complete a data access and correction request form (Appendix A), provide all necessary documents and make the requisite service fee payment, where relevant, as prescribed in the form. The Company aims to revert within 30 days from receipt of the form, or inform the customer of an extended timeframe if needed.
9.2) To the extent required by PDPA, upon request by a customer, the Company shall provide information relating to how the customer’s personal data has been or may have been used or disclosed within a year before the date of such request. The Company may provide a standard list of possible third parties as part of its response to access requests for information relating to disclosure of personal data.
9.3) Employees who wish to access their personal data should contact the HR Department. Potential employees who were subsequently not employed by the Company or former employees of the Company should complete the data access and correction request form.
9.4) The Company may not be able to provide access to all of the personal data that it holds about an individual. For example, access may not be provided if such provision could reveal personal data about another individual, if such information is subject to legal privilege or if provision will be contrary to national interest or where such refusal is permitted under the PDPA. If access to personal data cannot be provided, the reasons for denying access will be provided to the customer within 30 days of receipt of the form, subject to any legal or regulatory constraints.
10) Accuracy and Correction of Personal Data
10.1) A customer may make a request to correct or update his/her personal data which is in the Company’s possession or control. The customer must complete a data access and correction request form (Appendix A) and provide all necessary documents or information as prescribed. The Company will correct or update personal data found to be inaccurate or incomplete as soon as practicable. Any unresolved differences as to accuracy or completeness shall be noted in the customer’s records.
10.2) Employees who wish to correct or update their personal data should contact the HR Department. Potential employees who were subsequently not employed by the Company or former employees of the Company should complete the same form.
10.3) The Company may refuse to correct or update personal data as requested in certain instances, for example where the Company is unable to confirm the customer’s identity or where such refusal is permitted under the PDPA. If the Company denies a customer’s correction request, it will inform the customer of the reason for the refusal within 30 days of receipt of the form, subject to any legal or regulatory constraints.
11) Offences and Penalties
11.1) An organisation or person commits an offence if the organisation or person: (a) with an intent to evade a request under section 21 or 22, disposes of, alters, falsifies, conceals or destroys, or directs another person to dispose of, alter, falsify, conceal or destroy, a record containing personal data or information about the collection, use or disclosure of personal data; (b) obstructs or impedes the Commission or an authorised officer in the exercise of their powers or performance of their duties under this Act; or (c) knowingly or recklessly makes a false statement to the Commission, or knowingly misleads or attempts to mislead the Commission, in the course of the performance of the duties or powers of the Commission under this Act.
11.2) An organisation or person that commits an offence under section 11.1(a) is liable: (a) in the case of an individual, to a fine not exceeding $5,000; and (b) in any other case, to a fine not exceeding $50,000. An organisation or person that commits an offence under section 11.1(b) or (c) is liable: (a) in the case of an individual, to a fine not exceeding $10,000 or to imprisonment for a term not exceeding 12 months or to both; and (b) in any other case, to a fine not exceeding $100,000.
11.3) Where an offence under this Act committed by a body corporate is proved to have been committed with the consent or connivance of an officer, or to be attributable to any neglect on his part, the officer as well as the body corporate shall be guilty of the offence and liable to be proceeded against and punished accordingly. Where the affairs of a body corporate are managed by its members, this provision applies in relation to the acts and defaults of a member in connection with his functions of management as if he were a director of the body corporate.
11.4) Any act done or conduct engaged in by a person in the course of his employment (“the Employee”) shall be treated for the purposes of this Act as done or engaged in by his employer as well as by him, whether or not it was done or engaged in with the employer’s knowledge or consent. In any proceedings for an offence under this Act, it is a defence for the employer to prove that he took such steps as were practicable to prevent the Employee from doing the act or engaging in the conduct, or from doing or engaging, in the course of his employment, in acts or conduct of that description.
12) Retention of Personal Data
12.1) The Company will retain employees’ and/or customers’ personal data: for the duration of the relationship with us; for such period as may be necessary to protect the Company’s interests and/or our customers or employees; where otherwise required by laws, regulations and guidelines; and where required by the Company in order to perform its duties and obligations.
13) Data Protection Officer
13.1) Please refer to Appendix B for the appointed Data Protection Officer of the Company. Business contact information of the Data Protection Officer(s) will be available on the Company’s website. Under the PDPA, the Data Protection Officer is responsible for facilitating the Company’s compliance with the PDPA. For the avoidance of doubt, primary responsibility for compliance with the PDPA remains with the Company.
14) Complaints Procedures
14.1) If a customer or an employee of the Company has reason to believe that his/her personal data has been misused by the Company, the customer or the employee is advised to lodge a complaint with the Data Protection Officer of the Company who will handle the complaint.