yt’s Data Protection Governance Framework – Volume 2
()
About this ebook
Volume 2 of 2
In today's data-driven world, effective data protection governance is vital for organizations to ensure compliance, protect personal data, and maintain customer trust. This book provides a comprehensive examination of data protection governance frameworks, focusing on the Singapore Personal Data Protection Act (PDPA) as a case study, while drawing insightful parallels with the European Union's General Data Protection Regulation (GDPR) and other international references.
With a practical and informative approach, this book explores the key components of a robust data protection governance framework. It delves into the core principles of data protection, including consent, purpose limitation, protection, accountability, risk management, and others. Through a detailed analysis of the Singapore PDPA, readers gain a deep understanding of its requirements, scope, and implications for organizations operating in Singapore.
Furthermore, this book offers a chapter with valuable insights through a comparative study of its key provisions of PDPA alongside the GDPR. Readers will discover the similarities and differences between these two frameworks, gaining a global perspective on data protection practices and requirements.
To enhance comprehension and practical application, the book includes illustrations, flowcharts, and mind maps. These visual aids facilitate a clear understanding of complex concepts, governance structures, and compliance processes. Readers will find these visual representations invaluable in designing and implementing effective data protection governance frameworks.
Throughout the book, real-world case studies, best practices, and practical examples are used to illustrate the application of data protection principles and governance strategies. These examples demonstrate how organizations can navigate the complexities of data protection compliance and develop a culture of privacy within their operations.
Whether you are a data protection officer, privacy professional, legal practitioner, business or company executive, listed or large company, or small business owner, this book serves as a comprehensive guide to establishing and enhancing data protection governance frameworks. By examining the Singapore PDPA, drawing on international references like the GDPR, and providing visual aids for clarity, it equips readers with the knowledge and tools necessary to navigate the ever-evolving landscape of data protection.
Read more from Yang Yen Thaw
Common Contract Clauses 2023 Rating: 0 out of 5 stars0 ratingsyt’s Data Protection Governance Framework Volume 1 of 2 Rating: 5 out of 5 stars5/5Business Negotiations Rating: 0 out of 5 stars0 ratingsCurse of the Counsel: Crafting Conquests in the Cauldron of Chaos Rating: 0 out of 5 stars0 ratings
Related to yt’s Data Protection Governance Framework – Volume 2
Related ebooks
Data Protection Officer Rating: 0 out of 5 stars0 ratingsGDPR-standard data protection staff training: What employees & associates need to know by Dr Paweł Mielniczek Rating: 0 out of 5 stars0 ratingsGDPR For Dummies Rating: 0 out of 5 stars0 ratingsComprehensive Guide to Implementing Data Science and Analytics: Tips, Recommendations, and Strategies for Success Rating: 0 out of 5 stars0 ratingsA Corporate Librarian’s Guide to Information Governance and Data Privacy Rating: 0 out of 5 stars0 ratingsNavigating Compliance: A Comprehensive Guide for AI Tool Builders on GDPR and CCPA Data Regulations Rating: 0 out of 5 stars0 ratingsData Protection Officer Rating: 3 out of 5 stars3/5Privacy and Data Protection based on the GDPR Rating: 0 out of 5 stars0 ratingsEuroprivacy™/®: The first European Data Protection Seal Rating: 0 out of 5 stars0 ratingsEU General Data Protection Regulation (GDPR) - An Implementation and Compliance Guide Rating: 0 out of 5 stars0 ratingsAI4 Corporations Volume II: Empowering the AI-Ready Workforce: AI4 Rating: 0 out of 5 stars0 ratingsPrivacy & Data Protection Foundation Courseware - English Rating: 0 out of 5 stars0 ratingsIntelligent Document Processing (IDP): A Comprehensive Guide to Streamlining Document Management Rating: 0 out of 5 stars0 ratingsIAPP CIPP/US Certification A Practical Study Guide to Master the Certified Information Privacy Professional Exam Rating: 0 out of 5 stars0 ratingsThe Digital Polycrisis: Digital Polycrisis, #1 Rating: 0 out of 5 stars0 ratingsData Privacy for Everyone: A Simple Guide to Big Ideas Rating: 0 out of 5 stars0 ratingsIT Regulatory Compliance in the UK Rating: 0 out of 5 stars0 ratingsPrivacy & Data Protection Practitioner Courseware - English Rating: 0 out of 5 stars0 ratingsCybersecurity and Privacy Law Introduction: cybersecurity beginner, #1 Rating: 0 out of 5 stars0 ratingsPrivacy, Regulations, and Cybersecurity: The Essential Business Guide Rating: 0 out of 5 stars0 ratingsThe Manager’s Guide to Cybersecurity Law: Essentials for Today's Business Rating: 5 out of 5 stars5/5Intro to GDPR: A Plain English Guide to Compliance Rating: 0 out of 5 stars0 ratingsEU GDPR – An international guide to compliance Rating: 0 out of 5 stars0 ratingsPrivacy & Data Protection Essentials Courseware - English Rating: 0 out of 5 stars0 ratingsThe Layman's Guide GDPR Compliance for Small Medium Business Rating: 5 out of 5 stars5/5The Book of Mitigations Rating: 0 out of 5 stars0 ratingsFortify Your Data Privacy Rating: 0 out of 5 stars0 ratingsGdpr For Marketers And Online Businesses Rating: 0 out of 5 stars0 ratingsIAPP CIPM Certified Information Privacy Manager Study Guide Rating: 0 out of 5 stars0 ratingsStrategic Policy Insights in Data Science Rating: 0 out of 5 stars0 ratings
Law For You
Legal Research: a QuickStudy Laminated Law Reference Rating: 0 out of 5 stars0 ratingsLegal Words You Should Know: Over 1,000 Essential Terms to Understand Contracts, Wills, and the Legal System Rating: 4 out of 5 stars4/5The Socratic Method: A Practitioner's Handbook Rating: 4 out of 5 stars4/5Law For Dummies Rating: 4 out of 5 stars4/5The Everything Guide To Being A Paralegal: Winning Secrets to a Successful Career! Rating: 5 out of 5 stars5/5Legal Writing: QuickStudy Laminated Reference Guide Rating: 0 out of 5 stars0 ratingsWin In Court Every Time Rating: 5 out of 5 stars5/5Criminal Law Rating: 0 out of 5 stars0 ratingsTrans: When Ideology Meets Reality Rating: 3 out of 5 stars3/5Secrets of Criminal Defense Rating: 5 out of 5 stars5/5The Common Law Rating: 4 out of 5 stars4/5Wills and Trusts Kit For Dummies Rating: 5 out of 5 stars5/5Legal Demand Letters: A+ Guides to Writing, #10 Rating: 3 out of 5 stars3/5So You Want to be a Lawyer: The Ultimate Guide to Getting into and Succeeding in Law School Rating: 0 out of 5 stars0 ratingsGet It Together: Organize Your Records So Your Family Won't Have To Rating: 4 out of 5 stars4/5All You Need to Know About the Music Business: Eleventh Edition Rating: 5 out of 5 stars5/5Torts: QuickStudy Laminated Reference Guide Rating: 5 out of 5 stars5/5Win Your Case: How to Present, Persuade, and Prevail--Every Place, Every Time Rating: 5 out of 5 stars5/5Legal Writing in Plain English: A Text with Exercises Rating: 3 out of 5 stars3/58 Living Trust Forms: Legal Self-Help Guide Rating: 5 out of 5 stars5/5The Lawyer's Guide to Writing Well Rating: 3 out of 5 stars3/5Contracts: QuickStudy Laminated Reference Guide Rating: 0 out of 5 stars0 ratingsCivil Procedure: QuickStudy Laminated Reference Guide Rating: 0 out of 5 stars0 ratingsThe ZERO Percent: Secrets of the United States, the Power of Trust, Nationality, Banking and ZERO TAXES! Rating: 4 out of 5 stars4/5Evidence: QuickStudy Laminated Reference Guide Rating: 0 out of 5 stars0 ratingsThe Devil's Advocates: Greatest Closing Arguments in Criminal Law Rating: 4 out of 5 stars4/5Constitutional Law Rating: 5 out of 5 stars5/5
Reviews for yt’s Data Protection Governance Framework – Volume 2
0 ratings0 reviews
Book preview
yt’s Data Protection Governance Framework – Volume 2 - Yang Yen Thaw
About the Author
Yang Yen Thaw
Law & tech is a persuasion, management consultancy a profession, and teaching a passion
Yang Yen Thaw is a corporate lawyer, coach, and holds various certifications as AI consultant, management consultant, Associate Adult Educator, ACLP+ACTA, and CIPM+PC:PDP(S) (data protection). He has held senior management and executive positions in management and law in listed as well as private limited companies with businesses spanning the world. He ran his own law firm for 12 years from 1999-2010. Since then, he has held various positions as partner in law firms, GC, CLO, Chief Data Protection Consultant, DPO, management consultant, corporate trainer, and a professional coach.
He was the speaker for an online seminar on PDPA and Data Governance
for Smart Nation X conducted on 13 August 2021, which was jointly organized by the Prime Minister’s Office, SkillsFuture Singapore, and ntuc LearningHub. Yen Thaw has also been speaker and teacher for critical thinking and business negotiations for e2i, SkillsFuture, and PA in Singapore since 2021.
Yen Thaw is a regular trainer and consultant on data protection, AI, cybersecurity, and critical core skills. He has trained over 3,000 students comprising individuals and employees from over 100 companies ranging from public listed companies, public agencies (students from MHA, MOH, CSA, IMDA, PDPC), public sector companies, SMEs, educational institutes, PAP community schools, town councils, and their managing agents as well.
His work also covers consulting and teaching covers the following business areas:
Artificial Intelligence for Business & Enterprise
Business Negotiations
Critical Core Skills: Design Thinking, Critical Thinking 4.0
Data Protection + PDPA
Entrepreneurship, internationalization, and cross-border business
Joint Ventures, Mergers & Acquisitions
Law & Intellectual Property
Leadership & Management
Tech subjects: CyberSecurity, IoT
Yen Thaw has designed various original frameworks such as - Critical Thinking powered by QUESTS©, design thinking model – DT D.E.S.I.G.N. (also a Design Thinking for Data Protection course that was approved by IMDA/PDPC as well as WSG.), and DPGF – Data Protection Governance Framework. He has also designed, developed, and run his own courses such as – Artificial Intelligence for Business in Industry 4.0 – demystified, Surviving the Future of Work (Industry 4.0) With Critical Thinking (Powered by QUESTS©), and Cybersecurity Basics.
He has been consistently awarded Trainer Excellence Award
by ntuc LearningHub for Overall Training Hours and Performance and
Technology" since 2021.
Glossary
Definitions – in the context of Singapore
Data Protection Governance Framework
The Data Protection Governance Framework at a glance:
A picture containing text, screenshot, font, circle Description automatically generatedA picture containing text, screenshot, design Description automatically generatedContinued from Volume 1
Plan
The Personal Data Protection Act 2012, Singapore
For ease of reference, the following abbreviations will be used:
BCI: Business contact information
BCR: Binding Corporate Rules
CUD: Collection, use, and/or disclosure
DNC: Do Not Call
P&P: All corporate documentation used in running the organization and includes policies, processes, procedures, contracts, manuals, SOPs, etc.
PD: Personal Data
PDPA: Personal Data Protection Act 2012
All developed countries have data protection or privacy law. The primary law dealing with personal data in Singapore is the Personal Data Protection Act 2012, which came into effect on 2 July 2014, and its regulations. PDPA keeps and maintains Singapore’s approach to being business-friendly in mind.
PDPA regulates the collection, use, and disclosure of personal data by organizations in Singapore and provides individuals with certain rights over their personal data. Under PDPA, organizations are required to obtain an individual's consent before collecting, using, or disclosing their personal data. They must also ensure that personal data is kept secure and not disclosed without proper authorization. PDPA also requires organizations to appoint a Data Protection Officer to ensure compliance with the Act and handle data protection-related matters.
Though most organizations may adopt a generic email id for DPOs such as [email protected], though there needs to be a named DPOs that can be registered with ACRA – the Accounting and Corporate Regulatory Authority. ACRA is the regulator of business registration, financial reporting, public accountants, and corporate service providers. ACRA is also responsible for developing the accountancy sector and setting the accounting standards for companies, charities, co-operative societies, and societies in Singapore.
PDPA also establishes the Personal Data Protection Commission (PDPC), which is responsible for enforcing the Act and investigating complaints related to data protection. The PDPC has the power to impose fines and other penalties on organizations that violate PDPA.
PDPA Approach
Organizations must ensure compliance with the obligations within individual departments and not the organization as a whole.
The general approach of PDPA is to be technology neutral, principles-based, and compliant-based. Which means:
PDPA, in the words of PDPC, has been enhanced from 1 February 2021 which saw substantial amendments. Prior to the amendments, any public agency, or an organization while acting on behalf of a public agency in relation to the collection, use