Privacy Hub by Wrangu –
Solution for Singapore’s PDPA
Your go-to solution for Implementing Singapore’s PDPA into your organisation
Quick Look: Singapore’s PDPA
The Personal Data Protection Act (PDPA) passed into law in Singapore in 2012 places specific regulatory requirements on private sector organisations who process personal data of individuals located in Singapore. For most organisations, these requirements have led to the introduction of new processes, systems and personnel to enable them to meet their obligations. Privacy Hub by Wrangu, is a data privacy management solution that automates and harmonises the disparate activities of various teams into one seamless outcome ensuring ongoing compliance.
A look into the details of the PDPA articles immediately reveals several requirements of interest such as the rights of data subjects which organisations are required to fulfil as soon as reasonably possible following requests from data subjects. Organisations are also required to maintain a record of processing activities to enable them send purpose of processing notifications to data subjects and conduct data protection impact assessments to ensure appropriate safeguards are in place for secure personal data processing. There are also obligations on data intermediaries who process personal data on another organisation’s behalf under a written contract and data breach notification requirements from the Data Breach Guide.
Privacy Hub by Wrangu – Solution for PDPA
The data subject rights module provides the ability for data privacy teams and data subjects to raise and manage data subject rights requests allowing organisations:
- Capture DSR request details.
- Validate the data subjects, agents and data subject rights requests.
- Define SLA durations as appropriate for the organisation.
- Have a consolidated view of all open and closed data subject requests received from a particular data subject over a given period of time to manage excessive request.
- Indicate whether a DSR request should be fulfilled based on the lawful basis of processing the information and possible reasons to decline requests.
- Request approval from a data controller to process a DSR request when acting as a data intermediary.
- Confirm with data subjects how they would like to receive information in response to right to access requests.
- Dynamically create action tasks for the notification of third parties when fulfilling a right to erasure or right to rectification request.
Relevant PDPA Articles:
Part IV – Division 1 – Section 16, Part V – Section 21 – 22, Part X – Fifth Schedule and Sixth Schedule
The DPIA module provides the ability to perform an initial DPIA screening questionnaire to determine if a new processing is likely to result in a high risk to the rights and freedoms of data subjects and, if required, conduct a full assessment for new projects, ensuring adherence to privacy by design principles. The DPIA module also provides:
- Automatic evaluation of DPIA responses with possible concerns raised for consideration.
- Built-in configurable risk calculation engine with risk ratings displays based on responses.
- Configurable approval levels throughout the lifecycle of an assessment including facility to capture and monitor advice from data protection officers.
Relevant PDPA Articles:
Part III – Section 11, Part VI – Section 23 – 26
Comprehensive engine enabling the robust documentation of processing activities with the ability to relate a ROPA directly to services, processes or configuration items within the ServiceNow CMDB. The ROPA module also supports:
- Capture of all data sets required to fulfil the principles of the regulation on the treatment of personal data. These principles include accountability, identifying purposes of processing, consent, limiting collection, and limiting use, disclosure and retention.
- Maintain version history for each ROPA record to support auditing and complaints management activities.
- Flag changes in the CMDB and other sources that would suggest a need to update the ROPA including provision of adequate technical and organisational measures for the security of personal data.
- Generate and update a ROPA from a DPIA utilising the same data set from the DPIA.
- Automatically indicate what rights data subjects can exercise against the data collected as part of this processing.
Relevant PDPA Article:
Part IV – Division 1 – Section 13 – 17, Part IV – Division 2 – Section 18 – 20, Part VI – Section 23 – 26, Part X – Second Schedule, Third Schedule and Fourth Schedule
Acts as a register of all data breach incidents as they relate to personal data and facilitate the automatic determination of whether a report or notification should be sent to the Personal Data Protection Commission (PDPC) or affected data subjects. This module also provides
- Standard process to support data gathering to determine if the personal data breach is likely to cause relevant risk or damage to the data subjects.
- Automated data breach SLA calculator to ensure regulatory stated reporting timelines are monitored and complied with.
- Generate and assign dynamic tasks to relevant parties in addressing data breach reporting requirements.
- Support report creation for notification to the Personal Data Protection Commission (PDPC) or communication to affected data subjects.
- Ready integration with ServiceNow Security Incident Response module.
Relevant PDPA Article:
The PDPC’s Guide to Managing Data Breaches 2.0 (Data Breach Guide)