Gan Thiam Poh
Singapore
“Chairman, the ComLink+ Progress packages aim to support the efforts of eligible lower-income families with young children to help them achieve stability, self-reliance and social mobility.”
“Madam, our maritime sector has been a key growth engine for our economy and provide many jobs and business opportunities. In addition to being an international maritime centre, Singapore is the top bunkering port and busiest container transshipment hub in the world.”
“Chairman, in rating the quality of public transport, most commuters would consider the following factors, such as safety, affordability, connectivity, reliability, accessibility, frequency, speed and last but not least, comfort. All these factors contribute to our commuters’ experience, which many of us go through almost daily.”
“Chairman, many of my residents are appealing to have MRT stations in the proximity of their homes. Will LTA reconsider a new MRT line to support residents at Seletar, Yio Chu Kang, Fernvale at the central, north and northeast zones to the city at the south, and new Woodlands North, as well as to Changi Airport on the east and Tuas on the…”
“Chairman point-to-point (P2P) services play an important role being a convenient and, at times, essential supplement to our public transport system, by providing direct access to specific locations. Our main P2P providers are taxis and private hire vehicles (PHV).”
“Chair, our hawker centres are our national canteens and provide a wide variety of affordable food to suit more palates and budgets. We have had many popular hawker centres sited all over Singapore, which have served residents over many years.”
The complete record
Every one of 667 lines we hold for Gan Thiam Poh, in date order, each linked to its source. Free to read, in full, without an account. Page 14 of 14.
“" Members of this House will agree that this is an important legislation and a significant step forward for Singapore, and I hope they can support the Bill, Sir. [(proc text) Question put, and agreed to. (proc text)] [(proc text) Bill accordingly read a Second time and committed to a Committee of the whole House. (proc text)] [(proc text) The House immediately resolved itself into a Committee on the Bill. – [Assoc Prof Dr Yaacob Ibrahim]. (proc text)] [(proc text) Bill considered in Committee. (proc text)] [Mr Deputy Speaker (Mr Charles Chong) in the Chair] Clauses 1 to 68 inclusive ordered to stand part of the Bill. First Schedule ordered to stand part of the Bill. Page: 888 Second Schedule –”
“It will comprise members of the industry, members of the public and civil society. The exact composition of the PDPC and the advisory committee will be firmed up and announced in due course, if the Bill is passed. Page: 887 Sir, the Bill is not intended to be overly prescriptive as it applies to all sectors of the economy. To provide greater clarity on the interpretation and the application of the Act, the PDPC will issue advisory guidelines which will be developed in consultation with the industry. Public education will also be key as some Members have highlighted and, in this regard, the PDPC will reach out to the public, including our young children and schools, to raise awareness to the importance of personal data protection. So, while the Bill puts in place safeguards to protect consumers' personal data, ultimately, individuals will have to take responsibility for their own personal data. Sir, as you can see from the broad range of issues raised by Members of the House, from consumers and business interests to national and international considerations, we can appreciate the complexities of the issue of personal data protection and the importance of striking a balance within the various considerations. Sir, the issues that Members have raised are among the myriad issues we have considered in formulating a model that takes into account the interests of different stakeholders and Singapore's needs. We also recognise interests and circumstances may change. We will, therefore, need to continue to review and adjust the law to address new and emerging issues. As the Chinese proverb says – I will have to say this in English, Sir – "The journey of a thousand miles begins with one step.”
“The Bill provides the PDPC with a range of powers to enforce the Act effectively. It adopts what we call a complaints-based approach to enforcement and the PDPC will have the powers to initiate investigation or investigate if a complaint is lodged. It will have the power to investigate potential non-compliance and the power to issue directions to organisations to correct their non-compliance. In enforcing the law, the PDPC is expected to act on cases in a timely manner and may issue advisory guidelines on its procedures and associated timelines in due course. Mr Desmond Lee expressed concern about the dispute resolution and the appeal process being cumbersome. The approach, Sir, takes into consideration that a large majority of cases are likely to be resolved early, which may not require a decision by the PDPC. However, in instances where the PDPC is required to investigate and take enforcement action against an organisation, the appeals process allows for a quicker resolution through reconsideration while providing aggrieved parties the appropriate avenues to appeal to an independent appeal body. Further appeals to the High Court and the Court of Appeal are allowed on points of law or on the amount of the financial penalty imposed. Sir, this is in line with other laws such as the Competition Act. Sir, Mr Patrick Tay and Ms Jessica Tan spoke on the role of the composition of the PDPC. As mentioned in my earlier speech, the PDPC will serve as Singapore's main authority on matters relating to personal data protection. It will also undertake education and outreach activities to promote public awareness of personal data protection in Singapore. An advisory committee will be appointed to provide advice to the PDPC.”
“Do not forget the public also know that the Bill is coming. So they should be more cautious. Sir, the Bill has taken the approach of protecting individuals' personal data without imposing overly onerous requirements on organisations. Requiring organisations to notify or deem consent from individuals for all personal data previously collected, would be too onerous. The Bill, therefore, takes a balanced approach by allowing organisations to use the personal data collected before their appointed date for the purpose for which it is collected, provided the purposes are reasonable. After the law comes into effect, individuals can withdraw consent that was previously given. These measures will help protect consumers from those who seek to use the transition period to misuse personal data before the law comes into effect. Page: 886 Sir, several Members also requested for staggered transition periods. Ms Jessica Tan proposed different sunrise periods for 12 months for large businesses and two years for small businesses. We have proposed a single sunrise period for at least 18 months for all organisations, regardless of size, in order to minimise confusion and perhaps keep implementation simple and effective. Differential treatment for small companies in some jurisdictions was found to have added to the complexities of implementation. During the sunrise periods, the PDPC will conduct awareness-building activities for both businesses and consumers, in relation to their rights and obligations under the regime. These activities will be targeted at enhancing organisations' ability to comply with the PDPA when it comes into effect. Sir, several Members touched on the issue of enforcement and implementation.”
“The Bill also contemplates that the PDPC may establish arrangements with foreign data protection regulators, which may include cross-border co-operation. Sir, Asst Prof Eugene Tan asked about covering e-mails under the scope of the DNC registry. We have decided not to include e-mails as unsolicited e-mails can be blocked through e-mail filters and cause less of a nuisance to delete when received as compared to phone calls in the wee hours of the morning, SMSes and fax messages which are more difficult for the individuals to filter out. A significant proportion of spam e-mails also originate from overseas, which makes it difficult for any enforcement action to be taken, even if the e-mail messages were to be included. Sir, I take the point raised by Mr Dhinakaran that the DNC registry may lead to more organisations using mass marketing channels such as direct mailers and flyers. Sir, I would suggest that the DNC registry will better focus organisations' telemarketing efforts. This is because the DNC registry allows them to effectively target a group of consumers who are genuinely interested in receiving information on products and services, and eliminate time and resources wasted on those who do not wish to receive such information. It should drive more positive behaviour rather than negative behaviour. Individuals who change their minds can withdraw their numbers from the DNC registry using a similar method as registration. The process could be as simple as calling a number, using the phone of which the telephone number is to be registered or deregistered, or filling up an online form. Sir, several Members raised the possibility of organisations taking advantage of the transition period to collect and use personal data.”
“However, this individual should not receive any marketing messages after the 60-day or 30-day interval. Organisations may still send marketing messages to registered members if they have obtained clear and unambiguous consent to do so, in written or other accessible form. In the examples raised by Members, seeking consent to use personal data using general or vaguely-worded clause, buried within pages of other terms and conditions, is unlikely to be considered clear and unambiguous consent. This may not comply with the requirement to notify individuals of the purposes of collecting, using or disclosing their personal data and could also be considered a misleading or deceptive practice prohibited under the Bill. Organisations should also retain the records of consent that its customers have given, to indicate that they can be contacted for telemarketing. This is a practical way for organisations to demonstrate that they are compliant with the law. Page: 885 Sir, Mr Zaqy Mohamad and Mr Lim Biow Chuan made a valid observation about telemarketing calls originating overseas. Similar concerns of the abuse of personal data by overseas organisations were also raised. While the PDPC may seek to enforce the Act against overseas organisations, in reality it may be difficult to investigate and proceed with any enforcement action against such organisations. Recognising this limitation, clause 37 provides the ability to enforce against any local organisation that authorises sending of the marketing message. So, this will mitigate the problem as marketing messages targeting Singapore telephone numbers are likely to involve goods and services by organisations with a local presence.”
“The Bill imposes the necessary requirement on how organisations may collect, use or disclose personal data so as to protect individuals from the misuse of their personal data. To clarify a point mentioned by Mr Dhinakaran, the Bill does not prohibit the sharing of personal data between entities, as long as consent is obtained. This approach strikes a balance between allowing organisations to share personal data and allowing individuals to decide how their data may be used. The Bill also does not prescribe a retention period for personal data. It only states that organisations should not retain personal data when such retention no longer serves the purposes for which the data was collected. It does not make business sense – if you do not use it, delete it. This is in recognition that the appropriate retention period will vary according to the legal or the business needs of each organisation. Requirements of the DNC registry are not as complex as some Members may perceive. Organisations that send marketing messages must check their contact list with the DNC registry within the prescribed period before sending the message. A 60-day checking interval will be prescribed for the first six months of the DNC registry's operation. Thereafter, we will reduce the checking interval to 30 days. An organisation will not be in breach of the rules if it sends marketing messages to individuals who register their numbers within the interval period, after the organisation has checked with the DNC registry. So, if you check on day one and his number is not there on the registry, you can send a marketing message to him. On day two, he enters his number in the registry. This is still within the prescribed period.”
“For example, if the organisation needs to verify the individual's identity to provide certain services, such as for admission to a hospital or to check on his health insurance, it may be reasonable to require the individual to provide his NRIC details to prove his identity. Sir, several Members raised the need to provide for special groups of people such as children and the mentally incapacitated. Members may wish to note that the details of persons who may act for minors and the extent to which they can exercise their rights or powers of such individuals will be set out in the subsidiary legislation subsequently. The Bill is designed to allow sectoral legislation to provide higher level of protection on top of its baseline requirement. Additional protection for other special groups that is required can thus be catered for by sector-specific laws. I take Ms Low Yen Ling and Assoc Prof Fatimah Lateef's point that children's personal data will be an increasingly important issue, as tools and platforms for collecting children's data become more prevalent. Page: 884 The Bill, Sir, is a first step in putting in place a basic personal data protection regime for Singapore. We will continue to review and adjust the legislation to address additional areas of concerns where necessary. Sir, several Members raised queries about the Do Not Call or the DNC registry. Allow me to clarify some of these concerns. Mr Dhinakaran raised concerns about the DNC registry's impact on organisation practices. Today, nothing prevents organisations from freely collecting, using, sharing, or selling consumers' personal data without consent.”
“These are based on the overarching intent of ensuring adequate protection for individuals without placing onerous burdens on organisations to comply with the law. They also take into account international practice and Singapore's context. For example, exceptions apply in certain circumstances or situations where obtaining consent for the collection, use or disclosure of personal data may not be feasible. Such situations include collection of personal data for life-threatening emergencies. Exceptions are also necessary to enable certain organisations to effectively perform their functions, such as investigations or legal proceedings. Sir, let me now address some of the queries on specific situations. Sir, as I mentioned earlier, how the Bill applies will depend on the facts and circumstances of the case. In the example of the lucky draw forms, mentioned very often today, including by Mr Patrick Tay, that if the organisation had clearly stated on the lucky draw form that the personal data provided would be used for the purposes of contacting the individual to market certain products, then the organisation would be able to use it for those purposes. So, I advise that you read the fine print in future. If, however, there was no mention of the marketing purpose, then it is likely the organisation will be in breach of the provisions if they use the data for marketing activities. Likewise, for the example of the use of the NRIC details raised by Assoc Prof Fatimah Lateef, organisations should consider if collecting a person's NRIC number is reasonable for the purpose, and obtain the individual's consent.”
“The Government takes steps to ensure that officers comply with Government policies and regulations, including Data Protection, for example audits may be carried out, and where there are cases raised to the Government, these will be investigated and officers who are found to have violated these regulations may be disciplined according to the Public Service Disciplinary Regulations. Agencies have mechanisms and processes in place to receive and address complaints or enquiries about Government's policies and procedures relating to the handling of personal data. In relation to individual's access and correction rights, individuals can also request. Sir, I understand that individuals may also request Government agencies to correct inaccurate personal information held by the agencies. I would also like to reiterate that personal data held by Government agencies are protected by appropriate security safeguards against accidental or unlawful loss, as well as unauthorised access, use or disclosure. This is regardless of the format in which the personal data is kept. Mr Ang Wei Neng touched on how the Bill will apply to Members of Parliament. In general, Sir, Members are required to comply with the requirements under the Bill when collecting, using or disclosing personal data in the course of their work. In certain cases where an individual voluntarily provides his personal data to the Member for a purpose, such as for the Member's assistance, consent may be deemed to be given for the Member to pass the personal data to a relevant organisation for the purposes of providing assistance. Where the Member is acting on behalf of a public agency, the public sector rules will apply. Page: 883 Sir, Mr Desmond Lee asked about the exceptions provided in the Second to Fourth Schedules.”
“The Bill will apply to any organisation that collects, uses or discloses personal data in Singapore. This includes foreign companies operating in Singapore. We are not adopting a prescriptive approach of restricting transfers of personal data to countries that have an adequate level of data protection. Instead, the Bill adopts a "principle-based" approach, where the onus will be on the organisation in Singapore to put in place measures, such as contractual arrangements, to ensure a comparable standard of protection is accorded to personal data transferred overseas. Therefore, there is no need to further burden our organisations with disclosing to consumers where copies of their personal data will be transferred to. Page: 882 Sir, the Bill applies to all organisations across the private sector, regardless of whether they have commercial or non-commercial aims, such as NTUC. This is important as it will assure the public that there is a minimum set of data protection rules applied consistently across the private sector and foster greater trust. The Bill does not cover the public sector as it already has its own set of data protection rules that all public officers must comply with. These rules are guided broadly by the same principles under the Bill. Statutory provisions in several Acts also regulate the collection, use and disclosure of information by the public sector. These ensure that public agencies and officials are subject to responsibilities to maintain confidentiality and protection of personal data, while enabling them to carry out their statutory functions in an effective and accountable manner. All Ministries, Statutory Boards and Organs of State are required to comply with the public sector rules with regard to Data Protection.”
“The definition adopted in the Bill encompasses any data that can identify an individual, and it will cover the examples cited by the Member. The definition also covers personal data recorded in both electronic and non-electronic formats. Mr Ang Wei Neng spoke about CCTVs. The Bill covers CCTV recordings to the extent that images of identifiable people are captured. However, imagery captured by CCTV in public places may be considered as "publicly available" personal data, and can be collected, used or disclosed without consent. However, for CCTV surveillance at private premises, consent would generally be required unless other exceptions apply. In such cases, it may suffice to notify individuals through the placement of signs that CCTVs are monitoring the premises. The PDPC will provide more detailed guidance on the use of CCTV and surveillance cameras in due course. Sir, several Members asked how the Bill will apply to personal data posted online, such as social networking sites and blogs. Online sites, including social networking sites and blogs, may be considered "publicly available" sources depending on the circumstances. The collection, use or disclosure of "publicly available" data will not require the consent of the individual concerned. On Mr Zaqy Mohamad's suggestion to cover cyber-bullying and other undesirable online behaviour, the Bill is concerned with regulating the management and the protection of personal data. It does not govern other actions of individuals online. This would be more appropriately addressed by other laws. Sir, several Members asked about the application of the Bill to foreign organisations operating in Singapore, and ensuring personal data transferred overseas are accorded the same level of protection.”
“The Bill also supports Singapore's development as a global data hub by providing a conducive environment for global data management industries, such as cloud computing and business analytics, to operate in Singapore. Sir, Mr Desmond Lee asked how the Bill is envisaged to operate in relation to common law principles. The Bill does not seek to change any right or obligation conferred by or imposed under the common law, including the common law principles of confidentiality and consent. The Bill does address a number of issues that are not covered under the common law today. For example, the common law does not have a general requirement that consent must be obtained for the purpose for which personal data is collected, used or disclosed. The Bill, as we have mentioned, is a baseline legislation that will operate concurrently with other legislative and regulatory frameworks. Taking the example of the health sector, medical records that contain personal data are covered under the Bill. This includes personal data contained in electronic health records. Doctors will need to follow the rules for collection, use, disclosure, access and correction, and care when dealing with personal data in medical records. In addition, Sir, other relevant laws, such as those under the purview of the Ministry of Health, may also apply. Page: 881 Several Members also commented on the definition of personal data. Mr Zaqy Mohamad raised the concern that the definition is broad and vague and may not cover information such as a person's salary and religious preferences. As one can tell from the different situations that Members have raised, it is necessary for the definition to be sufficiently broad to allow the Bill to apply to differing circumstances.”
“Nonetheless, Sir, some costs are inevitable in complying with any new piece of legislation or regulation. Both Mr Zaqy Mohamad and Ms Low Yen Ling asked about training and financial assistance to help our SMEs comply with the Act. Sir, to ease organisations into the new law, the Bill provides a transition period of 12 to 18 months for organisations to adjust their practices to comply with the DNC registry and data protection requirements, respectively. During this period, the Personal Data Protection Commission (PDPC) will focus on building up the capabilities of organisations to comply with the Act. The PDPC will issue advisory guidelines, provide educational materials as well as conduct education and outreach activities to help both organisations and individuals better understand the Act. These education and outreach activities will continue beyond the transition period because it is in our interest to ensure that everybody knows the Act well so that they can comply with it effectively and efficiently. Sir, there are also existing industry assistance schemes, such as IDA's iSPRINT scheme and SPRING's Innovation and Capability Voucher scheme, that companies can potentially tap on to help defray costs in upgrading their systems or processes to comply with the Act. Sir, both Mr David Ong and Ms Jessica Tan rightly pointed out the need for a framework that balances innovation and flexibility with the need to ensure good data governance. A data protection regime can help promote business innovation and enhance competitiveness. It was also observed that consumer data, if appropriately used, can lead to better services and products that help local businesses become more competitive.”
“First, I thank the many Members of this House for their support for this Bill, and for sharing their thoughts on important issues that this piece of legislation seeks to address. Sir, Members have raised many different scenarios about the protection of individuals and the concerns of organisations. The Bill is drafted to apply to all sectors in the economy and necessarily contains broad and general principles. It will therefore not be possible to give a definitive answer to each and every scenario, as this would require an assessment of all the facts of the specific case. Sir, with this in mind, let me address the key themes and questions that Members have brought up. One of the key issues that Members have brought up is the issue of compliance costs, especially for SMEs. This is a key consideration for us in developing this Bill. We have sought to mitigate compliance costs for businesses where possible. Several requirements have been adjusted to take into account the feedback and suggestions received from the businesses during the public consultations period. [Mr Deputy Speaker (Mr Charles Chong) in the Chair] For example, Sir, the law will impose fewer obligations on organisations known as "data intermediaries", which process personal data on behalf of other organisations. Measures are also in place to mitigate organisations' costs for handling access requests. Business-to-business marketing calls and messages are also excluded from the Do Not Call (DNC) registry so as not to unduly hinder business-to-business marketing. Page: 880 Sir, I would like to assure Members that we have been mindful to ensure the Bill does not impose overly onerous requirements on our businesses, while maintaining an adequate level of protection for our consumers.”
“Mr Speaker, Sir, I rise in support of this Bill. I appreciate the Ministry's sincere efforts to take into account the concerns of all stakeholders regarding personal data protection. Not less than three rounds of public consultations were conducted between September last year and this April. Members of the public and industries had contributed close to 1,900 feedback regarding this protection framework, the Do Not Call (DNC) registry and the proposed legislation. I would just like to add a couple of points. Page: 879 Firstly, with 97% of the respondents in the MICA poll supporting the idea for a DNC registry, perhaps we should consider changing the registry to an opt-in list of phone and fax numbers instead. That is, only individuals who do not object to being contacted by organisations seeking to provide goods and services have to register for the list. The assumption is that the rest of the population does not desire unsolicited calls, SMSes and faxes. I think this is a more cost effective and efficient way. In addition, such a registry is more considerate of the needs of the vulnerable members of our society, including many elderly folks. Why should they be inconvenienced with the requirement of opting-out registration? In fact, I suspect after the passing of the Bill, telemarketers will end up targeting this group after the more savvy residents had submitted their opt-out applications. Secondly, we have this problem of calls originating from call centres overseas. May I ask the Minister to share with the House the legal implications and enforcement measures for businesses with multiple call centres in other jurisdictions, as this Bill only addresses organisations in Singapore. 6.17 pm Assoc Prof Dr Yaacob Ibrahim: Thank you, Mr Speaker.”
“Mr Speaker, Sir, thank you for allowing me at the last minute to raise some questions. Personally, I support this Bill. However, I would like to find out from the Minister how many cases of forgery have actually been uncovered each year by MOM regarding S Pass and EP applicants. Secondly, what makes me puzzled is why can there not be a system whereby people can make a check first, before the foreign workers are allowed in? I notice that under the current system, the foreign workers are allowed in first, and then we verify, and we set up enforcement teams to "catch" them. So, my question is: can there not be a check first, even before they are allowed into Singapore? 5.30 pm”