Section 33 of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (the PDPO) deals with the transfer of personal data, and prohibits the transfer of personal data outside Hong Kong except in specified circumstances, such as when:
- the data protection laws of the foreign country are similar to the PDPO; or
- the data subject has consented in writing to the transfer.
Under the requirements of Singapore’s Personal Data Protection Act 2012 (PDPA), the Personal Data Protection Commission (PDPC) is the enforcement agency tasked with the responsibility of monitoring compliance with the PDPA.
The first edition of The Privacy, Data Protection and Cybersecurity Law Review appears at a time of extraordinary policy change and practical challenge for this field of law and regulation. Several Sidley lawyers in the Privacy, Data Security and Information Law practice have contributed to this publication.
Editor’s Preface, Alan Charles Raul
- Chapter 1, “European Union Overview,” William Long, Geraldine Scali and Alan Charles Raul
- Chapter 2, “APEC Overview,” Catherine Valerio Barrad and Alan Charles Raul
- Chapter 9, “Hong Kong,” Yuet Ming Tham and Joanne Mok
- Chapter 12, “Japan,” Takahiro Nonaka
- Chapter 16, “Singapore,” Yuet Ming Tham, Ijin Tan and Teena Zhang
- Chapter 20, “United Kingdom,” William Long and Geraldine Scali
- Chapter 21, “United States,” Alan Charles Raul, Tasha D Manoranjan and Vivek Mohan
On December 26, 2013, Singapore’s Personal Data Protection Commission (the “Commission”) issued advisory guidelines on the “Do Not Call” Provisions (“DNC Guidelines”) of the Personal Data Protection Act 2012 (Act 26 of 2012) (“the Act”). The DNC Guidelines supplement the Commission’s earlier issued Advisory Guidelines1 on the Act. The DNC Provisions came fully into effect on January 2, 2014, and the DNC Guidelines serve to illustrate particular aspects of the DNC Provisions, though “they are not meant to exhaustively address every obligation in the Act.”2
The new year will ring in significant privacy, data protection and cybersecurity changes in the U.S., Europe, Asia and elsewhere around the world. Below are some key developments and possible concrete action items for General Counsels, Chief Privacy Officers and Chief Information Officers:
United States companies that conduct business in Canada, as well as most other organizations that collect, use or disclose personal information in the course of a commercial activity within Canada, may be subject to a new law providing expansive privacy protections for Canadian citizens. Effective January 1, 2004, such companies will have to comply with Canada’s Personal Information Protection and Electronic Documents Act. The Canadian Privacy Law deserves particular attention because it entails more extensive privacy requirements than are generally applicable under United States law.