SlideShare a Scribd company logo
1 of 25
Download to read offline
Personal Data Protection Act 2010:
Employee Data Privacy
Labour Law Conference
9 – 10 April 2015
Adlin Abdul Majid
Content
• Introduction
• Issues & Implications
• Conclusion
2
Introduction
Written / Oral
3
PERSONAL DATA PROTECTION ACT 2010
Application
• Applies to any person who processes or has control over or authorises
processing of personal data in respect of commercial transactions
• Applies if:
• PERSON ESTABLISHED IN MALAYSIA: Personal data is processed,
whether or not in context of that establishment, by that person or
any other person employed or engaged by that establishment
• PERSON NOT ESTABLISHED IN MALAYSIA: Uses equipment in
Malaysia to process personal data (otherwise than for purpose of
transit in Malaysia)
NOT
applicable
• Federal & State Governments
• Personal data processed outside Malaysia, unless intended to be further
processed in Malaysia
Complaints-based system
Application to employment relationships
4
• Any transaction of a commercial nature, whether contractual
or not
• Includes matters relating to:
• Supply or exchange of goods or services;
• Agency;
• Investments;
• Financing;
• Banking; &
• Insurance
• Does not include a credit reporting business
commercial transactions
Draft Guidelines on
Management of Employee Data
7 Principles of data protection
Written / Oral
5
Data Subject
General Principle
Data Processor/
3rd Party
Data User
Security Principle
Retention Principle
Integrity Principle
Notice &
Choice Principle
Disclosure
Principle
Access Principle
Employee
Employer
Service
providers
Content
• Introduction
• Issues & Implications
• Conclusion
6
Issues & Implications
7
Notice
Access
Retention
Consent
Issues & Implications
8
Notice
Access
Retention
Consent
What do you need consent for?
Written / Oral
9
Consent?
Non-sensitive
personal data
Disclosure of
personal data
to third parties
Transfer of
personal data
overseas
Sensitive
personal data
(explicit
consent)
Exemptions to consent
10
No Exemption Example
(a) For the performance of a contract to which
the data subject is a party
Existing bank customers
(b) For the taking of steps at the request of the
data subject with a view to entering into a
contract
Before the sale & purchase of a car, the
information requested by the salesman
in order to execute the contract
(c) For compliance with any legal obligation to
which the data user is the subject, other
than an obligation imposed by a contract
When an organisation is under a duty
pursuant to eg. tax laws, to provide
information of its employees to
authorities
(d) In order to protect the vital interests of the
data subject
In a situation where a person is
unconscious & needs medical
treatment to save his life
(e) For the administration of justice For the enforcement of a court order
(f) For the exercise of any functions conferred
on any person by or under any law
If an organisation is tasked to perform
a service by a law
Written / Oral
11
Explicit consent given by data subject
Processing is necessary
Personal data has been made public
Sensitive personal data may only be processed if…
Example of explicit consent
12
Consent: What does it entail?
Written / Oral
13
PDPA Regulations
DRAFT GUIDELINES ON
CONSENT
• Key test: Ability to
demonstrate that
consent exists /
given
• Data subject must
be fully aware of &
understand consent
• Consent
understood to have
been given when
individuals DO NOT
OBJECT or
volunteer personal
data after purposes
clearly explained
Issues & Implications
14
Notice
Access
Retention
Consent
Notice & choice
Written / Oral
15
• Data user shall provide a WRITTEN NOTICE to the data subject. To
include:
• That personal data of the data subject is being processed by or
on behalf of the data user
• Description of the personal data
• Purpose it is collected & further processed
• Class of 3rd parties to whom data user discloses / may disclose
the personal data
• Whether it is obligatory for the data subject to provide the
personal data
• Must be given as soon as practicable
• In national language & English
• Must be able to keep a record of service of notice
Issues & Implications
16
Notice
Access
Retention
Consent
17
Channels of serving notices to employees
Notice to
employees
Emails
Employment
forms
Employment
contracts
Salary slips
Right to access personal data
18
Right to
access
Full
disclosure
Partial
disclosure
Refuse to
disclose
Must respond within 21 days
When can you refuse to disclose / partially disclose?
Written / Oral
19
No sufficient
information on
identity of requestor
/ data subject
No sufficient
information to locate
personal data
Burden or expense of
providing access
Would disclose
information of
another individual
Another data user
controls personal
data
Violation of court
order
Would disclose
confidential
commercial
information
Access is regulated
by another law
Issues & Implications
20
Notice
Access
Retention
Consent
21
s10 PDPA
Employment
Draft
Guidelines
*Must destroy personal data
once purpose of processing has
lapsed
*Be aware of obligations
imposed by law, such as s61 of
Employment Act 1955
*Fresh consent needed for
future uses
*Should minimise cost by
deleting / anonymise when no
longer necessary
Retention of employee records
Retention of former employees’ data
22
HK
Guidance
Necessary for legal
/ contractual /
statutory obligation
Directly related to
managing the
relationship
between employer
& former employee
Need to defend
organisation in civil or
criminal suit
Consented to by
former
employee
Needed for job
references /
reapplication
Content
• Introduction
• Issues & Implications
• Conclusion
23
Conclusion
24
PRE-EMPLOYMENT
• Receipt of CVs
BEGINNING OF EMPLOYMENT
• Requests for personal data: Non-sensitive personal
data / sensitive personal data
DURING EMPLOYMENT
• Further requests for personal data
• Security / Access / Integrity / Disclosure
END OF EMPLOYMENT
• Retention
Thank you
(aam@lh-ag.com)

More Related Content

What's hot

Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018amirhannan
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Benjamin Ang
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsPriyanka Aash
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection ActSaimaRafiq
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance PreparationLawPlus Ltd.
 
Introduction to Data Protection and Information Security
Introduction to Data Protection and Information SecurityIntroduction to Data Protection and Information Security
Introduction to Data Protection and Information SecurityJisc Scotland
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Kimberly Simon MBA
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]TrustArc
 
Protección de Datos Personales
Protección de Datos PersonalesProtección de Datos Personales
Protección de Datos PersonalesDra. Myrna García
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 

What's hot (20)

Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance Preparation
 
Introduction to Data Protection and Information Security
Introduction to Data Protection and Information SecurityIntroduction to Data Protection and Information Security
Introduction to Data Protection and Information Security
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
 
Protección de Datos Personales
Protección de Datos PersonalesProtección de Datos Personales
Protección de Datos Personales
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
Data protection
Data protectionData protection
Data protection
 

Viewers also liked

Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSoneraOutsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSoneraSonera
 
Complying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideComplying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideDaniel Li
 
Personal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform AssessmentPersonal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform AssessmentJean Luc Creppy
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection ActYizi
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionDavid Erdos
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk- Mark - Fullbright
 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To KnowEamonnORagh
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...Brian Miller, Solicitor
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2safa
 
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...MongoDB
 
Sexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne LeoSexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne LeolegalPadmin
 
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cédric Laurant
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Russell_Kennedy
 
Data Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information SystemData Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information SystemQuotient Consulting
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet BankingMahyuddin Khalid
 
Hacking and Hacktivism
Hacking and HacktivismHacking and Hacktivism
Hacking and Hacktivismrashidirazali
 

Viewers also liked (20)

Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSoneraOutsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
 
Complying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideComplying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical Guide
 
Personal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform AssessmentPersonal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform Assessment
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To Know
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2
 
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
 
Cyberlaw
CyberlawCyberlaw
Cyberlaw
 
Sexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne LeoSexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne Leo
 
Data Protection Presentation
Data Protection PresentationData Protection Presentation
Data Protection Presentation
 
Chapter 1
Chapter 1Chapter 1
Chapter 1
 
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
Data Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information SystemData Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information System
 
Ethics and information security 2
Ethics and information security 2Ethics and information security 2
Ethics and information security 2
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet Banking
 
Hacking and Hacktivism
Hacking and HacktivismHacking and Hacktivism
Hacking and Hacktivism
 

Similar to Personal Data Protection Act - Employee Data Privacy

Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR PresentationLuke Kyte
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementTrustArc
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillAntaraa Vasudev
 
How to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageHow to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageBeamery
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfDaviesParker
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowTerry Gorry
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsPost Media
 
Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Jon Rathbone
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationEndcode_org
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill Komal Gadia
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillTrustArc
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentationIan Clive Oultram
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 

Similar to Personal Data Protection Act - Employee Data Privacy (20)

Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection Bill
 
How to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageHow to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive Advantage
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 
Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection Bill
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 

More from legalPadmin

Collective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumarCollective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumarlegalPadmin
 
Change Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of EmploymentChange Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of EmploymentlegalPadmin
 
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...legalPadmin
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationlegalPadmin
 
Managing Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparationManaging Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparationlegalPadmin
 
Managing Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparationManaging Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparationlegalPadmin
 
Managing Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid RepercussionsManaging Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid RepercussionslegalPadmin
 
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...legalPadmin
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationlegalPadmin
 
Managing Dismissal to Avoid Repercussion
Managing Dismissal to Avoid RepercussionManaging Dismissal to Avoid Repercussion
Managing Dismissal to Avoid RepercussionlegalPadmin
 
Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)legalPadmin
 
Employment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of EmployersEmployment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of EmployerslegalPadmin
 

More from legalPadmin (12)

Collective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumarCollective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumar
 
Change Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of EmploymentChange Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of Employment
 
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
 
Managing Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparationManaging Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparation
 
Managing Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparationManaging Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparation
 
Managing Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid RepercussionsManaging Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid Repercussions
 
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
 
Managing Dismissal to Avoid Repercussion
Managing Dismissal to Avoid RepercussionManaging Dismissal to Avoid Repercussion
Managing Dismissal to Avoid Repercussion
 
Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)
 
Employment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of EmployersEmployment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of Employers
 

Recently uploaded

如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书SD DS
 
SecuritiesContracts(Regulation)Act,1956.pdf
SecuritiesContracts(Regulation)Act,1956.pdfSecuritiesContracts(Regulation)Act,1956.pdf
SecuritiesContracts(Regulation)Act,1956.pdfDrNiteshSaraswat
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiBlayneRush1
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSDr. Oliver Massmann
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...shubhuc963
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书SD DS
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书SD DS
 
Difference between LLP, Partnership, and Company
Difference between LLP, Partnership, and CompanyDifference between LLP, Partnership, and Company
Difference between LLP, Partnership, and Companyaneesashraf6
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书srst S
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxsrikarna235
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书FS LS
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书SD DS
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptxAn Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptxKUHANARASARATNAM1
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A HistoryJohn Hustaix
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesHome Tax Saver
 

Recently uploaded (20)

如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
 
SecuritiesContracts(Regulation)Act,1956.pdf
SecuritiesContracts(Regulation)Act,1956.pdfSecuritiesContracts(Regulation)Act,1956.pdf
SecuritiesContracts(Regulation)Act,1956.pdf
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
 
Difference between LLP, Partnership, and Company
Difference between LLP, Partnership, and CompanyDifference between LLP, Partnership, and Company
Difference between LLP, Partnership, and Company
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptx
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptxAn Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A History
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax Rates
 

Personal Data Protection Act - Employee Data Privacy

  • 1. Personal Data Protection Act 2010: Employee Data Privacy Labour Law Conference 9 – 10 April 2015 Adlin Abdul Majid
  • 2. Content • Introduction • Issues & Implications • Conclusion 2
  • 3. Introduction Written / Oral 3 PERSONAL DATA PROTECTION ACT 2010 Application • Applies to any person who processes or has control over or authorises processing of personal data in respect of commercial transactions • Applies if: • PERSON ESTABLISHED IN MALAYSIA: Personal data is processed, whether or not in context of that establishment, by that person or any other person employed or engaged by that establishment • PERSON NOT ESTABLISHED IN MALAYSIA: Uses equipment in Malaysia to process personal data (otherwise than for purpose of transit in Malaysia) NOT applicable • Federal & State Governments • Personal data processed outside Malaysia, unless intended to be further processed in Malaysia Complaints-based system
  • 4. Application to employment relationships 4 • Any transaction of a commercial nature, whether contractual or not • Includes matters relating to: • Supply or exchange of goods or services; • Agency; • Investments; • Financing; • Banking; & • Insurance • Does not include a credit reporting business commercial transactions Draft Guidelines on Management of Employee Data
  • 5. 7 Principles of data protection Written / Oral 5 Data Subject General Principle Data Processor/ 3rd Party Data User Security Principle Retention Principle Integrity Principle Notice & Choice Principle Disclosure Principle Access Principle Employee Employer Service providers
  • 6. Content • Introduction • Issues & Implications • Conclusion 6
  • 9. What do you need consent for? Written / Oral 9 Consent? Non-sensitive personal data Disclosure of personal data to third parties Transfer of personal data overseas Sensitive personal data (explicit consent)
  • 10. Exemptions to consent 10 No Exemption Example (a) For the performance of a contract to which the data subject is a party Existing bank customers (b) For the taking of steps at the request of the data subject with a view to entering into a contract Before the sale & purchase of a car, the information requested by the salesman in order to execute the contract (c) For compliance with any legal obligation to which the data user is the subject, other than an obligation imposed by a contract When an organisation is under a duty pursuant to eg. tax laws, to provide information of its employees to authorities (d) In order to protect the vital interests of the data subject In a situation where a person is unconscious & needs medical treatment to save his life (e) For the administration of justice For the enforcement of a court order (f) For the exercise of any functions conferred on any person by or under any law If an organisation is tasked to perform a service by a law
  • 11. Written / Oral 11 Explicit consent given by data subject Processing is necessary Personal data has been made public Sensitive personal data may only be processed if…
  • 12. Example of explicit consent 12
  • 13. Consent: What does it entail? Written / Oral 13 PDPA Regulations DRAFT GUIDELINES ON CONSENT • Key test: Ability to demonstrate that consent exists / given • Data subject must be fully aware of & understand consent • Consent understood to have been given when individuals DO NOT OBJECT or volunteer personal data after purposes clearly explained
  • 15. Notice & choice Written / Oral 15 • Data user shall provide a WRITTEN NOTICE to the data subject. To include: • That personal data of the data subject is being processed by or on behalf of the data user • Description of the personal data • Purpose it is collected & further processed • Class of 3rd parties to whom data user discloses / may disclose the personal data • Whether it is obligatory for the data subject to provide the personal data • Must be given as soon as practicable • In national language & English • Must be able to keep a record of service of notice
  • 17. 17 Channels of serving notices to employees Notice to employees Emails Employment forms Employment contracts Salary slips
  • 18. Right to access personal data 18 Right to access Full disclosure Partial disclosure Refuse to disclose Must respond within 21 days
  • 19. When can you refuse to disclose / partially disclose? Written / Oral 19 No sufficient information on identity of requestor / data subject No sufficient information to locate personal data Burden or expense of providing access Would disclose information of another individual Another data user controls personal data Violation of court order Would disclose confidential commercial information Access is regulated by another law
  • 21. 21 s10 PDPA Employment Draft Guidelines *Must destroy personal data once purpose of processing has lapsed *Be aware of obligations imposed by law, such as s61 of Employment Act 1955 *Fresh consent needed for future uses *Should minimise cost by deleting / anonymise when no longer necessary Retention of employee records
  • 22. Retention of former employees’ data 22 HK Guidance Necessary for legal / contractual / statutory obligation Directly related to managing the relationship between employer & former employee Need to defend organisation in civil or criminal suit Consented to by former employee Needed for job references / reapplication
  • 23. Content • Introduction • Issues & Implications • Conclusion 23
  • 24. Conclusion 24 PRE-EMPLOYMENT • Receipt of CVs BEGINNING OF EMPLOYMENT • Requests for personal data: Non-sensitive personal data / sensitive personal data DURING EMPLOYMENT • Further requests for personal data • Security / Access / Integrity / Disclosure END OF EMPLOYMENT • Retention