SlideShare a Scribd company logo
Personal Data Protection Act 2010:
Employee Data Privacy
Labour Law Conference
9 – 10 April 2015
Adlin Abdul Majid
Content
• Introduction
• Issues & Implications
• Conclusion
2
Introduction
Written / Oral
3
PERSONAL DATA PROTECTION ACT 2010
Application
• Applies to any person who processes or has control over or authorises
processing of personal data in respect of commercial transactions
• Applies if:
• PERSON ESTABLISHED IN MALAYSIA: Personal data is processed,
whether or not in context of that establishment, by that person or
any other person employed or engaged by that establishment
• PERSON NOT ESTABLISHED IN MALAYSIA: Uses equipment in
Malaysia to process personal data (otherwise than for purpose of
transit in Malaysia)
NOT
applicable
• Federal & State Governments
• Personal data processed outside Malaysia, unless intended to be further
processed in Malaysia
Complaints-based system
Application to employment relationships
4
• Any transaction of a commercial nature, whether contractual
or not
• Includes matters relating to:
• Supply or exchange of goods or services;
• Agency;
• Investments;
• Financing;
• Banking; &
• Insurance
• Does not include a credit reporting business
commercial transactions
Draft Guidelines on
Management of Employee Data
7 Principles of data protection
Written / Oral
5
Data Subject
General Principle
Data Processor/
3rd Party
Data User
Security Principle
Retention Principle
Integrity Principle
Notice &
Choice Principle
Disclosure
Principle
Access Principle
Employee
Employer
Service
providers
Content
• Introduction
• Issues & Implications
• Conclusion
6
Issues & Implications
7
Notice
Access
Retention
Consent
Issues & Implications
8
Notice
Access
Retention
Consent
What do you need consent for?
Written / Oral
9
Consent?
Non-sensitive
personal data
Disclosure of
personal data
to third parties
Transfer of
personal data
overseas
Sensitive
personal data
(explicit
consent)
Exemptions to consent
10
No Exemption Example
(a) For the performance of a contract to which
the data subject is a party
Existing bank customers
(b) For the taking of steps at the request of the
data subject with a view to entering into a
contract
Before the sale & purchase of a car, the
information requested by the salesman
in order to execute the contract
(c) For compliance with any legal obligation to
which the data user is the subject, other
than an obligation imposed by a contract
When an organisation is under a duty
pursuant to eg. tax laws, to provide
information of its employees to
authorities
(d) In order to protect the vital interests of the
data subject
In a situation where a person is
unconscious & needs medical
treatment to save his life
(e) For the administration of justice For the enforcement of a court order
(f) For the exercise of any functions conferred
on any person by or under any law
If an organisation is tasked to perform
a service by a law
Written / Oral
11
Explicit consent given by data subject
Processing is necessary
Personal data has been made public
Sensitive personal data may only be processed if…
Example of explicit consent
12
Consent: What does it entail?
Written / Oral
13
PDPA Regulations
DRAFT GUIDELINES ON
CONSENT
• Key test: Ability to
demonstrate that
consent exists /
given
• Data subject must
be fully aware of &
understand consent
• Consent
understood to have
been given when
individuals DO NOT
OBJECT or
volunteer personal
data after purposes
clearly explained
Issues & Implications
14
Notice
Access
Retention
Consent
Notice & choice
Written / Oral
15
• Data user shall provide a WRITTEN NOTICE to the data subject. To
include:
• That personal data of the data subject is being processed by or
on behalf of the data user
• Description of the personal data
• Purpose it is collected & further processed
• Class of 3rd parties to whom data user discloses / may disclose
the personal data
• Whether it is obligatory for the data subject to provide the
personal data
• Must be given as soon as practicable
• In national language & English
• Must be able to keep a record of service of notice
Issues & Implications
16
Notice
Access
Retention
Consent
17
Channels of serving notices to employees
Notice to
employees
Emails
Employment
forms
Employment
contracts
Salary slips
Right to access personal data
18
Right to
access
Full
disclosure
Partial
disclosure
Refuse to
disclose
Must respond within 21 days
When can you refuse to disclose / partially disclose?
Written / Oral
19
No sufficient
information on
identity of requestor
/ data subject
No sufficient
information to locate
personal data
Burden or expense of
providing access
Would disclose
information of
another individual
Another data user
controls personal
data
Violation of court
order
Would disclose
confidential
commercial
information
Access is regulated
by another law
Issues & Implications
20
Notice
Access
Retention
Consent
21
s10 PDPA
Employment
Draft
Guidelines
*Must destroy personal data
once purpose of processing has
lapsed
*Be aware of obligations
imposed by law, such as s61 of
Employment Act 1955
*Fresh consent needed for
future uses
*Should minimise cost by
deleting / anonymise when no
longer necessary
Retention of employee records
Retention of former employees’ data
22
HK
Guidance
Necessary for legal
/ contractual /
statutory obligation
Directly related to
managing the
relationship
between employer
& former employee
Need to defend
organisation in civil or
criminal suit
Consented to by
former
employee
Needed for job
references /
reapplication
Content
• Introduction
• Issues & Implications
• Conclusion
23
Conclusion
24
PRE-EMPLOYMENT
• Receipt of CVs
BEGINNING OF EMPLOYMENT
• Requests for personal data: Non-sensitive personal
data / sensitive personal data
DURING EMPLOYMENT
• Further requests for personal data
• Security / Access / Integrity / Disclosure
END OF EMPLOYMENT
• Retention
Thank you
(aam@lh-ag.com)

More Related Content

What's hot

General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
BCC - Solutions for IBM Collaboration Software
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 
Data Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
Data Protection Indonesia: Basic Regulation and Technical Aspects_ErykData Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
Data Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
Eryk Budi Pratama
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
Naomi Holmes
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
Iain Wicks MCIPR
 
Personal Data Protection in Indonesia
Personal Data Protection in IndonesiaPersonal Data Protection in Indonesia
Personal Data Protection in Indonesia
Eryk Budi Pratama
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
Le GDPR (General Data Protection Regulation) - Diaporama
Le GDPR (General Data Protection Regulation) - DiaporamaLe GDPR (General Data Protection Regulation) - Diaporama
Le GDPR (General Data Protection Regulation) - Diaporama
Jean-Michel Tyszka
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
Caroline Boscher
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theft
Amber Gupta
 
Privacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationPrivacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program Implementation
Eryk Budi Pratama
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
RahulGarg294918
 
GDPR
GDPRGDPR
GDPR
Gopi PD
 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance
TrustArc
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
Acquia
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
Vertex Holdings
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
Russell_Kennedy
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
Martin Hawksey
 
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTIRingkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
Eryk Budi Pratama
 
Basic Data Privacy for Non Lawyers
Basic Data Privacy for Non LawyersBasic Data Privacy for Non Lawyers
Basic Data Privacy for Non Lawyers
JDP Consulting
 

What's hot (20)

General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
Data Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
Data Protection Indonesia: Basic Regulation and Technical Aspects_ErykData Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
Data Protection Indonesia: Basic Regulation and Technical Aspects_Eryk
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Personal Data Protection in Indonesia
Personal Data Protection in IndonesiaPersonal Data Protection in Indonesia
Personal Data Protection in Indonesia
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Le GDPR (General Data Protection Regulation) - Diaporama
Le GDPR (General Data Protection Regulation) - DiaporamaLe GDPR (General Data Protection Regulation) - Diaporama
Le GDPR (General Data Protection Regulation) - Diaporama
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theft
 
Privacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationPrivacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program Implementation
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
 
GDPR
GDPRGDPR
GDPR
 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTIRingkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
Ringkasan Standar Kompetensi Data Protection Officer | Agustus 2023 | IODTI
 
Basic Data Privacy for Non Lawyers
Basic Data Privacy for Non LawyersBasic Data Privacy for Non Lawyers
Basic Data Privacy for Non Lawyers
 

Viewers also liked

Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSoneraOutsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Sonera
 
Complying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideComplying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical Guide
Daniel Li
 
Personal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform AssessmentPersonal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform Assessment
Jean Luc Creppy
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection ActYizi
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
David Erdos
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
- Mark - Fullbright
 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To Know
EamonnORagh
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...
Brian Miller, Solicitor
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2safa
 
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
MongoDB
 
Cyberlaw
CyberlawCyberlaw
Sexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne LeoSexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne Leo
legalPadmin
 
Data Protection Presentation
Data Protection PresentationData Protection Presentation
Data Protection Presentation
IBM Business Insight
 
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cédric Laurant
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)
Benjamin Ang
 
Data Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information SystemData Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information System
Quotient Consulting
 
Ethics and information security 2
Ethics and information security 2Ethics and information security 2
Ethics and information security 2
PT Bank Syariah Mandiri
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet BankingMahyuddin Khalid
 
Hacking and Hacktivism
Hacking and HacktivismHacking and Hacktivism
Hacking and Hacktivism
rashidirazali
 

Viewers also liked (20)

Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSoneraOutsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
 
Complying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideComplying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical Guide
 
Personal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform AssessmentPersonal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform Assessment
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To Know
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2
 
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
 
Cyberlaw
CyberlawCyberlaw
Cyberlaw
 
Sexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne LeoSexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne Leo
 
Data Protection Presentation
Data Protection PresentationData Protection Presentation
Data Protection Presentation
 
Chapter 1
Chapter 1Chapter 1
Chapter 1
 
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)
 
Data Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information SystemData Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information System
 
Ethics and information security 2
Ethics and information security 2Ethics and information security 2
Ethics and information security 2
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet Banking
 
Hacking and Hacktivism
Hacking and HacktivismHacking and Hacktivism
Hacking and Hacktivism
 

Similar to Personal Data Protection Act - Employee Data Privacy

Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
Luke Kyte
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
Harrison Clark Rickerbys
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
TrustArc
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection Bill
Antaraa Vasudev
 
How to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageHow to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive Advantage
Beamery
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
DaviesParker
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
Terry Gorry
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
Post Media
 
Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18
Jon Rathbone
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
Endcode_org
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
Komal Gadia
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
BrightPay Payroll and Auto Enrolment Software
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection Bill
TrustArc
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentationIan Clive Oultram
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
Olivier Vandeputte
 

Similar to Personal Data Protection Act - Employee Data Privacy (20)

Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection Bill
 
How to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageHow to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive Advantage
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 
Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection Bill
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 

More from legalPadmin

Collective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumarCollective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumar
legalPadmin
 
Change Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of EmploymentChange Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of Employment
legalPadmin
 
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
legalPadmin
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
legalPadmin
 
Managing Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparationManaging Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparation
legalPadmin
 
Managing Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparationManaging Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparation
legalPadmin
 
Managing Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid RepercussionsManaging Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid Repercussions
legalPadmin
 
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
legalPadmin
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
legalPadmin
 
Managing Dismissal to Avoid Repercussion
Managing Dismissal to Avoid RepercussionManaging Dismissal to Avoid Repercussion
Managing Dismissal to Avoid Repercussion
legalPadmin
 
Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)
legalPadmin
 
Employment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of EmployersEmployment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of Employers
legalPadmin
 

More from legalPadmin (12)

Collective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumarCollective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumar
 
Change Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of EmploymentChange Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of Employment
 
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
 
Managing Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparationManaging Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparation
 
Managing Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparationManaging Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparation
 
Managing Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid RepercussionsManaging Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid Repercussions
 
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
 
Managing Dismissal to Avoid Repercussion
Managing Dismissal to Avoid RepercussionManaging Dismissal to Avoid Repercussion
Managing Dismissal to Avoid Repercussion
 
Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)
 
Employment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of EmployersEmployment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of Employers
 

Recently uploaded

Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
johncavitthouston
 
The Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptxThe Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptx
nehatalele22st
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
BridgeWest.eu
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
9ib5wiwt
 
new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.
niputusriwidiasih
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
ssuser5750e1
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Gabe Whitley
 
Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...
Finlaw Consultancy Pvt Ltd
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
9ib5wiwt
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
MwaiMapemba
 
VAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act PresentationVAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act Presentation
FernandoSimesBlanco1
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
9ib5wiwt
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
gaelcabigunda
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
9ib5wiwt
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
Abdul-Hakim Shabazz
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
BridgeWest.eu
 
ALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdfALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdf
46adnanshahzad
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
BRELGOSIMAT
 
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
o6ov5dqmf
 
WINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of DissolutionWINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of Dissolution
KHURRAMWALI
 

Recently uploaded (20)

Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
 
The Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptxThe Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptx
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
 
new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.new victimology of indonesian law. Pptx.
new victimology of indonesian law. Pptx.
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
 
Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
 
VAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act PresentationVAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act Presentation
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
 
ALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdfALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdf
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
 
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
 
WINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of DissolutionWINDING UP of COMPANY, Modes of Dissolution
WINDING UP of COMPANY, Modes of Dissolution
 

Personal Data Protection Act - Employee Data Privacy

  • 1. Personal Data Protection Act 2010: Employee Data Privacy Labour Law Conference 9 – 10 April 2015 Adlin Abdul Majid
  • 2. Content • Introduction • Issues & Implications • Conclusion 2
  • 3. Introduction Written / Oral 3 PERSONAL DATA PROTECTION ACT 2010 Application • Applies to any person who processes or has control over or authorises processing of personal data in respect of commercial transactions • Applies if: • PERSON ESTABLISHED IN MALAYSIA: Personal data is processed, whether or not in context of that establishment, by that person or any other person employed or engaged by that establishment • PERSON NOT ESTABLISHED IN MALAYSIA: Uses equipment in Malaysia to process personal data (otherwise than for purpose of transit in Malaysia) NOT applicable • Federal & State Governments • Personal data processed outside Malaysia, unless intended to be further processed in Malaysia Complaints-based system
  • 4. Application to employment relationships 4 • Any transaction of a commercial nature, whether contractual or not • Includes matters relating to: • Supply or exchange of goods or services; • Agency; • Investments; • Financing; • Banking; & • Insurance • Does not include a credit reporting business commercial transactions Draft Guidelines on Management of Employee Data
  • 5. 7 Principles of data protection Written / Oral 5 Data Subject General Principle Data Processor/ 3rd Party Data User Security Principle Retention Principle Integrity Principle Notice & Choice Principle Disclosure Principle Access Principle Employee Employer Service providers
  • 6. Content • Introduction • Issues & Implications • Conclusion 6
  • 9. What do you need consent for? Written / Oral 9 Consent? Non-sensitive personal data Disclosure of personal data to third parties Transfer of personal data overseas Sensitive personal data (explicit consent)
  • 10. Exemptions to consent 10 No Exemption Example (a) For the performance of a contract to which the data subject is a party Existing bank customers (b) For the taking of steps at the request of the data subject with a view to entering into a contract Before the sale & purchase of a car, the information requested by the salesman in order to execute the contract (c) For compliance with any legal obligation to which the data user is the subject, other than an obligation imposed by a contract When an organisation is under a duty pursuant to eg. tax laws, to provide information of its employees to authorities (d) In order to protect the vital interests of the data subject In a situation where a person is unconscious & needs medical treatment to save his life (e) For the administration of justice For the enforcement of a court order (f) For the exercise of any functions conferred on any person by or under any law If an organisation is tasked to perform a service by a law
  • 11. Written / Oral 11 Explicit consent given by data subject Processing is necessary Personal data has been made public Sensitive personal data may only be processed if…
  • 12. Example of explicit consent 12
  • 13. Consent: What does it entail? Written / Oral 13 PDPA Regulations DRAFT GUIDELINES ON CONSENT • Key test: Ability to demonstrate that consent exists / given • Data subject must be fully aware of & understand consent • Consent understood to have been given when individuals DO NOT OBJECT or volunteer personal data after purposes clearly explained
  • 15. Notice & choice Written / Oral 15 • Data user shall provide a WRITTEN NOTICE to the data subject. To include: • That personal data of the data subject is being processed by or on behalf of the data user • Description of the personal data • Purpose it is collected & further processed • Class of 3rd parties to whom data user discloses / may disclose the personal data • Whether it is obligatory for the data subject to provide the personal data • Must be given as soon as practicable • In national language & English • Must be able to keep a record of service of notice
  • 17. 17 Channels of serving notices to employees Notice to employees Emails Employment forms Employment contracts Salary slips
  • 18. Right to access personal data 18 Right to access Full disclosure Partial disclosure Refuse to disclose Must respond within 21 days
  • 19. When can you refuse to disclose / partially disclose? Written / Oral 19 No sufficient information on identity of requestor / data subject No sufficient information to locate personal data Burden or expense of providing access Would disclose information of another individual Another data user controls personal data Violation of court order Would disclose confidential commercial information Access is regulated by another law
  • 21. 21 s10 PDPA Employment Draft Guidelines *Must destroy personal data once purpose of processing has lapsed *Be aware of obligations imposed by law, such as s61 of Employment Act 1955 *Fresh consent needed for future uses *Should minimise cost by deleting / anonymise when no longer necessary Retention of employee records
  • 22. Retention of former employees’ data 22 HK Guidance Necessary for legal / contractual / statutory obligation Directly related to managing the relationship between employer & former employee Need to defend organisation in civil or criminal suit Consented to by former employee Needed for job references / reapplication
  • 23. Content • Introduction • Issues & Implications • Conclusion 23
  • 24. Conclusion 24 PRE-EMPLOYMENT • Receipt of CVs BEGINNING OF EMPLOYMENT • Requests for personal data: Non-sensitive personal data / sensitive personal data DURING EMPLOYMENT • Further requests for personal data • Security / Access / Integrity / Disclosure END OF EMPLOYMENT • Retention